Legal

Privacy Policy

What we collect, why, and what control you have over it.

Effective Aug 1, 2026Updated Aug 1, 2026

This document is a starting template prepared for RxCodz. Have it reviewed by a qualified professional in your jurisdiction before relying on it.

1. What we collect

When you create an account: your email address, username, password (stored only as a salted hash — we never see it), and anything you choose to add to your profile.

When you sign in: the time, your IP address, and your browser's user-agent string. This is shown back to you in your profile so you can spot access you do not recognise.

When you contact us: your name, email, optional Discord handle and company, and the content of your message.

Automatically: a session cookie if you are signed in, and a theme preference stored in your browser.

2. Why we collect it

  • To operate your account and keep it secure
  • To reply to your enquiry and deliver work you have asked for
  • To detect and prevent abuse, spam, and unauthorised access
  • To keep an audit record of administrative actions

We do not sell your data, and we do not use it for advertising.

3. Cookies

We use a small number of cookies. See the Cookie Policy for the full list. We do not use advertising or cross-site tracking cookies.

4. Retention

DataKept for
Account dataUntil you delete your account
SessionsUntil they expire or you revoke them
Login history180 days
Security logs365 days
Contact requests24 months
Audit logsRetained as a compliance record

5. Sharing

We share data only with service providers needed to run the site (hosting, and email delivery where configured), and where we are legally required to.

Contact through Discord is subject to Discord's own privacy policy — we do not control it.

6. Your rights

You can access, correct, export, or delete your data. Most of it you can change yourself in your profile. For anything else, ask us on Discord or through the contact form and we will action it within 30 days.

7. Security

Passwords are hashed with scrypt. Session tokens are stored only as hashes, so a database leak cannot be replayed as a login. Access to administrative functions is role-restricted and every privileged action is logged. No system is perfectly secure, but we treat your data as if a breach would matter — because it would.

8. Children

This site is not intended for people under 13, and we do not knowingly collect their data.

9. Changes

Material changes will be noted here with a new effective date.

Questions about this?

Ask us on Discord and we will explain any part of it in plain terms.