> For the complete documentation index, see [llms.txt](https://docs.zaroguard.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.zaroguard.com/privacy-policy.md).

# Privacy Policy

## Privacy Policy

**Effective date: August 3, 2026**

This Privacy Policy explains how ZaroGuard, also referred to as Zaro, collects, uses, stores, and shares information when developers use the ZaroGuard dashboard or API, when visitors use our website, and when users execute scripts protected by ZaroGuard.

By using ZaroGuard, you acknowledge the practices described in this Policy. If you do not agree with this Policy, do not use the service or execute a ZaroGuard-protected script.

### 1. Scope

This Policy applies to:

* the ZaroGuard website and dashboard;
* ZaroGuard APIs and authentication systems;
* scripts and loaders protected or delivered through ZaroGuard;
* security, anti-tamper, execution-verification, and key-system features; and
* support and administrative operations relating to ZaroGuard.

This Policy does not control independent scripts, websites, or services operated by script developers or other third parties. A script developer may add their own logging or data collection. ZaroGuard does not control collection performed independently by a developer's script.

### 2. Information We Collect

#### 2.1 Website visitors and account holders

Depending on how you use the service, we may collect:

* IP address and approximate country or region;
* browser or application User-Agent;
* session identifiers and security cookies;
* CAPTCHA or abuse-prevention verification results;
* Discord account information made available through Discord authentication, such as Discord ID, username, avatar, and email address when provided;
* ZaroGuard account ID, access key, subscription tier, activation and expiration information;
* dashboard settings, webhook URLs, script names, descriptions, notes, key-system settings, and other information submitted through the website or API; and
* access, authentication, denial, administrative, and security logs.

#### 2.2 Developers and protected scripts

When a developer submits a script for protection, ZaroGuard processes the submitted source to create a protected or obfuscated version.

ZaroGuard stores the resulting protected or obfuscated script in database chunks so it can be delivered to authorized users. ZaroGuard does not intentionally retain the original raw upload after the protection process has completed. Protected script data remains stored while the script remains available through the developer's account and may also exist temporarily in operational caches.

Depending on the selected protection method, script content may be processed by a configured local obfuscator or a third-party obfuscation provider.

#### 2.3 Users executing protected scripts

When a user executes a script protected by ZaroGuard, we may collect and process:

* IP address and approximate country or region;
* date and time of requests and execution events;
* Roblox username and Roblox user ID;
* an HWID, executor fingerprint, Roblox client identifier, or another persistent identifier supplied by the executor or client environment;
* executor name and version when available;
* User-Agent and relevant request headers;
* script ID, script name, access result, and denial reason;
* execution-stage progression
* stage heartbeats, timing information, temporary delivery-token activity, and incomplete execution information;
* client-side loader errors, warnings, kick reasons, and security diagnostic messages; and

Some request headers supplied by Roblox, Cloudflare, or an executor may contain game IDs, session IDs, network identifiers, request trace identifiers, or executor-specific fingerprints. These values may appear in operational server logs when request debugging is enabled.

An HWID is not guaranteed to be a cryptographic hash. Its format depends on the executor or fallback client API. ZaroGuard treats it as a persistent device or client identifier used for access control and abuse prevention.

ZaroGuard does not intentionally collect in-game inventory, currency, gameplay statistics, chat messages, or similar gameplay data. A protected script may independently collect such information if its developer added that behavior; that collection is the developer's responsibility.

### 3. How We Use Information

We use collected information to:

* authenticate users and maintain sessions;
* provide the dashboard, API, key system, subscriptions, and script-delivery service;
* protect, obfuscate, store, reconstruct, and deliver protected scripts;
* verify that execution stages occurred in the expected order;
* detect abuse, request replay, unauthorized access, tampering, environment logging, HWID spoofing, and attempted bypasses;
* apply script-specific blacklists, temporary restrictions, or global bans;
* investigate errors, failed deliveries, incomplete executions, and service outages;
* produce execution, country, success, denial, and security analytics;
* deliver optional success, denial, subscription, and security notifications through Discord webhooks;
* enforce our Terms of Service; and
* maintain and improve service reliability and security.

Some security decisions are automated. For example, the system may deny access, kick a client, blacklist an identifier, or apply a global ban when it detects spoofing, tampering or other security violations. False positives may be reviewed through the official ZaroGuard support channel.

