Privacy Policy
This Privacy Policy explains what ModGod (“ModGod”, “we”, “us”), the operator of modgod.tech, collects about you when you use the ModGod service, why we collect it, who we share it with and the choices you have. It applies to the website, the app and every mod build you run through them (together, the “Service”). It is part of the Terms of Service.
The short version: we collect what it takes to sign you in, build your mods, take payment and keep the Service safe. We do not run advertising or analytics trackers, we do not sell personal information, and the only cookies we set are the ones that keep you signed in.
What we collect
Account information from your identity provider
You sign in through an identity provider (Google, unless another is offered). When you do, the provider sends us: a stable identifier for your account with them, your email address and whether the provider has verified it, and the name on your account. We use the identifier and the verified email to recognise you when you return. We store the name only as a support record: it is never shown on the Service, never put into a mod and never sent to an AI provider. We do not receive your password, your contacts, your files or anything else from the provider.
The username you choose
You pick a username when you first sign in. It is public: it appears on every mod you list and is stamped as the author into every mod file you build (section 6).
What you create, and what the Service makes for you
Your prompts and messages in the build conversation; the mod brief the conversation produces; reference images you attach; the sprites you pick, the rerolls you ask for and the notes you leave; and what the Service produces from all of that: sprite candidates and finished art, the mod’s source code, the compiled mod file, build logs, build transcripts, in-game test results, and the working state the AI agent keeps between one build turn and the next.
Billing information
When you buy credits or a plan we record your Stripe customer identifier, your plan and its status and renewal date, and a ledger of every credit bought, reserved, spent, returned or refunded, with the amount paid and the currency. Stripe collects your payment details directly; we never receive or store card numbers.
Technical information
Each request to the Service carries your IP address, which we use to limit request rates and detect abuse; it is kept briefly in rate-limit records and in server logs together with a request identifier, the time, the address requested and any error. The Service records whether a mod download was made by its owner or by an anonymous visitor, without the visitor’s address. It sets the cookies in section 2 and nothing else.
Communications
Emails you send us, and our replies, including requests you make under this policy.
What we do not collect
No advertising or analytics trackers, no third-party cookies, no precise location, no contacts, no device fingerprinting, and no data from your game installation: a mod file you download does not report back to us.
Cookies and browser storage
We set two first-party cookies, both strictly necessary for signing in, which is why the Service shows no cookie banner: the law does not require consent for cookies that only do what you asked for.
| Cookie | What it does | Lifetime |
|---|---|---|
__Host-mg_session | Keeps you signed in. Holds an opaque token; we store only a hash of it. | 30 days from sign-in, or until you sign out |
__Host-mg_login | Carries a sign-in attempt from our site to the identity provider and back. | 10 minutes |
Both are HttpOnly and sent only over HTTPS. The landing page also keeps two settings in your browser’s local storage: whether the animated background is on, and a diagnostics level for the page’s own console output. They never leave your browser.
How we use information
We use the information above to:
- Provide the Service: sign you in, hold the build conversation, draw and build your mod, keep your library and versions, run the public catalog, and show you your balance and history.
- Take payment: open a checkout, grant the credits a payment bought, mirror your plan’s status, and keep the financial records the law requires.
- Keep the Service safe: limit request rates, prevent fraud and abuse, enforce the Terms and the Acceptable Use Policy, and investigate security incidents.
- Support you: answer your emails and handle your requests.
- Send service messages: notices about your account, your purchases, a build, or changes to the Service or these policies. We do not send marketing email without your consent.
- Improve the Service: we use build sessions (prompts, choices, the brief, the mods produced, and whether the build succeeded) to evaluate and improve how the Service works, including to train, tune and test the models, prompts and playbooks that drive it. Where practical we use de-identified data for this, and we do not use your email address, name or payment details for it.
- Comply with the law and protect our rights and those of others.
We do not make decisions about you by automated means that have legal or similarly significant effects on you.
Legal bases (EEA, UK and Switzerland)
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on:
- Performance of a contract for providing the Service you signed up for, building your mods and taking payment;
- Legitimate interests for keeping the Service secure, preventing abuse, operating the public catalog, improving the Service and communicating with you about it — interests we have weighed against yours and that you may object to (section 9);
- Consent, where we ask for it, which you may withdraw at any time; and
- Legal obligation, for financial records and lawful requests.
What is public
Your username is public. It is shown on every mod you list and is stamped as the author into every mod file you build, so anyone you give a mod file to can see it. Your email address and the name from your identity provider are never shown.
