Privacy

Privacy Policy

The Sephiria records service (sephidata.cloud) is a game records website operated by an individual. This policy explains the information we collect, why we use it, and how we keep and delete it. Send privacy inquiries to sephidata@gmail.com.

Last revised: September 25, 2026

1. Information we process and why

  • Sign-in and record management: We receive your SteamID64 through Steam authentication and mod submissions. Account identifiers are transformed using HMAC before being stored in the records database. They can link records from the same account, so they are not fully anonymous. We do not receive your Steam password or Steam Guard codes.
  • Records, profiles, and statistics: We process gameplay and submission times, game and mod versions, progress and clear results, equipment, costumes, damage, and other gameplay records. We also process nicknames and their change history, recorder numbers and public IDs, avatars and visibility settings, and personal collection marks and their timestamps. Manual marks are used only in your personal collection and do not affect public rankings or build statistics.
  • Comments, inquiries, and rights requests: We process post and reply text, nicknames, creation and edit times, account links, likes, anonymous comment password hashes, reply email addresses, and hiding and deletion requests and their processing history. We use security and request logs, which may include IP addresses, to investigate errors and prevent abuse.
  • Visitor statistics: If you allow analytics, we use Google Analytics to analyze pages visited, country, browser and device information, referral sources, and site usage. The view, download, and preset-copy events configured directly by this site do not include SteamIDs, nicknames, post text, or personal record identifiers in their event fields.
  • Advertising integration and delivery: If you allow advertising, Google AdSense and advertising providers may process page URLs, IP addresses, browser and device information, cookie identifiers, and ad interactions. This information is used to deliver ads, measure performance, and prevent abuse.

2. Record submissions and public visibility

The current SephiriaBuildReporter mod sends only build_snapshot events. These include the uploader's SteamID64, gameplay results, and equipment setup. In multiplayer, they may also include the number of participants and the uploader's own total damage. Other participants' SteamIDs, nicknames, and individual damage are not sent, nor is solo-play damage. Separate boss_clear and game_over events are not sent either. Accepted records may be used for recorder numbers, profiles, public records, and build statistics, whether or not they were submitted with an upload key. Account ownership and the authenticity of records submitted without a key are not fully verified.

After installation, the mod automatically submits records under its default settings. To stop, fully exit the game, set EnablePost=false in the configuration file, and restart. This does not delete records already stored.

Profiles are private by default. Making yours public displays your nickname, recorder number, avatar, aggregate statistics, and recent public records. Individual game records you submit may be used for public records and build statistics. Making your profile private does not stop this; you can hide individual records in My records. Public profiles do not display original SteamIDs or internal HMAC identifiers.

3. Retention and deletion

Game records, profiles, and personal collections are kept for as long as needed to provide the records service. Comments and inquiries are kept for as long as needed to publish posts, provide replies, and handle requests. Security logs and processing history are kept for as long as needed for their purposes, such as investigating errors and preventing abuse. We delete information without undue delay in response to a valid deletion request, when it is no longer needed, or when the service closes. If retention is required by law, only the relevant information is kept separately for the required period.

Hiding a record is different from deleting it. When a game record deletion request is processed, the target record and its original events are deleted, but your entire profile, comments, and inquiries are not deleted with them. Removing a personal collection mark deletes only that mark. Deleting a comment removes its text, nickname, author link, password hash, and likes, while preserving a minimal conversation structure and replies from other people. Inquiry posts can be deleted using the delete function on each post.

To request deletion of all account information or other personal information, email sephidata@gmail.com. The operator will verify your identity and the scope of the request before handling it. Electronic information marked for deletion is deleted so that it cannot be recovered or reproduced, and we also check copies such as backups and administrator notification emails. Copies are managed separately and may not be deleted at the same time as the originals. If any information remains, we explain why and how it will be handled. Signing out, stopping submissions, or deleting cookies does not delete existing information on the server.

4. Cookies, analytics, and ad settings

  • Sign-in cookies contain your SteamID64 and their issue and expiry times, and expire after 7 days. They are deleted when you sign out. Temporary sign-in verification cookies and mod download notice acknowledgement cookies last 10 minutes; language preference cookies last 1 year.
  • Analytics and advertising are off initially. Google Analytics and AdSense load only after you allow the respective purpose. You can change or withdraw your choices at any time through “Analytics & ad choices” in the page footer. Your choices are kept in this browser’s local storage for 180 days. If storage is unavailable or the choices expire, you must choose again. See Google’s Privacy Policy and its partner site information for details.
  • You can block or delete cookies through your browser settings, which may limit features such as staying signed in. In supported browsers, you can also use the Google Analytics opt-out tool. GA user and event data retention is set to 2 months, with the reset on new activity disabled. This setting does not determine the retention of most standard aggregate reports.
  • Even when you allow advertising, the site requests non-personalized ads. These ads may still use cookies and process information for ad delivery, measurement, and fraud prevention. Google may show an additional regional consent message. You can also manage choices in Google’s ad settings. Withdrawing permission on this site stops the relevant tags and reloads the page. It does not automatically delete data already sent to Google or game records on the server.

5. External services

Our servers and database operate in the AWS Seoul Region, and the backup mini PC is also in South Korea. We use Google Analytics (Google LLC) for visitor analytics, Google AdSense (Google Asia Pacific Pte. Ltd.) for advertising integration, and Gmail (Google LLC) to receive and reply to privacy inquiries. Administrator alerts are sent and received through NAVER SMTP and NAVER Mail (NAVER Corporation). Alert emails contain only the alert type and an administrator page link, without users’ nicknames, post text, or individual record identifiers. See the NAVER Privacy Policy for information about the mail service. External providers process information needed for their services, and this may take place abroad.

Steam sign-in uses Valve's authentication to provide us with your SteamID64. See Valve's Privacy Policy for information about Steam's processing. Loading fonts through Google Fonts may send IP addresses, browser information, and similar information to Google. External providers' policies also apply to retention, deletion, and choice settings within their services.

6. Contact and your rights

  • The operator of the Sephiria records service personally handles privacy matters. Send requests to access, correct, or delete personal information, suspend processing, or withdraw consent to sephidata@gmail.com; no sign-in is needed. The operator verifies the requester and the information concerned, handles the request under applicable laws, and informs you of the outcome. We may ask for the minimum additional information needed for verification.
  • In My records, you can manage profile visibility, hide records, request deletion, and block collection of new mod records. Blocking collection prevents new records submitted without a key from being accepted and hides existing records submitted without a key. Turning off the block does not automatically make hidden records public again. Blocking collection is separate from deleting information.
  • Posts on the public inquiries board are public. Do not post email addresses, identity documents, account recovery information, or anything you do not want made public. Use the email address above for privacy inquiries.

7. Protection measures

  • We transform account identifiers, check sign-in and management permissions, protect against forged requests, validate uploads, and limit request volume. Sign-in cookies are signed and use HttpOnly, and the production environment is configured to use HTTPS and secure cookies.

8. Revision history

The revision date appears at the top of this document. You can view the previous notice, dated August 20, 2026. Reading this policy or acknowledging the download notice does not by itself mean you consent to all personal information processing, advertising, or analytics.

Privacy Policy | Sephiria