Privacy Policy
Overview
OME.UNDFND.EU ("we", "us", "the Platform") is committed to handling your personal data responsibly. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
This policy applies to the OME.UNDFND.EU website, dashboard, API, and browser extension. By using any part of the platform, you acknowledge this Privacy Policy. If you do not agree, please stop using the service.
Data We Collect
Data You Provide via Discord OAuth2
When you log in with Discord, we receive and store:
- Discord User ID, used as your unique account identifier
- Username, displayed in the dashboard and admin logs
- Avatar URL, displayed in the navigation bar and dashboard
- Guild membership, used to verify your Discord server membership status (not stored persistently)
- Account locale: used to determine the preferred language (Polish, English or German)
We do not receive your Discord email, phone number, or password.
Data Collected Automatically
- IP address, collected at login and stored for security purposes (duplicate login detection, geo-restriction awareness)
- API request logs. Timestamps and request counts used for rate limiting and usage statistics
- Search history, every IP address you look up via the browser extension is stored against your account, together with the location and network data the lookup returned. This happens on every tier, not only VIP. Browsing that history in the VIP panel is a VIP feature, but the record is kept either way, so if you have never held VIP, you have a history you cannot currently see. Ask us and we will send you a copy or delete it, and deleting your account removes it entirely.
- Session data. a session cookie is used to maintain your authenticated state while using the dashboard
- Extension settings: your overlay preferences (theme, accent, panel layout, automation rules) are stored on your account so they follow you between browsers
- Product usage events, a first-party record of named actions (for example "opened a case", "claimed a season reward") with your account id and a small set of counters, used to see which features are actually used. It never contains message bodies, IP addresses or free text
Community & Feature Data
- ISP ratings, ratings you submit for internet service providers (ISP name, rating, timestamp)
- IP Notes: if you write a note about an IP address, we store the subject, the description, any image you attach, and your account as its author. Notes are visible to every member who looks up that address until they expire. See People You Connect To for what this means for the person on the other end
- Chat, guestbook and endorsements, messages you post in the lobby chat, notes you leave on another member's profile, and the endorsements and reputation you give or receive are stored with your account and shown to others
- Pixel canvas, every pixel you place on the community canvas is recorded with your account id and a timestamp in a permanent, append-only history. This history is what the canvas replay and leaderboards are built from and, unlike the rest of your data, it is not erased when you delete your account . The placements are instead detached from your identity
- Camera capture statistics, the extension reports counters about how much of a connection it got a usable camera view for. See People You Connect To
- VIP code redemption records. Which code was redeemed, when, and by which account
- Cases and rewards. Every case you open is logged with its random seed, the roll and the prize, so any opening can be independently re-checked on our fairness verifier
Payment & Billing Data
VIP is paid from a top-up balance held on your account. You add funds by sending a transfer off-platform: BLIK, PayPal, Revolut, or cryptocurrency (LTC, ETH, USDC), and either uploading a screenshot of it for us to verify or, for crypto, letting the transaction confirm on-chain. We never receive or store your card number, CVC, or bank login, and we don't use a hosted checkout or third-party payment processor. For your balance, top-ups, and purchases we keep records containing:
- Recharge orders: the top-up amount, the payment method you chose, the confirmation screenshot you upload as proof of the transfer, the order status, any note from the reviewer, and timestamps
- Crypto deposits: where you top up with cryptocurrency, a deposit address is derived for your account and we store the transaction hash, the amount and the confirmation state. Note that a blockchain is a public, permanent ledger outside our control: we cannot edit or erase what is recorded there, and anyone who knows the address can see its transactions
- Balance & purchase details: your current balance and, for each VIP purchase, the plan bought, amount and currency (in euro cents), the VIP code issued, any affiliate code applied, and timestamps
Affiliate Program Data
- Affiliate referral code, a unique code automatically assigned to your account on first login and stored on your user profile
- Referral records: when another user purchases VIP using your code, a record is created containing the purchase value (in euro cents), the commission rate locked in at that time, and the commission earned
- Withdrawal requests, when you request a payout we store the requested amount, your chosen payment method, and the associated payment details: a PayPal email address, a Revolut @tag, or. Where crypto payouts are enabled, the wallet address you supply and the hash of the transaction that settles it
Discord Bot Data
Our bot runs in our own community server only. It cannot be added to other servers, and it handles Discord data as follows:
- Message content, messages posted in the server are checked against automated moderation rules as they arrive. Content is not stored outside Discord, is never used for analytics or profiling, and is never used to train machine learning or AI models. Moderation-log entries stay in staff channels on Discord and are removed on request.
