Privacy Policy
How Project CPP handles account, device, and overlay data. Last updated September 1, 2026.
1. Who this covers
This Privacy Policy explains how Project CPP handles information when you use the website, dashboard, loader, overlay, cloud configs, and the control connection between the dashboard and a running executable.
It applies together with the Terms of Use. Contact for privacy requests is Discord: discord.gg/py5MekDYq.
2. Information we collect
Account data: username, email address, password hash, Discord user ID, subscription or license status, and optional avatar. Email is stored encrypted; we also keep an email hash so we can check uniqueness without storing the address in the clear.
License data: keys you redeem, duration, status, and when they were used.
Device and session data: hardware identifier (HWID) from the loader, optional device details (CPU, GPU, storage, motherboard, OS), user agent, IP address, device name/platform, session identifiers, and whether the loader is currently connected.
Security data: optional authenticator (TOTP) secret if you enable two-factor authentication, trusted-device flags, login and admin audit events, and rate-limit counters.
Product data: overlay configs you save or share, likes, apply/auto-apply choices, and control-channel messages needed to sync the dashboard with the loader.
Purchase data: checkout email, name, phone, and billing address for orders placed with or without an account. Receipts and license keys are sent to the checkout email. Email is stored encrypted, with a hash used to match unfinished orders and coupon limits.
We do not scrape FiveM character inventories or sell advertising profiles. Overlay settings you store with us are product data, not a public gameplay dossier.
3. How we use it
We use this information to create and authenticate accounts, bind a license to one user and one machine, detect shared or stolen sessions, serve the loader and build-status checks, store and apply cloud configs, pair the website with the exe, investigate abuse, and send account-critical notices (for example bans, HWID resets, or security events).
We do not use your email for marketing lists. Discord is the support and announcement channel.
4. Cookies and local storage
The website sets HttpOnly cookies for access and refresh tokens and a CSRF cookie so the dashboard can call the API. Tokens are not kept in localStorage. The browser may keep a copy of your public profile (username, email display, license status) in localStorage so the dashboard can render after a refresh; signing out clears it.
If you block cookies, checkout, login, and licensed features will not work.
5. Storage and security
Passwords are hashed. Email is encrypted at rest. Sessions use short-lived access tokens and rotating refresh tokens. The control websocket requires a ticket from a logged-in licensed session. Admins can reset HWID, revoke sessions, blacklist keys or users, and delete accounts.
No method of transmission or storage is perfectly secure. You still need a strong password and, if you enable it, two-factor authentication on the website.
6. Sharing
We do not sell your personal information. We share data only with infrastructure needed to run the Service (hosting, database, and similar processors acting on our instructions), when you choose Discord as the support channel, or if we are required by law or need to protect the Service against fraud or abuse.
Public or shared cloud configs may show your username and config metadata to other licensed users. Do not put secrets in a public config.
7. Retention
Account, license, HWID, and config records last for the life of the account unless an operator deletes them. Session records expire according to the login (“remember me” extends that window). Audit and live-monitor logs are kept for security and operations; older live-log views on the admin monitor are capped, not an archive of everything forever.
Ask on Discord if you want an account deleted. Deletion removes or de-identifies account data we control; backups and legal holds may last longer. We may keep identifiers needed to enforce a ban (for example a blacklisted HWID or Discord ID) so the ban cannot be bypassed by re-registering.
8. Your choices
You can update profile details available in the dashboard, change your password, enable or disable two-factor authentication, revoke devices/sessions, and stop using the loader. For access, correction, or deletion of personal data we hold, contact us on Discord from the Discord ID on the account.
Where data-protection law gives you additional rights (access, erasure, restriction, portability, objection), we will honor them to the extent they apply and we can verify you.
9. International processing
Servers and operators may be in a different country from you. By using the Service you understand your information may be processed where we host the API and database.
10. Children
The Service is not directed at children under 18. We do not knowingly collect personal information from them. If we learn we have, we will delete the account.
11. Changes
This policy was last updated September 1, 2026. We may change it as the product changes. The date on this page is the current version. Continued use after an update means you accept the revised policy.
12. Contact
Privacy questions and deletion requests: Discord at discord.gg/py5MekDYq.
See also the Terms of Use.