We collect what the site needs to work and nothing else. We do not sell your data, we do not run advertising trackers, and there is no analytics script watching you.
1. What we collect
When you make an account
- Handle and display name — public
- Email address — private, and the only way to recover your account
- Password — stored as a bcrypt hash. We cannot read it, and neither can anyone who steals the database.
- Avatar and bio, if you add them — public
When you use the site
- Posts, replies, reactions, and anything else you share
- Private messages — see section 3 on who can read these
- Groups you join and members you follow
- IP address — kept short-term for rate limiting and to spot abuse
- Last seen timestamp, so the site can show who is around
When you buy something
- Order records, what you bought, and what you paid
- Licence keys issued to you
- Download records — which file, when
- Name and address only if something physical needs posting
We never see or store card numbers. Payments go through Patreon, or are taken directly, off this site.
When you run one of our scripts
Licensed scripts check in with us to confirm the licence is valid. That check sends:
- Your licence key
- A hash of your server's licence key — never the key itself. We can tell one server from another; we cannot read your server key.
- Your server's public name and IP address
- Which of our resources is running, and its version
This is how we tell a paying customer's server from a copy. It does not read player data, files, or anything else on your server.
2. Why we collect it
- To run the site — you cannot have an account without an account record
- To let you back in — email is the only recovery route
- To deliver what you paid for — orders, licences, downloads
- To keep it safe — rate limits, abuse detection, admin audit logs
- To contact you about your account or an order
3. Who can see what
| Data | Who sees it |
|---|---|
| Handle, display name, avatar, bio, posts | Everyone |
| Email address | You and staff |
| Private group content | Group members and staff |
| Direct messages | You, the person you messaged, and staff |
| Orders, licences, downloads | You and staff |
| IP addresses, audit logs | Staff only |
Be straight with yourself about Messages: private messages are private from other members, not from us. They sit in our database and staff can read them. We do not go looking, but we can. Do not send anything through this site you would not want an administrator to see.
4. Dark Knight Security — data about YOUR players
This section only applies if you buy our security monitoring. If you do not, none of it happens.
The watch service works by your server telling us about connections it considers suspicious. That means we end up holding data about people who are not our customers — your players and whoever is attacking you. We take that seriously.
What your server sends us
- IP address of the connection
- What was attempted — a short label like "event spam" or "auth bruteforce", and how serious it looked
- Which resource was involved
- A hashed player identifier, if there was one
What it does not send
- No raw player identifiers. Licence, Steam and Discord IDs are hashed on the way in, salted per server. We can tell that the same player came back; we cannot tell you who they are, and neither can anyone who steals our database.
- No chat, no positions, no gameplay, no server files.
Third-party lookups
To show country and whether an address looks like a VPN, we send the IP address only to an IP intelligence provider (currently ip-api.com). No other data goes with it. Answers are cached for 30 days so the same address is not looked up repeatedly.
How long we keep it
- Low-severity events: 30 days
- Everything else: 180 days
- The per-address summary stays while the watch is active
Your obligations, plainly
If you run this on your server, you are responsible for telling your players that connection data is monitored. We are processing it on your behalf. Stop the watch and we stop receiving anything; ask us and we will delete what we hold for your server.
5. Third parties who touch your data
These are the only ones. If that changes, this page changes.
- Patreon — if you link your account, we receive your Patreon ID, email, and pledge tier. Patreon handles the payment; we never see the card.
- Groq — Morticia's replies are generated by an AI model hosted by Groq. What you type to her leaves our server and is sent to them to produce a reply. Do not send her anything sensitive. She is an assistant, not a confessional.
- Our email host — sends account and order email.
- ip-api.com — only if you buy the security watch. Receives an IP address and nothing else, to return a country and a VPN guess. See section 4.
- Our web host — stores the database and files.
We do not use Google Analytics, Facebook pixels, advertising networks, or any third-party tracker.
6. Cookies
One cookie: your login session. It is marked HttpOnly and Secure, which means scripts cannot read it and it only travels over HTTPS. There are no advertising or tracking cookies, which is why there is no cookie banner nagging you.
7. How long we keep it
- Account data — until you ask us to delete it
- Orders and licences — seven years, because tax law says so
- IP and rate-limit records — days
- Licence check logs — 90 days
- Admin audit log — kept, so there is a record of who did what
8. Your rights
Under Canadian privacy law (PIPEDA), you can:
- See what we hold about you
- Correct anything wrong
- Have it deleted — see below
- Withdraw consent and close your account
- Complain to the Office of the Privacy Commissioner of Canada if we get it wrong
Ask and we will action it within 30 days, usually much sooner.
What deletion actually means
We will remove your account, profile, drops, and messages. Being honest about the limits:
- Order and licence records stay — we are legally required to keep them for tax purposes. They are separated from your profile, but they exist.
- Content other people have quoted or replied to may leave a gap rather than vanish entirely.
- Backups roll off on their own schedule; deletion is not instant in every copy.
9. Security
- Passwords are bcrypt-hashed. A database leak does not expose them.
- The whole site runs over HTTPS.
- Credentials and API keys are stored outside the web root and encrypted at rest.
- Uploaded images are re-encoded, which destroys anything hidden inside them.
- Every write is CSRF-protected and every database query is parameterised.
No system is perfect. If we ever suffer a breach affecting your data, we will tell you and the Privacy Commissioner, promptly and plainly.
10. Children
This site is not for under-13s. If we find an account belonging to one, we delete it.
11. Changes
If we change this policy in a way that matters, we will say so on the site rather than quietly editing the page.