ARTEMIS GROUP TOOLS

Privacy Policy

Effective: August 11, 2026 · Posted: August 11, 2026 at 18:49 UTC

This Privacy Policy (this "Policy") explains how the operator of Artemis Group Tools ("Artemis," "we," "us," or "our") collects, uses, discloses, retains, and protects information in connection with the Artemis desktop software, our accounts and license services, our websites, and the optional Artemis Audit Bot for Discord. It also explains the choices and rights available to you. This Policy forms part of, and should be read together with, the User Agreement and the Refund Policy.

We have written this Policy to be complete rather than brief. Two disclosures deserve your attention before anything else, and both are described in full in Section 6: (a) the Artemis application computes and transmits a hashed, hardware-derived device identifier, which we use to bind licenses and sessions to devices and to enforce our terms; and (b) our servers record the IP address of requests made to our online services. Both are used for license enforcement, fraud and abuse prevention, security, and — where necessary — enforcement blocklists that may deny service to devices and network addresses associated with abuse. If you read only one section of this Policy, read Section 6.

1. Scope of This Policy; Definitions

This Policy covers the following, together the "Services":

In this Policy, "personal information" (or "personal data") means information that identifies, relates to, or could reasonably be linked with an identified or identifiable individual. It includes online and device identifiers such as IP addresses and the hashed device identifier described in Section 6. "You" means the person using the Services.

Who we are. The Services are operated by the operator of Artemis Group Tools. You can reach us for any privacy matter at dre@artemisvrc.com. Where data-protection law applies and uses the concept, we are the "controller" of the personal information described in this Policy, except where this Policy states that another party controls the data (for example, a Discord server operator's own channels, or PayPal's processing of your payment instrument).

Independence from third-party platforms. Artemis is an independent, unofficial third-party tool. We are not affiliated with, endorsed by, sponsored by, approved by, supported by, or in any way connected to VRChat Inc., Discord Inc., or any other platform the Software interoperates with. "VRChat," "Discord," and all related marks are trademarks of their respective owners and are used here only to describe compatibility. This Policy does not cover, and we are not responsible for, the privacy practices of VRChat, Discord, PayPal, or any other third-party platform or service; their own privacy policies govern their processing of your information. See the User Agreement for the full non-affiliation article.

What this Policy does not cover. This Policy does not cover (a) information you provide directly to third-party platforms; (b) the practices of Discord server operators, who control their own servers, channels, and Bot configurations (see Section 8); or (c) any website or service that links to us but that we do not operate.

This Policy is incorporated into the User Agreement and is governed by the governing-law and any dispute-resolution provisions stated there, including the laws of the State of Florida, USA, and any consumer savings provisions they contain. If you use or interact with the Services without an Artemis account (for example, visiting our websites or being a member of a Discord server that runs the Bot), this Policy applies to you as a notice of our practices; its incorporation into the User Agreement, and that Agreement's dispute-resolution provisions, apply to you only if and when you accept the User Agreement.

2. This Policy at a Glance

This summary is provided for convenience; the full sections below control.

3. Information We Collect

We collect information in three ways: you provide it, the Services collect it automatically, or it comes from an integration you use. For each item we state what it is and why we collect it.

(a) Information you provide directly.

(b) Information collected automatically.

(c) Information from integrations you use.

4. Information We Do Not Collect or Store

The following negative disclosures are as important as the affirmative ones, and we state them plainly:

One vocabulary note, in the interest of accuracy: the hashed device identifier is pseudonymous, not anonymous. We can associate the hash with your account for the enforcement purposes described in Section 6, and we therefore treat it as personal information under this Policy.

5. How We Use Information; Legal Bases for Processing

We use the information described in Section 3 for the following purposes. For users in jurisdictions whose law requires a stated legal basis (see Section 16), the applicable basis is noted; for everyone else, these labels are simply an additional layer of transparency.

We do not use your personal information for purposes materially incompatible with those above without updating this Policy (see Section 19) or, where required, obtaining your consent.

6. Device Identifiers, IP Addresses, and License Enforcement (Security and Anti-Abuse)

This section is the heart of this Policy. Artemis is paid, licensed software, and license enforcement is part of how the Services work. We would rather over-explain this than have you learn it from a forum post.

What we collect for enforcement. The signals used by our security and enforcement systems are:

How the device identifier is created. When the App runs, it computes a one-way cryptographic hash (SHA-256) of a machine identifier that Microsoft Windows itself generates and maintains (the Windows "MachineGuid" value), and encodes the result for transmission. This computation happens entirely on your device; only the resulting hash is ever transmitted to us. If that identifier is unavailable, the App instead computes the same kind of one-way hash from your device's machine name and Windows user name. The hash is designed to be one-way — we use it only by comparing hash values, never by reversing it — and the read is performed through ordinary, application-level Windows interfaces — no driver, no system-monitoring component, no collection of your files or activity. We designed it this way deliberately: it is the minimum signal that lets us tell devices apart for licensing purposes, without taking the underlying identifier off your machine. As stated in Section 4, the hash is pseudonymous rather than anonymous, because we can link it to your account, and we treat it as personal information.

