1. Scope and roles
NovaAC is an independent FiveM anti-cheat software project. This Privacy Policy applies to NovaAC websites, dashboard, checkout, support systems, Discord integrations, hosted APIs, WebSocket services, proxy upload service, update systems, and the NovaAC anti-cheat resource.
For account, website, checkout, support, license, and service-security data, NovaAC generally decides why and how the data is processed. For player data collected on a server protected by NovaAC, the server owner generally decides how NovaAC is configured, what enforcement rules apply, which staff can view evidence, and how player appeals are handled. In that situation, NovaAC may process data to provide anti-cheat and dashboard services to the server owner.
2. Information we collect
Based on the current NovaAC codebase and service design, we may collect or process the following categories of information:
- Account data: Discord ID, Google ID, username, email address, avatar, linked login providers, account creation time, admin status, ban status, and ban reason.
- Authentication data: OAuth access and refresh tokens, JWT session tokens, dashboard cookies, authorization headers, script tokens, generated license files, and token expiry data.
- Payment data: Stripe checkout/session ID, payment status, customer email returned by Stripe, product tier, generated license key, purchase amount, and delivery status. We do not intentionally receive full card numbers through Stripe embedded checkout.
- Server data: server name, server IP or connection IP, resource version, file names, file paths, file checksums, configuration values, startup/authentication status, update status, and API or WebSocket events.
- Player and punishment data: player name, punishment type, action ID, identifiers, IP identifiers, Steam/FiveM/Discord/license identifiers where supplied by the server, reason, admin name, screenshots, video or instant replay URLs, additional info, option values, tokens, and timestamps.
- Support data: Discord messages, bot commands, tickets, thread IDs, DM channel IDs, support attachments, webhook logs, support codes, appeal information, diagnostic logs, and communications with us.
- Website and dashboard data: theme preference in local storage, browser and device details, pages requested, IP address, security logs, rate-limit data, and diagnostics generated by hosting, API, or infrastructure providers.
3. How information is collected
Information may be collected directly from you, from OAuth providers, from Stripe, from Discord, from the NovaAC dashboard, from server owners or staff, from the installed anti-cheat resource, from browser local storage, from WebSocket connections, from webhook uploads, from server authentication requests, and from logs generated when our systems are used.
4. Why we use information
We use information for the following purposes:
- To create accounts, authenticate sessions, link Discord or Google identities, refresh avatars, and prevent unauthorized account access.
- To generate, deliver, redeem, validate, update, suspend, blacklist, and support licenses.
- To process checkout, verify Stripe sessions, generate license keys after payment, send license emails, and handle payment disputes or fraud prevention.
- To authenticate protected servers, validate script tokens, check resource integrity, detect tampering, and protect the service from bypass attempts.
- To provide dashboards, player lists, punishment logs, ban checks, warnings, kicks, configuration tools, live monitoring, evidence review, and WebSocket updates.
- To capture or process screenshots, video clips, instant replay, or live monitoring streams when configured for evidence, support, or anti-cheat review.
- To send Discord webhook logs, bot messages, support ticket updates, startup logs, security logs, and server notifications.
- To respond to support requests, appeals, account deletion requests, security reports, and legal requests.
- To secure NovaAC, detect abuse, investigate fraud, enforce Terms, debug errors, improve detections, and maintain service reliability.
- To comply with legal, tax, accounting, payment, platform, and security obligations.
5. Legal bases where GDPR or UK GDPR applies
Where European or UK data protection law applies, we rely on one or more of the following legal bases depending on the context:
- Contract: to provide accounts, licenses, downloads, dashboard access, support, checkout, and anti-cheat services requested by customers.
- Legitimate interests: to protect servers, detect cheating, prevent fraud, secure infrastructure, debug issues, enforce Terms, process limited evidence, and improve the service.
- Consent: where a feature, platform flow, or law requires consent, such as certain optional account linking or cookie-like technologies.
- Legal obligation: to keep records needed for tax, accounting, consumer, payment, law-enforcement, or compliance obligations.
- Vital or public interests are not normally expected to apply to NovaAC, but may apply in rare cases involving immediate safety or legal requirements.
6. Anti-cheat evidence, screenshots, replay, and streaming
NovaAC can be configured to create evidence for detections or staff review. Evidence may include screenshots, short gameplay video, instant replay clips, player identifiers, token matches, detection reasons, admin actions, timestamps, and live WebRTC monitoring streams.
Evidence may be uploaded through NovaAC proxy services to Discord webhooks or made available in the dashboard. Discord-hosted attachments and webhook messages are also subject to Discord's own terms and privacy practices. Server owners and staff must use evidence only for legitimate anti-cheat, moderation, security, appeal, and support purposes.
