X Naval Events — Privacy Policy
Operator: X Naval Events / LeMerc’s Pirate Fleet
Contact: staff in our Discord
Effective date: September 22, 2026
Scope
This policy describes information handled by the X Naval Events Discord application, AutoConfig, Event Admin, public assignment sheets, and Orders of Sailing. It does not cover unrelated websites such as Admiralty Archives or NavalReplay, which have their own practices.
Discord login information
When you authorize Discord login, the application requests basic identity and your membership information in our designated Discord server. We receive your Discord user ID, username, display name, server nickname where available, and server membership and role information. We use these to identify you, check administrative access, and show your name to other authorized administrators.
The login integration requests the identify and guilds.members.read permissions. It does not request your Discord password, email address, private messages, message history, or permission to post messages. Information you separately send to community staff through Discord is handled as a support communication, not collected by the website login integration.
We store authorization access and refresh tokens in private server-side session storage so we can maintain your login and recheck your role. The browser receives a random session identifier, not those Discord tokens. Membership and role checks are ordinarily repeated every five minutes while the session is used.
Event and administrative information
The tools store event settings, regiment names and identifiers, signup numbers and notes, ratings and attendance summaries, team and ship assignments, and information supplied by authorized organizers or connected signup and rating sources. Event Admin also receives game-server status, observed player identifiers and names, regiment tags, attendance information, and supported moderation or rule-event reports from connected game servers.
Administrative records may identify who saved settings or issued commands, when the action occurred, and its result. The Admin Online feature shows authorized administrators your name, the section of AutoConfig you are viewing, and whether you appear active or idle. It does not report your activity on unrelated websites.
Email addresses from the earlier email/PIN access system remain in approved-account settings and may appear in historical records. Email/PIN access is currently suspended for these tools; Discord login does not request your email address.
Why we use information
We use information to authenticate administrators, enforce server-role permissions, coordinate community events, prepare and publish assignments, operate game-server controls, display administrative presence, investigate errors or misuse, respond to support requests, and maintain operational records. The application does not use Discord information for advertising or sell it.
Who can see information
Authorized event administrators can see information needed to operate the tools, including event data, administrative presence, and relevant activity records. Operator access is also necessary for support and maintenance.
When an organizer publishes an event, public pages and downloads can include regiment names, team and ship assignments, rules, schedules, and game-server joining details. These pages may be copied or downloaded by visitors. Discord login tokens and private administrative credentials are not intended for public publication. Do not enter confidential personal information in fields intended for public display.
Cloudflare hosts and secures the websites and processes requests and stored application information on our behalf. Discord processes authentication and API requests. Configured Google Sheets, signup integrations, and game-server providers process information needed for their respective event functions. Website infrastructure may process IP addresses, browser or request metadata, and diagnostic logs for delivery and security. These providers may process information in countries other than your own and have their own privacy policies.
Information may also be disclosed where legally required or necessary to investigate unauthorized use and protect the service, consistent with applicable law.
Cookies and browser storage
The tools use secure login cookies to maintain sessions and a short-lived cookie to complete Discord authorization. They also use browser storage for local event data, recovery, or interface preferences. Existing Cloudflare login or security cookies may remain from earlier use. These application features do not require advertising cookies. You can clear cookies and site storage through your browser; doing so may sign you out or remove local recovery data.
Retention
Discord login sessions have a maximum lifetime of 30 days. Temporary authorization records expire after about ten minutes. Server-side session records are scheduled for deletion when they expire; logout or failed authorization checks can invalidate them sooner. Revoking the application in Discord prevents continued authorization, but may not immediately remove every stored event or audit record.
The Admin Online list expires entries after about 90 seconds without an update; stale stored entries are cleaned up as the list is updated. This is separate from persistent administrative audit records.
Event documents, audit history, support information, saved account settings, and recovery backups can remain after an event ends. They do not all have an automatic deletion deadline, and an event reset does not erase every historical record or backup. Contact staff to request review or deletion of information associated with you. Information may need to be retained where required by law or for a specific legitimate security or operational purpose. Public copies already downloaded by other people are outside our direct control.
Your choices and requests
You can stop using the tools and revoke X Naval Events under Authorized Apps in your Discord account settings. You can change your Discord profile or server nickname, and role changes affect website access when rechecked.
To request access to, correction of, or deletion of your information, contact staff in our Discord and ask for a privacy request. Identify your Discord account and the information concerned; do not send passwords, session cookies, or authorization tokens. Staff may need to verify that the request concerns your account. Requests will be handled according to applicable law, including any applicable response deadlines. Depending on your location, you may have additional rights such as restriction, objection, portability, or contacting your local data-protection authority.
Security and eligibility
Access restrictions, server-side token storage, and secure cookies help protect the tools. No online service can guarantee absolute security. Contact staff promptly if you suspect unauthorized access or accidental disclosure.
Discord login is intended for users who meet Discord's applicable minimum age requirements. If you believe information was provided by someone who does not meet those requirements, contact staff.
Policy changes and contact
Updates will be published here with a revised effective date. Material changes will be communicated through the website or community Discord where appropriate or legally required. For questions about this policy or the handling of information, contact staff in our Discord.