Skip to content
Grim ExecutorGRIMEXECUTOR

Privacy Policy

What we collect, how we use it, and the choices you have.

Last updated: May 21, 2026

This Privacy Policy explains what personal data Grim Executor ("we", "us") collects when you use our website and client, how we use it, and the choices you have. By using the Service, you consent to the practices described here.

1. Information We Collect

Information you give us

  • Account data: display name, email address, and password (stored as a salted hash, never in plain text).
  • Discord OAuth data (if you choose to link Discord): your Discord user ID, username, avatar, and email associated with that Discord account.
  • Support correspondence: the contents of any messages you send to support@grimexecutor.xyz.

Information collected automatically

  • Session data: your IP address, user agent, and rough geographic location, used for rate limiting, fraud detection, and audit logging.
  • Download events: a record each time you generate a signed download link for the client.
  • Hardware identifier (HWID): when the client is activated on a machine, we record a hashed device fingerprint to bind your license to one machine. This is required for the anti-resale protection described in the Terms.

Information from third parties

  • SellAuth (our payment processor — supports cryptocurrency and PayPal): we receive transaction metadata such as invoice ID, amount, currency, status, customer email, and your linked Discord ID. We never receive your full payment card or wallet details; those stay with SellAuth and the upstream wallet / PayPal provider.

2. How We Use Your Information

  • To deliver the Service: create your account, fulfil purchases, deliver and validate license keys, serve downloads.
  • To secure the Service: detect abuse, prevent credential stuffing, enforce rate limits, audit administrative actions.
  • To communicate with you: respond to support requests and send transactional emails about your account or purchases.
  • To comply with law: respond to lawful requests by public authorities and enforce our Terms.

3. Legal Basis (EEA / UK Users)

Where GDPR applies, we rely on:

  • Contract — to provide the Service you purchased;
  • Legitimate interests — security, anti-fraud, and improving the Service;
  • Consent — where you opt in to non-essential communications (you can withdraw at any time).

4. Third-Party Processors

We share the minimum data necessary with the following processors:

  • Supabase — primary database and authentication storage (hosted in the region shown in your Supabase project; for our deployment: Singapore).
  • Cloudflare — hosting (Cloudflare Pages / Workers), CDN, and DDoS protection.
  • SellAuth — payment processing (cryptocurrency, PayPal).
  • Discord — OAuth login and (optionally) automatic guild membership.
  • Our authentication server (operated by us on dedicated infrastructure) — license key issuance, validation, and HWID binding.

We do not sell your personal data. We do not share it with advertisers. Subprocessors handling EEA personal data do so under appropriate safeguards (Standard Contractual Clauses where applicable).

5. Cookies

We use strictly-necessary cookies for authentication (your session token and refresh token). We do not use third-party advertising or analytics cookies. A consent banner is not required for strictly-necessary cookies under most regulators' current guidance, but if you have questions, contact us.

6. Data Retention

  • Account data: kept while your account exists. If you request deletion (see section 8), we erase the account within 30 days unless we have a legal obligation to retain specific records (e.g. invoice records under tax law).
  • License keys and download events: retained for up to 24 months after the license expires for fraud-detection and audit purposes, then deleted or pseudonymised.
  • Server logs (IP, user-agent): retained for up to 90 days.

7. International Transfers

Your data may be processed in countries outside the EEA / UK, including Singapore (Supabase) and the United States (Cloudflare, Stripe, Discord). Where required, transfers are made under Standard Contractual Clauses or equivalent safeguards.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate data;
  • Request deletion of your data (subject to legal retention requirements);
  • Object to or restrict certain processing;
  • Receive a portable copy of your data;
  • Lodge a complaint with your local data-protection authority.

Send requests to support@grimexecutor.xyz. We respond within 30 days (extendable to 60 days for complex requests, as permitted by GDPR Art. 12(3)).

9. Security

Passwords are stored using bcrypt with a high work factor. All web traffic is TLS-encrypted. License validation uses signed tokens with hardware binding. Despite our safeguards, no system is perfectly secure; we encourage you to use a strong, unique password and to enable two-factor authentication when available.

10. Children

The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be announced on the website and take effect 14 days after posting (or immediately if required by law).

12. Contact

Privacy questions, requests, or complaints? Email support@grimexecutor.xyz.