Privacy

Privacy Policy

This Policy describes the information RobxScript actually processes when you browse the Website, create an account, publish content, use community features, or contact us.

EffectiveAugust 23, 2026Last updatedAugust 23, 2026
01

Data Controller

The operator of RobxScript.com determines why and how personal information is processed through the Website and is the data controller where that term applies. Privacy requests can be sent to robxscript@gmail.com or Telegram @roflandonabol.

This Policy does not state a legal entity name, registered address, country of establishment, or representative because those details are not identified in the Website project information available for this Policy.

02

Information We Collect

Depending on how you use RobxScript, the Website processes:

  • account credentials and account status information;
  • profile details and links that you choose to provide;
  • scripts, collections, comments, reports, votes, follows, saved items, and messages;
  • request, device, browser, security, and rate-limit information;
  • page-view and third-party analytics or advertising information;
  • cookies and browser storage described in the Cookie Policy.

RobxScript does not ask for payment-card details and the reviewed project does not contain a payment-processing flow.

03

Account Information

Registration and sign-in use a username, email address, display name, and password. The database stores a one-way password hash, not the ordinary password. Current passwords are pre-hashed and protected with bcrypt; supported legacy password hashes are upgraded after a successful sign-in.

Account records also contain the user role, email-verification status, creation date, and update date. The current database does not contain a dedicated “last login” field.

Sign-in sessions use a random session token. The browser receives the token in therobx_session HttpOnly cookie, while the database stores only a hash of the token and its expiry. The default session period is 30 days, but deployment configuration can change that period.

Password-reset links contain a random one-time token. Only its SHA-256 hash is stored. The token expires after 30 minutes, is marked when used, and a successful password reset invalidates the user's existing sessions.

04

User-Generated Content

User-provided information may include:

  • profile biography, avatar, cover image, style choices, tags, and external website, YouTube, Discord, GitHub, or other profile links;
  • script and collection titles, descriptions, code, source and community links, images, game information, developer details, features, platform support, key-system information, guides, FAQs, and updates;
  • comments, likes, dislikes, compatibility feedback, saved scripts, follows, and private messages where those features are used;
  • reports, reasons, details, and the page URL connected with a complaint or correction request.

Published profiles, scripts, collections, comments, and associated usernames can be visible publicly. Do not publish passwords, private access tokens, payment information, or other sensitive information in public fields or submissions.

05

Technical and Security Data

Requests can involve an IP address, user agent, request origin, page or API route, timestamps, and browser or device information. The application uses this information to enforce same-origin checks, reject known automated viewers from public view counts, apply rate limits, investigate errors, and protect accounts and submissions.

Rate limiting creates an in-memory identifier derived from the request IP address, action scope, and, where relevant, an account or form identifier. It expires with the applicable rate-limit window and is not stored in a dedicated database table.

Page-view deduplication stores a SHA-256 visitor hash, content identifier, and timestamps in the database. For signed-out visitors, the hash is derived from therobx_viewer cookie. RobxScript also stores daily aggregate view totals. The code contains application error logging, but no dedicated permanent security-audit log or last-login table. Hosting infrastructure may separately create ordinary server access and error logs according to its deployment configuration.

06

Cookies and Analytics

RobxScript uses cookies and local storage for sessions, anonymous votes and compatibility reports, view deduplication, theme selection, and dismissed prompts. Exact keys, purposes, and implemented retention settings are listed in the Cookie Policy.

The Website loads Yandex Metrica counter 103205924 globally after the first qualifying interaction or an approximately three-second fallback. The configured features include link tracking, click mapping, and bounce measurement; Webvisor session replay is disabled in the reviewed code.

On script and multi-script pages wider than 820 pixels, Yandex Ads and Digital Caramel advertising scripts are eligible to load after a user interaction and a short delay. The reviewed project does not load Google Analytics or Google AdSense client tags.

The current implementation does not present a site-level consent banner before those analytics and advertising scripts become eligible to load. Browser privacy controls, content blockers, and cookie settings can restrict them. This current behavior is stated here for transparency and is not a representation that prior consent is unnecessary in every jurisdiction.

