← Back to home

Privacy Policy

Last updated: August 15, 2026

1. Information collected

Project XORA may store your Discord account identifier, Discord username and avatar, linked Roblox username and User ID, internal account ID, purchases, product licenses, gift redemptions, support messages, bug reports, newsletter signup, Community Creation submissions and moderation state, synchronized official-server role state, and staff actions.

Payment-card details are entered directly on Stripe. Project XORA does not receive or store your full card number, CVC, or online-banking password.

2. Authentication

The website creates a short-lived, one-time code protected by a keyed hash. You complete pairing through the official Discord bot using /login after /link verifies a one-time proof in the exact Roblox profile About section. The proof is bound to your XORA, Discord, and Roblox identities; plaintext is shown once and is not stored. The bot supplies your Discord account ID to the pairing record. Project XORA never receives your Discord or Roblox password, browser cookie, or account security code.

3. How information is used

4. Analytics

The website records page path, a shortened hash of the browser user-agent, sanitized referrer origin/path, event type, and timestamp. Query strings, download tokens, gift codes, IP addresses, and full user-agent strings are not stored in analytics records.

5. Service providers

Project XORA may use Railway for hosting and databases, Redis for security limits/cache, Stripe for payments, Discord for bot-based account pairing, SMTP for email, and private R2/S3-compatible storage for delivery. Those providers process data under their own privacy terms.

6. Security and retention

Reasonable technical controls are used, including HTTPS-only production cookies, signed sessions, strict browser-security headers, rate limits, private file storage, expiring links, and role-protected staff tools. No service can promise absolute security.

Purchase and anti-fraud records may be retained as needed for accounting, license enforcement, chargebacks, and legal obligations. Support, bug, and mailing records may be removed when no longer needed.

7. Your choices

You may log out, request correction of account information, ask to unsubscribe from email updates, or request eligible data deletion by emailing support@projectxora.com. You can permanently delete your own Community Creation submission from the Creations page. Some purchase, fraud, tax, moderation-audit, and license records may need to be retained.

8. Children

If you are not old enough to make online purchases or accept these terms in your location, use Project XORA only with a parent or guardian.

9. Contact

Privacy questions: support@projectxora.com.