### 4. Information Shared With Script Developers

If a developer enables webhook delivery or views dashboard analytics, the developer may receive or view information relating to executions of their scripts, including:

* script name and script ID;
* Roblox username and user ID;
* executor name;
* HWID or client identifier;
* approximate country or region;
* execution success, denial, stage, or incomplete-progression status;
* security-event category; and
* relevant timestamps.

ZaroGuard does not ordinarily display a user's complete IP address to the script developer. Full IP addresses remain available internally for access control, security investigation, geolocation, logging, and enforcement. ZaroGuard's master security systems may receive more detailed diagnostic information than a script owner's webhook.

### 5. Service Providers and Third Parties

ZaroGuard may disclose or transmit limited information to providers that help operate the service. Depending on the feature used, these providers may include:

* **Cloudflare**, for networking, hosting, database infrastructure, tunneling, security, and Turnstile verification;
* **Discord**, for account authentication and optional webhook notifications;
* **hCaptcha**, for CAPTCHA and abuse-prevention verification;
* **ip-api.com**, for converting an IP address into an approximate country or region;
* configured **obfuscation providers**,
* infrastructure, session-storage, monitoring, or hosting providers configured by ZaroGuard.

These providers process information under their own terms and privacy policies. Information may be processed outside the user's country or region.

We may also disclose information when reasonably necessary to comply with law, respond to valid legal requests, protect ZaroGuard or its users, investigate fraud or abuse, or enforce our agreements.

We do not sell personal information.

### 6. Cookies and Sessions

ZaroGuard uses cookies and similar session technologies to keep users signed in, maintain CAPTCHA verification, protect authentication flows, and remember necessary account state.

Cookies may contain a random or signed session identifier. Account details and access information are generally stored server-side and associated with that identifier. Cookies are not intended to contain favicons or complete uploaded scripts.

You can remove cookies through your browser settings or by logging out. Disabling required cookies may prevent authentication or dashboard features from working.

### 7. Data Retention

Retention depends on the type of information and why it is needed:

* ordinary access-log records are scheduled for deletion after approximately 12 hours;
* temporary delivery links and tokens expire after short operational periods and are removed by cleanup jobs;
* in-memory heartbeat, stage, geolocation, and delivery caches are temporary and are cleared by expiration, cleanup, or server restart;
* protected or obfuscated script chunks and script configuration are retained while the developer keeps the script in ZaroGuard;
* account, Discord authentication, subscription, webhook, key-system, blacklist, and ban information may be retained while the account or enforcement record remains active or while it is reasonably required for security and administration;
* stage-tracking, security, server-console, and diagnostic records may be retained for operational and abuse-prevention purposes; and
* backups or provider-managed copies may remain for a limited period after deletion.

We may retain information longer when necessary to investigate abuse, enforce a ban, resolve a dispute, protect the service, or comply with legal obligations.

### 8. Security

ZaroGuard uses access controls, session protection, token validation, rate limiting, staged delivery, obfuscation, anti-tamper checks, and logging intended to protect scripts and account information. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or disclosure will never occur.

Developers are responsible for keeping access keys, passwords, webhook URLs, API credentials, and account sessions confidential.

### 9. Your Choices and Requests

Users may clear browser cookies and stop using the service at any time. Developers may delete scripts and may disable optional owner-webhook delivery through available account controls.

Account holders may request access, correction, Discord unlinking, or deletion of account-related information by contacting ZaroGuard through its official Discord support channel. Some information may be retained when required for security, active bans, fraud prevention, dispute resolution, or legal compliance.

Requests may require identity verification. Deleting required account information may result in loss of access to the service.

### 10. Children's Privacy

ZaroGuard is not intended for anyone who is not legally permitted to use the service or enter into these terms in their location. If you believe a child has provided personal information in violation of applicable law, contact ZaroGuard through the official support channel.

### 11. Changes to This Policy

We may update this Privacy Policy when the service, providers, or legal requirements change. The effective date at the top will be updated when material revisions are published. Continued use after publication means the revised Policy applies to future use of the service.

### 12. Contact

For privacy questions, data requests, account unlinking, or concerns about this Policy, contact ZaroGuard through the official ZaroGuard Discord support channel listed on the ZaroGuard website or documentation.
