ARTEMIS GROUP TOOLS
Privacy Policy
Effective: August 11, 2026 · Posted: August 11, 2026 at 18:49 UTC
This Privacy Policy (this "Policy") explains how the operator of Artemis Group Tools ("Artemis," "we," "us," or "our") collects, uses, discloses, retains, and protects information in connection with the Artemis desktop software, our accounts and license services, our websites, and the optional Artemis Audit Bot for Discord. It also explains the choices and rights available to you. This Policy forms part of, and should be read together with, the User Agreement and the Refund Policy.
We have written this Policy to be complete rather than brief. Two disclosures deserve your attention before anything else, and both are described in full in Section 6: (a) the Artemis application computes and transmits a hashed, hardware-derived device identifier, which we use to bind licenses and sessions to devices and to enforce our terms; and (b) our servers record the IP address of requests made to our online services. Both are used for license enforcement, fraud and abuse prevention, security, and — where necessary — enforcement blocklists that may deny service to devices and network addresses associated with abuse. If you read only one section of this Policy, read Section 6.
1. Scope of This Policy; Definitions
This Policy covers the following, together the "Services":
- the Artemis desktop application for Microsoft Windows (the "App" or "Software");
- our online services, including the Artemis account system, license and activation services, update services, and the real-time backend that powers in-app features (together, the "Online Services");
- our websites, meaning any website we operate for Artemis, including download, account, and informational pages; and
- the optional Artemis Audit Bot for Discord (the "Bot"), where a Discord server's operator chooses to install it.
In this Policy, "personal information" (or "personal data") means information that identifies, relates to, or could reasonably be linked with an identified or identifiable individual. It includes online and device identifiers such as IP addresses and the hashed device identifier described in Section 6. "You" means the person using the Services.
Who we are. The Services are operated by the operator of Artemis Group Tools. You can reach us for any privacy matter at dre@artemisvrc.com. Where data-protection law applies and uses the concept, we are the "controller" of the personal information described in this Policy, except where this Policy states that another party controls the data (for example, a Discord server operator's own channels, or PayPal's processing of your payment instrument).
Independence from third-party platforms. Artemis is an independent, unofficial third-party tool. We are not affiliated with, endorsed by, sponsored by, approved by, supported by, or in any way connected to VRChat Inc., Discord Inc., or any other platform the Software interoperates with. "VRChat," "Discord," and all related marks are trademarks of their respective owners and are used here only to describe compatibility. This Policy does not cover, and we are not responsible for, the privacy practices of VRChat, Discord, PayPal, or any other third-party platform or service; their own privacy policies govern their processing of your information. See the User Agreement for the full non-affiliation article.
What this Policy does not cover. This Policy does not cover (a) information you provide directly to third-party platforms; (b) the practices of Discord server operators, who control their own servers, channels, and Bot configurations (see Section 8); or (c) any website or service that links to us but that we do not operate.
This Policy is incorporated into the User Agreement and is governed by the governing-law and any dispute-resolution provisions stated there, including the laws of the State of Florida, USA, and any consumer savings provisions they contain. If you use or interact with the Services without an Artemis account (for example, visiting our websites or being a member of a Discord server that runs the Bot), this Policy applies to you as a notice of our practices; its incorporation into the User Agreement, and that Agreement's dispute-resolution provisions, apply to you only if and when you accept the User Agreement.
2. This Policy at a Glance
This summary is provided for convenience; the full sections below control.
- What we collect: your account email address and a salted cryptographic hash of your password (we keep no readable copy of the password); a public account handle in the form "ARTEMIS-############"; subscription and payment status via PayPal (never your full card or bank details); a hashed, hardware-derived device identifier; IP addresses on requests to our servers; limited application telemetry (update events, usage and diagnostic measurements, license activation and recheck calls, and tamper/integrity reports); records of your acceptance of our terms and enrollment consents; the public profile details of VRChat accounts you choose to link; public VRChat group-event data processed at your direction; messages you send through the App's friends feature; limited Discord data in servers whose operators run the Bot; and website cookie/analytics data.
- What we never collect or store: your VRChat password or session cookies (these stay on your own computer, encrypted); the raw machine identifier underlying the hashed device identifier; plaintext passwords; your Discord message content outside support-ticket channels; your full payment card or bank details.
- Why: to provide and secure the Services; to manage licenses, sessions, and subscriptions; to prevent fraud, abuse, account sharing, and ban evasion; and to communicate with you about your account.
- Sharing: we do not sell personal information and do not share it for cross-context behavioral advertising. We share it only with the service providers listed in Section 7, in legal and safety circumstances, or in a business transfer.
