Skip to content

Privacy

What Aurora Scripts collects, where it is kept, and what you can ask us to do with it.

Effective 8 August 2026. This notice covers this website, the store, and the Aurora Scripts Discord server. It is written against the General Data Protection Regulation (EU) 2016/679.

Controller: Aurora Scripts, a sole trader established in Portugal. Contact: support@aurora-scripts.com. Full legal identity is available on request and to any supervisory authority.

Reading the site identifies you to nobody. Buying does, and that part is covered under the store.

  • No cookies. Not one, on any page.
  • No third-party trackers. Nothing on the site follows you to other sites.
  • While you are only reading, one item is kept in your browser’s local storage, starlight-theme, which remembers whether you chose the light or dark theme. It never leaves your browser.
  • Hosting: Cloudflare Pages. Like any web server, it processes your IP address to deliver the page and to absorb attacks.
  • Audience measurement: Cloudflare Web Analytics, which is cookieless and does not build a profile of you or track you between sites. It tells us how many people read a page, not who they were.

Because there are no non-essential cookies and no tracking, there is no consent banner to click. That is deliberate.

Everything to do with money happens on Tebex, who license the resource to you and are the merchant of record. No card number, billing address or email ever reaches this website, and we have no way to read them afterwards.

Adding something to the basket asks you to sign in twice, and each sign-in earns its place:

Sign-in What we end up with Why it is needed
Cfx.re Nothing at all: Tebex ties the basket to your account and we never see it Your licence is delivered through Cfx.re asset escrow, so the purchase has to be attached to the account that will run it
Discord Your Discord user ID It travels with the order so Tebex’s own bot can give you the customer role when you type /claim

The Discord sign-in uses the identify scope, the narrowest one Discord offers: your ID, username and avatar, and no email address. We ask Discord for your ID, keep the ID, and discard the access key in the same breath. It is never stored, and your password stays between you and Discord.

Two items are kept in your browser’s local storage once you start buying, and neither is sent anywhere except where the table above says:

  • aurora-basket-ident: which basket is yours, so it survives the sign-in redirects and a closed tab.
  • aurora-discord-id: your Discord ID, so a second purchase does not walk you through the sign-in again.

Clearing this site’s browser data removes both. The basket itself lives on Tebex’s servers, under their retention rules.

Discord itself decides how it handles your account. See Discord’s privacy policy. What follows is only what our own bot stores, on a server we rent.

What Why
Your Discord user ID To connect a ticket, a sanction or a suggestion to you
Support tickets: your answers to the opening form, who handled it, when it opened and closed To answer you, and to know how many tickets are open
Moderation records: warnings, timeouts, kicks and bans, with the reason and the moderator So a third offence is treated as a third offence, and so an appeal has something to argue with
Suggestions you post and votes you cast To run the suggestions board
Reviews you write when a ticket closes See Reviews below; some of them are published

Three things we deliberately do not keep:

  • Your purchases. Buyer verification is done by Tebex’s own Discord bot. You type /claim and it gives you the role. We see the outcome, not the transaction. No purchase data reaches our database.
  • The roles you had when you left. Leaving drops them. If you come back and you have purchases, /claim gives them back, which means we do not have to keep a record of you after you are gone.
  • The conversation itself. When a ticket closes, the bot builds the transcript, sends it to you by direct message, and deletes the file. We do not keep a copy. The only one that exists is yours. What you do with it is your business, and if you come back with the same problem, bring it with you.

Legal basis. Tickets: performance of a contract, and answering you is the point of the channel. Moderation records: our legitimate interest in running a community that is usable for everyone else. Suggestions: your own act of posting them.

Where it is kept. On a virtual machine rented from Oracle Cloud, in Frankfurt, Germany. Backups sit on the same machine. Oracle operates the infrastructure under its own terms and privacy policy, which govern what it does as our processor.

How long. A routine in the bot deletes on a schedule. It is not a promise to do it by hand when someone remembers:

The ticket: its number, who opened it, when, and the answers you gave to the opening form 90 days after it closes
Moderation records 90 days. They stop counting towards escalation after 30; the rest is margin for an appeal
Suggestions While they are on the board. They go when you ask

The conversation is not on that list because it is not kept at all. See above.

You can ask for any of it to be deleted earlier, and we will unless the limit below applies.

When a ticket closes, the bot asks whether you want to rate it. Answering is optional and nothing happens if you ignore it. There are two kinds, and they do not end up in the same place:

Kind About Where it goes
Support How the ticket was handled Stays in Discord, in a channel the team reads
Product A script you own Published on that product’s page on this website

A product review is published only after someone on the team approves it. What goes on the page is the star rating, your words, the month, and the name you sign it with, a name you type yourself, in a box that starts empty. A first name is plenty. Nothing is taken from your Discord account: not your display name, not your avatar, not your tag, and not your user ID, which stays in our database so that we know you have already reviewed that script.

Legal basis. Your consent, given by writing it. You can withdraw it at any time.

How long. For as long as it is on the page. Ask us and it goes: the file the website reads is rebuilt from scratch on the next batch, so a removed review simply is not in it. A review the team refuses is not kept: the text and the name are wiped on the spot.

The Aurora HUD saves each player’s layout, settings, widget unlocks and stress value in a table called aurora_hud_presets. That table lives in the database of the server you are playing on. The server owner controls it; we never see it and it is never sent to us.

If you play on someone’s server and want your row removed, ask that server’s owner. If you are the server owner, you are the controller of that data.

Purchases go through Tebex, which is the seller of record. Whatever you type at checkout (name, address, payment details) goes to Tebex, not to us. See Tebex’s privacy policy.

We never see your card details. We can see the transaction itself (the packages, the amount, the date) because Tebex shows it to us in its creator dashboard, the same way any supplier sees what was ordered. That record is Tebex’s, held on Tebex’s systems under their policy. We do not copy it into a database of our own.

You can ask us to give you a copy of what we hold about you, correct it, delete it, restrict what we do with it, or hand it over in a portable form. You can object to processing we base on legitimate interest. Write to support@aurora-scripts.com; we answer within one month.

One limit worth being straight about: we will not delete a moderation record while the sanction it justifies is still in force. Deleting it would erase the reason for the sanction, and that helps nobody, including you, if you ever want to argue with it.

If you think we handled your data badly, you can complain to the Portuguese supervisory authority, the CNPD, or to the authority where you live.

This page keeps the date it last changed. Material changes are announced in the Discord.