Privacy Policy
- We collect the minimum needed to run your account — email, a hashed password, and your IP for abuse checks. That’s it.
- We never see your payment card. It goes straight to the payment processor.
- No advertising trackers. No third-party analytics beyond Cloudflare’s built-in access logs.
- We don’t sell your data. Ever. To anyone.
- You can access, export, correct, or delete your data any time by emailing us through /contact/.
This policy explains what data we collect, why we collect it, who we share it with, and how you control it. It’s written in plain English on purpose. If anything is unclear, ask us and we’ll rewrite the section — that’s a genuine offer.
What we collect and why
Account data. When you register through /signup/ we collect your email address and a password. The password is stored as a one-way hash — not the password itself, not something we can reverse into the password. Even we can’t read it. We also store an email-verification status so we know the address is real and belongs to you.
Usage data. When you sign up or log in, we log the IP address the request came from and a rough timestamp. This is used for one thing: catching abuse — credential stuffing, mass fake signups, chargeback fraud, and shared-account cheating on our licensing. We keep these logs short and don’t build any profile from them.
Order data. If you buy a licence we store which product you bought, the tier (1-day, 7-day, or 30-day), the price paid, the date, and the licence key we issued you. This is so your account area can show your history and so we can honour support and refunds.
What we don’t collect
We’re listing these out because a lot of sites bury it. We do not collect:
- Your real name, home address, or phone number — we never ask for them.
- Your payment card number, CVV, or bank details — those go straight to the payment processor and never touch our servers.
- Any data from inside the game. The loader does not read your Steam library, your friends list, your chat, your voice, your gameplay, or anything else on your machine that isn’t needed to load the menu into the target process.
- Location data beyond what an IP address reveals (roughly city-level, used only for abuse detection).
- Advertising identifiers, browser fingerprints, or cross-site tracking data.
Who we share it with
Three third parties, and only these three:
- Brevo — handles our transactional email. When you verify your email or receive a receipt, Brevo sends it. They see your email address and the content of that message. They don’t use it for their own marketing.
- Our payment processor — handles the actual card or crypto transaction at checkout. They see whatever is needed to complete the payment (name on card, card number, billing country) directly from you. We only receive back a confirmation that the payment succeeded and a reference ID.
- Cloudflare — hosts the site and sits in front of it as a security layer. They see request-level data (IP, URL, user agent) as part of standard access logging and DDoS protection.
We don’t share data with anyone else. No affiliates, no data brokers, no ad networks, no analytics companies.
Cookies
We use the bare minimum: a session cookie so you stay logged in, and a CSRF cookie so forms can’t be submitted from other sites on your behalf. Cloudflare may set its own security cookie to distinguish real visitors from bots. That’s the entire cookie list. No advertising cookies, no tracking pixels, no third-party analytics cookies.
Data retention
Your account data stays on our servers while your account is active. If you close your account, we keep the record for six months in case you come back or dispute a charge, then it’s deleted. Order records tied to a payment may be kept longer where tax or fraud-prevention law requires it — usually seven years for the transaction record itself, stripped of anything not legally required.
Abuse logs (IP addresses tied to signup and login events) are kept for 90 days, then rotated out.
Your rights
Whether or not you’re in the EU or UK, we honour the same set of rights for everyone:
- Access — ask for a copy of everything we hold on you.
- Export — get that copy in a portable format (usually JSON or CSV).
- Correct — tell us if something’s wrong and we’ll fix it.
- Delete — ask us to erase your account and associated data.
- Object — tell us to stop processing your data for a specific purpose.
To use any of these, email us through /contact/ from the address on your account. We reply within 30 days — usually much faster. If you’re in the EU or UK and think we’ve mishandled your data, you also have the right to complain to your national data protection authority.
Security
Honest picture, not marketing:
- Passwords are hashed with a modern algorithm (bcrypt-family, per-user salt). We can’t read them and neither can an attacker who somehow gets the database.
- All traffic to the site is TLS-encrypted. There is no non-HTTPS version.
- We keep the attack surface small on purpose — no third-party trackers, no unnecessary plugins, no unused admin panels exposed to the internet.
- The stack sits behind Cloudflare, which absorbs most automated attack traffic before it reaches us.
No system is unbreakable. If we ever have a breach that affects your data, we’ll tell you by email within 72 hours of confirming it, and we’ll tell you what happened and what to do — not spin it.
Changes to this policy
The effective date at the top of this page is the version you’re looking at. If we make a material change — new data collected, new third party added, changed retention — we’ll email every active account before it takes effect. Minor wording fixes we’ll just update in place.
Contact
Any privacy question — a data request, a concern, or just wanting something in this policy explained — reach us through /contact/. A real person reads that inbox.