- Your choices: access, correct, or delete your information (Section 14); unlink VRChat accounts from the App's Profile screen; manage cookies (Section 10); request human review of automated enforcement (Section 6).
- Age: the Services are for adults 18 and older only (Section 18).
3. Information We Collect
We collect information in three ways: you provide it, the Services collect it automatically, or it comes from an integration you use. For each item we state what it is and why we collect it.
(a) Information you provide directly.
- Account information — the email address and password you use to create an Artemis account. Passwords are sent to us only over encrypted connections when you create your account or sign in, are stored only as a salted cryptographic hash, and are never retained in plaintext. Purpose: creating and securing your account, signing you in, password resets, and account-related notices.
- Agreement and consent records — the date, time, account, terms version, and enrollment consents recorded when you accept our terms, affirm your age, or enroll in a recurring Plan (including the automatic-renewal consent collected at checkout). These records also include the IP address, browser or application identifier (user agent), and — for checkout consents — the country observed at the event, so the record can evidence who consented, from where, and to which version. Purpose: evidencing acceptance and consent, and complying with automatic-renewal and consumer-protection law.
- Purchase selections — the plan, plan configuration, or one-time offering you select at checkout, and any trial key you redeem. Purpose: provisioning the correct entitlement and administering trials. (Payment itself is handled by PayPal — see Section 11.)
- Communications — the content of emails and support requests you send us, including requests under Section 14. Purpose: responding to you, resolving issues, and keeping records of the resolution.
(b) Information collected automatically.
- Public account handle — a public per-account handle in the form "ARTEMIS-############," generated for your account. Purpose: identifying your account in support, licensing, and community contexts without exposing your email address.
- Hashed device identifier — a one-way cryptographic hash (SHA-256) of a hardware-derived machine identifier, computed on your device by the App. Only the hash is transmitted; the underlying raw identifier never leaves your device. Purpose: license-to-device binding, single-use key device pinning, session binding, fraud and abuse prevention, and enforcement of suspensions. This is described in full in Section 6.
- IP addresses — collected server-side at our network edge whenever your device makes a request to our Online Services (for example, signing in, activating a license, checking for updates), and recorded in standard hosting and server logs. Purpose: authentication logging, security alerting, abuse detection, rate limiting, service operation and troubleshooting, and enforcement of suspensions. This is also described in full in Section 6.
- Update-pipeline telemetry — lifecycle events from the App's update process (for example, that an update was offered, downloaded, or applied), consisting of the hashed device identifier and the App version. Purpose: operating the update pipeline reliably and diagnosing failed updates.
- Usage and diagnostic telemetry — aggregate usage measurements the App reports to us, consisting of the hashed device identifier, App version, session duration, counts of how often App features are used, counts of logged events by severity, and performance measurements (such as timing metrics). These are counts and measurements, not content: this telemetry does not include your messages, your VRChat data, file contents, or keystrokes. Purpose: understanding which features are used, finding defects, and keeping the App performant.
- License activation and recheck data — calls the App makes to our license server to activate an entitlement and to periodically re-verify it, including your account and license identifiers, the hashed device identifier, and the App version. Purpose: delivering the license you paid for and enforcing its terms.
- Tamper and integrity reports — if the App detects that its files or license state may have been modified or interfered with, it sends a report containing the license key identifier, customer identifier, hashed device identifier, App version, a cryptographic hash of the application binary, and the reason the report was generated. Purpose: detecting tampering, piracy, and circumvention of license controls.
- Server logs — standard technical logs of requests to our Online Services and websites (timestamps, request paths, response codes, IP address, and general request metadata). Purpose: security, reliability, troubleshooting, and abuse prevention.
- Website cookies and analytics data — described in Section 10.
(c) Information from integrations you use.
- Linked VRChat accounts — when you sign a VRChat account into Artemis while logged in to your Artemis account, we store that VRChat account's public user ID and display name (and which app slot it was used in) on our servers, linked to your Artemis account, so the association follows your account across devices. We do not store your VRChat password or login cookies (see Section 4). You can remove a link at any time from the Profile screen in the App, which deletes that link from our servers.
- VRChat group event data — when you use group-management or audit features (in the App or via the Bot), we process the public VRChat user IDs and display names of group members involved in group events (joins, leaves, kicks, bans, role changes), including people who are not Artemis users, to display, log, and relay those events at your direction. Purpose: providing the group-management and audit features you operate.
- Payment confirmations from PayPal — transaction and subscription identifiers, billing email, payment status, plan details, and related details PayPal includes in its payment notifications, received from PayPal when you purchase or renew. We never receive or store your full card or bank details. See Section 11.
- Friends messages — messages you send through the App's friends feature, which are relayed through and stored on our real-time backend so they can be delivered. See Section 9.
