Privacy Policy

Last updated: October 7, 2026

Stumble-Bot (stumble-bot.com) is operated by BOT-HOLDINGS, LLC, doing business as codedatda.casa ("BOT-HOLDINGS", "we", "us"), based in Las Vegas, Nevada, United States. We are the data controller for the personal data described here. Questions and requests go to [email protected].

This policy covers the Stumble-Bot website and its API, including use through the companion mobile apps when they are released.

What the service is

Stumble-Bot is a web discovery service: you choose interests and we show you one web page at a time drawn from those interests. It is invite-only. It uses no artificial-intelligence or machine-learning profiling; what you see is selected with simple arithmetic from your own picks and your own ratings, as described on the crawler page.

What we collect

We set no advertising or tracking cookies, and we do not sell, rent or share personal data for advertising. Cloudflare, which fronts our server, injects its cookieless Web Analytics beacon into pages; it reports aggregate page-performance metrics (page URL, timing, country, browser family) to Cloudflare under its privacy policy and sets no cookie and no identifier. Your browser's local storage is not used for anything beyond the session cookie.

Third-party websites you are shown

The point of the service is to show you other people's websites. When a page is shown inside the Stumble-Bot bar, your browser loads it directly from that site, exactly as if you had opened it yourself: that site sees your IP address, may set its own cookies and runs its own scripts, under its own privacy policy. We instruct your browser to send no referrer, so the site is not told that you arrived from Stumble-Bot. Preview images (for example YouTube and Flickr thumbnails) are likewise loaded by your browser from those services. Video embeds use YouTube's privacy-enhanced domain (youtube-nocookie.com) and Vimeo's do-not-track mode.

How we use data

To run the service you asked for (choosing pages from your interests and ratings, keeping your likes and lists), to keep accounts secure, to enforce the invite system and the terms, and to fix problems. Our legal bases, where the GDPR or UK GDPR applies, are performance of our contract with you and our legitimate interest in keeping the service secure and working.

Processors and infrastructure

WhoRoleWhere
Our own serversApplication hosting and the page index, on hardware we operateUnited States
Cloudflare, Inc.DNS, TLS termination, tunnel and edge protection in front of our server; sees your IP address and requests in transit; cookieless Web Analytics beaconUnited States / global network

Our team also administers our sites and services from Hong Kong, and working copies of some production data may be kept on our administrators' workstations there, protected by the same access controls.

Retention

Your rights

You can see and change your interests, likes, lists and notes in the service itself. You can ask us at any time to access, correct, export or delete your personal data, or to object to or restrict its processing, by emailing [email protected]; we answer within 30 days. If you are in the EEA, the UK or Switzerland you may also complain to your local data-protection authority. California residents have the rights described in the CCPA; we do not sell personal information and we do not discriminate against anyone who exercises their rights.

Children

You must be at least 18, or the age of majority where you live, to create an account. Stumble-Bot is not directed to children and we do not knowingly collect personal data from anyone under 13 (or under 16 in the EU). If you believe a minor has an account, tell us and we will remove it.

Security

All traffic is encrypted with HTTPS and HSTS. Passwords are hashed with scrypt. Session cookies are HttpOnly, Secure and SameSite. Login and signup are rate-limited. The service runs with least-privilege credentials on our own hardware behind Cloudflare, and the indexer can only fetch public internet addresses. No system is perfectly secure; if you discover a vulnerability, please see security.txt.

Changes

When this policy changes we update the date at the top and, for material changes, tell members in the service.