legal
Privacy policy
Effective
This Privacy Policy explains what personal data The Krew (“we”, “us”, “our”) collects when you use Panopticon, why we collect it, and the choices you have. It covers the Panopticon moderation panel (the “App”), the Panopticon community forum (the “Forum”), and this website.
The Krew is an unincorporated association that operates these services. You can reach us about privacy at [email protected].
The short version
- The App has no passwords — you sign in with Steam. You can optionally add and verify an email so you can sign in to the community forum with your Panopticon account.
- We run no advertising, no analytics, and no third-party trackers, and we do not sell your personal data.
- Panopticon is a moderation tool, so it necessarily records moderation actions and evidence — including data about the game-server players who are moderated.
- The Forum uses an email address and password, and adds a few services common to a community forum (spam filtering and optional Discord sign-in). You can also sign in to the Forum with your Panopticon account.
- Some records — especially the App’s tamper-evident audit log — are kept on purpose and cannot be edited, so they can outlast your account.
Who this policy is about
Panopticon involves three groups of people:
- Panel users — the moderators, admins, and owners who sign in to the App.
- Forum members — people who register on the community forum.
- Game-server players who are moderated — the people a moderator acts on (mutes, kicks, bans, notes, reports). Players do not have Panopticon accounts and do not sign in; they appear in the App because a moderator records an action about them.
What we collect
In the App (Panopticon panel)
- From Steam, when you sign in: your SteamID, your Steam display name, and your Steam avatar image URL. We do not receive or store a password, and Steam does not release your email to us.
- An optional email address. The App does not use email to sign in, but you may add one — confirmed through a verification link — so you can use your Panopticon account to sign in to the community forum. You can change it at any time; it is stored only on your account.
- A session cookie. A single functional cookie named
panopticon_sessionkeeps you signed in. It is HttpOnly, sent only over HTTPS, and expires after 24 hours. Your light/dark theme choice is stored locally in your browser (pan.theme); it never leaves your device. - Security and audit data. For each action you take, the App records it in an immutable audit log together with your IP address, your browser’s user-agent, the time, and an identifier for your session.
- Moderation data you create. The reasons, notes, watchlist entries, reports, escalations, and the mutes, kicks, and bans you issue — each tied to the target player’s SteamID — along with any evidence you attach (links to screenshots, clips, or logs) and server events your servers send us through the API (which can include events such as player joins and chat lines).
- API keys. If you create API keys for your servers, we store only a hashed form of each key (not the key itself), plus its name, scope, and any IP restrictions.
About moderated players
Because Panopticon is a moderation tool, moderators record data about players on the servers they run. This can include a player’s SteamID, and — if a moderator notes a player — a cached copy of that player’s Steam display name and avatar, fetched from Steam. It also includes whatever a moderator records: reasons, notes, evidence, and mute, kick, ban, watchlist, and escalation history. The server owner decides what to record about players on their own servers; we provide the tools and operate the shared global ban list.
In the Forum
- Account data: your email address, username or display name, and a password (stored in hashed form by the forum software).
- Profile data you choose to add, such as which games you run, an approximate player count, or a Discord handle.
- Content: your posts, replies, uploads, likes, and flags.
- Technical data: IP addresses and logs kept by the forum software to run the site and fight spam.
- Discord (optional): if you sign in with Discord, we receive your Discord account identifier and basic profile details from Discord.
On this website
This marketing site sets no cookies and runs no analytics or trackers. Your theme preference is stored locally in your browser and never sent to us.
How we use your data
We use personal data to:
- sign you in and keep your session secure;
- provide the moderation panel and let you moderate your servers;
- operate the shared global ban list and the anti-cheat review process;
- keep the tamper-evident audit log for accountability and security;
- run the community forum, including spam prevention and the invite gate;
- respond to you when you contact us; and
- protect the Services and comply with the law.
We do not use your data for advertising or for automated decisions that have legal effects on you.
When we share data
We do not sell your personal data. We share it only in these cases:
- Steam (Valve). When you sign in to the App and when we look up a player’s Steam profile, we exchange the relevant SteamID with Steam. Steam’s handling of your data is governed by Steam’s own privacy policy.