- Discord data via the Bot — limited Discord data in servers whose operators install the Bot. See Section 8.
4. Information We Do Not Collect or Store
The following negative disclosures are as important as the affirmative ones, and we state them plainly:
- Your VRChat credentials never reach us. Your VRChat username, password, and session cookies are stored only locally on your own computer, in encrypted form, and are never transmitted to or stored on our servers. The App interacts with VRChat from your device, using your credentials, at your direction.
- The raw machine identifier never leaves your device. The device-identification process described in Section 6 transmits only a one-way cryptographic hash. The underlying raw Windows machine identifier is read locally, hashed locally, and never transmitted to us in raw form.
- No low-level monitoring component. The device identifier is derived by reading a standard Windows configuration value through ordinary, application-level operating-system interfaces. The App does not install any driver or system-monitoring component for this purpose, and does not scan, log, or collect your files, keystrokes, or activity in other software.
- No plaintext passwords. Artemis account passwords are stored only as salted cryptographic hashes.
- No Discord message content outside tickets. The Bot does not request Discord's "Message Content" privileged intent and does not read or store your Discord messages outside of a support-ticket channel you take part in (see Section 8).
- No full payment instrument details. We never receive or store your full payment card number, bank account number, or PayPal credentials. PayPal processes payment instruments under its own privacy policy.
- No sale, no ad profiling. We do not sell personal information, do not share it for cross-context behavioral advertising, do not provide it to data brokers, and do not use the enforcement data described in Section 6 for advertising or marketing profiles.
One vocabulary note, in the interest of accuracy: the hashed device identifier is pseudonymous, not anonymous. We can associate the hash with your account for the enforcement purposes described in Section 6, and we therefore treat it as personal information under this Policy.
5. How We Use Information; Legal Bases for Processing
We use the information described in Section 3 for the following purposes. For users in jurisdictions whose law requires a stated legal basis (see Section 16), the applicable basis is noted; for everyone else, these labels are simply an additional layer of transparency.
- Providing the Services (performance of our contract with you) — creating and maintaining your account; authenticating sign-ins; activating and re-verifying licenses; delivering updates; operating the friends-messaging feature; operating the Bot's features for servers that install it; and providing support.
- Billing and subscription management (performance of contract; legal obligation) — provisioning entitlements, processing renewals and cancellations through PayPal, honoring existing one-time entitlements, maintaining agreement and consent records, and maintaining transaction records required for tax and accounting purposes.
- Security, license enforcement, and anti-abuse (our legitimate interests in preventing license fraud, account sharing, tampering, ban evasion, and abuse of our Services, and in securing our network and users) — the full program described in Section 6, including device binding, session binding, rate limiting, security alerting, tamper detection, and enforcement blocklists. We do not rely on consent for these activities, because they protect the Services and other users and must not be switchable-off by the very conduct they guard against.
- Communications about your account (performance of contract; legitimate interests) — password resets, purchase and renewal confirmations, renewal reminders, security alerts, and important service notices, sent through our transactional email provider. We send only transactional and account-related email; we do not send marketing email, and we do not use Discord DMs for marketing.
- Service improvement and analytics (legitimate interests; consent where required for cookies) — aggregate usage analytics on our websites, as described in Section 10, and aggregate operational metrics from server logs and update telemetry.
- Legal compliance and protection of rights (legal obligation; legitimate interests) — complying with law and lawful requests; establishing, exercising, or defending legal claims; enforcing the User Agreement; and protecting the rights, property, safety, and security of Artemis, our users, and the public.
We do not use your personal information for purposes materially incompatible with those above without updating this Policy (see Section 19) or, where required, obtaining your consent.
6. Device Identifiers, IP Addresses, and License Enforcement (Security and Anti-Abuse)
This section is the heart of this Policy. Artemis is paid, licensed software, and license enforcement is part of how the Services work. We would rather over-explain this than have you learn it from a forum post.
What we collect for enforcement. The signals used by our security and enforcement systems are:
- the hashed device identifier described below;
- your IP address, collected server-side at our network edge on requests to our Online Services;
- your license key identifier and customer identifier;
- the App version and, in tamper/integrity reports, a cryptographic hash of the application binary and the reason the report was generated; and
- authentication and request logs associated with your account.
How the device identifier is created. When the App runs, it computes a one-way cryptographic hash (SHA-256) of a machine identifier that Microsoft Windows itself generates and maintains (the Windows "MachineGuid" value), and encodes the result for transmission. This computation happens entirely on your device; only the resulting hash is ever transmitted to us. If that identifier is unavailable, the App instead computes the same kind of one-way hash from your device's machine name and Windows user name. The hash is designed to be one-way — we use it only by comparing hash values, never by reversing it — and the read is performed through ordinary, application-level Windows interfaces — no driver, no system-monitoring component, no collection of your files or activity. We designed it this way deliberately: it is the minimum signal that lets us tell devices apart for licensing purposes, without taking the underlying identifier off your machine. As stated in Section 4, the hash is pseudonymous rather than anonymous, because we can link it to your account, and we treat it as personal information.
