Privacy.
§ 01 Who we are
Drakos ("we") operates this website, the account portal, and the license service the Drakos plugin connects to. For any question or request under this policy, contact [email protected] from the email address on your account, or message us on Discord.
§ 02 Account data
We store your email address, a hash of your password (Argon2id; we cannot recover the password itself), your login sessions and password-reset tokens, and the license keys and prepaid time blocks that belong to your account.
If you are locked out of your account, we cannot recover it on your behalf. You must reset your password via the email you registered.
We encourage users to use a secondary email address not linked to their identity when registering for Drakos.
We do not ask for a name, a phone number, or any other profile information.
§ 03 Payment data
Checkout happens on Stripe's hosted payment page. Card details go directly to Stripe and never reach our servers; no page of ours renders a card field. Stripe reports back to us that a checkout completed, which product was bought, a payment reference, and the email address used. Stripe processes payment data under its own privacy policy.
§ 04 Data from the plugin
When the plugin connects to the license service, it sends your license key and a per-install token issued by our server (the token rotates with the key). While connected, the plugin exchanges periodic keepalive messages that carry no data.
The plugin does not collect hardware identifiers, machine fingerprints, character names, or any other in-game identifiers. The protocol has no field for them. However, the plugin does create local folders corresponding to your character names for configuration settings for multiboxing users of Drakos. We do not see those local folders on our end.
As with any online service, our servers see the IP address of each connection. IP addresses are used for rate limiting and abuse prevention, and appear in server logs (§ 07). License keys and install tokens are excluded from logs on both ends; where a log or a support conversation needs to refer to a key, a short digest of it is used instead.
§ 05 Email
We send transactional emails only: your key after a purchase and password resets when you request them. We do not send marketing email, and we do not give your address to anyone else.
§ 06 Cookies
The account portal sets two cookies, both functional: a login session and a security (CSRF) token. Neither tracks you. The rest of the site sets no cookies, and we run no analytics trackers and no ads.
§ 07 Retention
- Account records (email, keys, time blocks) are kept for as long as the account exists. We do not purge inactive accounts; the data stays until you request deletion (§ 08).
- Server logs are kept for 14 days.
- Encrypted database backups are kept for about 28 days, at a separate provider.
- The purchase ledger — which blocks were bought, when, and under which payment reference — is a financial record and is retained for accounting purposes.
§ 08 Account deletion
Email us from your account address and we will erase the account. In the interest of precision, this is what erasure does:
- Everything that identifies you (email, password hash, sessions, reset tokens) is scrubbed immediately. Your keys stop working and can no longer be recovered.
- The purchase ledger remains as a financial record, no longer linked to your email.
- Copies of your email age out of server logs within 14 days and out of encrypted backups within about 28 days.
- Stripe retains its own records of your payments under its own legal obligations, and any correspondence you sent to support remains in the support mailbox until closed out.
After erasure we can no longer verify who you are, so we cannot recover keys or purchases or assist with the account in any way.
§ 09 Your rights
Under the GDPR (EU/EEA and UK) and the CCPA/CPRA (California), you may request access to the personal data we hold about you, correction, deletion (§ 08), and a copy in portable form. You may lodge complaints with your data-protection authorities. We do not sell or share personal information as the CCPA defines those terms. Send requests to [email protected] from your account address or message us on Discord; we respond within one month.
§ 10 Where data is stored
Our servers are located in the European Union, with a replica in the United States for failover and encrypted backups at a separate provider. Data on the EU primary is therefore also present in the United States. The replica and the backups carry the same protections as the primary.
§ 11 Changes
This policy is versioned and dated at the top. Material changes are announced on the updates page.