Privacy Policy
Last updated: October 1, 2026
Everfall ("we," "us," or "our") operates everfallcommunity.com, the Everfall FiveM community and game servers, and Everfall Discord applications and bots (the "Services"). This policy explains what personal information we process, why we use it, who may receive it, and how to make a privacy request.
Everfall is responsible for the information it processes for these community services. Other platforms, including Discord and the store checkout provider, also process information under their own privacy notices. Our Terms of Service govern use of the Services.
For privacy questions or requests, email [email protected]. The Services are intended for people who are at least 18 years old.
Contents
- Information We Process
- Where Information Comes From
- Why We Use Information
- Discord Data and Bot Permissions
- Who Can Receive Information
- Cookies, Sessions, Analytics, and Diagnostics
- How Long We Keep Information
- Security
- Your Privacy Rights and Requests
- Account and Browser Choices
- International Processing
- AI and Future Support Tools
- Automated Community Rules
- Age Eligibility
- Third-Party Services
- Policy Changes and Contact
Information We Process
The information involved depends on the features you use:
- Discord identity and membership. Discord user ID, username, display name, avatar, email address provided through authorized sign-in, multi-factor-authentication status, server membership, and roles used for identity and access checks. We do not receive your Discord password.
- Accounts and sessions. Everfall account identifiers, authentication-provider records and tokens, session identifiers and expiration, IP address, user agent, and security or administrative status. Authentication tokens let the authorized connection work; do not share them with others.
- Game-platform and connection identifiers. Steam identifiers, Cfx.re/FiveM account identifiers,
Discord identifiers, and Rockstar license identifiers (
licenseandlicense2). Game admission requires Discord, Steam, FiveM, and an available Rockstar license identifier. We store supplied account identifiers in player-account and relevant ban records; we do not treat them as anonymous simply because a platform represents a license as a hash. Xbox Live or Microsoft Live identifiers and IP addresses may also be available through the game connection and used in relevant security, diagnostic, or recent-disconnection records. Platform-generated FiveM player tokens are used for session and replay checks; they are not account passwords. - Community and game records. Character names and identifiers, fictional personal details, character appearance and saved outfits, organization and permission memberships, jobs, skills, achievements, onboarding progress, playtime, game activity, in-game transactions and invoices, and ownership or use of vehicles, items, property, and businesses. Connection and queue records can include identity, membership or priority status, timestamps, and disconnect reasons.
- Moderation and game security. Reports, warnings, bans, appeals, staff actions, linked-account checks, suspected cheating or exploit activity, relevant game events and anti-cheat results, and screenshots taken for moderation or evidence. Identifiers may be correlated across related records to investigate abuse and ban evasion.
- In-game phone and social content. Character phone numbers, contacts, call history, messages and group participants, read status, photos, uploaded videos, voice memos, call recordings where enabled, social profiles and posts, comments, follows, direct messages, room messages, and notifications. In-game app credentials and preferences can include hashed app passwords, a phone passcode, wallpaper, tones, and Face Unlock settings. Use a fictional app password and never reuse a real account password. Face Unlock uses a simulated game-character check, not a real face scan. Phone recording features can capture in-game call or nearby voice when used. Recording a video or going live can mix the transmitted voices of nearby players into the recording or broadcast. Voice systems also transmit speech and maintain call, radio, proximity, and channel state; ordinary voice transmission does not mean every conversation is permanently recorded.
- Game locations and activity. Last saved character position, property or vehicle locations, evidence coordinates, and location sightings used by relevant phone features, with timestamps. A map can use your live in-game position while open. These are locations in the game world, rather than GPS readings of your real-world location; network services can separately receive your IP address or infer an approximate real-world location.
- Roleplay records and documents. Fictional medical conditions, injuries, treatment, reports, criminal or court records, incidents, DNA and fingerprint identifiers, evidence and chain of custody, notes, signatures, documents, and images; in-game banking accounts, balances, invoices, transaction descriptions and audit history; and property, business, employment, customer, loyalty, sales, and inventory records tied to characters or participants. Game DNA and fingerprint identifiers represent characters; they are not measurements of your real genetic or biometric data.
- Applications, support, and communications. Form answers, applications, tickets, reports, messages, comments, votes, reactions, feedback, and communications with staff or community bots, including authors, recipients or participants, timestamps, assignment and read status, and ticket edit or deletion history. These may include information about you supplied by another user or staff member. Designated Discord moderation logs can contain copies of deleted messages and attachment links; deleting the original message does not automatically delete those copies.