What we use these signals for. The following list is exhaustive as to enforcement uses:
- License-to-device binding — associating your entitlement with your device, including the device limits described in the User Agreement (currently one device at a time, as displayed in-app; the User Agreement's device-limit provisions control if the permitted number changes);
- Single-use key pinning — binding single-use keys (including trial keys) to the first device that redeems them;
- Session binding — tying an active sign-in session to the device that created it;
- Fraud, abuse, and sharing prevention — detecting account sharing, key resale, trial abuse, payment fraud, and circumvention or spoofing of license controls;
- Tamper detection — identifying modified or interfered-with installations via the integrity reports described in Section 3(b);
- Rate limiting and security alerting — limiting abusive request volumes and alerting on suspicious authentication activity; and
- Enforcement of suspensions and terminations — maintaining blocklists as described next.
How enforcement works. Devices and IP addresses associated with fraud, payment reversals or chargebacks, tampering, circumvention, ban evasion, or other violations of the User Agreement may be added to an enforcement blocklist keyed to the hashed device identifier and/or IP address, and may be refused service. If a payment is reversed, refunded, or charged back, the corresponding entitlement ends immediately, as described in the Refund Policy. Attempting to evade an enforcement action — including by creating new accounts, using new devices, or altering or spoofing the device identifier — is itself a violation of the User Agreement and may extend enforcement to the accounts, devices, and network addresses involved. We disclose here the categories, purposes, and consequences of enforcement; we do not disclose detection logic or thresholds, because doing so would primarily help the small number of people trying to evade them.
What we do not do with enforcement data. Enforcement signals are used for security and enforcement only. They are not used for advertising, are not sold, are not provided to data brokers, are not linked to any marketing profile, and are kept separate from website analytics. And, as stated above, the raw machine identifier is never transmitted to us.
Automated decisions and human review. Some enforcement decisions (for example, a suspension triggered by fraud or tamper signals, or a blocklist match) may be made by automated systems. If you believe an automated enforcement action affected you in error, contact us at dre@artemisvrc.com and a human will review the decision. We take false positives seriously; the blocklist exists to stop abuse, not to strand paying customers.
Retention of enforcement data. Fraud, tamper, and blocklist records are retained for as long as necessary to protect the Services, our users, and our legal rights — including after the associated account is closed. A fixed deletion schedule for this category would simply advertise the waiting period for ban evasion, so we use this criteria-based standard instead. We maintain a documented legitimate-interests assessment covering this enforcement processing and will make it available to supervisory authorities on request. Section 18 governs records of users we learn are under 13. Benign operational data follows the shorter schedules in Section 12.
7. How We Share Information; Service Providers
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as follows:
- Service providers. We use a small number of providers to operate the Services, each limited to the processing needed for its function:
- PayPal — payment processing for all purchases and subscriptions. PayPal acts as an independent controller of the payment instrument data you provide to it (see Section 11).
- Cloudflare — hosting, security, edge networking, and database infrastructure for our Online Services and websites. IP addresses are observed at Cloudflare's edge as part of serving requests.
- Resend — transactional email delivery (password resets, receipts, service notices).
- Google — aggregate website analytics on our websites, via services such as Google Analytics (see Section 10).
- Discord — the platform on which the Bot operates; Bot data necessarily transits and resides on Discord's platform (see Section 8).
- Clockwork Labs (SpacetimeDB) — the real-time database backend that relays and stores friends messages and related real-time feature data (see Section 9).
- Legal process and protection. We may disclose information where required by law or lawful request, or where reasonably necessary to establish, exercise, or defend legal claims, to enforce the User Agreement, to detect and prevent fraud or security threats, or to protect the rights, property, or safety of Artemis, our users, or the public.
- Business transfers. If the Artemis business is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. Any successor remains bound by this Policy with respect to information collected under it, or must provide notice of a new policy as described in Section 19.
- With your direction or consent. We share information where you direct us to (for example, the public VRChat profile details you choose to link) or otherwise consent.
Our agreements with service providers limit their processing of personal information they handle for us to providing their services to us and prohibit them from selling it. Google's processing of website analytics data is described in Section 10; we configure our analytics for first-party, aggregate measurement and do not enable advertising, cross-site, or data-sharing features. Providers' own independent services (for example, your own PayPal or Discord account) are governed by their own privacy policies.
