Privacy information Effective date: August 20, 2026 The Sephiria records service uses game records submitted by users and account information verified through Steam sign-in to provide record browsing, build statistics, and personal profiles, and to protect the service. 1. Information we store - The 17-digit SteamID64 verified through Steam OpenID sign-in. The records database stores an identifier transformed using HMAC with a server secret. We do not receive your Steam password or Steam Guard codes. - A signed HttpOnly cookie for your sign-in session and a temporary nonce cookie for sign-in verification. - Gameplay records you submit: submission time; game, mod, and schema versions; clear outcome; stage; and gameplay data such as character, costume, weapon, equipment, passives, miracles, and damage. - Personal profile information: a nickname of up to 8 characters, nickname changes and their timestamps, a recorder number that is never reassigned, a random identifier for the public URL, the selected character costume image key, and visibility settings. - Statistics calculated from records, including submission, play, and clear counts; clear rate; most-played weapons and costumes; and recent records. - Items you manually mark in the unplayed collection and the times they were marked. - Comments and replies on AI-recommended builds, optional anonymous nicknames, creation/edit/deletion timestamps, and the build revision at the time of posting. Anonymous comment passwords are stored as verification hashes rather than plaintext. Steam comments and likes use hashed account identifiers. - Record-hiding and deletion requests, inquiry text and processing status, and security, error, and rate-limit logs. - When Google Analytics is enabled, site usage statistics such as pages visited, access environment, referral sources, and usage flows. 2. Profiles and recorder numbers - After signing in through Steam, you can save a nickname and avatar before submitting records. When the first validated record is stored, the server assigns a number once, starting at #0000 in the order records are received. A number is never reassigned to another person, even after a nickname change or account deletion. - Your nickname is stored separately from the player name in the original record. Changing it updates the nickname shown on past records in public views, while the original data received is preserved for record integrity. - Profiles are private by default. Only when you make your profile public do we display your nickname, recorder number, character avatar, aggregate statistics, and recent public records at a random public URL. - Private or hidden records are excluded from public profile statistics and recent records. Public profiles do not display the original SteamID64 or internal HMAC identifier. 3. Record submission and public collection The currently distributed SephiriaBuildReporter sends records to the public collection API without a separate API key. All records accepted after checks on format, request volume, and SteamID consistency may be used to assign recorder numbers and provide personal profile statistics, public records, and build statistics, whether they were submitted with a legacy upload key or without a key. Submission time is the time the server successfully accepted the record, not the client time. Keyless submission is not linked to Steam sign-in. We check the SteamID64 format and consistency between fields in the payload, but cannot fully prove that the submitter owns the account or that the record reflects actual gameplay. Inclusion in recorder numbers and profile statistics means the received data was grouped by that SteamID64; it does not guarantee account ownership or the authenticity of the result. The current release sends only one event type: build_snapshot. It may include the uploader's SteamID64, the ending outcome, run/stage/difficulty, costume and weapon progression, and equipment/passive/miracle information. It does not send other participants' SteamIDs, nicknames, or individual damage, and does not send solo-play damage either. It also does not send separate boss_clear or game_over events. 4. How information is used - To let you view and hide your records, request deletion, and manage your personal profile. - Manual marks are used only for your personal collection and do not affect public rankings or build statistics. - To provide public records, popular and recent builds, weapon statistics, and detailed gameplay information. - To merge duplicate submissions, limit invalid or repeated requests, investigate service errors, and prevent abuse. - To identify inquiry authors, verify permission to edit or delete inquiries, and maintain operational audit records. - To publish feedback on AI-recommended builds, verify comment ownership and duplicate likes, and review suggestions for improving builds. - To improve features and usability using anonymized site usage statistics. 5. Retention, hiding, and deletion Submitted records and profiles are retained for as long as needed to provide record browsing and statistics. In My records (https://sephidata.cloud/en/me), you can make your profile private, hide your own records, or request deletion. During deletion processing, request status, the reason for the action, and minimal audit logs may be kept longer to protect the service and prevent duplicate processing. Removing a manual mark from the unplayed collection deletes that manual-mark row. Submitted original game records are stored separately and are not deleted by this action. Deleting a comment or reply on an AI-recommended build removes its text, nickname, author-account link, anonymous password hash, and likes. Minimal history, such as build/reply links and the deletion time and category, is retained to preserve the deleted position and conversation structure. Replies written by others remain when the original comment is deleted. 6. Cookies and external analytics - Steam session and nonce cookies use HttpOnly and SameSite settings. - When Google Analytics is enabled, Google may process site usage statistics using cookies or similar technologies. See Google's Privacy Policy (https://policies.google.com/privacy) for details. - You can limit analytics collection through browser settings or the Google Analytics opt-out tool (https://tools.google.com/dlpage/gaoptout). 7. Security measures - SteamID64 is transformed using HMAC with a server secret before storage. - Profile modification APIs use sign-in sessions, internal service authentication, and CSRF protection. - We validate upload size, format, SteamID format, and duplicate IDs, and limit request rates by IP address and account. - The production environment is configured to use HTTPS and secure cookie settings. 8. Contact You can manage profile settings, hide records, and request deletion in My records (https://sephidata.cloud/en/me). For other questions, sign in and use the inquiries page. Avoid including sensitive information that you do not want to make public in your inquiry. Back to home (https://sephidata.cloud/en)