Privacy Policy

Last updated: March 25, 2026

1. Introduction

Auxvyn ("we", "us", "our") operates the auxvyn.com website and related services. This Privacy Policy explains how we collect, use, and protect your information when you use our platform.

2. Information We Collect

Account Information: When you sign up, we collect your email address and authentication data through our authentication provider (Clerk). If you link your Roblox account, we store your Roblox username and user ID.

Game Data: Data you store through the Auxvyn API (player data, game settings, etc.) is stored in our database. This data belongs to you.

Usage Data: We collect information about how you use the Service, including API call counts, storage usage, and feature usage for analytics and rate limiting purposes.

Technical Data: We collect IP addresses and browser fingerprints for security purposes, including fraud prevention, abuse detection, and enforcement of account restrictions. This data is used solely for platform security and is not shared with third parties.

3. How We Use Your Information

We use collected information to:

  • Provide and maintain the Service
  • Authenticate your identity and manage your account
  • Process payments for Pro subscriptions
  • Enforce our Terms of Service and prevent abuse
  • Detect and prevent fraudulent or unauthorized access
  • Send important service-related communications
  • Improve the Service based on usage patterns

4. Data Storage and Security

Your data is stored securely using Supabase with row-level security (RLS) policies. API keys are hashed using SHA-256 before storage — we never store your raw API keys. Sensitive data like Roblox Open Cloud keys are encrypted with AES-256-GCM.

Security-related data (IP addresses, browser fingerprints) is stored in access-restricted tables that cannot be queried by regular users. Only authorized staff can access this data for moderation purposes.

5. Data Sharing

We do not sell, rent, or share your personal information with third parties except in the following circumstances:

  • Service Providers: We use third-party services for authentication (Clerk), database hosting (Supabase), and hosting (Vercel). These providers only process data as necessary to provide their services.
  • Legal Requirements: We may disclose information if required by law or in response to valid legal processes.
  • Workspace Members: If you share a workspace with other users, they can see the game data within that workspace according to their assigned permissions.

6. Browser Fingerprinting

We collect browser fingerprints (derived from your browser's canvas rendering, screen resolution, timezone, and hardware information) for security purposes only. This data is hashed and used to:

  • Prevent banned users from creating new accounts
  • Detect suspicious login patterns
  • Protect against automated abuse

Browser fingerprints are not used for advertising, tracking across websites, or any purpose other than platform security.

7. Cookies

We use essential cookies for authentication and session management. We do not use advertising or tracking cookies. Our authentication provider (Clerk) may set cookies necessary for login functionality.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Export your game data through the API
  • Revoke API keys at any time through the dashboard

To exercise these rights, contact us through the Support page.

9. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

Game data stored through the API may contain Roblox user IDs of players of any age. This data is controlled by the game developer (our user) and is subject to Roblox's own privacy policies.

10. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data and game data within 30 days. Security logs (IP addresses, fingerprints) may be retained for up to 90 days after account deletion for fraud prevention.

11. Changes to This Policy

We may update this Privacy Policy at any time. We will notify you of material changes through the dashboard or via email. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact

If you have questions about this Privacy Policy or how we handle your data, contact us through the Support page.