8. Discord Bot (Artemis Audit Bot)
Some customers run our optional Discord bot in their own Discord server. The Bot processes data only in servers whose operator installs and configures it, and only to provide the features that operator enables. The server operator — not Artemis — decides which features are on, which channels they use, and how their community is informed; operators who enable these features are responsible for giving their members any notice their community requires. The Bot is intended for use in communities for adults. Server operators must not enable Bot features — in particular tickets and applications — in servers directed to children, and we will delete personal information the Bot holds about a user we learn is under 13. When a server's operator enables it, the Bot processes the following, solely to provide its features:
- Audit relay — the Bot posts your VRChat group's audit events (joins, leaves, kicks, bans, role changes) to a Discord channel the operator chooses. It reads VRChat group data for this, not your Discord messages. Audit events necessarily identify the VRChat accounts involved in a group action — including people who are not Artemis users — and operators choose the channels where these are posted.
- Welcome messages — when a member joins the server, the Bot may post a greeting that mentions them, using only the new member's Discord user ID; it stores nothing else about them for this feature.
- Support tickets — if the operator enables tickets, the Bot stores the Discord user IDs of the person who opened a ticket and the staff member who handled it, plus the ticket's channel and type. When a ticket is closed, the Bot can save a transcript of that ticket's channel (including the messages and usernames in it) to a transcripts channel the operator controls.
- Moderation accountability log — the Bot records which Discord user ran a moderation command, posted to a log channel the operator chooses.
- Clan/community applications — if the operator enables the application feature, the Bot stores each applicant's Discord user ID and the answers the applicant submits to the operator's application questions, so that the server's staff can review the application. The operator writes the questions and controls how applications are handled; submit only information you are comfortable sharing with that server's staff.
- Creator notifications — if the operator enables creator-notification alerts, the Bot posts notifications about designated creators to channels the operator chooses, using the configuration the operator sets; it does not collect additional personal information about server members for this feature.
- Server protection (anti-nuke) — if the operator enables protection features, the Bot monitors the server's Discord audit log and keeps short-lived, per-moderator counters of destructive actions (for example bans, kicks, and channel or role deletions) so it can detect and stop mass-destructive activity. The counters are transient operational data used only for protection; when protection triggers, the Bot may act on the offending moderator's account in that server and sends a security alert to the specific staff recipients the operator has designated (including by direct message to those designated recipients).
The Bot does not request the Message Content privileged intent, does not read or store your messages outside of a support ticket you take part in, does not send server members unsolicited direct messages or marketing (the only direct messages it sends are the security alerts described above, to the staff recipients a server's operator designates), and never asks you for your Discord password or login. Bot data is used only to provide the features above; it is never sold, shared with data brokers or advertisers, or used to profile you, and it is shared only within your own Discord server and with Discord itself.
Retention and deletion of Bot data. Open-ticket records are deleted when the ticket is closed. Ticket transcripts, accountability-log messages, and application-review posts live in Discord channels the server's operator controls and can be deleted there at any time by the operator. We automatically delete a server's stored Bot data when the Bot is removed from that server. To access or request deletion of Discord data the Bot holds about you, contact us at dre@artemisvrc.com or your server's operator; we honor deletion requests from you, from the server's operator, and from Discord, subject to the retention rules in Sections 6 and 12 (records needed for security, enforcement, or legal compliance may be retained). Content already saved to a channel controlled by a server's operator is under that operator's and Discord's control; request deletion of that content from them.
9. In-App Friends Messaging
The App includes a friends feature that lets you exchange messages with other Artemis users, including when the recipient is offline. To make that possible, messages you send through the friends feature are relayed through and stored on our real-time database backend (SpacetimeDB cloud, operated by Clockwork Labs) until they can be delivered and as needed to provide the feature (for example, so your conversation is available when you or your friend next signs in).
- Transport security: messages travel over encrypted connections between the App and the backend.
- Not end-to-end encrypted: friends messages are not end-to-end encrypted. The backend necessarily stores message content in a form the service can read in order to deliver it, including offline delivery. Do not use friends messaging for information you need to keep confidential from everyone but the recipient.
- Access: access to stored messages is limited to what is needed to operate the feature and to investigate abuse, security incidents, or violations of the User Agreement. We do not read your messages for advertising, and we do not sell them.
- Retention: messages are retained as needed to provide delivery (including while a recipient is offline) and the ordinary operation of the feature; Section 12 states the retention criteria for this category.
