Legal — Privacy

Privacy Policy

How MogDive Client collects, uses, and protects your information. We collect the minimum needed to run the service — nothing about your gameplay.

Effective July 18, 2026
v 4.2
GDPR & CCPA compliant
✓ We do
Encrypt your email, hash your device fingerprint, and log only what's needed to detect license abuse.
✗ We don't
Read your screen, record gameplay, scrape Discord, or sell anything to advertisers.

01What we collect

When you create an account, we ask for the absolute minimum needed to deliver a license key and let you sign in later. We never request, intercept, or store anything happening inside the games you play.

Account information

  • Email address — for login, key delivery, and security notifications.
  • Username — chosen by you, shown on support tickets and in our Discord.
  • Password hash — Argon2id; the plaintext password is never written to disk.

Hardware & session

  • Hashed device fingerprint — a one-way identifier that ties your license to your machine.
  • IP address — at signup and login, for fraud detection. Discarded after 30 days.
  • Client version — to deliver the correct release and updates.

Anonymous live analytics

After analytics consent, we hold a random per-tab identifier and the current page path briefly to show administrators an aggregate live visitor count. This counter does not store your IP address, and inactive sessions are removed after 15 minutes.

Payment

Payments are processed by Stripe and NOWPayments. MogDive Client never sees your card number, wallet private keys, or complete payment credentials. We receive the transaction status, purchase email, amount, and selected plan needed to deliver your order.

02How we use it

Your data is used exclusively to operate the service, secure your account, and improve detection of license-key abuse. We do not use it for advertising, profiling, or any kind of analytics resale.

  • Authenticate you and bind your license to your device.
  • Detect shared accounts, key resellers, and credential stuffing.
  • Send transactional email — receipts, license confirmations, and security alerts.

03Device & licensing

The loader generates a SHA-256 of your motherboard serial, primary disk serial, and BIOS UUID, salted with a per-account secret. We store the resulting hwid_hash — never the underlying values.

This means we cannot identify your hardware from our database, and a stolen copy of our database cannot be used to identify any user's machine.

Each license is bound to the first activated device.

04Sharing & third parties

We share data with a small, named set of processors required to run the service. We do not sell or rent personal data to anyone, ever.

  • Stripe, Coinbase Commerce — payment processing.
  • Cloudflare — DDoS protection & CDN. Sees IP addresses for routing only.
  • Hetzner (Falkenstein, DE) — primary application hosting.
  • Postmark — transactional email delivery.

If we are ever required by a valid court order to disclose data, we will notify the affected account holder unless legally prohibited from doing so.

05Retention

  • Account data — kept as long as your account is active.
  • Login IPs — 30 days, then permanently deleted.
  • Support tickets — 12 months from last reply.
  • Payment records — 7 years (legal requirement).
  • Deleted accounts — purged from active systems within 24 hours, from backups within 30 days.

06Your rights

Under GDPR (EU/UK) and CCPA (California), and regardless of where you live, you can request any of the following from your dashboard or through the support form:

  • Access — a copy of everything we hold about you, in JSON.
  • Correction — fix anything that's wrong.
  • Erasure — close your account and wipe the data.
  • Portability — export your data and take it elsewhere.
  • Objection — tell us to stop processing for any specific purpose.

We answer requests within 14 days, usually much faster.

07Security

The website and dashboard run over TLS 1.3 only. Application databases are AES-256 encrypted at rest. Production access requires hardware security keys and is logged.

We support 2FA via TOTP and security keys. If we ever detect a breach affecting your account, we will email you within 72 hours.

08Contact

Questions, requests, complaints — we read every email.

Contact privacy support Open a support ticket