Calvary Protect
ProtectStatusSetupRegistrySecurityTrustDevelopersVerifyAccountDashboard
Invite
Calvary Protect legal center

Privacy Policy

What Calvary Protect collects, why it is used, how long it is kept, and the choices available to you.

Policy version 1.3 Effective July 27, 2026 Build 6.15.0-trust-reliability
On this page
01Who we are02Information we collect03Protected devices and staff evidence access04What we do not do05How we use information06Automated processing and human review07When information is shared08Retention and deletion09How we protect information10Your privacy choices11Age, regional rights, and international processing12Third-party services13Changes and contact
Read the Terms of Service →
CP
Evidence-led and reviewable by design

Pending reports stay private and do not create public findings or automatic punishment. Verified registry findings require two distinct eligible reviewers, and subjects can appeal.

01

Who we are

Stars & Stripes Mods operates Calvary Protect (“Protect,” “we,” “us,” or “our”), a developer-protection service for the FiveM community. This policy applies to the Protect website and installable web app, Discord bot, API, customer and staff accounts, registry, report and appeal workflows, and connected FiveM resources.

02

Information we collect

We collect only information needed to operate, secure, and review the service:

  • Account data: email address, encrypted email record, password hash, account role and status, Discord-link status, login timestamps, failed-login controls, and account audit events.
  • Discord data: user IDs, usernames or display names, server IDs and names, relevant roles and permissions, installation and configuration choices, and the commands, forms, or attachments you intentionally submit to Protect.
  • FiveM and developer data: Cfx/FiveM, license, Steam, or Discord identifiers submitted in a report or received from a configured server; protected server heartbeats; developer, store, domain, Cfx profile, Tebex, resource, entitlement, release-signature, fingerprint, and privacy-safe watermark records.
  • Case data: permanent case numbers, automated intake checks, private evidence indexes and hashes, report and appeal statements, target details, evidence links and encrypted files, timestamps, reviewer decisions, linked registry or blacklist records, enforcement results, correction requests, and audit history.
  • Appeal-intake data: a restricted Appeal Access role, private support-ticket ID, linked case and registry record numbers, ticket messages, and staff routing. Protect does not copy evidence into an automatically opened appeal ticket.
  • Security and device data: request timestamps, build and service-health data, rate-limit events, truncated cryptographic request fingerprints derived from network address and user agent, essential session cookies, local PWA cache state, notification permission or health state stored by your browser, protected-device labels, and self-reported security controls.
  • File safety data: filename, byte size, SHA-256, antivirus engine and result, detection name when malware is found, scan purpose, related case or account ID, and timestamp. Customer safety-scan files are streamed to our private antivirus engine and discarded after the result; case evidence follows the separate encrypted-evidence retention rules.
03

Protected devices and staff evidence access

If you choose to register a protected device, we store the device name you enter, its selected type (phone, tablet, computer, or other), a broad browser-platform label, creation and last-seen times, revocation status, and any security checklist you submit. The checklist may include operating-system family; whether antivirus or platform protection, firewall, automatic updates, encryption, and screen lock are on; and your last scan date. These answers are self-reported unless a future signed native agent explicitly says otherwise.

Protect does not collect a hardware fingerprint, precise location, installed-app inventory, serial number, or device contents. A recognized-device cookie never grants login by itself, and you can revoke the record from your account. Case evidence is available only to authorized staff through a current MFA-backed staff account or a signed, one-time Discord staff dashboard session. Evidence responses are no-store, verify the preserved SHA-256 integrity record, and create an access audit event. Customer, developer, and public sessions cannot open staff evidence routes.

04

What we do not do

Protect does not sell personal information, use it for targeted advertising, or continuously read ordinary Discord conversations or direct messages. The bot does not request Discord’s Message Content privileged intent. It processes slash-command inputs, forms, evidence, member and server information required for configured protection features, and operational events sent by connected services.

Public registry pages exclude pending, denied, removed, and appealed findings and mask sensitive identifiers. Sharing a server, customer, partner, or community with a reported person is not treated as a match.

05

How we use information

We use information to create and secure accounts; link Discord identities; verify developers, stores, ownership, entitlements, and signed releases; receive and investigate reports; preserve, index, and validate evidence; perform advisory 24/7 completeness triage; provide case tracking and appeals; detect exact registry matches; auto-provision requested Discord roles and channels; route verified subjects into private appeal intake in the official support guild; alert configured servers; apply their opt-in verified-case policies; prevent fraud and abuse; maintain audit records; and monitor service reliability.