10. Our Websites, Cookies, and Analytics
Our websites use cookies and similar technologies for two purposes: (a) essential operation (for example, keeping you signed in to account pages and protecting against abuse) and (b) aggregate analytics, using analytics services such as Google Analytics, which set cookies or use device identifiers to help us understand, in aggregate, how our websites are used (pages visited, approximate region, browser type). We use analytics to improve the websites, not to build advertising profiles, and we do not use cross-context behavioral advertising. Our analytics are configured for first-party, aggregate measurement only; we do not enable advertising, cross-site, or data-sharing features in them, and we instruct the analytics service, through its consent controls, to treat advertising-related storage and signals as denied.
Bot protection (Cloudflare Turnstile). Account sign-up and sign-in — on our websites and inside the App, which displays the same check in an embedded browser view — may include a Cloudflare Turnstile challenge to distinguish people from bots. Turnstile is operated by Cloudflare and evaluates request and browser-environment signals as described in Cloudflare's own privacy policy; we receive only a pass/fail token, never the underlying signals.
Referral download links. When you download the App through a partner referral link (a "/dl/…" address), we record the partner tag, the time, and the IP address of the download, and we may compare that IP address with the IP later observed at a trial sign-up so the referring partner is credited. These records are used for referral attribution and abuse prevention, not advertising, and are not shared with the partner beyond aggregate counts.
Your controls:
- You can block or delete cookies through your browser settings; essential features may not work without essential cookies.
- For Google Analytics specifically, Google offers a browser opt-out add-on, and your browser's tracking-protection features also apply.
- Where a cookie-consent banner is presented in your region, non-essential analytics cookies are used in accordance with your choices there.
- Some browsers offer a "Do Not Track" (DNT) setting. There is no common industry standard for responding to DNT signals, and our websites do not currently respond to them; the cookie and analytics controls above, and the opt-out preference signals described below, remain available regardless of your DNT setting.
- Where applicable law gives effect to recognized opt-out preference signals such as Global Privacy Control (GPC), they are given effect with respect to the activities they govern. Because we do not sell personal information or share it for cross-context behavioral advertising, such signals generally do not change how we process your information.
Analytics data is kept separate from the enforcement signals described in Section 6, and enforcement data is never fed into analytics or advertising tools.
11. Payments and Subscription Information
All payments for Artemis are processed by PayPal. When you buy a subscription (including a plan configuration you compose, on any billing interval displayed at checkout) or a one-time offering, PayPal collects and processes your payment instrument under its own privacy policy and user agreement, as an independent controller. We receive from PayPal limited information needed to run your entitlement, including transaction and subscription identifiers, billing email, payment status, amount, the plan or configuration purchased, and related details PayPal includes in its payment notifications (such as the name associated with the PayPal account). We never receive or store your full card number, bank account details, or PayPal credentials.
We use payment information to provision and manage your entitlement, process renewals and cancellations, honor existing one-time entitlements, prevent payment fraud, respond to payment disputes with delivery and activation records (for example, license issuance timestamps and activation logs), and meet tax and accounting obligations. If a payment is reversed, refunded, or charged back, the associated entitlement ends immediately, and the event may feed the enforcement systems described in Section 6. See the Refund Policy and the User Agreement for the billing, renewal, and cancellation terms themselves.
12. Data Retention
We retain personal information only as long as needed for the purposes described in this Policy, and we set retention per category rather than as a single blanket period. Where a fixed period is not stated, the criteria noted for that category determine the period.
- Account information (email, password hash, handle, linked VRChat public profile data) — for the life of your account, plus a short wind-down period after account deletion, subject to legal holds and the fraud-records exception below.
- Agreement and consent records — for the life of your account and thereafter as needed to evidence acceptance and consent, and at least as long as applicable automatic-renewal law requires.
- Payment and subscription records — as required for tax, accounting, and audit obligations (typically up to seven years), and as needed to respond to payment disputes.
- Server, authentication, and IP logs — for a limited rolling window sized for security investigation and troubleshooting, after which they are deleted or aggregated, except entries preserved for an active security investigation or legal hold.
- Update-pipeline, usage, and diagnostic telemetry and license activation/recheck records — for a limited period sufficient to operate, troubleshoot, and audit the update, licensing, and diagnostics pipelines.
- Tamper reports, fraud records, and blocklist entries — for as long as necessary to protect the Services, our users, and our legal rights, including after account closure (see Section 6).
- Friends messages — as needed to provide delivery (including offline delivery) and the ordinary operation of the feature.
- Bot data — open-ticket records are deleted when the ticket closes; a server's stored Bot data is automatically deleted when the Bot is removed from that server; content saved to operator-controlled Discord channels is retained under that operator's and Discord's control.
- Website analytics — per the retention period configured in the analytics service.
- Support correspondence — as long as needed to resolve the matter and maintain a record of the resolution.