- Files and evidence. Uploaded images, documents, screenshots, audio or video clips, file names, types, sizes, storage metadata, integrity checks, and upload status. Evidence may contain voices, character activity, usernames, or information about other people.
- Purchase support. Transaction references, receipts, purchase details, and delivery or billing information supplied to us for support. Tebex separately processes checkout and payment information under its own privacy notice. Do not send full payment-card details to Everfall.
- Notification devices. If you enable browser notifications, the push-subscription endpoint, delivery keys, device label, browser family, and notification preferences needed to send updates to that browser. A delivery endpoint is a browser subscription, not your phone number.
- Technical and diagnostic information. Pages visited, referrers, network information, approximate location, browser and device type, operating system, request timing, errors, performance measurements, and sampled session replays used to diagnose website failures.
Roleplay medical, justice, banking, and incident records describe fictional characters. They can still be linked to a real account and are treated as community data. Do not submit real medical records, bank details, passwords, identity documents, or unrelated sensitive personal information into game records, applications, or ordinary support tickets.
Where Information Comes From
We receive information:
- directly from you when you sign in, play, complete a form, open a ticket, upload evidence, or communicate with staff or a bot;
- from Discord through authorized sign-in and bot access to the servers and channels where a bot is installed;
- from Steam, Cfx.re/FiveM, Rockstar, and other platform identifiers supplied through your game connection, and from relevant moderation or anti-cheat integrations;
- from connected Everfall game servers and community systems;
- from other users or staff who submit reports, messages, applications, evidence, or moderation records involving you; and
- automatically from browsers, network requests, hosting, security, analytics, and diagnostic tools.
Public Discord profile or community-channel information may be available to us through those platform features. You can read public website pages without an Everfall account, although technical information may still be processed. Authenticated features require the identity and membership information needed to grant access; without it, those features may be unavailable.
Why We Use Information
We use information to:
- sign you in, maintain sessions, and link the correct Discord account, community identity, and game character;
- operate gameplay, applications, forms, support tickets, messaging, notifications, and uploads;
- check permissions, synchronize relevant roles, and limit staff or department tools to authorized users, and manage connection eligibility and queue priority;
- investigate reports, enforce community rules, prevent abuse, support appeals, and keep relevant security and audit records, including identifying linked accounts, suspected cheating, exploits, and ban evasion;
- provide purchase-delivery assistance and respond to requests you send us;
- diagnose errors, measure performance and reliability, and improve the Services; and
- meet legal obligations and protect the rights and safety of users, Everfall, and others.
Where a data-protection law requires a legal basis, the purpose determines the basis:
- Providing the requested service or performing our agreement: account access, gameplay, and handling the applications, support requests, and community features you choose to use.
- Legitimate interests: maintaining a safe community, preventing fraud and abuse, protecting systems, keeping proportionate moderation and appeal records, and measuring reliability where that basis is permitted. These interests must be balanced against your rights.
- Consent: processing for which applicable law requires consent. You may withdraw consent by contacting us or using the relevant feature's withdrawal control, where one is provided.
- Legal obligations: retaining or disclosing information when applicable law requires it.
Accepting our terms or reading this policy does not by itself provide consent for processing that requires a separate choice. Withdrawing consent does not affect earlier lawful processing or processing supported by another applicable basis.
Discord Data and Bot Permissions
Everfall bots support member and role updates, game authorization, and designated moderation, suggestion, application, ticket, invite, notification, and audit workflows. Their current functions use Discord's Guild Members and Message Content privileged intents; they do not require the presence intent.
Bot access depends on the permissions granted and the channels or workflows involved. Message data may include content, authors, attachments, and metadata needed for those functions. Website sign-in access and a bot's server permissions are separate connections.
Moderation logs may record member departures, kicks, bans, warnings, command activity, and deleted messages, with relevant identities, reasons, timestamps, and attachments. Application submissions may be stored in application systems and forwarded to authorized Discord application channels. Designated support integrations can post a linked player's server ID, account or character name, character identifier, and Discord mention in the support channel. Ticket-notification DMs contain a private ticket link; access to the ticket itself is checked separately.
We use Discord API data for the stated functionality. We do not sell it, license it as a dataset, disclose it to advertising networks or data brokers, or use it for advertising or unrelated profiling. Authorized providers may process it for the relevant service within Discord's requirements. Any additional use must comply with Discord's applicable developer terms and permissions; a content permission in our terms does not override those requirements.
