Jump to main

// legal

Privacy policy.

Last updated · what we collect, what we don’t

The short version: we store the minimum needed to run the account and license system. Email + payment token + hardware fingerprint on activation. No behavioural tracking, no third-party analytics beyond Cloudflare’s edge logs, no data sharing beyond what payment processing requires.

What we collect

  • Email address — supplied at signup, used to deliver your license key and any account-critical communication. Nothing else.
  • Payment token — the paid-flag issued by our payment processor against your order. We never see or store your card number; only the processor does.
  • Hardware fingerprint (HWID) — on first activation of a license key, the loader computes a hash of your motherboard, CPU, and disk serial and binds the license to that hash. This is how license reuse is prevented. Two self-serve resets per license cycle allow you to rebind if your hardware changes.
  • Server access logs — Cloudflare (our CDN + edge host) records IP addresses and user agents in transient logs for abuse prevention. These logs age out after 30 days.
  • Discord identity, if you join — Discord itself sees your username and any messages you post in the server. We don’t sync Discord identities to license records unless you specifically link them for support purposes.

What we don’t collect

  • Steam credentials. The loader doesn’t log into Steam, doesn’t read your Steam account info, doesn’t know which Steam account you use.
  • In-game telemetry. The loader doesn’t report what you do in-game to us. Match state, KDR, playtime — none of that leaves your machine.
  • Behavioural analytics. No Google Analytics, no Mixpanel, no cookies used for tracking beyond a session ID for logged-in state on the site.
  • Device data beyond the HWID hash. We don’t harvest browser fingerprints, MAC addresses, or serial numbers beyond the three fields used for the license bind.

How we use it

Every data point above serves a specific operational purpose:

  • Email → deliver the license key, send account-critical updates (major EAC pauses, terms changes).
  • Payment token → verify your paid-status, process refunds when they apply.
  • HWID → prevent license sharing, allow self-serve resets on legitimate rig changes.
  • Server logs → abuse prevention, rate-limit debugging.

Who we share it with

Three parties, only when the specific transaction requires it:

  • Our payment processor — sees your email and card info at checkout. Card data is stored on their side per PCI-DSS; we only receive a paid-flag against your order.
  • Cloudflare — our edge host + CDN, sees your IP and user agent for any request to the site. Their privacy policy covers their logging.
  • Email deliverability provider — our transactional email service sees the message body of any email we send you. Standard receipts, verification links, key delivery, account notifications.

We don’t sell data. We don’t buy ads. We don’t syndicate to third-party ad platforms. If we ever change that, it will be announced explicitly and require your opt-in.

Your rights

Under GDPR / CCPA, you have the right to:

  • Export your data — email us and we’ll send a JSON dump of every field associated with your account.
  • Delete your account — request via Discord or email; processed inside 30 days. Active license time is not refunded on account deletion unless you also meet a refund trigger.
  • Correct incorrect data — if the email on your account is wrong, DM Discord to fix.
  • Object to any specific processing — email support with the objection; we’ll walk through what’s possible.

Retention

  • Active accounts — kept as long as the account is active.
  • Inactive accounts (no license activity for 18 months) — automatically deleted.
  • Deleted accounts — email + payment token + HWID scrubbed within 30 days of deletion request. Server logs age out on their own 30-day window.
  • Financial records — kept for the period required by tax law in the operating jurisdiction (typically 7 years) even after account deletion. Records reduced to receipt / invoice level, not linked back to your email or HWID.

Cookies

One cookie: atlas_session, set when you sign in, cleared on sign-out. No third-party cookies, no marketing cookies, no analytics cookies. The site works fine with cookies disabled — you just can’t stay signed in between visits.

Contact for privacy matters

Email [email protected] with any privacy question, data request, or deletion request. Response inside one business day.

Changes to this policy

We can update this policy. Material changes get announced by email to account holders at least 14 days before they take effect. The last-updated date at the top of this page reflects the current version.