When a retention period ends, we delete or de-identify the data. Where immediate deletion is not possible (for example, in backups), the data remains protected until deletion completes on the backup cycle.
13. Security
We use administrative and technical measures designed to protect personal information, appropriate to the nature of the data we hold:
- Encryption in transit — connections between the App, our websites, and our Online Services use TLS.
- Password protection — account passwords are stored only as salted cryptographic hashes, never in plaintext.
- Data minimization by design — the device identifier is hashed on your device so the raw value never reaches us; VRChat credentials never leave your machine; the Bot is designed not to receive message content outside ticket channels.
- Edge and infrastructure protections — our Online Services sit behind edge security and rate-limiting infrastructure, and access to production data is restricted to what service operation requires.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident affecting your personal information occurs, we will notify affected users and, where required, regulators, as required by applicable law and without unreasonable delay. Please also protect your own account: use a strong, unique password, and contact us immediately at dre@artemisvrc.com if you suspect unauthorized access.
14. Your Rights and Choices
We extend the following choices to all users, regardless of where you live and regardless of whether a particular privacy statute applies to us. Sections 15 and 16 add region-specific detail.
- Access and correction — you may request a copy of the personal information we hold about you, and correction of inaccurate information, by emailing dre@artemisvrc.com.
- Deletion — you may request deletion of your account and associated personal information. We will honor the request subject to the retention rules in Section 12, including the fraud-records exception in Section 6: records reasonably necessary for security, fraud prevention, enforcement of the User Agreement, legal compliance, or the establishment, exercise, or defense of legal claims may be retained after deletion. We tell you this up front because it is the honest position: deleting an account does not erase a blocklist entry created by the conduct that led to it.
- Unlinking VRChat accounts — you can unlink any linked VRChat account yourself from the Profile screen in the App, which deletes that link from our servers.
- Bot data — access and deletion for Bot-held data work as described in Section 8.
- Cookies and analytics — controls are described in Section 10.
- Transactional email — password resets, receipts, renewal notices, and security and service notices are part of operating your account and cannot be opted out of while you keep the account.
- Human review of automated enforcement — as described in Section 6.
Verification. To protect your information, we verify requests — ordinarily by corresponding through the email address on the account, and where appropriate by asking you to confirm account details (such as your ARTEMIS handle). We may decline requests we cannot verify. An authorized agent may submit a request on your behalf with proof of authorization; we may still verify directly with you.
Timing and no discrimination. We respond within the time applicable law requires or, where no period is prescribed, within a reasonable time. We will not deny you the Services, charge you a different price, or degrade the Services because you exercised a privacy right — though features that depend on the data you ask us to delete (for example, an account) cannot function without it, and enforcement records retained under Section 6 are unaffected by this commitment.
Appeals. If we decline a request, we will explain why, and you may appeal by replying to our response; a human will review the appeal. Residents of some U.S. states may also contact their state Attorney General, and EEA/UK users have the complaint rights described in Section 16.
15. Additional Disclosures for United States State Residents
A number of U.S. states have comprehensive privacy laws granting residents rights of access, correction, deletion, portability, and opt-out of "sales," "sharing," targeted advertising, and certain profiling. Whether a given statute applies to a business depends on thresholds (such as revenue or volume of residents' data processed) that a small operator like us may not meet. Rather than have your rights depend on that analysis, we voluntarily extend the rights in Section 14 to all users, and we have designed this Policy's disclosures to align with the categories those laws use. We do not represent that any particular statute applies to us or that we are a covered "business" under any of them.
- Categories collected: identifiers (email, account handle, hashed device identifier, IP address, Discord user ID, VRChat public user ID and display name, VRChat group-event identifiers (including of non-users), PayPal transaction/subscription identifiers); internet or other electronic network activity (server and authentication logs, update telemetry, tamper/integrity reports, website analytics); commercial information (subscription and entitlement status, payment status via PayPal, agreement and consent records); and communications (friends messages; support correspondence; and, in Bot-enabled servers, ticket transcripts and application answers).
- Sources: you; your device and the App automatically; and the integrations described in Section 3(c).
- Purposes: as stated per item in Section 3 and per purpose in Sections 5 and 6.
- Disclosures: only to the service providers and in the circumstances listed in Section 7.
- Sale/sharing: we do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so. We do not use or disclose sensitive personal information for purposes requiring a right to limit.
- Retention: per category, as stated in Section 12.
- Opt-out preference signals: handled as described in Section 10.
To exercise any right, use the contact and verification process in Sections 14 and 20.
16. Additional Disclosures for Users in the EEA, United Kingdom, and Switzerland
If you use the Services from the European Economic Area, the United Kingdom, or Switzerland, this section provides the additional information those laws call for. The controller is the operator of Artemis Group Tools, reachable at dre@artemisvrc.com.
