This Privacy Policy explains what information Nebula ("we", "us", or "our") collects when you use our client portal, software, Discord bot, and related services (collectively, the "Service"), how that information is used, who it is shared with, and the choices you have. By creating an account or using the Service, you acknowledge and accept the practices described here.
Bot commands, support, and community features. Subject to Discord's privacy policy.
Cloud hosting provider
All stored data
The Service is hosted on secured cloud infrastructure. Data resides on encrypted persistent volumes.
We do not sell, rent, or trade your personal data with any other party.
5. Data Sharing & Disclosure
We share your personal data only in the following circumstances:
With service providers — third parties that process data on our behalf to operate the Service (see section 4). These providers are bound by contractual obligations to protect your data and may not use it for any other purpose.
For legal compliance — if required by law, court order, or government regulation, we may disclose data to the relevant authorities.
For safety and security — to protect the rights, property, safety, or security of Nebula, our users, or the public, including investigating fraud, violations of our Terms, or security incidents.
In connection with a business transfer — if Nebula is involved in a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. You will be notified via email before such a transfer occurs.
With your consent — we may share data with third parties when you explicitly consent to the sharing.
We never share your data for advertising purposes or with data brokers.
6. International Data Transfers
The Service is hosted on cloud infrastructure that may be located in a country other than your country of residence. When we transfer your personal data across borders, we take steps to ensure that the transfer is lawful under applicable data protection laws:
For transfers from the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or another lawful transfer mechanism.
For transfers from other regions, we comply with the data protection laws of your jurisdiction.
Our third-party service providers may also process data in their own regions, under their own privacy policies and transfer mechanisms.
If you would like more information about the specific safeguards we use for international transfers, contact us as described in section 16.
7. Data Retention
Data category
Retention period
Account & licence records
For the life of the account + 90 days after deletion
Password hash
Until account deletion
Password-reset tokens
30 minutes, then purged
Session cookies
7 days of inactivity
Portal action & download logs
180 days
Software operational logs
90 days
Ban records
For the duration of the ban + 12 months
Where a retention period has not yet been enforced by an automated purge job, data may be retained longer until the next purge cycle. You may request earlier deletion as described in section 9.
8. Security
Passwords are stored as salted hashes. Plaintext passwords are never stored or logged.
All portal traffic is served over HTTPS / TLS.
Session tokens are protected against cross-site and interception attacks.
Authentication and download endpoints are rate-limited to prevent abuse.
Security measures are in place to protect the integrity of the Service and prevent abuse.
Admin access is separately authenticated and role-restricted.
No method of transmission or storage is fully secure. If a breach occurs that is likely to affect you, we will notify you via email within 72 hours of becoming aware.
9. Software Integrity
Protecting your licence
To protect the value of your purchase and keep the Service fair for all users, the software performs integrity checks while it is running. These checks are limited to protecting the software itself and do not monitor your personal activity.
Device binding — your licence is bound to a single device to prevent unauthorised sharing.
Integrity checks — the software includes measures to protect against tampering and unauthorised use.
Licence validation — the software validates your licence to keep your session active.
These measures are limited to protecting the software and your licence. They do not collect personal files, browsing history, or any data unrelated to the software's integrity.
10. Cookies & Sessions
Session cookie — a single cookie authenticates your portal session. It expires after 7 days of inactivity and carries no personal data beyond a session reference.
Security cookie — a non-identifying token used to validate form submissions and protect against cross-site attacks.
We do not use advertising, tracking, or analytics cookies. No third-party tracking pixels are present on the portal.
11. Your Rights (GDPR)
Depending on your jurisdiction (GDPR, CCPA, and similar laws), you may have the following rights:
Access — request a copy of the personal data we hold about you.
Rectification — correct inaccurate or incomplete data.
Erasure — request deletion of your account and associated data, subject to legitimate retention (e.g. fraud investigations).
Restriction — ask us to limit processing in certain circumstances.
Portability — receive your data in a structured, machine-readable format.
Objection — object to processing based on legitimate interests.
Withdrawal of consent — for any processing based on consent, withdraw it at any time.
To exercise any of these rights, contact us as described in section 16. We will respond within 30 days. We do not charge a fee unless requests are manifestly unfounded or excessive.
You also have the right to lodge a complaint with your local data protection authority (DPA) if you believe our processing of your data violates the GDPR. You can find your local DPA's contact details on the EDPB website.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
Right to know — request the categories and specific pieces of personal data we collect, the sources, the purpose of collection, and the third parties we share it with.
Right to delete — request deletion of your personal data, subject to exceptions (e.g. completing transactions, detecting security incidents, complying with legal obligations).
Right to correct — request correction of inaccurate personal data.
Right to opt out of sale or sharing — we do not sell or share your personal data for cross-context behavioural advertising, so no opt-out is necessary. This right is listed for completeness.
Right to limit use of sensitive personal data — we do not collect sensitive personal data as defined by the CCPA beyond what is necessary to provide the Service.
Right to non-discrimination — we will not discriminate against you for exercising any of these rights.
To exercise your CCPA rights, contact us as described in section 16. We will verify your identity before processing your request and respond within 45 days.
Categories of data collected: identifiers (username, email, Discord ID, IP address), commercial information (purchase history, licence keys), internet activity (user-agent, session data), and inferences drawn from the above (country, derived indicators).
13. Data Breach Notification
We maintain security measures designed to protect your personal data (see section 8). However, no system is completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:
We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
We will notify affected users via email without undue delay, including the nature of the breach, the likely consequences, and the measures we are taking to address it.
If direct notification to all affected users is not feasible, we will publish a public notice on our website and Discord server.
We will document all breaches, their effects, and the remedial action taken, as required by law.
14. Children's Privacy
The Service is not directed at children under 13 (under 16 in the EU/UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be notified via email to registered users at least 14 days before taking effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
16. Contact
For any privacy-related question, data request, or complaint, you can reach us through any of the following: