Privacy Policy

Last updated: 25 July 2026. Effective 25 July 2026. Version 2.0.

This Privacy Policy explains what information Nebula ("we", "us", or "our") collects when you use our website, client portal, software, Discord bot, and related services (collectively, the "Service"), how that information is used, who it is shared with, and the choices you have. By creating an account or using the Service, you acknowledge and accept the practices described here.

Contents

  1. Data We Collect
  2. How We Use Your Data
  3. Legal Basis (GDPR)
  4. Third-Party Services
  5. Data Sharing & Disclosure
  6. International Data Transfers
  7. Data Retention
  8. Security
  9. Software Integrity
  10. Cookies & Sessions
  11. Your Rights (GDPR)
  12. California Privacy Rights (CCPA)
  13. Data Breach Notification
  14. Children's Privacy
  15. Changes to This Policy
  16. Contact

1. Data We Collect

Account & identity data

  • Username: the name you choose when registering for the client portal.
  • Email address: required for password recovery and key delivery.
  • Password: stored only as a salted hash. The plaintext password is never stored or logged.
  • Discord ID: if you received your licence through Discord or linked your account.

Licence & entitlement data

  • Licence key(s): the keys attached to your account, their product type, duration, status, and expiry.
  • Device identifier: used to bind your licence to a single device.

Network & session data

  • IP address: collected on login, registration, downloads, and other portal actions for security and abuse prevention.
  • Country: derived from your IP address for analytics and abuse detection.
  • Browser user-agent: collected on portal actions for abuse detection.
  • Derived indicators: used for abuse prevention and service protection.

Software telemetry

  • Software version & status: used to keep your session valid and up to date.
  • Licence status: whether your licence is active, expired, or revoked.
  • Operational logs: used to diagnose issues and improve stability.

Activity & audit logs

  • Portal action log: records portal actions (such as login, download, and settings changes) with relevant security metadata and timestamp.
  • Download log: which file you downloaded and your IP at the time.
  • Ban records: if your account or IP is banned, the reason and timestamp are retained.

2. How We Use Your Data

  • Authentication & access: to verify your identity, issue sessions, and gate access to downloads and the proxy.
  • Licence enforcement: to bind your key to a single device and manage licence status and expiry.
  • Abuse & fraud prevention: to detect and prevent unauthorised use, sharing, and other abuse.
  • Service integrity: to protect the software against tampering and unauthorised use (see section 7).
  • Security incident response: to investigate and respond to unauthorised access, leaks, or attacks.
  • Service operation: to deliver password-reset emails, key-delivery emails, and Discord notifications.
  • Legal compliance: to respond to lawful requests and protect our rights where required.

We do not use your data for advertising, profiling, or selling to third parties.

For users in the European Economic Area, United Kingdom, and Switzerland, we process personal data on the following lawful bases:

  • Contractual necessity (Art. 6(1)(b)): to deliver the Service you purchased and enforce the licence terms.
  • Legitimate interests (Art. 6(1)(f)): fraud prevention, security, and service integrity.
  • Legal obligation (Art. 6(1)(c)): where we are required to retain records.
  • Consent (Art. 6(1)(a)): for any optional telemetry you explicitly enable.

4. Third-Party Services

Your data is processed by the following third parties. Each operates under its own privacy policy.

  • IP lookup service. Data shared: your IP address. Purpose: country detection for abuse prevention.
  • Email delivery provider. Data shared: recipient email, subject, message body. Purpose: transactional email delivery (password resets, key delivery).
  • Discord. Data shared: Discord ID, username. Purpose: bot commands, support, and community features. Subject to Discord's privacy policy.
  • Cloud hosting provider. Data shared: all stored data. Purpose: the Service is hosted on secured cloud infrastructure. Data resides on encrypted persistent volumes.
  • Payment processor. Data shared: payment token, billing email. Purpose: processes your purchase. We never see or store your full card number.

We do not sell, rent, or trade your personal data with any other party.

5. Data Sharing & Disclosure

We share your personal data only in the following circumstances:

  • With service providers: third parties that process data on our behalf to operate the Service (see section 4). These providers are bound by contractual obligations to protect your data and may not use it for any other purpose.
  • For legal compliance: if required by law, court order, or government regulation, we may disclose data to the relevant authorities.
  • For safety and security: to protect the rights, property, safety, or security of Nebula, our users, or the public, including investigating fraud, violations of our Terms, or security incidents.
  • In connection with a business transfer: if Nebula is involved in a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. You will be notified via email before such a transfer occurs.
  • With your consent: we may share data with third parties when you explicitly consent to the sharing.

We never share your data for advertising purposes or with data brokers.