Legal bases. We process personal information on the bases described in Section 5: performance of our contract with you (account, licensing, updates, messaging, transactional email); our legitimate interests (preventing license fraud, account sharing, tampering, ban evasion, and abuse of our Services; securing our network and users; and aggregate analytics), which we have assessed against your interests and rights in a documented legitimate-interests assessment available to supervisory authorities on request — noting that the device signal is hashed on your device, minimal, and used only for security and enforcement, and that users of paid licensed software reasonably expect license enforcement; compliance with legal obligations (tax, accounting, lawful requests); and consent, where we ask for it (for example, non-essential cookies where a consent banner is shown). We do not rely on consent for fraud prevention and enforcement.
Your rights. Subject to the conditions and exceptions in applicable law, you have the right to: access your personal data; rectify inaccurate data; erasure ("right to be forgotten") — noting that we may retain fraud-prevention, enforcement, and blocklist records where processing remains necessary for legitimate interests in securing the Services or for the establishment, exercise, or defense of legal claims; such fraud-prevention and ban-evasion records fall within the exemptions of Article 17(3)(b) and (e) of the GDPR (and their UK equivalents), and we retain them notwithstanding an erasure request to the extent those exemptions apply; restriction of processing; data portability; and objection to processing based on legitimate interests. If you object to fraud-prevention or enforcement processing, we will assess the objection, but we may continue processing where compelling legitimate grounds override under Article 21(1) — preventing license fraud and ban evasion will ordinarily constitute such compelling grounds, and we keep the retained signals minimal (the hashed identifier and IP address) to support that balance. Where processing rests on consent, you may withdraw it at any time without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concern first.
Automated decisions. Automated security systems may suspend access based on fraud, tamper, or abuse signals, as described in Section 6. If such a decision significantly affects you, you may contact us for human review, express your point of view, and contest the decision.
Transfers. Our Services are operated from the United States; see Section 17.
17. International Data Transfers
We operate the Services from the United States, and our service providers may process data in the United States and in other countries where they maintain infrastructure. These countries may have data-protection laws different from those of your home jurisdiction. Where EEA, UK, or Swiss data-protection law requires a lawful transfer mechanism for personal data sent to us or our providers, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum or Swiss adaptation, as applicable) incorporated into our agreements with the service providers listed in Section 7, or on another mechanism recognized by that law, such as a provider's participation in a recognized data-transfer framework. You may request a summary of the relevant safeguards at dre@artemisvrc.com. Our Services are hosted in the United States.
18. Age Requirement; Children
The Services are intended solely for adults 18 years of age or older, as required by the User Agreement. Creating an account, redeeming a trial key, or completing a purchase each constitutes your affirmation that you are 18 or older — the applicable sign-up or purchase surface states so, and no separate step is required — and we keep a record of that affirmation (date, time, account or key, terms version, IP address, and user agent). We do not knowingly collect personal information from anyone under 18, and no one under 13 may use the Services under any circumstances. If we learn we have collected personal information from a child under 13, we will delete that information and terminate the associated account, as required by law. If we learn any other user is under 18, we will terminate the account and delete its personal information, except that we may retain the minimal records applicable law permits us to keep where strictly necessary for the security, fraud-prevention, and enforcement purposes described in Section 6 or for legal compliance. We may require reasonable verification of a claim of age before acting on it. If you are a parent or guardian and believe a child has provided us information, contact us at dre@artemisvrc.com and we will address it promptly.
19. Changes to This Policy
We may modify, replace, or update this Policy at any time, at our sole discretion, consistent with the changes article of the User Agreement. Changes take effect when posted, as reflected by the updated effective date shown above. For material changes, we will provide notice — by posting the updated Policy and/or by email. Your continued use of the Services after a change's effective date constitutes acceptance of the updated Policy; if you do not agree, your remedy is to stop using the Services and, if you wish, request account deletion under Section 14. A change to this Policy does not apply retroactively to a dispute that arose before its effective date; the version in effect when the dispute arose governs that dispute. We maintain an archive of superseded versions of this Policy, and you may request any prior version at dre@artemisvrc.com. No modification of this Policy creates any refund right, and no oral or informal statement (including Discord messages or support replies) modifies this Policy.
20. Contact Us
For any question about this Policy, to exercise any right described in it, or to request human review of an enforcement action, contact us at dre@artemisvrc.com. To help us locate your records and verify your request, please write from the email address on your account and include your ARTEMIS handle (the "ARTEMIS-############" identifier) or the email or order reference used at purchase. For Bot data in a specific Discord server, you may also contact that server's operator, as described in Section 8.