Privacy Policy

Last Updated: February 5, 2026

1. Introduction

This Privacy Policy explains how Cephie Studios collects, uses, stores, and manages your information when you use our Services. We maintain comprehensive data collection and monitoring capabilities to ensure service quality, security, and compliance. By using our Services, you acknowledge and consent to all data practices described in this policy.

2. Information We Collect

We collect extensive information to provide, secure, and improve our services:

Account and Authentication Data

Discord user ID, username, display name, avatar, account creation and last activity timestamps, authentication tokens and session data, IP addresses and device information

Service Usage Data

All user interactions with our Services, command usage patterns and frequency, API request logs and responses, error logs and diagnostic information, feature usage statistics, performance metrics, user behavior analytics

Server and Guild Data

Discord server configurations and settings, server member lists and roles, channel configurations and permissions, bot installation and usage data, server activity metrics, administrative actions and changes

Flight and Operations Data

Flight logs including all submitted details (routes, aircraft, times, etc.), pilot statistics and performance metrics, virtual airline configurations, leaderboard and ranking data, historical flight data and patterns

Communications Data

Chat messages and communications within our Services, support ticket conversations, feedback and bug reports, user-generated content and uploads, voice chat metadata and participation logs

Technical and Security Data

IP addresses and geolocation data, connection logs and timestamps, security event logs, rate limiting and abuse detection data, system performance and monitoring data

3. How We Use Information

We use collected information for comprehensive service management:

Service Operations and Functionality

Maintain and restore server configurations, process and validate flight logs, generate statistics and leaderboards, authenticate users and manage permissions, provide customer support and troubleshooting

Security and Compliance

Monitor for abuse, fraud, and policy violations, implement security measures and access controls, enforce terms of service and community guidelines, comply with legal requirements and law enforcement requests, investigate and respond to security incidents

Service Improvement and Analytics

Analyze usage patterns to improve functionality, develop new features and services, optimize performance and reliability, conduct research and development, create aggregated statistics and reports

Communication and Marketing

Send service announcements and updates, provide customer support communications, share community highlights and achievements, notify users of policy changes or important information

4. Data Storage and Access

Our comprehensive data storage and access practices:

Administrative Access Rights

Cephie Studios staff maintain full administrative access to all stored data for service operations, security monitoring, compliance enforcement, and support purposes. This includes the ability to view, modify, or delete any data as necessary for business operations

Third-Party Data Sharing

We may share data with approved third-party services, partners, and integrations to enhance service functionality. Partners may receive access to server configurations, flight data, and user statistics as part of approved integrations

Data Monitoring and Analysis

All data is subject to continuous monitoring, automated analysis for patterns and anomalies, machine learning algorithms for service improvement, and regular auditing for compliance and security purposes

5. Data Security and Protection

We implement comprehensive security measures:

Technical Security

Enterprise-grade encryption (TLS 1.3+) for all data transmission, AES-256 encryption for sensitive data at rest, multi-factor authentication for administrative access, regular security audits and penetration testing, automated intrusion detection and response systems

Access Controls

Role-based access controls for all systems, comprehensive audit logging of all data access, regular access reviews and permission updates, secure API key management and rotation

Monitoring and Incident Response

24/7 security monitoring and alerting, automated threat detection and response, comprehensive incident response procedures, regular security training for all staff members

6. Data Retention and Deletion

We maintain flexible data retention policies based on operational needs:

Operational Data

Server configurations: Retained until manually deleted or service termination, Flight logs: Retained for 24 months minimum, may be retained longer for historical analysis, User account data: Retained for the duration of account existence plus 12 months

Security and Compliance Data

Security logs: Retained for 12 months minimum, may be retained longer for ongoing investigations, Abuse and violation records: Retained indefinitely for enforcement purposes, Legal compliance data: Retained as required by applicable laws and regulations

