forked from Valour-Software/Valour
-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathPRIVACY
More file actions
438 lines (331 loc) · 17.8 KB
/
Copy pathPRIVACY
File metadata and controls
438 lines (331 loc) · 17.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
Privacy Policy
==============
Last updated: September 26, 2026
This Privacy Policy explains what data Valour collects, why we collect it,
who receives it, and how you can control or delete it. We aim to collect
only what is necessary to run the service.
Valour is operated by Valour Software LLC ("the Company", "we", "us", "our").
This policy covers Valour on every platform: the website (valour.gg), the
web app (app.valour.gg), and the Valour apps for desktop and mobile devices.
You can reach us at support@valour.gg.
What We Collect
===============
Account Information
-------------------
When you register, we collect:
* Email address: for account verification, password recovery, security
notices, and important service or policy updates
* Username and tag: your display identity on the platform
* Password: stored as a salted hash, never in plain text
* Date of birth: to confirm you meet the minimum age and to apply safer
defaults for users under 18
Optionally, you may provide:
* Invite code: records which invite brought you to Valour
* Referral source: how you heard about us (e.g. YouTube, Twitter)
* Two-factor authentication: a secret used to generate sign-in codes
* Linked accounts: if you sign in with Google or Discord, we receive that
account's ID, email address, name or username, and profile picture. We
keep the account ID and a label (your Google email or Discord username)
so you can sign in with it and see it in your settings. The picture is
used only if you choose it as your avatar.
* Fingerprint sign-in: your fingerprint never leaves your device. The
Valour app creates a key on your device that only works after your
fingerprint is checked. We store the public part of that key and your
device's name.
Profile Information
-------------------
You may optionally fill in:
* Profile headline and bio
* Avatar and profile background images
* Theme colors and border style
All profile information is user-provided and publicly visible to other
Valour users.
Messages and Content
--------------------
Chat messages in direct messages, group chats and planet channels are end-to-end
encrypted. Your device encrypts the text and embeds of each message
before sending it, and only members of the conversation hold the keys to
read it. Our servers store the encrypted message, but not the keys needed
to read it.
To deliver messages, our servers still see information about them: who
sent a message, to which channel, and when; which message it replies to;
who it mentions; its reactions and custom emoji; and records of its
attachments. The servers can read message content in these cases:
* Messages sent by webhooks, automated moderation, and the system itself
are encrypted by our servers.
* When you report a message, the report includes its readable text so
moderators and our staff can review it.
* Messages sent before end-to-end encryption was introduced may remain
stored without it.
Other content is not end-to-end encrypted. It is stored so that the
people who can access it are able to see it:
* Files, images and GIFs attached to messages
* Threads and thread comments, wiki pages, and calendar events in planets
* Planet names, channel names, roles, and other planet settings
* Link previews: when a message contains a link, our servers fetch the
page to build a preview
Voice and Video Calls
---------------------
Voice and video calls are carried by Cloudflare's real-time service, or by a
server the planet's owner has configured for the planet. Calls are not
recorded or stored, and they are not end-to-end encrypted. We store basic
call records: who called whom and when the call started and ended.
Technical Data
--------------
* IP address: recorded on each sign-in session for account security.
It is kept with the session record until the session is removed.
* Device type: a mobile or desktop flag, used to show your online status
* Presence and activity: your online status, when you were last active,
which messages you have read, and one record per day you use Valour,
used to run the service and to count active users
* Push notification registrations: to deliver notifications to your
devices
We do NOT collect:
* Your real name, phone number, or physical address
* Your location, contacts, or advertising identifiers
* Browser fingerprints or tracking pixels
* Page views or session analytics from third-party analytics tools
We do not use Google Analytics or any other third-party tracking or
advertising software.
Device Permissions
------------------
The Valour apps may ask for these permissions, depending on your device:
* Microphone and camera: for voice and video calls
* Notifications: to show message and call notifications
* Fingerprint: to sign in with your fingerprint, if you turn it on
* Files and photos: only the files you choose to upload, using the system
file picker
How We Use Your Data
====================
We use your data to:
* Operate the service: deliver messages, manage your account, authenticate you
* Verify your age: ensure compliance with COPPA (minimum age 13)
* Keep accounts and communities safe: detect unauthorized access, enforce
our rules, and review reports
* Send service emails: account verification, password recovery, security
notices, and important updates about the service or our policies
* Process payments: if you purchase a subscription (handled by Stripe)
* Fix problems: diagnose errors and keep the service running reliably
We do NOT use your data to:
* Send advertising or marketing on behalf of anyone else
* Serve advertisements
* Build behavioral profiles
* Sell or rent to third parties
Legal Basis for Processing (GDPR)
----------------------------------
If you are in the EU/EEA, here is the legal basis we rely on for each type
of processing:
* Contract (Art. 6(1)(b)): account registration, message delivery,
calls, payment processing, and all core service functionality. We need
your email, username, password, and messages to provide the service you
signed up for.