We update or delete Discord API data when it is no longer needed for the stated feature, when Discord requires it, or following a valid deletion request, subject to applicable legal retention requirements. Contact us using the privacy-request process below to request deletion or report a concern about an Everfall bot.
Who Can Receive Information
Information may be available to:
- Authorized staff. Owners, administrators, moderators, support teams, and relevant department or organization staff, according to their roles and the application's, ticket's, or record's visibility rules. A private submission is not necessarily visible only to its author.
- Other users and participants. People participating in a ticket or workflow may see the content made available to them. Public posts, community channels, and gameplay may be seen, recorded, or copied by others. Player recordings and streams may include your voice, character, chat, or actions; their publishers and hosting platforms control those copies.
- Authorized game participants. Phone recipients, group or room members, property or business participants, item holders, and relevant roleplay departments can see records made available through their feature permissions. Public social or business posts can be shown across the community. Police and medical tools can expose character profiles, evidence, reports, and related records to authorized department users. In-game messages and fictional records are not confidential professional communications or a guarantee of end-to-end encryption.
- Service providers. Discord supplies identity and bot services; Vercel hosts the website and supplies Web Analytics and Speed Insights; Sentry supplies error, performance, and replay diagnostics; Fillout and Google Forms support relevant applications and forms; UploadThing and Cloudflare R2 support uploads and file storage; Cloudflare also supports ticket hosting and operational diagnostics; Tebex handles the official store checkout; browser push services deliver notifications you enable; and hosting, networking, and database providers support the Services. Providers receive information relevant to their function.
- Game platforms, anti-cheat, and media services. Steam, Cfx.re/FiveM, and Rockstar operate the underlying account and game platforms. Fini/FiniAC integrations support relevant anti-cheat and ban workflows; linked game identifiers and detection or moderation information may be sent to the vendor. FiveManage receives relevant game photos, screenshots, videos, audio, and evidence uploads, with filenames and associated upload or evidence metadata. Some media is uploaded directly from a game interface; storage can be separate from the database record holding its URL. Fini's own notice describes player names, identifiers, IP addresses, and connection logs. A staff screenshot can also be sent with the relevant player and staff identity to an authorized Discord moderation channel. Vendor-operated software and platforms have their own processing practices, in addition to information sent by Everfall's integrations.
- Voice, network, and embedded-content providers. FiveM/Mumble supports game voice, and Google STUN supports relevant phone voice connections and can receive client network information. If a TURN relay such as Cloudflare is configured for a feature, it can receive network information and carry microphone audio used by recording or live features. Map-tile or media CDNs, Giphy, YouTube, and other content hosts can receive requests and technical information when an enabled feature loads their content. GIF searches can send the entered search text to Giphy; YouTube playback can expose the requested video identifier and client IP. Playing external media may contact its host directly from your browser or game interface.
- Text-to-speech services. The phone's relevant text-to-speech feature sends the text entered and selected voice to a third-party TikTok-TTS relay hosted on Cloudflare Workers, then stores the resulting audio through the configured media provider. Do not put private account details or unrelated sensitive information into text intended to be spoken or shared.
- Operational logging. Everfall-operated Loki logging and monitoring infrastructure receives relevant event messages, account and character identifiers, names, game coordinates, connection or combat details, and caller-supplied diagnostic context. Designated Discord logging channels can also receive moderation, gameplay, inventory, business, and phone social-post information, such as author names, captions, media links, optional game location, and timestamps. Sentry receives relevant server exceptions and their supplied context as well as website diagnostics.
- Legal or safety recipients. Where reasonably necessary to comply with law or lawful process, investigate abuse, protect rights or safety, or enforce our agreements.
- A successor operator. If the Services are transferred or reorganized, relevant records may transfer subject to this policy and applicable law.
Providers may act on our behalf or independently for their own platform functions, as described in their notices. Publicly sharing content can make it difficult to recover every copy.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use Discord API data for advertising or marketing.
Cookies, Sessions, Analytics, and Diagnostics
Authentication storage. The website uses cookies for sign-in, session security, and service operation. Sessions can remain valid for up to 30 days and renew during continued use; they may end earlier when you sign out, access is revoked, or a security check requires another sign-in. Blocking essential storage may prevent authenticated features from working. Session expiration does not automatically delete an account or its community records.
Preferences. Features can remember your selected character, sidebar state, ticket sorting, and saved views using cookies or local browser storage. The selected-character cookie can last up to one year and the sidebar cookie up to seven days; local preferences can remain until you change them or clear site data. These preferences do not themselves grant account permissions.
