Draft for review — not yet effective
Version 2026-10-02-draft.5 · Effective date: Not adopted
Operator information has not yet been confirmed.
A short explanation
RoCreators uses account connections to run a creator community, public portfolios, applications, hiring listings, and private support conversations. This draft describes the implemented application. Operator details, service-provider identities, served markets, and jurisdiction-specific rights need confirmation before launch. Contact details appear above when configured; a private request receipt is available without signing in.
Account and connection information
We store Discord identifiers, names, avatars, guild membership and role IDs, linked Roblox identifiers and basic profile data, account-link history, verification attempts, and consent records. OAuth state and nonce protect authorization. Session cookies identify an authenticated session; database session identifiers are hashed. Provider tokens are handled on the server. Revocation retries store tokens encrypted for a limited period and erase them after success or expiry. No Roblox password, .ROBLOSECURITY cookie, identity document, biometric information, or voice recording is requested.
Content and visibility
Published portfolios, selected projects and games, approved showcases, published listings, and consented staff credits are public. Drafts, role applications, reviewer decisions, tickets, hiring conversations, and uploaded evidence are private to their authorized participants and purpose-specific staff. Staff reports exclude recorded conflicts. Infrastructure operators can access underlying data to operate the service; private does not mean anonymous from them. Public biographies and badges do not grant staff permissions.
Project and studio verification
RoCreators compares public Roblox experience and group ownership metadata with the linked Roblox account ID. We record the resource, owner, source, check time and outcome. A creator may ask the actual owner to confirm a specific contribution revision or submit private supporting evidence for staff review. We store request history, decisions, links and uploaded media; access is limited to the claimant, the expected owner where applicable, and eligible reviewers. Public labels distinguish ownership, owner-confirmed contribution, staff-reviewed contribution and self-reported work. A credit does not prove current editing access or guarantee hiring. Connecting a studio gives control of its RoCreators page, not additional Roblox access. Optional group permission checks are disabled pending provider validation. Members can withdraw a request or seek correction through Privacy & Data.
Services, work history, and reviews
Creators may publish service descriptions, prices, packages, media, and self-reported work history after automated content checks. A named RoCreators participant is linked in Worked With only after confirming the exact claim revision; a private-client entry omits the client identity. Inquiries and mutually accepted engagement snapshots remain private to their participants. A review requires either a mutually accepted RoCreators engagement or staff-checked private evidence of an external working relationship. A relationship check does not verify payment or the truth of every statement. Published reviews, ratings, optional work images and captions, the review author’s chosen public identity, and creator responses are public. Review images require the author to confirm publication rights; they remain private before publication and cease public display after withdrawal or removal. Private eligibility documents, dispute evidence, case notes, and review revision history are restricted by role and case assignment. Withdrawn or removed review images may be retained for up to 180 days for dispute and appeal handling, subject to account erasure and applicable retention rules. A creator cannot hide selected low ratings. Withdrawal, moderation, and account erasure may change public rating aggregates.
Messages and third parties
Website tickets and bot DMs use one persisted conversation history. When you use bot conversations or enable eligible notifications, Discord receives the relayed information and processes it under its policies. Ticket conversations are staff-readable and are not end-to-end encrypted. Hosting, storage, network, and backup providers process service data. Browser requests for provider avatars or Roblox game thumbnails reveal network information to those hosts. A configured Cloudflare Turnstile challenge contacts Cloudflare when the challenge loads. External project and video links open at your choice; this build does not automatically embed third-party videos.
Participation and security
The bot records eligible text and voice participation XP and voice-channel checkpoints, not audio. Cooldowns and duplicate-message hashes are short-lived Redis entries. Participation levels are community features, not scores used to decide employment or developer suitability. Verification attempts, known identity relationships, restrictions, and security events help assess abuse and appeals. Shared Wi-Fi is not proof of an alternate account. Where trusted proxy support is enabled, network information is used for bounded abuse limits. Operational logs are size-rotated; storage encryption and deployment-provider controls require separate verification.
Cookies and this browser
Necessary rc_session cookies last up to seven days. rc_oauth and rc_roblox cookies protect short authorization flows. A signed, HttpOnly rc_visitor cookie lasts up to one day when you start anonymous sign-in or use the public privacy-request form; it keeps ordinary request budgets separate for visitors sharing a network. Repeated new-cookie attempts from one network may require a Cloudflare Turnstile security check. The optional appearance preference rc-theme lasts up to one year after you choose it. Portfolio and project draft recovery uses local storage in this browser. Privacy & Data can clear those drafts and the appearance preference. Optional first-party traffic measurement is available only after a separate Allow measurement choice; Terms acceptance does not grant analytics consent. The HttpOnly rc_campaign cookie contains a random token for up to 30 days. Public page events are retained for 90 days and daily aggregates for 400 days. Confirmed registration, verification and first portfolio publication may be attributed to the first eligible campaign within the configured window. Decline measurement and browser DNT/GPC signals disable collection and account linkage; navigation continues. No advertising analytics SDK is installed. Privacy acknowledgement and optional Discord notifications are separate choices.
Retention and deletion
The current technical cleanup schedule appears below. Ordinary content remains while its account and purpose remain active, until deletion or a reviewed retention decision. Account deletion removes public content, account-owned records and media, sessions, subscriptions, and queued work; shared conversations may keep a neutral deleted-message marker. A narrow legal retention exception requires an identified obligation and review, not a blanket security exemption. Provider-side Discord messages and copies held by other people are outside the website database; contact the operator for assistance. Backup erasure follows the actually operated backup schedule, which still needs deployment verification. A deletion ledger prevents a restored backup from reactivating erased accounts when the documented restore procedure is followed.
Your choices and requests
Privacy & Data lets you request a private export, disconnect Roblox, manage notifications, unpublish your portfolio, or request account deletion. Fresh Discord authentication and explicit confirmation protect sensitive actions. Exports exclude internal staff notes, reports against other people, and secrets. Unlinking stops the connection but does not silently erase existing content or active restrictions. For access, correction, deletion, an appeal, or help without account access, use the public data-request form. Save its private receipt to read the operator’s response. Do not include passwords, medical or financial records, or unnecessary personal data.
Uses we do not make
RoCreators does not sell provider data, send it to advertising brokers, train models on Discord messages, or create hidden cross-community identity profiles. Account ownership, abuse-risk decisions, participation levels, and portfolio/application review are separate purposes. This policy does not claim provider approval, legal compliance, malware scanning, or encryption of all deployed storage.
Installed technical cleanup schedule
- Exports: 24 hours.
- Closed privacy requests: 90 days.
- Encrypted provider revocation retries: up to 7 days, then credentials erased and status marked unconfirmed.
- Completed delivery jobs: 30 days.
- Private evidence for decided review cases and decided external relationship checks: default 180 days after decision. The Owner's upload-limit setting can change this to 30–3650 days; active cases and appeals are not cleared by that schedule.
- Restoration suppression ledger: 210 days; this remains personal security data while linkable.
These are implemented product defaults, subject to Owner and legal review. Actual deployment cleanup, backup expiration and storage encryption must be verified before launch.
Update history
Added separately consented first-party campaign measurement, attribution and bounded retention.