* Legal obligation (Art. 6(1)(c)): age verification (COPPA), preserving
material related to child sexual abuse when required by law, and
responding to lawful government requests.
* Legitimate interest (Art. 6(1)(f)): IP address on sign-in sessions for
account security and fraud prevention, server error monitoring, and
counting active users. Protecting accounts on the platform requires
this processing, so it cannot be disabled on a per-user basis.
* Consent (Art. 6(1)(a)): error reports sent from your device to Sentry.
You can withdraw consent at any time in your preferences.
Third-Party Services
====================
These services receive limited data to provide specific functionality:
* Microsoft Azure: hosts our servers and databases.
Privacy statement: https://privacy.microsoft.com/privacystatement
* Cloudflare: protects and speeds up our network traffic, stores uploaded
files and images, and carries voice and video calls. For calls,
Cloudflare receives your username, user ID, and the channel you join.
Privacy policy: https://www.cloudflare.com/privacypolicy/
* SendGrid: delivers our emails (verification, password recovery, security
notices, and service updates). We have disabled click tracking.
Privacy policy: https://www.twilio.com/legal/privacy
* Sentry: receives error reports. Reports from your device are sent ONLY if
you opt in via your preferences. Errors on our servers are also reported
to Sentry, without request contents or personal details such as your
email or IP address.
Privacy policy: https://sentry.io/privacy/
* Stripe: processes card payments, subscription billing, and checkout
sessions. We never see or store your full payment card details.
Privacy policy: https://stripe.com/privacy
* Firebase Cloud Messaging (Google): delivers push notifications on
Android. A notification includes the sender's name and the channel and
planet it came from. The message text inside it stays encrypted.
Privacy policy: https://policies.google.com/privacy
* Browser push services (such as those run by Google, Mozilla, Apple and
Microsoft): deliver push notifications to web browsers. The contents of
these notifications are encrypted to your browser.
* Google and Discord: if you choose to sign in with one of them, you sign
in on their site and they send us the account details listed above.
Privacy policies: https://policies.google.com/privacy and
https://discord.com/privacy
* Klipy: powers GIF search. When you search for GIFs, your device sends
your search text directly to Klipy, which can see your IP address. Your
GIF favorites are stored on our servers, not shared with Klipy.
Privacy policy: https://klipy.com/support/privacy-policy
We do not share your data with advertisers, data brokers, or any parties
not listed in this policy.
Content From Other Providers
----------------------------
Some content in Valour is loaded directly from other companies. When this
happens, your device connects to that company, which can see your IP
address and may apply its own privacy policy:
* Embedded media in messages, such as YouTube, Vimeo, Twitch, TikTok, X,
Reddit, Instagram, Bluesky, Spotify, SoundCloud and GitHub content
* Images linked from sites such as Discord, Imgur, X, Tenor and Klipy
* Stock ticker widgets from TradingView, shown when a message mentions a
ticker such as $AAPL
* Code libraries and emoji images served by public content networks
(jsDelivr, unpkg and cdnjs)
Images from other websites that are not on this list are loaded through our
servers, so those websites do not see your IP address.
Community Nodes and Other Operators
-----------------------------------
Valour lets communities run planets on independently operated servers,
called community nodes. Before you connect to a new node, Valour asks you
to accept its domain. When you join a planet on a community node, that node
receives your user ID, username, tag, avatar, subscription tier, the age of
your account, and your planet memberships. It also receives everything you
post in its planets, and your device connects to it directly. Each node is
run by its own operator, not by us.
Similarly, a planet owner can configure the planet to store files or carry
calls on servers they operate. Files and calls in that planet then go to
the owner's servers.
Bots and third-party applications you authorize can access the data you
grant them, and bots in a planet can see the activity their permissions
allow.
International Data Transfers
-----------------------------
Our servers and several of our third-party service providers are based in
the United States. If you are located outside the US, your data will be
transferred to and processed in the US. Our third-party providers each
publish their own GDPR compliance documentation and data processing terms,
which you can review at the links in the Third-Party Services section
above. These transfers are necessary to perform our contract with you
(Art. 49(1)(b)) and are further protected by our providers' data
processing agreements.
Valour Software LLC is the data controller. Our third-party service
providers act as data processors under data processing agreements.
Error Reporting (Opt-In)
========================
The Valour apps use Sentry for error reporting. Reports from your device
are fully opt-in. By default, no error data is sent. You can control this
in your user preferences:
* Off (default): no error data is sent
* On: error logs, stack traces, and basic device info are sent to Sentry
You can change this setting at any time.
Data Retention and Deletion
===========================
We retain your data for as long as your account exists, with these
exceptions:
* Sign-in sessions expire after 7 days. Session records, including their
IP address, are kept until you sign out, revoke the session, or delete
your account.