- Discord (Forum, optional). If you link Discord to your Forum account, your Discord data is handled under Discord’s privacy policy.
- Community forum single sign-on. When you choose to sign in to the Forum with your Panopticon account, we share with the Forum what it needs to create or update your forum account and set your groups: an identifier for your Panopticon account, your username and display name, your verified email, and whether you are a tenant owner or a server moderator. This happens only when you start a forum sign-in, or when your tenant role later changes; we do not otherwise send your data to the Forum.
- Email delivery (optional). If you add an email to your account, we send a confirmation message through an email delivery provider to verify it.
- Spam filtering (Forum). The Forum sends post content and related metadata, including your IP address, to the Akismet spam-filtering service to detect spam.
- Ko-fi (donations, optional). If you donate, Ko-fi processes the payment; we never receive your card details.
- Infrastructure providers. We use hosting and infrastructure providers to run the Services; they process data on our behalf under their own terms.
- The global ban list is shared across tenants by design. A player added to it — their SteamID and the reason — is visible to and enforceable by other participating servers.
- Legal reasons. We may disclose data if required by law or to protect the Services, our users, or the public.
Cookies and tracking
The App uses one functional cookie (panopticon_session) to keep you signed in, and stores your theme choice locally. The
Forum uses functional cookies needed to run a forum and keep you signed
in. This website uses none. We do not use advertising cookies,
cross-site trackers, or analytics anywhere.
How long we keep data
- Audit log: kept for about 365 days in active storage, then moved to archival storage rather than deleted. Audit records are immutable and are retained for security and accountability.
- Moderation records (bans, mutes, kicks, notes, watchlist, escalations, global bans): kept for as long as they are needed for moderation — for example, while a tenant exists or while a global ban stands. Notes are versioned and their history is retained.
- Sessions: expire automatically after 24 hours; signing out ends them sooner.
- Your email: kept while it is set on your account, and removed when your account is deleted. Unclicked verification links expire after 24 hours.
- Forum accounts and posts: kept while your account is open. You can request export or deletion (see below).
Your rights and choices
- Forum members can export their data and request account deletion directly through the Forum’s built-in privacy tools.
- Panel users can ask us to access, correct, or delete their account data by emailing [email protected]. Please note two limits that exist for integrity and safety: the audit log is immutable and cannot be edited or erased, and we may keep records that are necessary for the global ban list or for security. Account deletion is carried out by an administrator on request and may be limited where you have moderation history, so that the record of past actions stays intact.
- Moderated players. If you are a player and want to know about, correct, or dispute data held about you — such as a global ban — contact us at [email protected] or use the dispute process. For records specific to one server, the tenant that moderated you is the primary decision-maker.
- Region-specific rights. Depending on where you live — for example in the EEA, the UK, or California — you may have rights to access, correct, delete, or port your data, to object to or restrict certain processing, and to complain to a regulator. Because we do not sell personal data, there is nothing to opt out of on that front. Email us to exercise any of these rights.
Community forum sign-on and your account
Signing in to the Forum with your Panopticon account links the two. The forum groups tied to Panopticon — Tenant Owner and Server Moderator — follow your Panopticon roles: if you stop owning or moderating a tenant, we remove the matching group, but we never delete your forum account or your ability to use the Forum as an ordinary member. If you delete your Panopticon account, or an administrator revokes your forum access, we stop authorizing forum sign-in for you and remove the forum groups we manage; your forum account itself remains and is governed by the Forum’s own tools, including its data-export and account-deletion features.
Security
We protect data with measures including HTTPS, signed session cookies, hashed API keys, tenant isolation, and the tamper-evident audit log. No system is perfectly secure, however, and Panopticon is early software — we cannot guarantee absolute security.
International transfers
We and the services we rely on — including Steam, Discord, and Akismet — may process your data in the United States and in other countries. Where required, we rely on appropriate safeguards for these transfers.
Children
The Services are not directed to, and may not be used by, anyone under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has given us data — including a player’s data that appears in moderation records — contact us and we will address it.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will change the effective date above, and for material changes we will give reasonable notice through the Services.
Contact
Questions, requests, or complaints about your privacy? Email us at [email protected].