Privacy Policy
Last Updated: February 5, 2026
1. Introduction
This Privacy Policy explains how Cephie Studios collects, uses, stores, and manages your information when you use our Services. We maintain comprehensive data collection and monitoring capabilities to ensure service quality, security, and compliance. By using our Services, you acknowledge and consent to all data practices described in this policy.
2. Information We Collect
We collect extensive information to provide, secure, and improve our services:
Account and Authentication Data
Discord user ID, username, display name, avatar, account creation and last activity timestamps, authentication tokens and session data, IP addresses and device information
Service Usage Data
All user interactions with our Services, command usage patterns and frequency, API request logs and responses, error logs and diagnostic information, feature usage statistics, performance metrics, user behavior analytics
Server and Guild Data
Discord server configurations and settings, server member lists and roles, channel configurations and permissions, bot installation and usage data, server activity metrics, administrative actions and changes
Flight and Operations Data
Flight logs including all submitted details (routes, aircraft, times, etc.), pilot statistics and performance metrics, virtual airline configurations, leaderboard and ranking data, historical flight data and patterns
Communications Data
Chat messages and communications within our Services, support ticket conversations, feedback and bug reports, user-generated content and uploads, voice chat metadata and participation logs
Technical and Security Data
IP addresses and geolocation data, connection logs and timestamps, security event logs, rate limiting and abuse detection data, system performance and monitoring data
3. How We Use Information
We use collected information for comprehensive service management:
Service Operations and Functionality
Maintain and restore server configurations, process and validate flight logs, generate statistics and leaderboards, authenticate users and manage permissions, provide customer support and troubleshooting
Security and Compliance
Monitor for abuse, fraud, and policy violations, implement security measures and access controls, enforce terms of service and community guidelines, comply with legal requirements and law enforcement requests, investigate and respond to security incidents
Service Improvement and Analytics
Analyze usage patterns to improve functionality, develop new features and services, optimize performance and reliability, conduct research and development, create aggregated statistics and reports
Communication and Marketing
Send service announcements and updates, provide customer support communications, share community highlights and achievements, notify users of policy changes or important information
4. Data Storage and Access
Our comprehensive data storage and access practices:
Administrative Access Rights
Cephie Studios staff maintain full administrative access to all stored data for service operations, security monitoring, compliance enforcement, and support purposes. This includes the ability to view, modify, or delete any data as necessary for business operations
Third-Party Data Sharing
We may share data with approved third-party services, partners, and integrations to enhance service functionality. Partners may receive access to server configurations, flight data, and user statistics as part of approved integrations
Data Monitoring and Analysis
All data is subject to continuous monitoring, automated analysis for patterns and anomalies, machine learning algorithms for service improvement, and regular auditing for compliance and security purposes
5. Data Security and Protection
We implement comprehensive security measures:
Technical Security
Enterprise-grade encryption (TLS 1.3+) for all data transmission, AES-256 encryption for sensitive data at rest, multi-factor authentication for administrative access, regular security audits and penetration testing, automated intrusion detection and response systems
Access Controls
Role-based access controls for all systems, comprehensive audit logging of all data access, regular access reviews and permission updates, secure API key management and rotation
Monitoring and Incident Response
24/7 security monitoring and alerting, automated threat detection and response, comprehensive incident response procedures, regular security training for all staff members
6. Data Retention and Deletion
We maintain flexible data retention policies based on operational needs:
Operational Data
Server configurations: Retained until manually deleted or service termination, Flight logs: Retained for 24 months minimum, may be retained longer for historical analysis, User account data: Retained for the duration of account existence plus 12 months
Security and Compliance Data
Security logs: Retained for 12 months minimum, may be retained longer for ongoing investigations, Abuse and violation records: Retained indefinitely for enforcement purposes, Legal compliance data: Retained as required by applicable laws and regulations
Communication Data
Support communications: Retained for 24 months, Chat logs and transcripts: Retained for 30 days by default, may be retained longer for investigations, User-generated content: Retained until manually deleted or policy violation removal
7. Third-Party Services and Data Sharing
We work with various third-party services and may share data as necessary:
Service Providers
Discord API for authentication and bot functionality, Cloud hosting providers for infrastructure and storage, Security services for threat detection and prevention, Analytics services for service improvement and optimization
Business Partners
Virtual airline management platforms, Community tools and integrations, Statistical and leaderboard services, Developer API access for approved projects
Legal and Compliance
Law enforcement agencies when required by law, Legal advisors for compliance and dispute resolution, Regulatory authorities as required by applicable laws, Court orders and legal process compliance
8. User Rights and Data Control
Users have limited control over their data, subject to operational requirements:
Access and Portability
Users may request access to their personal data, subject to verification and security requirements. Data portability requests will be considered on a case-by-case basis and may be subject to technical limitations
Correction and Updates
Users may request corrections to inaccurate personal data, subject to verification. Some data corrections may not be possible due to system limitations or operational requirements
Deletion Requests
Users may request deletion of their personal data, subject to our retention policies and legal requirements. Some data may be retained for security, compliance, or operational purposes even after deletion requests
10. Age Restrictions and Children's Privacy
Our Services are not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information. Users between 13 and 18 must have parental consent to use our Services.
11. International Data Transfers and Compliance
We may transfer and process data internationally as necessary for service operations. We comply with applicable data protection laws including GDPR, CCPA, and other regional regulations. Users consent to international data transfers as necessary for service provision. We maintain appropriate safeguards for international data transfers as required by law.