- Ticket transcripts: when a support ticket is closed, a plain-text transcript is generated, sent to the ticket owner and archived in a staff channel on Discord. Both copies live on Discord and are removed on request.
- Presence, used only to produce an aggregate online count shown in the bot status, the extension widget and the site statistics. No per-member presence is stored and no history is kept; members who appear offline are simply not counted.
- Member data: your Discord ID, username, avatar, locale and derived role tier form your account record. We do not store role lists, join dates, nicknames or the member list itself. Leaving the server revokes your API access.
Your Public Profile
/u/<your Discord ID> that is public by default: visible to anyone with the link, signed in or not. You can switch it off entirely, or hide individual sections, at any time.The page is addressed by your Discord user ID, so the ID is visible to anyone who opens it. Depending on which sections are left on, it can show your username and avatar, your level and XP, badges and achievements, cases you have opened, the countries you have connected to, your activity heatmap, your pixel-canvas contributions, your reputation score and endorsements, your bio, and the guestbook notes other members have left you.
Profiles are also listed in the member directory and may be indexed by search engines while public. To change any of this, open Profile → Settings → Privacy: the master switch takes the whole page offline, and the per-section toggles carve individual blocks out of an otherwise public page. New accounts are asked to make this choice during onboarding.
People You Connect To
This section is about someone other than you: the stranger on the other end of an Ome.tv connection. They are not our user, they have not agreed to these terms, and we think it is only fair to be plain about what the product derives from their connection.
When you look up a connection, the following is processed about that person:
- Their IP address, and the location and network data it resolves to. This is the core of the service. The lookup is recorded in your search history
- An estimated age and gender, where the camera analysis features are in use. This is computed in your browser from the video already on screen; the video itself never reaches our servers. What reaches us is one verdict per connection, folded immediately into a daily per-user total. No record of an individual connection is kept, and the estimate is never linked to an IP address
- Bot-detection signals, short one-way hashes that describe the video content (a looping sequence, a frozen frame, a burned-in overlay), not the person in it. A verdict is only ever produced when many members independently report the same content, and the link between a signal and an IP address is deleted after three weeks
- Anything a member writes about them in an IP Note, including an optional captured frame of their video. This is the one place where the product publishes something about an individual rather than about a network
We rely on legitimate interests, letting people see who they are about to talk to on an anonymous video platform, and filter out bots and abuse, and we have deliberately designed the telemetry above so it cannot single anyone out: it is aggregated, hashed or expiring by construction. We do not build profiles of non-users, we do not attempt to identify anyone, and we do not sell or share any of it.
IP Notes are the exception, and we treat them as such. They are member-written, so they can be wrong, unfair, or about whoever holds an address next. Notes expire on their own (one day for mobile addresses, otherwise 7–30 days), are screened, and can be reported and removed. Notes that identify, target or harass someone are not allowed and cost the author the feature.
If you were on the other end of a connection and want to know what is held about an address, have a note about it removed, or object to this processing, email us at [email protected]. You do not need an account with us to ask, and we will act on it the same as any other request under Your Rights.
How We Use Your Data
We use the data we collect for the following purposes:
- Authentication & authorization, verifying your identity and access level on each request
- Service delivery: generating your API token, serving your dashboard, processing ISP ratings, storing search history
- Security: detecting suspicious login patterns, preventing account sharing and abuse
- Platform analytics, understanding aggregate usage to improve the service (no personally identifiable analytics are shared externally)
- Communication, notifying you of significant platform changes via Discord (we do not send email)
- VIP management: tracking subscription status, expiry, and Discord role synchronization
- Payment processing: verifying your balance top-ups, debiting your balance for VIP purchases and case openings, issuing your VIP code, and keeping a billing history in your dashboard
- Community features: running the lobby chat, public profiles, guestbook, endorsements, badges, seasons and the pixel canvas, and moderating them
- Affiliate commission tracking, calculating and crediting commissions earned through referrals, and processing payout withdrawal requests
We do not use your data for advertising, profiling, or any purpose beyond running and improving the platform.
Data Sharing
We do not sell, rent, or trade your personal data to third parties. Data is shared only in the following limited circumstances:
- Discord. We interact with the Discord API to manage server roles and authenticate users. Discord's own Privacy Policy governs data processed on their end
- Google Analytics: aggregate, anonymized traffic data is sent to Google Analytics. See the Cookies & Tracking section for details
- Legal obligations. We may disclose data if required by law, court order, or to protect the rights, safety, or property of OME.UNDFND.EU or others
Data Retention
We retain your data for as long as your account is active. Specific retention periods:
- Account data (Discord ID, username, avatar), retained until you request deletion
- Search history. Retained until deletion is requested; VIP users can clear their own history from the panel, and anyone can ask us to clear it
- Login IP address, retained alongside account data; used only for security purposes
- API request logs, retained for up to 90 days for rate limiting and abuse detection
- Product usage events: 90 days, then deleted automatically
- IP Notes: expire on their own: one day for mobile addresses, otherwise 7–30 days as chosen by the author. Expired notes stop being served immediately and are deleted by a daily sweep
- Bot-detection signals, the link between a signal and an IP address is deleted after 21 days, so a verdict can never outlive the address's current occupant
- Camera capture statistics, kept only as per-day totals per account; no individual connection is ever stored, so there is nothing narrower to delete
- Notifications and scheduler logs, 60 and 14 days respectively
- Profile activity heatmap, daily activity cells age out after roughly 400 days
- ISP ratings, retained indefinitely as part of the anonymized community dataset; individual attribution may be removed on request
- Pixel-canvas history, permanent. The canvas replay, timelines and leaderboards are all derived from this append-only log, so placements are not deleted; on account deletion they are detached from your identity instead
- Affiliate & referral records, retained until you request account deletion; withdrawal records may be retained for financial record-keeping purposes even after account deletion
- Billing & payment records, retained for financial and tax record-keeping purposes, and may be kept even after account deletion to the extent required by law
- Shared-device records, when you generate a script we store your browser fingerprint and network address against your account, so we can tell when several accounts are being run from one device. Kept for 90 days, and deleted with your account
- Free-allowance record, a one-way cryptographic hash of your Discord ID, recorded when your free lookups are granted. See the note below: this is the one record that survives account deletion
- Session cookies, expire on browser close or logout
You can delete your account yourself from the dashboard. Deletion runs after a short grace period, so you can cancel if you change your mind, and it removes your personal data from our active databases. Some aggregated or de-identified data, ISP ratings without user attribution, canvas placements detached from your identity, and billing records we are required to keep, remains as described above.
One exception, stated plainly. Every account receives a one-time allowance of free lookups. To stop the same person collecting it over and over by deleting and re-creating their account, we keep a record that a given Discord account has already had its allowance, and that record is not deleted when you delete your account. It contains no username, no IP address and no usable identifier: only a keyed one-way hash of the Discord ID, which we can compare against but cannot reverse, and which is meaningless to anyone who does not hold our server-side key. We keep it under our legitimate interest in preventing fraud and abuse of a free service. If you delete your account and later sign up again with the same Discord account, this is the reason the free allowance is not granted a second time.
Security
We implement reasonable technical and organizational measures to protect your data against unauthorized access, disclosure, alteration, or destruction. These include:
- HTTPS encryption for all data in transit
- Server-side session management with cryptographically signed cookies
- Rate limiting on authentication and API endpoints
- Access tokens that can be regenerated by the user at any time
- Discord OAuth2 authentication (we never handle your Discord password)
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.