6. International Data Transfers

The Service is hosted on cloud infrastructure that may be located in a country other than your country of residence. When we transfer your personal data across borders, we take steps to ensure that the transfer is lawful under applicable data protection laws:

  • For transfers from the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or another lawful transfer mechanism.
  • For transfers from other regions, we comply with the data protection laws of your jurisdiction.
  • Our third-party service providers may also process data in their own regions, under their own privacy policies and transfer mechanisms.

If you would like more information about the specific safeguards we use for international transfers, contact us as described in section 16.

7. Data Retention

  • Account & licence records: for the life of the account + 90 days after deletion.
  • Password hash: until account deletion.
  • Password-reset tokens: 30 minutes, then purged.
  • Session cookies: 7 days of inactivity.
  • Portal action & download logs: 180 days.
  • Software operational logs: 90 days.
  • Ban records: for the duration of the ban + 12 months.

Where a retention period has not yet been enforced by an automated purge job, data may be retained longer until the next purge cycle. You may request earlier deletion as described in section 9.

8. Security

  • Passwords are stored as salted hashes. Plaintext passwords are never stored or logged.
  • All portal traffic is served over HTTPS / TLS.
  • Session tokens are protected against cross-site and interception attacks.
  • Authentication and download endpoints are rate-limited to prevent abuse.
  • Security measures are in place to protect the integrity of the Service and prevent abuse.
  • Admin access is separately authenticated and role-restricted.

No method of transmission or storage is fully secure. If a breach occurs that is likely to affect you, we will notify you via email within 72 hours of becoming aware.

9. Software Integrity

Protecting your licence

To protect the value of your purchase and keep the Service fair for all users, the software performs integrity checks while it is running. These checks are limited to protecting the software itself and do not monitor your personal activity.

  • Device binding: your licence is bound to a single device to prevent unauthorised sharing.
  • Integrity checks: the software includes measures to protect against tampering and unauthorised use.
  • Licence validation: the software validates your licence to keep your session active.

These measures are limited to protecting the software and your licence. They do not collect personal files, browsing history, or any data unrelated to the software's integrity.

10. Cookies & Sessions

  • Session cookie: a single cookie authenticates your portal session. It expires after 7 days of inactivity and carries no personal data beyond a session reference.
  • Security cookie: a non-identifying token used to validate form submissions and protect against cross-site attacks.

We do not use advertising, tracking, or analytics cookies. No third-party tracking pixels are present on the website or portal.

11. Your Rights (GDPR)

Depending on your jurisdiction (GDPR, CCPA, and similar laws), you may have the following rights:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your account and associated data, subject to legitimate retention (e.g. fraud investigations).
  • Restriction: ask us to limit processing in certain circumstances.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Withdrawal of consent: for any processing based on consent, withdraw it at any time.

To exercise any of these rights, contact us as described in section 16. We will respond within 30 days. We do not charge a fee unless requests are manifestly unfounded or excessive.

You also have the right to lodge a complaint with your local data protection authority (DPA) if you believe our processing of your data violates the GDPR. You can find your local DPA's contact details on the EDPB website.

12. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know: request the categories and specific pieces of personal data we collect, the sources, the purpose of collection, and the third parties we share it with.
  • Right to delete: request deletion of your personal data, subject to exceptions (e.g. completing transactions, detecting security incidents, complying with legal obligations).
  • Right to correct: request correction of inaccurate personal data.
  • Right to opt out of sale or sharing: we do not sell or share your personal data for cross-context behavioural advertising, so no opt-out is necessary. This right is listed for completeness.
  • Right to limit use of sensitive personal data: we do not collect sensitive personal data as defined by the CCPA beyond what is necessary to provide the Service.
  • Right to non-discrimination: we will not discriminate against you for exercising any of these rights.

To exercise your CCPA rights, contact us as described in section 16. We will verify your identity before processing your request and respond within 45 days.

Categories of data collected: identifiers (username, email, Discord ID, IP address), commercial information (purchase history, licence keys), internet activity (user-agent, session data), and inferences drawn from the above (country, derived indicators).

13. Data Breach Notification

We maintain security measures designed to protect your personal data (see section 8). However, no system is completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
  • We will notify affected users via email without undue delay, including the nature of the breach, the likely consequences, and the measures we are taking to address it.
  • If direct notification to all affected users is not feasible, we will publish a public notice on our website and Discord server.

We will document all breaches, their effects, and the remedial action taken, as required by law.

14. Children's Privacy

The Service is not directed at children under 13 (under 16 in the EU/UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be notified via email to registered users at least 14 days before taking effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.

16. Contact

For any privacy-related question, data request, or complaint, you can reach us through any of the following:

  • Discord: open a ticket in our support server: discord.gg/nebulanetwork
  • Email: reply to any key-delivery or password-reset email you received from us, or contact an admin via Discord.

If you are in the EU/UK and unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.