Privacy
Updated 23 August 2026
What is stored, and why:
- Your account: username, email, Discord ID and an optional alt Discord ID. These identify you and let staff reach you.
- Your password: only as an Argon2id hash. Nobody at cfxaim can read it, including staff.
- Sessions: the device description and IP address of each sign-in, so you can spot one you do not recognise. Only a hash of the session token is kept.
- Your licence: the key, its dates, and an opaque device fingerprint derived from an enrolled public key. No motherboard or TPM serial is collected; the fingerprint is what stops one key being shared around.
- Launches: the time, outcome and IP of each authentication, which is what the usage figures are counted from.
None of it is sold or handed to advertisers. Staff can see your account, your key and your recent launches, and every staff action is written to an activity log.
Ask staff to delete your account and it goes, along with its sessions and licence. Launch records are kept without your account attached to them.