Data handling

Privacy, without fog.

VividHub stores only the data needed to authenticate users, validate access, and investigate abuse.

What is stored

Discord account identifiers and usernames, hashed access keys, key status, IP addresses, HWIDs, user agents, and security event timestamps.

Why it is stored

Account data connects keys to users. Device and network data enforces access rules, rate limits validation, and supports abuse investigation.

Retention

Administrators should define a retention period appropriate to their jurisdiction. Audit logs can be deleted from D1 after that period without affecting active keys.

Security

Full access keys are never stored after a KeyAuth CSV import. D1 keeps SHA-256 hashes and short display prefixes. Session cookies are signed, HTTP-only, and secure in production.