* Read notifications are deleted after 30 days.
* When you edit or delete a message, a record that proves the change
(without the message text) is kept for 180 days.
* Our hosting provider keeps automatic database backups for disaster
recovery. Backups expire on a rolling schedule, and deleted data is
removed from them when they expire.
* Our servers keep operational logs for troubleshooting and security.
These logs can include user IDs and the email addresses we send mail to.
You can permanently delete your account at any time through the app or at
app.valour.gg. Deletion is immediate. When you delete your account, we
delete:
* Your account details, credentials, linked Google and Discord accounts,
fingerprint sign-in keys, sessions, profile and preferences
* All your messages, their attachments, and your direct message
conversations
* Files you uploaded
* Threads you started; comments you left on other threads become empty
placeholders
* Your friends, blocks, and memberships
* Your notifications, push registrations, and activity records
* Your economy accounts and transaction history
* Your encryption key backups and linked devices
* Your referral records
Your subscription is cancelled when you delete your account. Some data is
kept after deletion: planets you own stay with their communities, shared
planet content (such as wiki pages and calendar events) stays without a
link to you, your public encryption keys stay so others can verify past
messages, and safety records are kept as the law requires. See
https://valour.gg/delete-account/ for step-by-step instructions and the
full list.
This deletion is permanent and cannot be undone.
Data Security
=============
All connections to Valour are encrypted in transit with TLS. Passwords are
hashed with PBKDF2 (SHA-256, 600,000 iterations) and a unique salt before
storage. Authentication uses token-based sessions stored on your device; we
do not use HTTP cookies for authentication or tracking. The private keys
used for end-to-end encryption are created and kept on your devices. You can
view and revoke individual sessions from your account settings.
No method of electronic storage is 100% secure. While we use reasonable
measures to protect your data, we cannot guarantee absolute security.
If you are a security professional and discover a vulnerability,
please report it to us at support@valour.gg and consider contributing
to our open-source codebase to help us improve security.
Your Rights
===========
Regardless of where you live, you can:
* Access your data: view your profile, messages, and active sessions
through the app
* Correct your data: update your profile, email, and username at any time
* Delete your data: delete individual messages and files, or permanently
delete your account
* Revoke sessions: individually revoke any active login session
* Control error reporting: opt in or out of error reporting at any time
For EU/EEA Residents (GDPR)
----------------------------
You additionally have the right to:
* Request a copy of your personal data
* Object to processing of your data
* Request restriction of processing
* Data portability: receive your data in a machine-readable format
* Withdraw consent at any time
* Lodge a complaint with your local data protection authority
For California Residents (CCPA/CPRA)
-------------------------------------
We do not sell or "share" (as defined by the CPRA) your personal
information for cross-context behavioral advertising.
The table below fulfills our disclosure obligations under Cal. Civ. Code
§ 1798.110 and § 1798.115:
| Category | What we collect | Source | Purpose | Shared with |
| --- | --- | --- | --- | --- |
| Identifiers | Email, username, IP address | You / automatic | Account operation, security | Azure (hosting), SendGrid (email), Cloudflare (calls) |
| Customer records (Cal. Civ. 1798.80e) | Email, hashed password | You | Authentication | Azure (hosting) |
| Internet activity | Device type, online status, last active time, days active | Automatic | Online status, service delivery, active user counts | None |
| Sensory data | User-uploaded images, video, audio; live call audio and video (not recorded) | You | Message delivery, content sharing, calls | Cloudflare (storage, calls) |
| Commercial info | Subscription status | You / Stripe | Payment processing | Stripe |
| Age / DOB | Date of birth | You | COPPA age verification | None |
We do not collect: protected classifications, biometrics, geolocation,
professional/employment info, education records, or inferences.
Your CCPA/CPRA rights:
* Right to know: what data we collect and how we use it (see above)
* Right to delete: request deletion of your data at any time
* Right to opt-out of sale: we do not sell your data, so there is
nothing to opt out of
* Right to non-discrimination: we will not treat you differently for
exercising your rights
To exercise any of these rights, contact us at support@valour.gg.
Children's Privacy
==================
Valour requires users to be at least 13 years old. We collect date of birth
at registration to verify this. Accounts of users under 18 only accept
direct messages from friends by default. If you believe a child under 13
has created an account, please contact us at support@valour.gg and we will
delete it.
Disclosure for Legal Reasons
============================
We may disclose your data if required by law, court order, or government
request. We also reserve the right to reject unlawful requests to protect
our users' privacy and safety.
Changes to This Policy
======================
We will notify you of significant changes by posting the updated policy and
updating the date above. Continued use of Valour after changes constitutes
acceptance of the revised policy.
Contact
=======
If you have questions about this Privacy Policy:
* Email: support@valour.gg