Privacy Policy

Your privacy is important to us

1 Information Collection

We collect minimal information required to provide and secure our services, including:

  • Account details (email address, username, referral links).
  • Third-party integration data (Discord ID, Discord username, Discord email, and Discord avatar URL) if you link your Discord account.
  • Connection data (IP addresses - IPv4 and IPv6, timestamps, browser/launcher User-Agent).
  • Hardware Identifier (HWID): We collect a unique identifier of your device to prevent multi-accounting abuse and ban evasion.
  • Security logs (2FA activation/deactivation, login attempts, account linking/unlinking).
  • Game-related data (character progress, inventory).

We do not sell or share your personal information with third parties, except for essential service providers required for security (Cloudflare Turnstile) and payments (Stripe, PayPal).

2 Use of Data

Your data is used solely for:

  • Account management, authentication, and Discord integration.
  • Security monitoring, fraud prevention, and bot protection.
  • Technical support via our ticket system.
  • Improving your gaming experience on NosLegacy.

3 Storage & Technology

We use various technologies to maintain your session and improve usability:

  • Cookies: Used to maintain your authenticated session (`auth-session`) and secure the OAuth2 process (`oauthstate`).
  • Windows Registry: The NosLegacy Launcher uses the Windows Registry (`HKEY_CURRENT_USER\Software\NosLegacy\Launcher`) to securely store your preferences (language, theme) and credentials if "Remember Me" is enabled.
  • Local HTTP Server: During Discord authentication, the launcher may temporarily start a local HTTP server on your machine to securely receive the authentication token from our website.
  • Cloudflare Turnstile: We use Turnstile to protect our site from bots and spam. This involves the collection of hardware and software information, such as device and application data, to perform security challenges.
  • Local Storage: On the website, if you use the "Remember Me" feature, your email is stored in your browser's local storage to facilitate future logins.

4 Security

We implement industry-standard security measures to protect your data, including password hashing (Pepper + BCrypt) and session versioning to ensure immediate logout across all devices when requested. We strongly recommend enabling Two-Factor Authentication (2FA) in your dashboard to add an extra layer of security to your account.

5 Your Rights

You have the right to access, correct, or delete your personal information. You can unlink your Discord account or manage most of your data directly through the user dashboard or by contacting support.

Last updated: January 30, 2026

NosLegacy Privacy