Browser notifications. Where available, notifications require your browser permission. You can revoke that permission in browser settings and manage registered devices in the ticket notification settings. Push services process the delivery information needed for that browser.
Analytics and performance. Vercel Web Analytics supplies aggregate page, referrer, approximate location, browser, device, and operating-system statistics. Speed Insights measures loading, responsiveness, and visual stability. Cookieless measurement can still process technical information; blocking cookies alone may not stop it.
Errors and session replays. Sentry receives error details, traces, technical context, and sampled recordings of website interactions, including recordings associated with errors. Replay is configured to mask text and form inputs and block media. That masking does not make every diagnostic record anonymous: URLs, error messages, timing, and other technical context may still contain information linked to your activity.
These tools may run when you load the website. Browser privacy controls or content blockers can limit some requests, although they may also affect site functionality. Contact us to raise an objection or ask about the processing that applies to you. We do not treat browser cookie blocking as a complete analytics or diagnostics opt-out.
How Long We Keep Information
Retention depends on why a record exists and whether it remains necessary:
- Account and authentication records: while needed to provide the account, authorize a connection, maintain sessions, or address security issues. A token's expiry limits its use; it does not by itself establish when every database record is deleted.
- Applications, tickets, evidence, and moderation records: during the workflow and afterward where needed for follow-up, appeals, community safety, dispute resolution, or audit integrity. Closing a ticket or application does not automatically erase its history or attachments.
- Discord moderation copies: deleted-message logs, forwarded applications, and support-channel replies are separate records from the original message or submission. They follow the relevant moderation or application purpose and platform retention; removing an original or leaving a server does not automatically remove those copies.
- Game records: while needed for the character and game systems, linked community workflows, moderation, or integrity of related records. Some messages, calls, temporary evidence, workspace documents, and activity records have feature-specific pruning. Removing a character, phone message, evidence item, or game account does not guarantee deletion of all linked department, business, banking, inventory, or media-host records. Ledger and audit history or evidence copied into another workflow can remain when there is a lawful continuing purpose.
- Purchase-support records: while needed to verify delivery, resolve a billing or support issue, or meet applicable recordkeeping duties. Tebex has its own retention practices.
- Notification subscriptions: while registered for delivery, until removed through notification settings or cleanup of an invalid subscription. Revoking browser permission does not necessarily immediately remove the server's subscription record; you can request removal.
- Temporary state and uploads: caches and authentication or signed identity tokens have their own expiration periods. Expiry of a pending upload's authorization does not guarantee immediate deletion of the stored file. File deletion depends on the relevant storage and workflow process; not every abandoned object or completed attachment has an automatic expiry.
- Diagnostics and analytics: according to the relevant provider's configured retention and our operational needs.
- Backups: copies may remain until the normal backup cycle overwrites them. Where retained solely for recovery, they are not a substitute for an active account.
We use the record's purpose, sensitivity, continuing workflow, security needs, and applicable legal duties to decide whether to retain it. We delete or de-identify information when it is no longer needed. A valid deletion request is assessed against those needs and applicable law; retention exceptions do not authorize keeping information for unrelated purposes indefinitely.
Security
We use measures designed to protect information, including access controls, role-based authorization, server-side validation, encrypted transport, protected service credentials, integrity checks, and encryption for supported stored ticket attachments. These measures do not mean every attachment or record is encrypted end to end.
No system is completely secure, and we cannot guarantee that unauthorized access, disclosure, or loss will never occur. Keep your account and devices secure, and report a suspected incident privately through support tickets or the contact address below. Where a security incident requires notice under applicable law or platform requirements, we will provide it.
Your Privacy Rights and Requests
Depending on where you live and the processing involved, you may have rights to:
- learn whether we hold your personal information and request access or a copy;
- correct inaccurate information;
- request deletion, restriction, or a portable copy;
- withdraw consent where processing relies on it; and
- appeal a denied request or complain to the appropriate privacy regulator.
You may also have a right to object to processing based on legitimate interests. Contact us to explain the processing you object to and any relevant circumstances. We assess requests under the law that applies to you and will not unlawfully discriminate against you for exercising a right.
Send a request to [email protected]. Describe what you want us to do and include your Discord user ID or other information sufficient to locate the relevant account or record. Do not send a password, authentication token, full payment-card details, or an unrequested identity document. We may ask for proportionate verification so we do not disclose or delete another person's data.
We respond within the period required by applicable law. If an extension, refusal, or retention exception applies, we will explain it as required. A request may be limited where necessary to protect another person's information, preserve evidence, meet a legal obligation, or address security or fraud, to the extent permitted by law. Where applicable, an authorized agent may submit a request with proof of authority.