07

How We Use Information

Information is used to:

  • create accounts, authenticate users, and recover account access;
  • display and manage profiles, submissions, publications, and community features;
  • moderate content, review reports, correct listings, and enforce Website rules;
  • record votes, follows, compatibility reports, saves, messages, and page views;
  • operate, diagnose, secure, measure, and improve the Website;
  • deliver and measure advertising on supported pages;
  • respond to privacy, support, and copyright requests;
  • comply with legal obligations and protect legal rights.
09

Service Providers and Data Sharing

Information can be processed by or disclosed to:

  • the server, database, storage, and network infrastructure used to operate RobxScript;
  • Yandex for Metrica analytics and Yandex advertising;
  • Digital Caramel for advertising on supported desktop pages;
  • Resend when password-reset email delivery is configured;
  • professional advisers, authorities, or rights holders when reasonably necessary to address a legal claim, valid request, abuse, or infringement report;
  • a successor operator if the Website or its relevant assets are reorganized or transferred.

RobxScript does not claim to sell account or profile information. Advertising and analytics providers may independently process browser and advertising information under their own terms and privacy notices.

10

International Data Transfers

Website infrastructure and third-party providers may process information in countries other than the visitor's country. Their laws may provide different levels of protection. Where transfer rules apply, the operator and relevant provider must use a lawful transfer mechanism or another permitted basis appropriate to the transfer.

Visiting or continuing to use the Website is not described as consent to an international transfer.

11

Data Retention

Account and profile records are kept while needed to provide the account and until they are deleted or anonymized following a valid request, subject to legal, security, dispute, backup, and recordkeeping needs. Published content and moderation records may be retained while they remain relevant to operating the catalog, documenting changes, resolving reports, preventing repeat abuse, or protecting rights.

Sessions remain valid until their configured expiry or earlier invalidation. Password-reset tokens are valid for 30 minutes. Cookie and browser-storage periods are listed in the Cookie Policy. Where the code does not implement a fixed deletion schedule, retention is determined by purpose, account status, legal obligations, dispute needs, security value, and the ability to safely delete or anonymize the record.

12

Account and Data Deletion

The current account interface does not contain a self-service account-deletion control. Request account or personal-data deletion by emailing robxscript@gmail.com. Include the account username and use the account email where possible so the request can be verified.

A response may require identity verification. Some records can be anonymized rather than removed, and some information may be retained when reasonably necessary for legal claims, security, fraud prevention, moderation history, or compliance. Removing an account may also require removing attribution or access to account-only features.

13

User Rights

Depending on where you live, you may have rights to:

  • request access to personal information;
  • correct inaccurate or incomplete information;
  • request deletion or restriction;
  • object to certain processing;
  • receive portable information where required;
  • withdraw consent without affecting earlier lawful processing;
  • complain to a competent data-protection authority.

Send requests to robxscript@gmail.com. Rights are subject to applicable conditions and exceptions, and identity may need to be verified.

14

Children’s Privacy

RobxScript is not intended for children under 13. A person who is not old enough to consent to an online service or enter these Terms independently in their jurisdiction must not create an account or submit personal information without authorization from a parent or legal guardian where required.

The current registration flow does not perform verified age assurance or collect verified parental consent. If you believe a child has submitted personal information improperly, contact us so the information and account can be reviewed.

15

Data Security

The reviewed implementation uses hashed passwords, hashed session and password-reset tokens, HttpOnly session cookies, same-origin checks, and request rate limits for relevant functions. Access to administrative functions is role-restricted in the application.

No Internet transmission, third-party service, or storage system can be guaranteed completely secure. Users should use a unique password and promptly report suspected account compromise.

16

Policy Changes

This Policy may be updated when Website features, providers, data practices, or legal requirements change. The fixed “Last updated” date identifies the version currently published. Material changes may also be communicated through the Website when appropriate.

17

Contact Information

Privacy and data requests:
Email: robxscript@gmail.com
Telegram: @roflandonabol

RobxScript policiesNeed another policy?

Use the legal links below to review the rest of the Website policies.