Data Controller
The operator of RobxScript.com determines why and how personal information is processed through the Website and is the data controller where that term applies. Privacy requests can be sent to robxscript@gmail.com or Telegram @roflandonabol.
This Policy does not state a legal entity name, registered address, country of establishment, or representative because those details are not identified in the Website project information available for this Policy.
Information We Collect
Depending on how you use RobxScript, the Website processes:
- account credentials and account status information;
- profile details and links that you choose to provide;
- scripts, collections, comments, reports, votes, follows, saved items, and messages;
- request, device, browser, security, and rate-limit information;
- page-view and third-party analytics or advertising information;
- cookies and browser storage described in the Cookie Policy.
RobxScript does not ask for payment-card details and the reviewed project does not contain a payment-processing flow.
Account Information
Registration and sign-in use a username, email address, display name, and password. The database stores a one-way password hash, not the ordinary password. Current passwords are pre-hashed and protected with bcrypt; supported legacy password hashes are upgraded after a successful sign-in.
Account records also contain the user role, email-verification status, creation date, and update date. The current database does not contain a dedicated “last login” field.
Sign-in sessions use a random session token. The browser receives the token in therobx_session HttpOnly cookie, while the database stores only a hash of the token and its expiry. The default session period is 30 days, but deployment configuration can change that period.
Password-reset links contain a random one-time token. Only its SHA-256 hash is stored. The token expires after 30 minutes, is marked when used, and a successful password reset invalidates the user's existing sessions.
User-Generated Content
User-provided information may include:
- profile biography, avatar, cover image, style choices, tags, and external website, YouTube, Discord, GitHub, or other profile links;
- script and collection titles, descriptions, code, source and community links, images, game information, developer details, features, platform support, key-system information, guides, FAQs, and updates;
- comments, likes, dislikes, compatibility feedback, saved scripts, follows, and private messages where those features are used;
- reports, reasons, details, and the page URL connected with a complaint or correction request.
Published profiles, scripts, collections, comments, and associated usernames can be visible publicly. Do not publish passwords, private access tokens, payment information, or other sensitive information in public fields or submissions.
Technical and Security Data
Requests can involve an IP address, user agent, request origin, page or API route, timestamps, and browser or device information. The application uses this information to enforce same-origin checks, reject known automated viewers from public view counts, apply rate limits, investigate errors, and protect accounts and submissions.
Rate limiting creates an in-memory identifier derived from the request IP address, action scope, and, where relevant, an account or form identifier. It expires with the applicable rate-limit window and is not stored in a dedicated database table.
Page-view deduplication stores a SHA-256 visitor hash, content identifier, and timestamps in the database. For signed-out visitors, the hash is derived from therobx_viewer cookie. RobxScript also stores daily aggregate view totals. The code contains application error logging, but no dedicated permanent security-audit log or last-login table. Hosting infrastructure may separately create ordinary server access and error logs according to its deployment configuration.
How We Use Information
Information is used to:
- create accounts, authenticate users, and recover account access;
- display and manage profiles, submissions, publications, and community features;
- moderate content, review reports, correct listings, and enforce Website rules;
- record votes, follows, compatibility reports, saves, messages, and page views;
- operate, diagnose, secure, measure, and improve the Website;
- deliver and measure advertising on supported pages;
- respond to privacy, support, and copyright requests;
- comply with legal obligations and protect legal rights.
Legal Bases for Processing
Where data-protection law requires a legal basis, the applicable basis depends on the activity:
- contract or steps requested by you for account access, publication, community, and support functions;
- legitimate interests in operating, securing, moderating, debugging, and protecting the Website, balanced against user rights;
- consent where valid consent is obtained for a specific optional activity;
- legal obligations for valid legal requests, disputes, and compliance duties.
The Website's current absence of a prior cookie-consent control is described above. This Policy does not treat continued browsing as consent where the law requires an affirmative choice.
Service Providers and Data Sharing
Information can be processed by or disclosed to:
- the server, database, storage, and network infrastructure used to operate RobxScript;
- Yandex for Metrica analytics and Yandex advertising;
- Digital Caramel for advertising on supported desktop pages;
- Resend when password-reset email delivery is configured;
- professional advisers, authorities, or rights holders when reasonably necessary to address a legal claim, valid request, abuse, or infringement report;
- a successor operator if the Website or its relevant assets are reorganized or transferred.
RobxScript does not claim to sell account or profile information. Advertising and analytics providers may independently process browser and advertising information under their own terms and privacy notices.
International Data Transfers
Website infrastructure and third-party providers may process information in countries other than the visitor's country. Their laws may provide different levels of protection. Where transfer rules apply, the operator and relevant provider must use a lawful transfer mechanism or another permitted basis appropriate to the transfer.
Visiting or continuing to use the Website is not described as consent to an international transfer.
Data Retention
Account and profile records are kept while needed to provide the account and until they are deleted or anonymized following a valid request, subject to legal, security, dispute, backup, and recordkeeping needs. Published content and moderation records may be retained while they remain relevant to operating the catalog, documenting changes, resolving reports, preventing repeat abuse, or protecting rights.
Sessions remain valid until their configured expiry or earlier invalidation. Password-reset tokens are valid for 30 minutes. Cookie and browser-storage periods are listed in the Cookie Policy. Where the code does not implement a fixed deletion schedule, retention is determined by purpose, account status, legal obligations, dispute needs, security value, and the ability to safely delete or anonymize the record.
Account and Data Deletion
The current account interface does not contain a self-service account-deletion control. Request account or personal-data deletion by emailing robxscript@gmail.com. Include the account username and use the account email where possible so the request can be verified.
A response may require identity verification. Some records can be anonymized rather than removed, and some information may be retained when reasonably necessary for legal claims, security, fraud prevention, moderation history, or compliance. Removing an account may also require removing attribution or access to account-only features.
User Rights
Depending on where you live, you may have rights to:
- request access to personal information;
- correct inaccurate or incomplete information;
- request deletion or restriction;
- object to certain processing;
- receive portable information where required;
- withdraw consent without affecting earlier lawful processing;
- complain to a competent data-protection authority.
Send requests to robxscript@gmail.com. Rights are subject to applicable conditions and exceptions, and identity may need to be verified.
Children’s Privacy
RobxScript is not intended for children under 13. A person who is not old enough to consent to an online service or enter these Terms independently in their jurisdiction must not create an account or submit personal information without authorization from a parent or legal guardian where required.
The current registration flow does not perform verified age assurance or collect verified parental consent. If you believe a child has submitted personal information improperly, contact us so the information and account can be reviewed.
Data Security
The reviewed implementation uses hashed passwords, hashed session and password-reset tokens, HttpOnly session cookies, same-origin checks, and request rate limits for relevant functions. Access to administrative functions is role-restricted in the application.
No Internet transmission, third-party service, or storage system can be guaranteed completely secure. Users should use a unique password and promptly report suspected account compromise.
Policy Changes
This Policy may be updated when Website features, providers, data practices, or legal requirements change. The fixed “Last updated” date identifies the version currently published. Material changes may also be communicated through the Website when appropriate.
Contact Information
Privacy and data requests:
Email: robxscript@gmail.com
Telegram: @roflandonabol
Use the legal links below to review the rest of the Website policies.