What we use these signals for. The following list is exhaustive as to enforcement uses:

How enforcement works. Devices and IP addresses associated with fraud, payment reversals or chargebacks, tampering, circumvention, ban evasion, or other violations of the User Agreement may be added to an enforcement blocklist keyed to the hashed device identifier and/or IP address, and may be refused service. If a payment is reversed, refunded, or charged back, the corresponding entitlement ends immediately, as described in the Refund Policy. Attempting to evade an enforcement action — including by creating new accounts, using new devices, or altering or spoofing the device identifier — is itself a violation of the User Agreement and may extend enforcement to the accounts, devices, and network addresses involved. We disclose here the categories, purposes, and consequences of enforcement; we do not disclose detection logic or thresholds, because doing so would primarily help the small number of people trying to evade them.

What we do not do with enforcement data. Enforcement signals are used for security and enforcement only. They are not used for advertising, are not sold, are not provided to data brokers, are not linked to any marketing profile, and are kept separate from website analytics. And, as stated above, the raw machine identifier is never transmitted to us.

Automated decisions and human review. Some enforcement decisions (for example, a suspension triggered by fraud or tamper signals, or a blocklist match) may be made by automated systems. If you believe an automated enforcement action affected you in error, contact us at dre@artemisvrc.com and a human will review the decision. We take false positives seriously; the blocklist exists to stop abuse, not to strand paying customers.

Retention of enforcement data. Fraud, tamper, and blocklist records are retained for as long as necessary to protect the Services, our users, and our legal rights — including after the associated account is closed. A fixed deletion schedule for this category would simply advertise the waiting period for ban evasion, so we use this criteria-based standard instead. We maintain a documented legitimate-interests assessment covering this enforcement processing and will make it available to supervisory authorities on request. Section 18 governs records of users we learn are under 13. Benign operational data follows the shorter schedules in Section 12.

7. How We Share Information; Service Providers

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as follows:

Our agreements with service providers limit their processing of personal information they handle for us to providing their services to us and prohibit them from selling it. Google's processing of website analytics data is described in Section 10; we configure our analytics for first-party, aggregate measurement and do not enable advertising, cross-site, or data-sharing features. Providers' own independent services (for example, your own PayPal or Discord account) are governed by their own privacy policies.

8. Discord Bot (Artemis Audit Bot)

Some customers run our optional Discord bot in their own Discord server. The Bot processes data only in servers whose operator installs and configures it, and only to provide the features that operator enables. The server operator — not Artemis — decides which features are on, which channels they use, and how their community is informed; operators who enable these features are responsible for giving their members any notice their community requires. The Bot is intended for use in communities for adults. Server operators must not enable Bot features — in particular tickets and applications — in servers directed to children, and we will delete personal information the Bot holds about a user we learn is under 13. When a server's operator enables it, the Bot processes the following, solely to provide its features:

The Bot does not request the Message Content privileged intent, does not read or store your messages outside of a support ticket you take part in, does not send server members unsolicited direct messages or marketing (the only direct messages it sends are the security alerts described above, to the staff recipients a server's operator designates), and never asks you for your Discord password or login. Bot data is used only to provide the features above; it is never sold, shared with data brokers or advertisers, or used to profile you, and it is shared only within your own Discord server and with Discord itself.

Retention and deletion of Bot data. Open-ticket records are deleted when the ticket is closed. Ticket transcripts, accountability-log messages, and application-review posts live in Discord channels the server's operator controls and can be deleted there at any time by the operator. We automatically delete a server's stored Bot data when the Bot is removed from that server. To access or request deletion of Discord data the Bot holds about you, contact us at dre@artemisvrc.com or your server's operator; we honor deletion requests from you, from the server's operator, and from Discord, subject to the retention rules in Sections 6 and 12 (records needed for security, enforcement, or legal compliance may be retained). Content already saved to a channel controlled by a server's operator is under that operator's and Discord's control; request deletion of that content from them.

9. In-App Friends Messaging

The App includes a friends feature that lets you exchange messages with other Artemis users, including when the recipient is offline. To make that possible, messages you send through the friends feature are relayed through and stored on our real-time database backend (SpacetimeDB cloud, operated by Clockwork Labs) until they can be delivered and as needed to provide the feature (for example, so your conversation is available when you or your friend next signs in).

