Policy
Privacy
Owner/legal review draft describing the data RaidCreator uses for accounts, builder storage, public community activity, thumbnails, notifications, and security.
Last updated: June 22, 2026. This first-pass notice is grounded in the current repo and provider guidance, but it should be reviewed before being treated as final policy.
Owner/legal review draft
Data map
Information RaidCreator may process
This page avoids invented business details and focuses on data categories visible in the current app implementation.
Account and authentication
- Supabase Auth manages account sessions, email/password sign-in, Google sign-in, and authentication cookies.
- Google sign-in can provide basic OAuth profile metadata such as name, email, avatar, or picture depending on the account and provider settings.
- RaidCreator uses this information to authenticate users, show account controls, protect private Library pages, and connect creator profile display data.
Builder and Library content
- Private packs can include pack names, pack types, manifests, layout JSON, type configuration, NPC configuration, vendor configuration, version data, folders, and preview thumbnails.
- Layout JSON can include creator-authored prefab placement, anchor placement, rotations, positions, pack settings, and export-related metadata.
- Preview thumbnails and community prefab thumbnails can be stored through server-managed storage paths.
Community activity
- Creator profiles can include handle, display name, bio, avatar URL, banner URL, website URL, creator XP, levels, and badges.
- Published prefab listings can include names, descriptions, tags, facets, snapshots, thumbnails, status, stars, saves, adds, views, and reports.
- Private shares, imported prefabs, creator follows, notification records, notification preferences, and moderation reports are stored to support community workflows.
Device, cookies, and local storage
- The app uses cookies for Supabase sessions and a community viewer id cookie for anonymous view dedupe.
- Local storage can hold theme preference, dev/offline testing data, builder draft fallback data, clipboard state, viewport preferences, and view-dedupe markers.
- Server logs and provider infrastructure can process technical request data needed to operate, secure, and debug the service.
How the information is used
Uses should stay tied to visible product features and operational needs.
- Provide the builder, Library, Community, account, notification, and export workflows.
- Authenticate users, protect private content, and show profile-backed account controls.
- Generate, store, retain, replace, or delete thumbnails through supported save and publish flows.
- Track public community interactions such as views, stars, saves, imports, follows, reports, and updates.
- Troubleshoot errors, prevent abuse, apply moderation decisions, and improve product reliability.
User choices
These are practical controls visible in the current product shape.
- You can choose what to publish publicly; private Library packs are separate from public Community prefab listings.
- You can edit creator profile fields from account/community surfaces where those controls are available.
- You can change notification preferences from account notification settings.
- You can remove or hide public listings through supported creator or admin moderation flows.
- Access or deletion requests need an owner-reviewed contact path before this draft becomes final policy.
Security, retention, children, and providers
This draft follows the principle of describing practices accurately and not promising retention or compliance details that are not yet confirmed.
RaidCreator relies on Supabase, browser session handling, and server-side authorization checks to protect private account and Library surfaces.
Retention periods should be finalized by the owner. Current app behavior keeps account, pack, community, notification, report, and thumbnail records as needed for the feature unless removed through supported flows.
RaidCreator is not written as a child-directed service. The final policy should state any age requirements chosen by the owner.