Communication Data

Support communications: Retained for 24 months, Chat logs and transcripts: Retained for 30 days by default, may be retained longer for investigations, User-generated content: Retained until manually deleted or policy violation removal

7. Third-Party Services and Data Sharing

We work with various third-party services and may share data as necessary:

Service Providers

Discord API for authentication and bot functionality, Cloud hosting providers for infrastructure and storage, Security services for threat detection and prevention, Analytics services for service improvement and optimization

Business Partners

Virtual airline management platforms, Community tools and integrations, Statistical and leaderboard services, Developer API access for approved projects

Legal and Compliance

Law enforcement agencies when required by law, Legal advisors for compliance and dispute resolution, Regulatory authorities as required by applicable laws, Court orders and legal process compliance

8. User Rights and Data Control

Users have limited control over their data, subject to operational requirements:

Access and Portability

Users may request access to their personal data, subject to verification and security requirements. Data portability requests will be considered on a case-by-case basis and may be subject to technical limitations

Correction and Updates

Users may request corrections to inaccurate personal data, subject to verification. Some data corrections may not be possible due to system limitations or operational requirements

Deletion Requests

Users may request deletion of their personal data, subject to our retention policies and legal requirements. Some data may be retained for security, compliance, or operational purposes even after deletion requests

9. Cookies and Tracking Technologies

We use various tracking technologies for functionality and analytics:

Essential Cookies

Authentication and session management, Service functionality and preferences, Security and fraud prevention, Load balancing and performance optimization

Analytics and Performance

User behavior analysis and service improvement, Performance monitoring and optimization, Feature usage statistics and trends, Error tracking and debugging information

Third-Party Tracking

Integration with third-party services may involve additional tracking. Users consent to all tracking technologies used by our Services and integrated third-party services

10. Age Restrictions and Children's Privacy

Our Services are not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information. Users between 13 and 18 must have parental consent to use our Services.

11. International Data Transfers and Compliance

We may transfer and process data internationally as necessary for service operations. We comply with applicable data protection laws including GDPR, CCPA, and other regional regulations. Users consent to international data transfers as necessary for service provision. We maintain appropriate safeguards for international data transfers as required by law.

12. Changes to This Policy

We reserve the right to modify this policy at any time without prior notice. Significant changes will be communicated through our Discord server, website announcements, or direct communication. Continued use of our Services after policy changes constitutes acceptance of the modified policy.

13. Cephie Studios Bot Specific Privacy Terms

The following privacy terms apply specifically to the Cephie Studios Discord Bot:

Discord Data Collection

Discord server member lists and roles, Channel configurations and message history (where bot has access), User interaction patterns with bot commands, Server administrative actions and changes, Bot permission levels and scope changes

Flight Data Processing

All flight log submissions are permanently stored and analyzed, Flight data is used for statistics, leaderboards, and service improvement, Flight patterns and user behavior are monitored for compliance and fraud detection

Server Monitoring

Bot monitors server activity for compliance with terms of service, Server configurations and member activity are logged and analyzed, Administrative actions are tracked and may be reviewed for policy enforcement

Cross-Server Data Sharing

Bot may share data across servers for approved integrations and partnerships, User statistics and achievements may be displayed across multiple servers, Server data may be used for platform-wide analytics and improvements

14. Cephie Studios Charts Specific Privacy Terms

The following privacy terms apply specifically to Cephie Studios Charts:

Profile Information

User profiles, bios, and display names are collected and stored, Profile pictures and avatars are processed and cached, User preferences and customizations are tracked and stored

Chart Access and Usage

Chart access patterns and preferences are monitored, Navigation and search history is tracked for service improvement, User-generated content and annotations are stored and may be shared

Community Features

Community interactions and sharing activities are tracked, User contributions and ratings are stored and analyzed, Social features may involve data sharing with other users

15. Cephie Studios CD Specific Privacy Terms

The following privacy terms apply specifically to Cephie Studios CD image hosting:

Image Storage and Access

All uploaded images are stored indefinitely and are publicly accessible via direct URLs, Image metadata including upload timestamps, file sizes, and user information is stored, Images may be analyzed for content compliance and security purposes

Content Monitoring

All uploaded content is subject to automated and manual review, Content may be scanned for inappropriate material, security threats, or policy violations, Users' upload patterns and behavior are monitored for abuse detection

Data Retention

Images and associated metadata are retained indefinitely unless manually deleted, Deletion requests are processed manually and may take time to complete, Some image data may be retained for security or legal purposes even after deletion

16. Cephie Studios API Specific Privacy Terms

The following privacy terms apply specifically to the Cephie Studios API:

Comprehensive API Monitoring

All API requests are logged with full details including endpoint, parameters, response data, and execution time, API keys are tracked with associated user information, IP addresses, and usage patterns, Request/response data is stored for security analysis, debugging, and service improvement purposes

Enhanced Data Access and Sharing

API provides multiple access levels: (1) Server-specific access for authorized users to their server's data, (2) Cross-server access for approved partners to access data from all servers using Cephie Studios, (3) Administrative access for Cephie Studios staff to access all data for operational purposes, (4) Third-party integrations may access flight data and server configurations across the entire Cephie Studios network

Data Processing and Analytics

All API data is processed in real-time for service functionality, Data is analyzed using machine learning algorithms for pattern recognition and fraud detection, Statistical models are created from aggregated data across all servers and users, Usage patterns are monitored to identify trends and improve service offerings

Extended Data Retention

API request logs are retained for 12 months minimum, may be retained longer for security investigations, Abuse and violation records are retained indefinitely for enforcement purposes, All flight data and server configurations are retained for 24 months minimum, may be retained longer for historical analysis

Partner Data Sharing

Approved third-party projects receive comprehensive access to: (1) Flight data from all servers using Cephie Studios services, (2) Server configuration data and administrative settings, (3) User statistics and behavioral data, (4) Historical data and trends across the entire platform, (5) Real-time data feeds for approved integrations

Security and Compliance Monitoring

All API activity is monitored 24/7 for security threats and policy violations, Automated systems detect and respond to suspicious activity, Rate limiting and abuse detection systems collect and analyze usage patterns, Security incidents are logged and investigated with full data retention

17. Data Subject Rights Limitations

While we respect user privacy, data subject rights are limited by operational requirements:

Right to Access

Access requests are subject to verification and security review, Some data may be withheld for security, legal, or operational reasons, Access may be denied if it conflicts with our legitimate business interests

Right to Rectification

Data corrections are subject to verification and technical feasibility, Some data may be immutable due to system architecture or legal requirements, Corrections may be denied if they conflict with operational integrity

Right to Erasure

Deletion requests are subject to our retention policies and legal obligations, Some data must be retained for security, compliance, or operational purposes, Erasure may be denied if it conflicts with legitimate business interests or legal requirements

Right to Portability

Data portability is subject to technical limitations and security requirements, Some data may not be portable due to system architecture or third-party integrations, Portability requests may be denied for security or operational reasons

18. Enforcement and Compliance

We maintain comprehensive enforcement and compliance measures:

Policy Enforcement

All policy violations are investigated with full data retention and analysis, Enforcement actions may include permanent bans, data sharing restrictions, and legal action, Violation records are shared with partners and third-party services as necessary

Legal Compliance

We comply with all applicable laws and regulations, including data protection, privacy, and security requirements, Legal process and law enforcement requests are handled with full cooperation and data disclosure as required

Audit and Review

All data practices are subject to regular internal audits and reviews, Third-party audits may be conducted for compliance verification, Audit results may be shared with partners, regulators, or legal authorities as required

19. Contact Information

For privacy-related questions or requests, contact us at [email protected]. Please note that all communications are subject to review and may be used for service improvement purposes. Response times may vary based on the nature of your request and operational priorities.