10. Our Websites, Cookies, and Analytics

Our websites use cookies and similar technologies for two purposes: (a) essential operation (for example, keeping you signed in to account pages and protecting against abuse) and (b) aggregate analytics, using analytics services such as Google Analytics, which set cookies or use device identifiers to help us understand, in aggregate, how our websites are used (pages visited, approximate region, browser type). We use analytics to improve the websites, not to build advertising profiles, and we do not use cross-context behavioral advertising. Our analytics are configured for first-party, aggregate measurement only; we do not enable advertising, cross-site, or data-sharing features in them, and we instruct the analytics service, through its consent controls, to treat advertising-related storage and signals as denied.

Bot protection (Cloudflare Turnstile). Account sign-up and sign-in — on our websites and inside the App, which displays the same check in an embedded browser view — may include a Cloudflare Turnstile challenge to distinguish people from bots. Turnstile is operated by Cloudflare and evaluates request and browser-environment signals as described in Cloudflare's own privacy policy; we receive only a pass/fail token, never the underlying signals.

Referral download links. When you download the App through a partner referral link (a "/dl/…" address), we record the partner tag, the time, and the IP address of the download, and we may compare that IP address with the IP later observed at a trial sign-up so the referring partner is credited. These records are used for referral attribution and abuse prevention, not advertising, and are not shared with the partner beyond aggregate counts.

Your controls:

Analytics data is kept separate from the enforcement signals described in Section 6, and enforcement data is never fed into analytics or advertising tools.

11. Payments and Subscription Information

All payments for Artemis are processed by PayPal. When you buy a subscription (including a plan configuration you compose, on any billing interval displayed at checkout) or a one-time offering, PayPal collects and processes your payment instrument under its own privacy policy and user agreement, as an independent controller. We receive from PayPal limited information needed to run your entitlement, including transaction and subscription identifiers, billing email, payment status, amount, the plan or configuration purchased, and related details PayPal includes in its payment notifications (such as the name associated with the PayPal account). We never receive or store your full card number, bank account details, or PayPal credentials.

We use payment information to provision and manage your entitlement, process renewals and cancellations, honor existing one-time entitlements, prevent payment fraud, respond to payment disputes with delivery and activation records (for example, license issuance timestamps and activation logs), and meet tax and accounting obligations. If a payment is reversed, refunded, or charged back, the associated entitlement ends immediately, and the event may feed the enforcement systems described in Section 6. See the Refund Policy and the User Agreement for the billing, renewal, and cancellation terms themselves.

12. Data Retention

We retain personal information only as long as needed for the purposes described in this Policy, and we set retention per category rather than as a single blanket period. Where a fixed period is not stated, the criteria noted for that category determine the period.

When a retention period ends, we delete or de-identify the data. Where immediate deletion is not possible (for example, in backups), the data remains protected until deletion completes on the backup cycle.

13. Security

We use administrative and technical measures designed to protect personal information, appropriate to the nature of the data we hold:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident affecting your personal information occurs, we will notify affected users and, where required, regulators, as required by applicable law and without unreasonable delay. Please also protect your own account: use a strong, unique password, and contact us immediately at dre@artemisvrc.com if you suspect unauthorized access.

14. Your Rights and Choices

We extend the following choices to all users, regardless of where you live and regardless of whether a particular privacy statute applies to us. Sections 15 and 16 add region-specific detail.

Verification. To protect your information, we verify requests — ordinarily by corresponding through the email address on the account, and where appropriate by asking you to confirm account details (such as your ARTEMIS handle). We may decline requests we cannot verify. An authorized agent may submit a request on your behalf with proof of authorization; we may still verify directly with you.

Timing and no discrimination. We respond within the time applicable law requires or, where no period is prescribed, within a reasonable time. We will not deny you the Services, charge you a different price, or degrade the Services because you exercised a privacy right — though features that depend on the data you ask us to delete (for example, an account) cannot function without it, and enforcement records retained under Section 6 are unaffected by this commitment.

Appeals. If we decline a request, we will explain why, and you may appeal by replying to our response; a human will review the appeal. Residents of some U.S. states may also contact their state Attorney General, and EEA/UK users have the complaint rights described in Section 16.

15. Additional Disclosures for United States State Residents

A number of U.S. states have comprehensive privacy laws granting residents rights of access, correction, deletion, portability, and opt-out of "sales," "sharing," targeted advertising, and certain profiling. Whether a given statute applies to a business depends on thresholds (such as revenue or volume of residents' data processed) that a small operator like us may not meet. Rather than have your rights depend on that analysis, we voluntarily extend the rights in Section 14 to all users, and we have designed this Policy's disclosures to align with the categories those laws use. We do not represent that any particular statute applies to us or that we are a covered "business" under any of them.

To exercise any right, use the contact and verification process in Sections 14 and 20.

16. Additional Disclosures for Users in the EEA, United Kingdom, and Switzerland

If you use the Services from the European Economic Area, the United Kingdom, or Switzerland, this section provides the additional information those laws call for. The controller is the operator of Artemis Group Tools, reachable at dre@artemisvrc.com.