You can raise a complaint with your local data-protection authority without first contacting us. UK residents can contact the Information Commissioner's Office; EEA residents can find their authority through the European Data Protection Board.
Account and Browser Choices
- Sign out: ends your current website session; it does not delete account or community records.
- Revoke Discord authorization: remove Everfall through Discord's Authorized Apps settings to revoke that authorized connection. This does not remove a bot from a shared server or automatically delete data already held by Everfall.
- Leave a server or remove a bot: can limit future bot access through that server. A server administrator with the relevant permissions can remove a bot. These actions do not erase existing workflow records or copies controlled by others.
- Request deletion or account closure: email the privacy contact above. There is no need to regain access to a suspended account to make a privacy request.
- Adjust browser controls: manage cookies, stored site data, and content-blocking preferences. Some controls may prevent sign-in or other features from working.
- Manage notifications: use the ticket notification settings to remove registered devices, or revoke notification permission through your browser settings.
Website account changes do not automatically cancel a store subscription. Use the cancellation method in your purchase receipt or the checkout provider's account tools.
International Processing
Everfall's providers may process information outside the country where you live, including in the United States and other countries where they operate. Data-protection laws may differ between those places. Any transfer subject to legal safeguards must meet the requirements that apply, which may include an adequacy decision or approved contractual protections. Contact us to ask where relevant information is processed and about applicable transfer safeguards.
AI and Future Support Tools
Everfall is not currently training AI or machine-learning models on community message content. The existing text-to-speech feature sends entered text to generate audio, as described above. That use is separate from Everfall training a model. We may introduce AI-assisted support, search, summarization, moderation assistance, or other internal tools. Depending on the feature, relevant messages, ticket content, attachments, and limited account or workflow context may be processed by a provider such as OpenAI, Anthropic, Cloudflare, or another provider identified for that feature. These are possible future providers; this paragraph does not mean they currently receive community content for those purposes.
Using a model to answer a support question or search records is different from using content to train or fine-tune a model. If we introduce either kind of processing, we will describe the feature's purpose, information involved, recipients, and applicable choices before starting it, and obtain any consent or platform permission required. Training or fine-tuning for internal tools may be introduced only with those requirements satisfied; there is no unrestricted right to repurpose every past conversation.
Discord-sourced information remains subject to Discord's developer requirements, including any permission required for model training. A private submission does not become public merely because an internal tool processes it. Earlier privacy commitments and restrictions on information already collected still apply unless a change is lawfully authorized.
AI output may be incomplete or inaccurate. If an AI-assisted feature is introduced, do not treat its output as professional advice or a guaranteed staff decision; use support to request staff review of a community decision.
Automated Community Rules
The Services use automated identity and permission checks, queue rules, anti-cheat and anti-abuse controls, and submission validation. These may prevent sign-in or connection, restrict a feature, reject an invalid submission, flag activity for staff, or result in a kick or ban. Checks can use account and platform identifiers, membership, roles, character or moderation status, game activity, and detection signals. Relevant vendor ban integrations may also receive linked identifiers.
These systems support recreational community access; they are not designed to decide real-world employment, credit, healthcare, or other matters with legal or similarly significant effects. You can ask staff to review a community decision through support or contact us if that route is unavailable.
Age Eligibility
The Services are intended for people who are at least 18 years old. We do not knowingly allow under-18 participation. Staff may check eligibility under the community rules. Do not publish age-verification information in a public channel; ask staff for the appropriate private process and share only what is necessary.
If you believe someone under 18 has supplied personal information, contact [email protected] so we can investigate, restrict access, and delete information where appropriate or legally required.
Third-Party Services
Linked or embedded platforms apply their own privacy notices to their independent processing. For more information, read the notices from Discord, Vercel, Sentry, Fillout, Google, UploadThing, Cloudflare, Tebex, Steam, Rockstar Games and Cfx.re/FiveM, Fini/FiniAC, Giphy, and FiveManage.
A request sent to Everfall covers information under our control. For independent platform accounts or records, you may also need to contact that provider.
Policy Changes and Contact
We may update this policy when the Services, data practices, or applicable requirements change. We will update the date at the top and provide additional notice of material changes through the website or an appropriate community channel when required. Where a new use requires consent, we will obtain it before starting that use.
For privacy questions, access or deletion requests, account closure, and bot-data concerns:
- Operator: Everfall
- Email: [email protected]
- Website: everfallcommunity.com
For gameplay and general community help, use Support Tickets.