A mod you list in the catalog is public: its name, summary and brief (what each piece is, its tooltip and how a player comes by it), its art, its contents, its build results, its versions, the game and version it was built for, its download counts and, if it was forked, the mod it came from. Anyone can download it, and any signed-in creator can fork it into a mod of their own that records where it came from. Unlisting stops new downloads and forks but cannot recall copies or forks already made.
Mods you do not list, and every build conversation, are private to your account. A mod that is not listed cannot be told apart from one that does not exist.
Where your data lives and international transfers
The Service runs in the United States: our servers, database, file storage and the machines that build mods are hosted there, and our providers process data there and wherever they operate. If you use the Service from outside the United States, your information is transferred to and processed in the United States, whose laws may differ from those of your country.
For transfers from the EEA, the UK and Switzerland we rely on the safeguards our providers offer (participation in the EU-US Data Privacy Framework or standard contractual clauses) and, where they apply, on the necessity of the transfer for the contract you have with us. Contact us for more about these safeguards.
How long we keep information
| Information | Kept for |
|---|---|
| A sign-in attempt in progress | 10 minutes |
| A signed-in session | 30 days from sign-in, or until you sign out |
| Your account record (identifier, email, provider name, username, plan) | While your account exists |
| Build conversations, briefs, choices, art, source code, mod files, logs, transcripts and test results | While your account exists: they are the versions of your mods and the record of how each was built |
| Reference images | Until you remove one from a conversation that has not yet been confirmed; otherwise with the conversation |
| Credit ledger, purchases, subscription and payment-event records | 7 years after the transaction, as financial records |
| Rate-limit records | Hours |
| Server logs | A limited period, normally no more than 90 days |
| Emails you send us | As long as needed to handle them, then as a record of the request |
Closing your account
Email founder@modgod.tech from the address on your account and ask us to close it. Within 30 days we close the account and delete your personal information and content, except: the financial records above; what we must keep for a legal claim, a legal hold or to enforce a ban; and copies and forks of mods you listed that other people already made, which are theirs. Download the mods you want to keep before you ask.
Your rights and choices
Wherever you live, you can:
- see the email, username and plan on your account on the profile and credits pages;
- change your username on the profile page;
- list and unlist mods, and remove a reference image before a build is confirmed;
- sign out, which ends the session cookie; and
- ask us for a copy of your personal information, to correct it, or to delete it and close your account, by emailing founder@modgod.tech.
EEA, UK and Switzerland
You have the rights to access, rectify, erase and receive a portable copy of your personal data, to restrict or object to our processing (including any processing based on legitimate interests), to withdraw consent, and to lodge a complaint with your data-protection authority. We answer requests within one month.
California and other US states
You have the rights to know what personal information we collect, use and disclose; to access, correct and delete it; and not to be discriminated against for exercising those rights. We do not sell or share personal information as those words are defined in the California Consumer Privacy Act, and we do not use or disclose sensitive personal information for anything but providing the Service. In the past twelve months we have collected the categories in section 1 (identifiers, commercial information, internet activity, and the content you create) from you, your identity provider and our payment processor, for the purposes in section 3, and disclosed them to the providers in section 5. Under California’s “Shine the Light” law you may ask what personal information we have disclosed to third parties for their direct marketing: the answer is none.
How to exercise a right
Email founder@modgod.tech from the address on your account. We may ask for more information to confirm it is you before we act. An authorised agent may make a request for you with your written permission. If we refuse a request we will say why, and you may appeal by replying to our answer.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has an account, email founder@modgod.tech and we will close it and delete the information. Users under 18 need a parent or guardian’s permission under the Terms.
Security
Every connection to the Service is encrypted, session tokens are stored only as hashes, provider credentials never reach a build machine’s environment or our logs, and each build runs in an isolated machine that is destroyed when it finishes. No system is perfectly secure, so we cannot guarantee the security of your information; if you discover a vulnerability, please tell us at founder@modgod.tech. If a breach affects your personal information we will notify you and the authorities as the law requires.
Information from Google
Signing in with Google asks for the basic sign-in scopes only (openid, email and profile): your Google account identifier, your email address and whether it is verified, and the name on your account. We use them to create your ModGod account, to recognise you when you sign in again (by the identifier, so a change of email at Google does not lose your account), to send you service notices, and to keep the name as a support record. You can see and revoke ModGod’s access at any time at myaccount.google.com/permissions.
ModGod’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell it, we transfer it only to the providers in section 5 as needed to run the Service, and no person reads it except with your consent, for security or support, or where the law requires.
Changes to this policy
We may update this policy. The effective date at the top states when the current text took effect. If a change materially affects how we use your personal information we will notify you by email or by a notice in the Service before it takes effect.
Contact
ModGod, operator of modgod.tech, is the controller of your personal information. Questions, requests and complaints: founder@modgod.tech.