Skip to content

Privacy policy

What UA Guild stores, who sees it, where it lives and how to have it deleted.

In short: we keep what the sign-in provider gives us and what you do on the platform. We sell nothing, we set no analytics cookies, and there are no ads here.

1. What we store

From signing in with Discord or Google — your name, avatar, e-mail address and the id of your account with that provider. We never see your password: the sign-in happens on their side.

About the session — a hash of the session token, the IP address and browser you signed in from, and the time of your last activity. That is what keeps you signed in and lets you see where your account is open.

About your work — translations, suggestions, comments, glossary entries, the history of changes (who changed a string and when), achievements, and the screenshots you attach to strings.

Personal API tokens, if you create them: we keep a hash and the first few characters so you can recognise a token in the list. The token itself is shown once and never stored. The UA Guild Desktop app keeps its token in the Windows password store on your computer.

Your Claude API key, if you are a manager who runs AI translation or proofreading with your own key: it is stored encrypted, never shown in full (only its last four characters) and used only for your runs. You can remove it at any time on the "AI translation" tab.

Notification settings — whether to send you e-mails and Discord direct messages, and how often.

2. What other people see

Public: your name, avatar, translations and suggestions, comments, the change history, achievements and a profile page with your contribution counters. That is how working together works — it is visible who did what.

Your e-mail address is never shown to anyone but the platform's administrators. Neither is the IP address or the browser.

3. Cookies and your browser

We set two cookies: uag_session keeps you signed in (scripts cannot read it) and uag_csrf protects against forged requests. A third one, NEXT_LOCALE, remembers the language you chose.

There are no analytics or advertising cookies. Local storage holds interface details only: the theme, the width of the editor's panel, a hint for first-time visitors.

4. Who else receives it

Discord and Google — when you sign in. They see that a sign-in happened; we receive from them what §1 describes.

The community's Discord server, where our bot posts: project events and a daily digest go there, and the digest names the most active contributors of the day along with the progress.

Discord direct messages from the bot, unless you turned them off: the bot writes to you about events that concern you — accepted suggestions, replies, mentions.

E-mails are sent through Resend: it receives your address and the text of the letter (the same notifications as the bell). You can turn letters off in your notification settings or with the "Unsubscribe" link in any letter.

AI translation and proofreading. When a project manager runs them, the strings (source, translation, context), the glossary, the style guide and the project's rules are sent to Anthropic, the maker of the Claude model, through its API. No personal data of yours (name, e-mail) is in those requests.

An error-tracking service. When a request fails, the report may go to Sentry. It carries the numeric account id and the address of the page; headers, cookies and anything that looks like a credential are stripped before it leaves.

Supporting the project. The "Top up the jar" button leads to a monobank jar page. The payment happens there, and we receive none of your payment details — only the total in the jar.

We do not sell data, do not hand it to advertisers, and run no third-party scripts on the site.

5. Where it lives

The platform runs on Railway, with servers in Amsterdam (the Netherlands, EU). Files — exports, screenshots, news images — live in Cloudflare R2. The daily database backups go to R2 as well: we do not encrypt the dump ourselves — it is protected by the storage provider's encryption at rest and by keys only the service holds.

6. How long we keep it

Account data lives as long as the account does. Background job records are cleaned up automatically: successful ones after a week, failed ones after a month.

If you ask us to delete your account, the profile, e-mail, avatar, sessions, tokens, notifications, your suggestions and your comments go with it. The translations stay: they are published under CC0 and have become part of the project — but they are no longer linked to you.

7. Your rights and how to reach us

You can ask to see, correct or delete your data, or to take it with you in a usable format. Write to minenko.den@gmail.com or on our Discord — we answer as soon as we can.

If this page changes, the current version is always here.