7. Cookies, local storage, and similar technologies
NovaAC uses browser cookies, local storage, and similar storage for dashboard authentication, bearer tokens, theme preferences, configuration caching, anti-cheat local IDs, ESP/settings preferences, and interface preferences such as multi-stream sorting.
You can control browser storage through your browser settings. Blocking storage may break dashboard login, theme persistence, configuration caching, checkout return flows, anti-cheat token generation, or other service features.
8. When we share information
We do not sell personal information. We may share or disclose information in the following ways:
- With server owners and authorized staff through dashboards, logs, WebSocket updates, Discord webhooks, and evidence tools for servers they administer.
- With Stripe to create checkout sessions, verify payments, process subscriptions or one-time payments, handle disputes, and prevent fraud.
- With Discord for login, guild membership, support, bot commands, tickets, webhooks, and evidence delivery.
- With Google when you choose to link or use a Google login provider.
- With Resend or email providers to send license keys, account deletion OTPs, password reset messages, or service emails.
- With hosting, database, infrastructure, monitoring, security, and storage providers needed to operate NovaAC.
- With law enforcement, regulators, courts, payment networks, or other parties if required by law or reasonably necessary to protect rights, safety, security, or service integrity.
- With another operator or successor if NovaAC is transferred, reorganized, merged, or substantially restructured, subject to appropriate protections.
9. Public or semi-public support spaces
If you post in Discord channels, tickets, forums, public chats, or community spaces, other users or staff may see your messages and attachments according to the permissions of that space. Do not post license keys, secrets, payment details, private player data, webhook URLs, or sensitive evidence in public channels.
10. Retention
We keep information only as long as reasonably needed for the purposes described in this policy, unless a longer period is required or allowed by law. Current code automatically deletes kick and warn punishment records older than 30 days. Ban records, license records, payment checkout records, account records, blacklist records, configuration records, and support records may be kept for longer because they are needed for security, license enforcement, appeals, fraud prevention, accounting, and service continuity.
Media uploaded to Discord webhooks may remain available according to Discord's retention practices and the server owner's webhook/channel configuration. Backups and logs may persist for a limited period after deletion from active systems.
11. Account deletion
NovaAC provides an account deletion flow protected by an email OTP. Deletion may remove your account and licenses linked to it. Some records may remain where needed for payment records, tax/accounting, fraud prevention, security investigations, legal obligations, backup integrity, Discord records, webhook records, or server-owner records that are not controlled by NovaAC alone.
12. Security
We use technical and organizational measures intended to protect NovaAC data, including authentication, rate limiting, token validation, encrypted request handling for certain anti-cheat flows, access controls, server-side validation, database controls, and operational monitoring. No system is perfectly secure.
Customers and server owners must protect their own Discord accounts, Google accounts, dashboard cookies, JWTs, license keys, generated files, Discord webhooks, server files, API credentials, and staff permissions.
13. International processing
NovaAC, its operators, service providers, infrastructure, payment providers, Discord, Google, Stripe, Resend, and hosting providers may process information in countries other than where you live. Those countries may have different data protection laws. Where required, transfers may rely on adequacy decisions, standard contractual clauses, provider data-processing terms, or other safeguards.
14. Your privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review of certain automated decisions. You may also have the right to complain to a data protection authority.
Some requests may be limited if fulfilling them would harm security, reveal private detection logic, expose another person's information, interfere with fraud prevention, conflict with legal obligations, or affect records controlled by a server owner.
15. Player requests and appeals
If you are a player on a server protected by NovaAC, contact that server owner first for ban appeals, staff decisions, server-specific evidence, or moderation questions. NovaAC does not control every server's rules, staff, Discord channels, or appeal process.
If you contact NovaAC directly, include enough information to identify the relevant server, license, player identifier, Discord account, action ID, or evidence record. We may need to involve the server owner to handle the request.
16. Automated detection and human review
NovaAC may automatically flag, log, kick, warn, ban, or generate evidence based on configured detections. Server owners choose configuration and enforcement settings. Server staff should review relevant evidence and provide appeal paths where appropriate, especially if enforcement affects a player's access to a community.
17. Third-party links and platforms
Our websites and services may link to or integrate with Discord, Google, Stripe, Resend, Cfx.re/FiveM, status pages, documentation, hosting providers, and other third parties. Their privacy practices are governed by their own policies, not this Privacy Policy.
18. Changes to this Privacy Policy
We may update this Privacy Policy as NovaAC changes. If changes are material, we will take reasonable steps to notify users through the website, dashboard, Discord, email, or another appropriate channel. The "Last updated" date shows when this policy was last revised.
19. Contact
Contact us through discord.nova-ac.com for privacy, account, license, support, or legal requests. Include enough detail for us to identify the relevant NovaAC account, Discord account, Google account, server, license key, transaction ID, player identifier, action ID, or evidence record.