Your Rights
Depending on your location, you may have certain rights regarding your personal data under applicable law (including GDPR for users in the EU/EEA):
- Right of access. You can request a copy of the personal data we hold about you
- Right to rectification. You can request correction of inaccurate data (most account data updates automatically on next login)
- Right to erasure. You can request deletion of your account and associated personal data. Two things survive, both listed in Data Retention: records we are legally required to keep (billing and tax), and the one-way hash recording that your Discord account has already received its free allowance
- Right to restriction. You can request that we limit processing of your data in certain circumstances
- Right to data portability. You can request your data in a structured, machine-readable format
- Right to object. You can object to processing based on legitimate interests
- Right to withdraw consent. You can withdraw consent for analytics cookies at any time via cookie preferences
The quickest route for erasure is the self-service account deletion in your dashboard. For anything else, email [email protected] or contact us via Discord. We will respond within 30 days. We may need to verify your identity before processing requests.
You do not need an account to exercise these rights. If you believe you appear in our data as someone else's connection (see People You Connect To), write to the same address.
If you are in the EU/EEA and are unhappy with how we handled your request, you have the right to lodge a complaint with your national data protection authority.
California residents
If you live in California, the CCPA (as amended by the CPRA) gives you the rights above under different names, and they apply to you the same way: to know what personal information we collect and why (see Data We Collect), to delete it, to correct it, and to opt out of its sale or sharing.
There is nothing to opt out of on that last one. We do not sell or share personal information as those terms are defined by the CCPA, we do not use it for cross-context behavioural advertising, and we have not done either in the preceding 12 months. See Data Sharing for the complete list of who receives data and on what basis.
Exercise any of these at the address above. We will not discriminate against you for doing so: your account, your balance and your VIP time are unaffected by a privacy request. An authorized agent may make a request on your behalf, in which case we will ask for proof of their authorization and verify your identity directly.
Other US states
Several other states now have comprehensive privacy laws granting substantially the same rights — to know, to delete, to correct, to a portable copy, and to opt out of the sale of personal data or its use for targeted advertising. If you live in one of them, those rights apply to you here on the same terms and through the same address. We do not sell personal data, we do not use it for targeted advertising, and we do not profile anyone in a way that produces legal or similarly significant effects, so there is nothing to opt out of. If your state gives you a right to appeal a refused request, write to the same address and say so, and a human who did not handle the original request will answer.
Children's Privacy
OME.UNDFND.EU is an 18+ service. It is built for use alongside an adult video-chat platform and it sells paid digital items, so it is not directed at children and we do not knowingly collect personal data from anyone under 18.
If you are a parent or guardian and believe a minor has created an account, contact us at [email protected] and we will close it and delete the data promptly.
Third-Party Services
The platform integrates with the following third-party services. Each has its own privacy policy:
- Discord, authentication provider. Discord Privacy Policy
- Google Analytics, aggregate traffic analytics (only with consent). Google Privacy Policy
- Google Fonts & CDN. Fonts and icons are loaded from Google CDN/Cloudflare CDN. Standard CDN request logs apply
- Cloudflare Turnstile: the "are you human" check on login, case openings and the welcome pack. Cloudflare receives your IP address and browser characteristics to run it. Cloudflare Privacy Policy
- Map tile providers, the overlay and dashboard maps draw their tiles from CARTO (street and dark styles) and Esri/ArcGIS (satellite). Loading a tile discloses your IP address and the map area you are viewing to that provider
- FlagCDN, country flag images shown next to a looked-up location are loaded from flagcdn.com. That request discloses your IP address and, by which flag is requested, the country of the connection you are viewing
- Blockchain networks, where you top up or withdraw with cryptocurrency, the transaction is recorded on a public ledger (Litecoin, Ethereum or Polygon) that we neither control nor can erase
The browser extension's own libraries, the map renderer and the in-page camera-analysis model: are served from our own domain, not from a public CDN, so using the extension does not disclose your activity to a third-party script host.
We are not responsible for the privacy practices of these third-party services. We encourage you to review their policies.
Policy Changes
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes may be announced via our Discord server. Your continued use of the platform after a policy update constitutes acceptance of the revised policy.
Contact
For privacy questions, data access or deletion requests, or complaints, write to [email protected]. This address is monitored and does not require a Discord account. Use it for anything you want on record.
For quick, informal questions our Discord server is faster: open a ticket in #open-ticket and a staff member will pick it up.
Privacy questions or data requests?
Email [email protected] for anything formal, data access, correction, deletion or a complaint. You do not need a Discord account to use it. For a faster, informal answer, open a support ticket in our Discord server.