12. Changes to This Policy
We reserve the right to modify this policy at any time without prior notice. Significant changes will be communicated through our Discord server, website announcements, or direct communication. Continued use of our Services after policy changes constitutes acceptance of the modified policy.
13. Cephie Studios Bot Specific Privacy Terms
The following privacy terms apply specifically to the Cephie Studios Discord Bot:
Discord Data Collection
Discord server member lists and roles, Channel configurations and message history (where bot has access), User interaction patterns with bot commands, Server administrative actions and changes, Bot permission levels and scope changes
Flight Data Processing
All flight log submissions are permanently stored and analyzed, Flight data is used for statistics, leaderboards, and service improvement, Flight patterns and user behavior are monitored for compliance and fraud detection
Server Monitoring
Bot monitors server activity for compliance with terms of service, Server configurations and member activity are logged and analyzed, Administrative actions are tracked and may be reviewed for policy enforcement
Cross-Server Data Sharing
Bot may share data across servers for approved integrations and partnerships, User statistics and achievements may be displayed across multiple servers, Server data may be used for platform-wide analytics and improvements
14. Cephie Studios Charts Specific Privacy Terms
The following privacy terms apply specifically to Cephie Studios Charts:
Profile Information
User profiles, bios, and display names are collected and stored, Profile pictures and avatars are processed and cached, User preferences and customizations are tracked and stored
Chart Access and Usage
Chart access patterns and preferences are monitored, Navigation and search history is tracked for service improvement, User-generated content and annotations are stored and may be shared
Community Features
Community interactions and sharing activities are tracked, User contributions and ratings are stored and analyzed, Social features may involve data sharing with other users
15. Cephie Studios CD Specific Privacy Terms
The following privacy terms apply specifically to Cephie Studios CD image hosting:
Image Storage and Access
All uploaded images are stored indefinitely and are publicly accessible via direct URLs, Image metadata including upload timestamps, file sizes, and user information is stored, Images may be analyzed for content compliance and security purposes
Content Monitoring
All uploaded content is subject to automated and manual review, Content may be scanned for inappropriate material, security threats, or policy violations, Users' upload patterns and behavior are monitored for abuse detection
Data Retention
Images and associated metadata are retained indefinitely unless manually deleted, Deletion requests are processed manually and may take time to complete, Some image data may be retained for security or legal purposes even after deletion
16. Cephie Studios API Specific Privacy Terms
The following privacy terms apply specifically to the Cephie Studios API:
Comprehensive API Monitoring
All API requests are logged with full details including endpoint, parameters, response data, and execution time, API keys are tracked with associated user information, IP addresses, and usage patterns, Request/response data is stored for security analysis, debugging, and service improvement purposes
Enhanced Data Access and Sharing
API provides multiple access levels: (1) Server-specific access for authorized users to their server's data, (2) Cross-server access for approved partners to access data from all servers using Cephie Studios, (3) Administrative access for Cephie Studios staff to access all data for operational purposes, (4) Third-party integrations may access flight data and server configurations across the entire Cephie Studios network
Data Processing and Analytics
All API data is processed in real-time for service functionality, Data is analyzed using machine learning algorithms for pattern recognition and fraud detection, Statistical models are created from aggregated data across all servers and users, Usage patterns are monitored to identify trends and improve service offerings
Extended Data Retention
API request logs are retained for 12 months minimum, may be retained longer for security investigations, Abuse and violation records are retained indefinitely for enforcement purposes, All flight data and server configurations are retained for 24 months minimum, may be retained longer for historical analysis
Partner Data Sharing
Approved third-party projects receive comprehensive access to: (1) Flight data from all servers using Cephie Studios services, (2) Server configuration data and administrative settings, (3) User statistics and behavioral data, (4) Historical data and trends across the entire platform, (5) Real-time data feeds for approved integrations
Security and Compliance Monitoring
All API activity is monitored 24/7 for security threats and policy violations, Automated systems detect and respond to suspicious activity, Rate limiting and abuse detection systems collect and analyze usage patterns, Security incidents are logged and investigated with full data retention
17. Data Subject Rights Limitations
While we respect user privacy, data subject rights are limited by operational requirements:
Right to Access
Access requests are subject to verification and security review, Some data may be withheld for security, legal, or operational reasons, Access may be denied if it conflicts with our legitimate business interests
Right to Rectification
Data corrections are subject to verification and technical feasibility, Some data may be immutable due to system architecture or legal requirements, Corrections may be denied if they conflict with operational integrity
Right to Erasure
Deletion requests are subject to our retention policies and legal obligations, Some data must be retained for security, compliance, or operational purposes, Erasure may be denied if it conflicts with legitimate business interests or legal requirements
Right to Portability
Data portability is subject to technical limitations and security requirements, Some data may not be portable due to system architecture or third-party integrations, Portability requests may be denied for security or operational reasons
18. Enforcement and Compliance
We maintain comprehensive enforcement and compliance measures:
Policy Enforcement
All policy violations are investigated with full data retention and analysis, Enforcement actions may include permanent bans, data sharing restrictions, and legal action, Violation records are shared with partners and third-party services as necessary
Legal Compliance
We comply with all applicable laws and regulations, including data protection, privacy, and security requirements, Legal process and law enforcement requests are handled with full cooperation and data disclosure as required
Audit and Review
All data practices are subject to regular internal audits and reviews, Third-party audits may be conducted for compliance verification, Audit results may be shared with partners, regulators, or legal authorities as required
19. Contact Information
For privacy-related questions or requests, contact us at [email protected]. Please note that all communications are subject to review and may be used for service improvement purposes. Response times may vary based on the nature of your request and operational priorities.
