Legal
Privacy Policy
What we collect
Account details. When you register, we store your email address, username, and a secure hash of your password. If you sign in through discord or Google, we store the profile handle that provider returns.
Projects and keys. The projects you create, the keys you issue, and their licence records live in your account. Keys are tied to hardware identifiers (HWIDs) so they can be bound to a device and can't be shared.
Hardware and device signals. When a key is activated or validated, we receive the hardware fingerprint and user-agent sent by the requesting client. These are used only to enforce HWID binding.
Checkpoint activity. When a user goes through a checkpoint flow, we record session progress and which ad networks completed. For anon/user sessions we may capture an approximate country code; raw IP addresses are not stored.
Scripts you upload. Lua scripts you add to a project are stored so they can be loaded at runtime. Files must be under 8 MB and only one script is attached per project.
Why we process it
Everything we collect exists to make the service work: issuing and validating keys, enforcing hardware binding, delivering scripts, running checkpoint flows, and showing developers aggregate usage analytics. We also use limited data to protect the platform — throttling abusive requests and blocking attempts to bypass or scrap the system.
Vampauth is free for developers and users. The platform earns a share of ad-network revenue generated when users complete checkpoint links; this is a product fact, not a reason to process anything beyond what the flow itself sends us.
What we don't share
We do not sell user data. We do not rent lists. We never expose hardware identifiers or private project signing keys through public endpoints. Data is shared only with the infrastructure providers that run the platform (hosting and object storage) and only to the extent they need to serve those systems.
Infrastructure providers
Vampauth runs on Supabase (database, authentication) and Backblaze B2 (private object storage for scripts). These providers process data on our behalf under their own terms and security commitments. Checkpoint links direct users to third-party ad networks (linkvertise, lootlabs, and others); those services are controlled by their respective operators, and what they collect after a redirect is governed by their policies, not ours.
Retention
We keep your account, projects, keys, and scripts while the account is active. HWIDs and session records are retained to keep binding state consistent and are deleted when the related key is deleted or an account is removed. When you delete your account, the associated records are removed from the system.
Cookies and local storage
The dashboard stores your session token in a cookie so you stay signed in, and saves your appearance preset (accent, shade, font) in local storage on your device. These are functional, not tracking: there are no advertising or cross-site tracking cookies on our own pages.
Security
Passwords are hashed, connections are encrypted, and database access is locked down with per-table permissions so no role can reach data it doesn't need. All script files sit in a private bucket and go out only through guarded endpoints. No storage is perfect, but we keep exposure to the minimum the product requires.
Children
Vampauth is not directed at children under 13 and we do not knowingly collect their information. If you believe a child has given us data, contact us and we will delete it.
Your choices
You can update your profile, rotate your client secret, and delete your account at any time from the dashboard. To exercise any privacy right — access, correction, deletion — or to request details of what we hold about you, write to us at the address below.
Changes
We may update this policy as the product grows. When we do, the date above changes and, for important changes, we'll call it out inside the dashboard before it takes effect.