The analyzer reads public Bluesky data. Connecting an account lets the service store and manage the data described below. Technical connection data is also processed to deliver and protect the service.
Using the analyzer without an account
The service is operated from Italy. Its production server is hosted by Hetzner in Germany. Other providers described in this policy may process data elsewhere.
When you analyze a handle we call Bluesky’s public API and cache the result for 24 hours, so the page loads instantly for the next visitor and so a second look costs the network nothing. That cache contains only public profile data, handle, display name, avatar, follower counts, for the account that was analyzed. The “run it again” link on a cached result goes round that cache and asks Bluesky afresh. We do not store your IP address alongside it, and we do not build a profile of you.
Rate limiting keeps a short-lived, in-memory count of requests per IP address. It is never written to disk and disappears when the process restarts.
Connecting a Bluesky account
If you sign in and connect an account, we store:
- Your identity on the network, your DID and handle.
- An access credential. A revocable OAuth token, issued when you approve access on Bluesky. It is the only way to connect a new account, and you can withdraw it from your Bluesky settings at any time. Accounts connected before that was true still work on the app password they were connected with, held the same way and deleted by the same button. The token, its refresh token and the key that signs our requests are all encrypted at rest with AES-256-GCM.
- A cached copy of your follow graph, who you follow, who follows you, and the public profile fields the network publishes about them: handle, display name, avatar, bio, follower and post counts, whether Bluesky reports them as verified, the languages their recent posts are tagged with, and when they last posted. Plus when you followed them, and a record of the moments people followed you or stopped following you, which is what the “unfollowed you” list is built from. That record is kept for at least six months and then deleted; on the top plan, which offers the full history, it is kept for as long as the account is connected. Disconnecting deletes it either way.
- Posts, replies and reposts you read, their metadata and the record of deletions, plus protected accounts, saved searches and temporary search results.
- Your action log, the follows and unfollows you ran through the tool. It is what enforces the rate budget and what makes undoing a run possible; it is not shown as a feed anywhere in the app.
- A session cookie (
__Host-bh_session), HttpOnly and Secure, so you stay signed in. It is not used for tracking and is not shared with anyone.
Disconnecting removes the account credential and associated data from the active database. It does not immediately erase existing backups, separate feedback messages or a Paddle subscription. Account deletion also removes your user account and sessions. You can revoke access in Bluesky settings.
Feedback
The feedback box inside the app stores what you wrote, the language the app was in, and the browser string your request carried. If you fill in the optional email field, that address is stored with the message, and it is used for one thing: answering you. It is not added to any list, and leaving it empty is a supported way to write to us.
Feedback is kept until it has been dealt with. Ask at the address below and it will be deleted sooner.
Payments
If you subscribe, the payment is handled by Paddle.com Market Ltd, who are the merchant of record: the checkout is theirs, the card details go to them and never to us, and they are the ones who charge the tax owed where you are. What they collect to do that, which is your email address, your country and the card itself, is held under their privacy policy, at paddle.com/legal/privacy.
What this service stores about a subscription is the identifier Paddle gives the customer, the identifier of the subscription, which plan it is for, whether it is active, and the dates it runs between. That is what the account screen reads to tell you what you have, and it is what decides which ceilings apply. There is no card number, no billing address and no tax number in this database.
Deleting your account removes that record along with everything else. It does not cancel a subscription, which only Paddle can do, so cancel first or write to us and we will make sure it is stopped.
Advertising
The public pages and the free plan show ads served by Google AdSense; it is part of what pays for the service, and Pro and Max disable ads inside the app. Google may use cookies or similar technologies to serve and measure ads. If you are in the EEA, the UK or Switzerland you will be asked for consent through a Google-certified consent platform before any personalised advertising cookie is set, and you can change or withdraw that choice at any time from the link in the footer of the consent notice. Ad delivery depends on the applicable consent choices and Google’s eligibility rules; rejecting personalisation does not guarantee that an ad will be served.
Google’s own explanation of how it uses data from partner sites is at policies.google.com/technologies/partner-sites.
Analytics
We use Google Analytics 4 to count visits and see which pages people actually read. It runs on the public pages and inside the app. We look at it to decide what to build and what to write; we do not use it to build a profile of you, and we do not join it to your connected Bluesky account.
Concretely: the address of an analysis page carries the handle you are looking at, and that handle is not reported. Google is given the analyser page without it, and the page is set so the full address does not travel in the Referer header to the other services it loads either.
Analytics storage starts denied. With the current configuration, the tag can send cookieless requests before consent, so connection data including your IP address can reach Google. Google’s applicable privacy information describes its processing and international transfers. Cookie storage is subject to your consent choices.
You can opt out for every site with Google’s browser add-on, or refuse consent in the notice.
What we do not do
- No sale or rental of your data. The providers described above process data to deliver their services.
- No posting, replying or messaging on your behalf.
- No advertising or analytics profile that follows you from here to other websites.
- No access to anything the AT Protocol does not expose publicly or that you did not explicitly authorise.
Legal basis and your rights
If you are in the EU/EEA: we process connected-account data to perform the service you asked for (Art. 6(1)(b) GDPR) and advertising data on the basis of your consent (Art. 6(1)(a)). You can access, correct, export or delete your data, use the account controls for deletion from the active service. Backups and separately submitted feedback are described above. For anything else, write to the contact address below.
You may also request restriction or object where applicable, withdraw consent and complain to your competent data protection authority. Personal-data rights do not depend on a paid plan.
Retention
- Public analysis cache: served for 24 hours, deleted within 48.
- Connected account data: until you disconnect or delete the account.
- Who followed you and who stopped: at least six months, then deleted, whether or not you are still connected. On the plan that offers the full history it is kept while the account is connected, and goes with it when you disconnect.
- Feedback: until it has been dealt with, or sooner on request.
- Backups: up to 14 rolling snapshots, replaced as new snapshots are made.
Contact
Questions, or a data request: webmaster@pudgycat.io.
This policy may change as the product grows; the date at the top always reflects the current version.