AOX privacy details

Who operates AOX

AOX Community Client is operated by Pavel Vacek, known as PAVVAC. Privacy contact: pavvac.aoex@gmail.com. You can also send a private request at the bottom of Client settings. This free community project does not require your address or legal name for ordinary use.

Discord sign-in and your account

Discord provides your account identifier, username, display name and, where available, your community nickname. We use this to create and identify your AOX account. We do not request your Discord email address or read your Discord messages. Discord access and refresh tokens are not kept after sign-in. Sign-in on your PC remains active until you sign out, your account is disabled, or access is revoked for security or account recovery. Your client sign-in credential is protected by Windows for your Windows user account.

Community profile and messages

Signed-in players can see your display name, selected portrait and frame, community statistics, titles and online status. Your account also holds Exigo Tokens and progress recorded by the service. General chat is visible to signed-in players. Direct messages are visible through the service to their participants; they are not imported from Discord. Local game saves, local preferences and local test unlocks are not automatically uploaded.

Why information is used

Account identification, community profiles and delivery of messages are necessary to provide the service you choose to use. Security, moderation and prevention of abuse are based on the project’s legitimate interests. Handling privacy requests is necessary to meet data protection obligations. We do not sell personal information, use advertising profiles or add tracking analytics.

Security and service providers

The client connects to the account service over HTTPS. Cloudflare Workers and D1 host the service and database; D1 encrypts stored data. Direct messages are not end-to-end encrypted: the backend processes readable message content and the operator can access stored data when necessary for operating the service, security or handling a request. This is not a promise that the operator can never read a message. Discord operates its own sign-in service under its own privacy terms. Hosting providers may process data internationally under their applicable contractual transfer safeguards.

How long information is kept

Account data is kept while your account exists. Chat history is never automatically removed because it is old. Deleting a message clears its stored text and retains a deleted-message marker to keep conversation ordering and prevent duplicate sends. Abandoned Discord sign-in attempts expire after 10 minutes. Short security rate-limit records are cleaned after approximately a day. Prepared personal-data download copies expire after 14 days; this does not remove the original account data or chat. Privacy request text and verification notes are cleared one year after closure, while minimal request outcome records remain. An account removal clears account identifiers, profile data, progress and authored message text. Anonymous conversation markers, other participants’ messages, and minimal moderation or request outcome evidence may remain to protect other people’s rights and maintain service integrity. Provider backups can temporarily retain previous data until the provider’s configured backup period ends; restoration must reapply completed erasure actions.

Your choices and rights

You can sign out, change your unlocked appearance, delete your messages and block direct messages. At Client settings → Privacy → Contact / My requests you can ask for a copy of your personal data, correction, removal of your AOX account, recovery or transfer, or send another privacy question. You can also request restriction of processing, object to processing based on legitimate interests, and request portability where applicable. Requests are normally answered within one calendar month. If an extension is legally needed, you will be told within that period with the reason. A data copy can include information about other people, so it is reviewed before delivery and any withholding is explained. If you have concerns, contact PAVVAC. You can also complain to the relevant data protection authority. Sending a request is optional and no extra privacy confirmation is required to use the client.

Account recovery and removal

If you lose access to Discord, sign in with your new Discord account and explain which AOX account you want to recover, or email the operator if you cannot sign in. Ownership is checked manually. An approved transfer changes the Discord sign-in for the existing AOX profile and revokes its previous sign-ins. Current progress is preserved, including progress earned before a later transfer back. Staff privileges are not transferred by this tool. Accounts with conflicting progress or restrictions are not automatically merged. Removing an AOX account does not remove Discord or local game saves. The removed account cannot receive further in-client replies. PAVVAC explains the removal decision before acting. For follow-up questions after removal, contact pavvac.aoex@gmail.com. Notifications and request replies are provided inside the client; no automated notification emails are sent.

Version: 2026-10-06-draft

Contact PAVVAC