06

Automated processing and human review

Protect may continuously check whether a submission has evidence, integrity hashes, exact identifiers, required context, related cases, or registered-release matches; calculate advisory risk signals; compare submitted identifiers or file fingerprints with registry records; and scan a configured guild for exact Discord ID matches. This automated triage can organize a case or request missing information, but it cannot decide guilt, verify a finding, publish a registry entry, or authorize enforcement.

A supported verified finding requires approval from two distinct eligible reviewers. Discord enforcement is limited to supported verified leak or theft categories, exact Discord IDs explicitly included in the reviewed incident, servers that enabled auto-ban, and the permissions Discord allows. A case may include a primary account and separately reviewed linked accounts; Protect does not infer links from names, avatars, IP addresses, devices, or shared servers. The official support guild is an appeal-safe exception: a verified subject is routed to a restricted private ticket instead of an automatic ban, and that ticket contains case metadata but no evidence. Appeals and approved reversals can remove supported Protect enforcement.

07

When information is shared

We may provide the minimum necessary information to authorized Protect staff and reviewers, administrators of a server involved in an alert or enforcement result, and infrastructure providers that host the website, database, encrypted evidence, or communications. When enabled by a developer or server, Discord, Cfx.re/FiveM, and Tebex may process identifiers or integration events under their own policies.

We may also disclose information when required by law, to address a credible safety or security threat, to investigate abuse of Protect, or as part of a business transfer subject to appropriate safeguards. We do not publish raw evidence, reporter identities, reviewer identities, full private identifiers, account emails, or passwords in the public registry.

08

Retention and deletion

Configured servers select an evidence-retention period from 30 to 365 days. Evidence for a closed, denied, removed, resolved, upheld, rejected, or withdrawn matter is eligible for automated deletion after that matter’s configured period. Open investigations, appeals, account and entitlement integrity, fraud prevention, security incidents, backups, or legal obligations may require records to be kept longer.

Account, registry, decision, and audit records are retained only while reasonably needed for the service, security, dispute resolution, or legal obligations. Deletion or correction may be limited where removing a record would compromise another person’s rights, an active case, enforcement integrity, or a legal duty; the reason should be documented during review.

09

How we protect information

Protect uses HTTPS, access controls, secure HTTP-only session cookies, salted scrypt password hashes, encrypted account email records, a managed database, rate limits, audit events, and signed service requests. Submitted files stream through a private ClamAV engine before preservation; known malware is blocked, scanner outages fail closed into quarantine, executable content is blocked, and ZIP archives remain quarantined even after a clean result. Preserved evidence is encrypted with AES-256-GCM and plaintext integrity is recorded with SHA-256.

Antivirus detects known and suspicious content but cannot guarantee that a file or device is harmless. A web application cannot inspect an entire PC, phone, or tablet. Continue using supported operating-system security, updates, backups, and a trusted endpoint product. If you discover a vulnerability, report it privately through support and do not include unrelated personal data or publicly exploit the issue.

10

Your privacy choices

You may request access, export, correction, or eligible deletion of information associated with you. Use /data-request in Discord, open your Protect account, or contact support. You may also submit an appeal or counter-evidence if a finding concerns you.

You can disable browser notifications in device settings, clear the Protect PWA cache or local health state, sign out to remove active session cookies, unlink Discord through support, or ask a server administrator to disable local Protect screening or enforcement. We may need to verify your identity before fulfilling a request.

11

Age, regional rights, and international processing

You must meet the minimum age required by Discord, Cfx.re/FiveM, and the law where you live. Protect is not directed to children below those requirements, and we do not knowingly create accounts for them.

Your information may be processed where Protect and its service providers operate. Depending on your location, privacy law may give you additional rights to access, correct, delete, restrict, object, or complain to a regulator. We will evaluate verified requests under the law that applies to you.

12

Third-party services

Discord, Cfx.re/FiveM, Rockstar Games, Take-Two Interactive, Tebex, and external developer stores are separate services with their own terms and privacy practices. Calvary Protect is not affiliated with, endorsed by, or sponsored by those parties unless expressly stated. Their services may collect information independently when you use their sites, accounts, or integrations.

13

Changes and contact

We may update this policy when Protect’s features, providers, or legal obligations change. Material updates will receive a new effective date and may also be announced through the Protect website or support Discord. Continued use after an update is governed by the updated policy, subject to any consent required by law.

For privacy questions, a rights request, or an urgent correction, use the Calvary Protect support Discord linked below. Share only the minimum information needed and use a private support ticket for evidence.

Questions, rights, or urgent corrections

Contact Calvary Protect support.

Include only the minimum information needed to locate your account or case. Do not post private evidence in a public channel.

Open support DiscordOpen my account
Calvary Protect

Evidence-led protection for FiveM creators.

StatusTrust centerInstall appSetupRegistryDevelopersReportAppealPrivacyTermsSupport

Build 6.15.0-trust-reliability