Privacy Policy
Last updated: August 14, 2026
1. Information collected
Project XORA may store your Discord account identifier, Discord username and avatar, linked Roblox username and User ID, internal account ID, purchases, product licenses, gift redemptions, support messages, bug reports, newsletter signup, and staff actions.
Payment-card details are entered directly on Stripe. Project XORA does not receive or store your full card number, CVC, or online-banking password.
2. Authentication
The website creates a short-lived, one-time code. You complete the pairing through the official Discord bot using /login after linking a Roblox username with /link. The bot supplies your Discord account ID to the pairing record. Project XORA never receives your Discord or Roblox password.
3. How information is used
- Attach model purchases and gifts to your XORA library.
- Generate protected downloads and ownership certificates.
- Deliver receipts and product files.
- Answer support and investigate bug reports.
- Prevent fraud, duplicate redemption, leaking, and account abuse.
- Operate privacy-friendly aggregate site analytics.
4. Analytics
The website records page path, a shortened hash of the browser user-agent, sanitized referrer origin/path, event type, and timestamp. Query strings, download tokens, gift codes, IP addresses, and full user-agent strings are not stored in analytics records.
5. Service providers
Project XORA may use Railway for hosting and databases, Redis for security limits/cache, Stripe for payments, Discord for bot-based account pairing, SMTP for email, and private R2/S3-compatible storage for delivery. Those providers process data under their own privacy terms.
6. Security and retention
Reasonable technical controls are used, including HTTPS-only production cookies, signed sessions, strict browser-security headers, rate limits, private file storage, expiring links, and role-protected staff tools. No service can promise absolute security.
Purchase and anti-fraud records may be retained as needed for accounting, license enforcement, chargebacks, and legal obligations. Support, bug, and mailing records may be removed when no longer needed.
7. Your choices
You may log out, request correction of account information, ask to unsubscribe from email updates, or request eligible data deletion by emailing support@projectxora.com. Some purchase, fraud, tax, and license records may need to be retained.
8. Children
If you are not old enough to make online purchases or accept these terms in your location, use Project XORA only with a parent or guardian.
9. Contact
Privacy questions: support@projectxora.com.