Draft pending legal review
This text is a template and has not been reviewed by a lawyer. Highlighted {{PLACEHOLDERS}} still have to be filled in. Do not rely on it as final.
Privacy Policy
Effective: {{EFFECTIVE_DATE}}
This Policy explains what personal data Terasuv10 collects, why, how long it is kept and what rights you have. It covers visitors, account holders, customers, gift recipients and community participants.
1. Controller and scope
{{COMPANY_NAME}}, {{COMPANY_ADDRESS}}, is the controller of personal data processed to run Terasuv10. Privacy questions and rights requests can be sent to {{PRIVACY_EMAIL}}.
Depending on where you live, mandatory local privacy rights may apply in addition to this Policy. Nothing in the Terms removes them.
2. Data we collect
Depending on the features you use, we store the following.
- Account: email address, username, biography, avatar, registration date, last-active time, account status, your privacy and notification settings, and your date of birth (private, used only to check age eligibility).
- Sign-in: a hashed one-time email code with the requesting IP address and attempt count.
- Sessions and security: for every signed-in device, a hashed session token, the IP address, the browser user agent, an approximate country and city derived from the IP address by Cloudflare, a label, and the time of last activity; your two-factor secret (stored encrypted) and hashed recovery codes; restrictions placed on your account.
- Purchases: checkouts, subscriptions and their adjustments, gifts, license keys you activate, promo codes you use, and the ledger of your balance (credits, debits, refunds, referral rewards, compensation).
- Referrals: your referral code, who you referred or were referred by, and for visits to a referral link a hashed IP address (not the IP address itself).
- Device and deployment: see the next section.
- Community and support: topics, replies, votes, reports you file, support tickets and their messages, and files you attach.
- Notifications: the notifications we send you in the app.
- Operations: audit records of actions staff take on accounts (who, what, when, and the reason they entered), request identifiers, and error and performance logs produced by the hosting platform.
3. Device identifier and hardware summary
When you run the PowerShell deployment, the script computes a device identifier (HWID) as a one-way SHA-256 hash of your Windows machine GUID combined with a salt provided by the server, and collects a short summary of your hardware: processor name, graphics adapter name, installed memory size, and Windows edition and build. Both are sent to Terasuv10 together with the deployment token and are stored against your account together with the IP address of the request and the outcome of the deployment (success, failure and a short technical detail).
We use this to enforce the one-device-per-account rule, to review hardware reset requests, to support you when a deployment fails and to detect account sharing and fraud. The raw machine GUID is not sent or stored. To find your game folder the script reads your Steam installation path and library list locally; that information is not sent to us. The script does not read your personal documents or browsing data, and it writes only the game files it listed for you before making changes.
The device binding is kept while your account exists. Staff with the corresponding permission can see it and can reset it when you ask. A new device that differs from the bound one is stored as “pending” until support reviews it.
4. Why we process data
We process data where necessary to:
- create, authenticate, secure and administer your account, and keep sessions and two-factor protection working;
- perform our agreement: deliver subscriptions, keys, gifts, deployments and support, and keep the balance ledger;
- operate the community, notifications and moderation;
- prevent fraud, account sharing, abuse and attacks on the service, including rate limiting and bot protection;
- meet accounting, recordkeeping, legal and dispute-resolution obligations;
- diagnose failures and keep the service reliable, based on our legitimate interests that do not override your rights.
5. What others can see
Your username, avatar, biography, registration date, role icon and community activity can be visible to other users. If you turn off the public profile, your profile page is no longer discoverable, but content you already posted stays visible. You can hide your online status. Topics and replies may remain after account closure under a “Deleted user” label so discussions stay readable.
Support tickets are visible to you and authorised support staff. Staff actions are recorded in the audit log.
6. Service providers and disclosure
We do not sell personal data. Terasuv10 runs on Cloudflare, which acts as our processor for hosting (Workers), database (D1), file storage (R2), realtime connections (Durable Objects), bot protection (Turnstile), email delivery (Email Service), network security and delivery. Cloudflare may process network and security information such as IP addresses when delivering and protecting the service.
We do not use third-party advertising or behavioural analytics.
We may also disclose data to professional advisers, to a successor of the service, or to a competent authority where the law requires it or where it is reasonably necessary to protect users, rights, safety or the integrity of the service.
7. International transfers
Cloudflare operates a global network, so your data may be processed in countries other than your own. We rely on the safeguards offered by our providers and applicable law for such transfers.
8. Retention
We keep data as follows. Figures below are enforced by the service itself.
- Sign-in sessions expire 30 days after they are created; you can revoke any session earlier under Security.
- Content you delete (topics, replies, attachments) is hidden immediately and permanently removed after 30 days. Uploads that were never completed are removed after 24 hours.
- Read notifications are removed after 90 days.
- Email sign-in codes expire after 10 minutes; realtime connection tickets expire after 60 seconds; the idempotency records that protect against double submissions are removed after 14 days.
- Deployment tokens are valid for 10 minutes and can be used once; signed file links are valid for 15 minutes.
Other records (account data, device binding, session history, support tickets, ledger entries and audit records) are kept while your account exists and afterwards only as long as needed for accounting, security, dispute and legal purposes; they are not deleted automatically on a fixed schedule. Database backups are retained by Cloudflare for its Time Travel window and expire on their own cycle. Retention may be extended for an active investigation, chargeback, legal hold or security incident.
9. Account closure and deletion
You can ask support to close your account. We verify the request, revoke sessions and access, remove or anonymise the public profile and begin deleting personal data that is no longer needed. Public discussions may stay under the label “Deleted user”.
Closure does not erase ledger, security, audit or dispute records before their retention ends. A suspended account is not treated as a deletion request.
10. Your rights and choices
Subject to applicable law, you may ask for access to your data, correction, deletion, restriction, portability and information about sharing, and you may object to processing based on legitimate interests. Send the request from your account email to {{PRIVACY_EMAIL}} or through support. We may need to verify your identity. If you are unhappy with our answer you may complain to your local data-protection authority.
12. Email
We send transactional email only: sign-in codes, security alerts, purchase and gift confirmations, support replies and essential service notices. These are necessary to run your account. We do not send marketing email.
13. Security
Safeguards include least-privilege permissions, secure HTTP-only sessions with hashed tokens, optional two-factor authentication with encrypted secrets, rate limiting, Turnstile bot protection, private file storage, upload type and size validation, encryption in transit, balance constraints in the database and an audit log of staff actions.
Uploaded files are validated by type and size but are not scanned for malware. No system is completely secure; protect your email and devices and report suspected compromise promptly. We will notify affected users and authorities of a qualifying breach where the law requires it.
14. Age
Terasuv10 is intended for people aged 16 or older, and gifting and any future wallet features for people aged 18 or older. We do not knowingly collect personal data from younger users; contact {{PRIVACY_EMAIL}} if you believe we did so that we can remove it.
15. Changes and contact
We may update this Policy when processing, providers or the law change. Material changes are announced in the service or by email before they take effect where required. Questions: {{PRIVACY_EMAIL}}.