UTGARD operates this training platform and acts as the party responsible for the personal data described in this Policy. We do not have a dedicated privacy office or email address at this time — all privacy-related matters must be raised through a support ticket in our official Discord server.
By using the Platform, you acknowledge that you have read this Privacy Policy. We recommend reading it in full before creating an account or making a purchase.
The Platform is available only to individuals who are at least 15 years old. We do not knowingly collect personal data from anyone below this age. If we become aware that an account belongs to someone under 15, we will delete the associated data and revoke access.
Age is self-reported at sign-up; we do not currently operate a separate age-verification system beyond what Discord itself requires of its users.
When you sign in, we retrieve the following from Discord via OAuth 2.0:
This data is fetched fresh at every login and stored only inside your encrypted session (see 3.2) — we do not keep a separate database of Discord profiles.
Your session is a single encrypted, tamper-proof cookie — there is no server-side session database. It contains your Discord ID, display info, tier, an expiry timestamp, and a random session ID, encrypted with AES-256-GCM. A short-lived, encrypted state cookie is also used during login only, to prevent cross-site request forgery (CSRF), and is deleted immediately once login completes.
To enforce a one-account-per-device policy and reduce subscription sharing, we set two additional first-party cookies and record a binding record on our server:
This binding record is stored server-side in a private data file (not a public or third-party database) and is used exclusively to detect and block a purchased account being used from more than one device.
We temporarily track request counts per IP address in server memory to enforce rate limits (e.g. to slow down automated login attempts). These counters reset automatically and are never written to disk. Server logs may include IP addresses and request paths for a short period for debugging and abuse investigation.
A small UI preference (your chosen presence indicator — online / idle / do not disturb / offline) is saved using your browser's own local storage. This value never leaves your device and is not transmitted to us.
We do not currently collect or store lesson-progress history, quiz results, bookmarks, personal notes, uploaded videos, or any file-analysis submissions — these features do not exist on the Platform today. If any of them are introduced in the future, this Policy will be updated accordingly beforehand.
We only process personal data where it is necessary to:
We do not process your data for advertising, profiling, or any purpose unrelated to running the Platform. We do not use your personal data for any automated decision-making that produces legal or similarly significant effects on you — tier access is checked against your actual Discord roles, not an automated profile of you.
| Data | Retention |
|---|---|
| Session cookie | 24 hours, or immediately destroyed on logout |
| Login state (CSRF) cookie | 10 minutes, deleted after login completes |
| Device identifier & fingerprint cookies | Up to 1 year, refreshed on use |
| Device/account binding record | Retained while your account remains linked to a device; removed on a valid deletion request or staff unbind |
| Rate-limiting counters | In-memory only; auto-expire every 60 seconds; cleared on server restart |
| Server logs | Short-lived, kept only as long as reasonably needed for debugging/abuse review |
All cookies we set are strictly necessary for authentication and security. We do not use advertising, analytics, or third-party tracking cookies.
utgard_session — your encrypted session; HttpOnly, SameSite=Lax, Secure in production; 24 hours.utgard_state — CSRF protection during login only; HttpOnly; 10 minutes.utgard_device — random device identifier for anti-sharing enforcement; HttpOnly; up to 1 year.utgard_fp — your device's fingerprint hash for anti-sharing enforcement; HttpOnly; up to 1 year.A single local-storage value on your own device stores your chosen presence indicator (Section 3.5) and is never sent to our servers.
We use Discord as our sole authentication provider and community platform. When you sign in, Discord processes your login under its own Privacy Policy and Terms of Service. We only receive and store the profile fields described in Section 3.1.
The Platform loads typography and icon assets from Google Fonts and a public content-delivery network (jsDelivr). Loading these resources may expose your IP address to those providers under their own respective policies; we do not share any personal data with them ourselves.
We do not sell, rent, or trade your personal data to any third party, and we do not share it with advertisers or data brokers.
The Platform may be hosted and operated from infrastructure located outside your own country of residence. By using the Platform, you understand that your data may be processed in a different country than where you live, which may have different data protection laws than your own. We take reasonable steps to keep your data secure regardless of where it is processed, as described in Section 9.
If we become aware of a security incident that results in unauthorized access to or disclosure of your personal data, we will notify affected users through our official Discord server without undue delay, describe the nature of the incident to the extent known, and outline the steps we are taking in response.
Regardless of where you live, we aim to honour the following rights over your personal data. To exercise any of them, open a support ticket via our official Discord server:
The Platform may link to external websites or services, including Discord. We have no control over their content or privacy practices and are not responsible for them. We recommend reviewing the privacy policy of any external site you visit.
We may update this Privacy Policy from time to time. Material changes will be announced on our Discord server at least 7 days before they take effect. The date at the top of this page always reflects the latest revision. Continuing to use the Platform after a change takes effect means you accept the revised Policy.
For any privacy-related question or request, please open a support ticket via our official Discord server. We do not currently provide email or web-based support.