Legal bases. We process personal information on the bases described in Section 5: performance of our contract with you (account, licensing, updates, messaging, transactional email); our legitimate interests (preventing license fraud, account sharing, tampering, ban evasion, and abuse of our Services; securing our network and users; and aggregate analytics), which we have assessed against your interests and rights in a documented legitimate-interests assessment available to supervisory authorities on request — noting that the device signal is hashed on your device, minimal, and used only for security and enforcement, and that users of paid licensed software reasonably expect license enforcement; compliance with legal obligations (tax, accounting, lawful requests); and consent, where we ask for it (for example, non-essential cookies where a consent banner is shown). We do not rely on consent for fraud prevention and enforcement.

Your rights. Subject to the conditions and exceptions in applicable law, you have the right to: access your personal data; rectify inaccurate data; erasure ("right to be forgotten") — noting that we may retain fraud-prevention, enforcement, and blocklist records where processing remains necessary for legitimate interests in securing the Services or for the establishment, exercise, or defense of legal claims; such fraud-prevention and ban-evasion records fall within the exemptions of Article 17(3)(b) and (e) of the GDPR (and their UK equivalents), and we retain them notwithstanding an erasure request to the extent those exemptions apply; restriction of processing; data portability; and objection to processing based on legitimate interests. If you object to fraud-prevention or enforcement processing, we will assess the objection, but we may continue processing where compelling legitimate grounds override under Article 21(1) — preventing license fraud and ban evasion will ordinarily constitute such compelling grounds, and we keep the retained signals minimal (the hashed identifier and IP address) to support that balance. Where processing rests on consent, you may withdraw it at any time without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to address your concern first.

Automated decisions. Automated security systems may suspend access based on fraud, tamper, or abuse signals, as described in Section 6. If such a decision significantly affects you, you may contact us for human review, express your point of view, and contest the decision.

Transfers. Our Services are operated from the United States; see Section 17.

17. International Data Transfers

We operate the Services from the United States, and our service providers may process data in the United States and in other countries where they maintain infrastructure. These countries may have data-protection laws different from those of your home jurisdiction. Where EEA, UK, or Swiss data-protection law requires a lawful transfer mechanism for personal data sent to us or our providers, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum or Swiss adaptation, as applicable) incorporated into our agreements with the service providers listed in Section 7, or on another mechanism recognized by that law, such as a provider's participation in a recognized data-transfer framework. You may request a summary of the relevant safeguards at dre@artemisvrc.com. Our Services are hosted in the United States.

18. Age Requirement; Children

The Services are intended solely for adults 18 years of age or older, as required by the User Agreement. Creating an account, redeeming a trial key, or completing a purchase each constitutes your affirmation that you are 18 or older — the applicable sign-up or purchase surface states so, and no separate step is required — and we keep a record of that affirmation (date, time, account or key, terms version, IP address, and user agent). We do not knowingly collect personal information from anyone under 18, and no one under 13 may use the Services under any circumstances. If we learn we have collected personal information from a child under 13, we will delete that information and terminate the associated account, as required by law. If we learn any other user is under 18, we will terminate the account and delete its personal information, except that we may retain the minimal records applicable law permits us to keep where strictly necessary for the security, fraud-prevention, and enforcement purposes described in Section 6 or for legal compliance. We may require reasonable verification of a claim of age before acting on it. If you are a parent or guardian and believe a child has provided us information, contact us at dre@artemisvrc.com and we will address it promptly.

19. Changes to This Policy

We may modify, replace, or update this Policy at any time, at our sole discretion, consistent with the changes article of the User Agreement. Changes take effect when posted, as reflected by the updated effective date shown above. For material changes, we will provide notice — by posting the updated Policy and/or by email. Your continued use of the Services after a change's effective date constitutes acceptance of the updated Policy; if you do not agree, your remedy is to stop using the Services and, if you wish, request account deletion under Section 14. A change to this Policy does not apply retroactively to a dispute that arose before its effective date; the version in effect when the dispute arose governs that dispute. We maintain an archive of superseded versions of this Policy, and you may request any prior version at dre@artemisvrc.com. No modification of this Policy creates any refund right, and no oral or informal statement (including Discord messages or support replies) modifies this Policy.

20. Contact Us

For any question about this Policy, to exercise any right described in it, or to request human review of an enforcement action, contact us at dre@artemisvrc.com. To help us locate your records and verify your request, please write from the email address on your account and include your ARTEMIS handle (the "ARTEMIS-############" identifier) or the email or order reference used at purchase. For Bot data in a specific Discord server, you may also contact that server's operator, as described in Section 8.


Artemis Group Tools · Contact: dre@artemisvrc.com · Privacy Policy · User Agreement · Refund Policy