VETRA / SERVICE DISCLOSURES
Data and privacy
Updated September 13, 2026 · Commercial terms in preparation.
Account and access
Existing accounts use a username, salted password hash and a session cookie. Discord sign-in, when configured, requests only the identify permission. Provider access tokens are not stored. Membership and report access are checked by the server.
Scan information
With the player's approval, the scanner checks system configuration, processes, drivers, game files and relevant execution, history and network artifacts. Reports may include device and account names, a hashed device identifier, file paths, process details and matching technical evidence. Findings can contain personal information and should be handled accordingly.
Recipients and processing
Reports are delivered to the account that created the review. Authorized Vetra administrators with Manager, Upper Management or Owner roles can view PIN results and detailed reports across accounts; these accesses are logged. Staff can see scan operation metadata but not detailed evidence. The service uses an OVH server and Cloudflare for traffic protection. Dedicated raw hardware identifier fields, Steam/Discord account lists, debug dumps and telemetry logs are excluded from new stored reports. No external detection partner integration is currently active.
Storage and retention
Accounts, invitations and reports are stored in the server database. Daily database backups are retained for 14 days on that server. Authentication sessions expire after 12 hours; OAuth requests expire after 5 minutes. A final report retention schedule and a dedicated privacy request channel have not yet been published. Contact the administrator who provided access for account or report requests in the meantime.
