Privacy Policy

Last updated July 2026 · applies to cryon.rocks and everything under it

The short version

We collect the bare minimum to run the app: your Discord login info, whatever you type into sessions and work orders, and screenshots you choose to upload. We don't run ad trackers, we don't have an analytics pixel farming your behavior, and we've never sold anyone's data to anyone, and never will. If you register a developer app or generate an API key, we collect what's needed to run those safely and nothing more. Message us on Discord.

1. Who we are

Motherlode is built and run by Cryon Dynamics, a small team, not a company with a dedicated privacy office. This policy is written by that team, in plain language, because most privacy policies are unreadable and we didn't want ours to be one more.

2. What we collect

Account info. We don't build or run our own login system — that's not something a small team should roll by hand, so sign-in goes through Discord using standard OAuth. You authenticate directly with Discord; we never see, touch, or store your password. What comes back to us afterward is the basic profile info Discord hands over — your username, display name, avatar, and Discord ID — which we store so the app can identify you.

Guest sessions. If you join a session as an anonymous guest, we don't attach any identity to what you enter beyond whatever name you type in for that session.

Content you create. Sessions, work orders, scouting finds, org data, saved loadouts, profile stats — anything you fill into a form gets stored so the app can show it back to you (and to your session or org members, where it's meant to be shared).

Push notifications. If you opt into refinery alerts, your browser gives us a push subscription endpoint so we can wake up your device when a work order is ready. Turning alerts off removes it.

The boring infrastructure stuff. Our host and database provider generate the standard request logs any web service does — IP address, timestamps, basic request metadata. We use this for debugging and abuse prevention, not for building a profile of you.

API keys and developer apps. If you generate an API key from your Developer page, we store the name you gave it, a hash of the key (never the raw key itself, so we can't see it even if we wanted to), and when it was last used — that's enough to let you manage and revoke it, and to enforce rate limits. If you register an OAuth app so other people can "Connect with Motherlode," we store the app's name, description, logo, and redirect URLs, same as any developer-platform registration.

Connected apps. When you authorize a third-party OAuth app, we store which scopes you approved (e.g. your display name and avatar, your ore inventory, or the names of orgs you belong to — never more than what's shown on the consent screen) and a record of the access grant so you can review and revoke it later from Connected Apps. What that third-party app does with the data after we hand it over is governed by that app's own privacy practices, not this one — check them before connecting something you don't trust.

3. What we don't do

  • No ad networks, no ad trackers, no third-party analytics pixels
  • No selling, renting, or trading your data — full stop

4. Who can see what

Session data is visible to the members of that session, and to the public if the session owner marks it public. Org data is visible to org members, plus whatever a public org profile chooses to show. Data exposed through the public API (ore, ship, and price reference data) is the same non-personal reference data anyone can already see on the site — it doesn't include your account, sessions, or org details. A third-party app you've connected only sees what you approved for it on the consent screen.

5. Where it lives

We don't run our own servers or database in a closet somewhere — the app, its database, and file storage all sit on established, industry-standard managed infrastructure, the same kind of setup most modern web apps use. Same story as auth: we'd rather lean on providers who do this for a living than roll our own and get it wrong. Anything they hold on our behalf is still covered by this policy — using a managed provider doesn't mean we've outsourced our responsibility for your data.

6. Cookies and local storage

We use the login cookie our authentication provider sets to keep you signed in between visits, and some local browser storage for client-side preferences (like streamer mode or your last-used session). That's it — no tracking cookies, no cross-site identifiers.

7. Your controls

You can update your profile info from your profile page at any time, delete individual sessions, scout finds, or work orders you own, leave any org or session you're part of, and revoke any API key or connected app from your Developer and Connected Apps pages whenever you want — revoking is immediate. If you want your account and associated data removed entirely, message us on Discord and we'll take care of it — we may hang on to anonymized aggregate stats, like a scouting data point stripped of who submitted it.

8. Changes to this policy

If this changes in a way that matters, we'll note it in the changelog and bump the date at the top. We're not going to quietly rewrite this to grab more data later — if that's ever on the table, you'll hear about it first.

9. Contact

Same as everything else on this site: Discord is fastest.

Terms of ServiceHomeChangelog