AUV Military Roleplay
Privacy Policy
The AUV Personnel Portal is a private document archive for AUV personnel. It asks Roblox who you are, checks your rank, and shows you the documents you are cleared for. This page explains exactly what that involves, in the order it happens.
The short version
- We never see, ask for, or store your Roblox password.
- We do not collect your email address, your age, or any payment information.
- We do not use analytics, advertising, or third-party tracking of any kind.
- We keep the minimum needed to know who you are, whether you are cleared, and which documents were opened.
- We do not sell or share your data with anyone for their own purposes.
What we collect, and when
When you verify with Roblox
Signing in sends you to Roblox’s own consent page. You type your password there, on Roblox’s site, never on ours. When you approve, Roblox tells us four things:
- your Roblox user ID
- your username
- your display name
- the address of your avatar headshot image
That is the whole of it. We request only the openid and profile permissions, so Roblox does not give us your email address, your friends, your inventory, or anything else — and it could not, because we never asked for it. You can withdraw the application’s access at any time from your Roblox account settings.
When we check your clearance
To decide what you may read, we look up your rank in the Roblox group [AUV] Training & Education Command. This comes from Roblox’s public group API — the same information anyone can see on your profile — so it needs no permission from you. We store the rank number, the role name, and the time we checked, and we re-check periodically so that a promotion or a demotion takes effect on its own.
While you are signed in
The portal keeps a session record containing:
- a random session identifier, and a one-way hash of the session secret
- when the session was created, last used, and when it expires
- the IP address and browser user-agent the session was created from
The session secret itself is never stored — only a hash of it, keyed with a secret held outside the database. A stolen copy of the database therefore contains no usable session.
When you open a document
The archive records who opened what and when: your user ID and username, the document, the action, whether it was allowed or refused, the time, your IP address, and your user-agent. This is a deliberate feature, not a side effect — AUV keeps a record of who has read its material.
Cookies
Three, all strictly necessary for signing in and staying signed in. None of them is used for analytics or advertising, and there are no third-party cookies.
| Cookie | Purpose | Lifetime |
|---|---|---|
auv_session | Keeps you signed in. Unreadable by page scripts. | Up to 30 days |
auv_csrf | Protects sign-out and re-verify against forged cross-site requests. | Same as the session |
auv_oauth | Ties one sign-in attempt to one browser while it is in progress. | 10 minutes |
Why we hold it
To confirm you are who you say you are, to work out what you are cleared to read, to keep you signed in between visits, and to maintain a record of access to AUV material. We do not use any of it for anything else.
Who else is involved
- Roblox Corporation — verifies your identity and provides your group rank. Your dealings with Roblox are governed by Roblox’s own privacy policy, not this one.
- Our hosting and database providers — run the servers this site and its database sit on, and process data only on our instructions.
Nobody else. We do not sell personal data, we do not share it for advertising, and we do not transfer it to anyone for their own purposes. We may disclose information if we are legally required to.
How long we keep it
- Sessions — expire after 30 days of disuse, and expired records are cleared out routinely. Signing out ends a session immediately, on the server.
- Your identity and clearance record — kept while you continue to use the portal, and removed on request.
- The access log — retained indefinitely, and deliberately append-only: entries cannot be altered or removed individually, by us or by anyone else. That is what makes it trustworthy as a record, and it is the one place where a request to erase specific data cannot be honoured in the ordinary way. Tell us if this matters to you and we will explain what can be done.
Your choices
You can, at any time:
- sign out, which ends the session on our servers rather than merely on your device;
- revoke the portal’s access from your Roblox account settings, which stops any future sign-in;
- ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it, subject to the note about the access log above.
Most of what we hold is a copy of information Roblox already publishes about your account, and it refreshes itself each time you sign in.
Younger members
Roblox is used by children, and AUV members may be under 13. This is why the portal asks for as little as it does: no email address, no age, no password, no contact details, and no tracking. If you are a parent or guardian and want a member’s record removed, contact us and we will remove it.
Security
Documents are stored outside the public web root and can only be reached through a route that re-checks your session and your rank on every single request. Sign-in uses Roblox’s official OAuth 2.0 flow with PKCE; the application secret and all tokens stay on the server and never reach your browser. Traffic is served over HTTPS only. No system is perfect, and we do not claim otherwise — but access to AUV material is decided on the server, every time, and never in the page.
Changes
If this policy changes in substance we will update the effective date above. Continuing to use the portal after a change means you accept the revised policy.
Contact
Contact AUV command through the group [AUV] Training & Education Command on Roblox, or through the AUV Discord if you are a member of it. We aim to answer within a reasonable period, and we will tell you if a request needs longer.