Privacy policy.
What we collect, why we collect it, and how to make us forget. Minimal data, no creepy tracking, no ads — promise.
Information We Collect
We collect data, not hangovers. Here's what information we gather when you use Pika Radio, the 3DXChat Prelauncher and our other services:
- 01Account Information. Username, email address, and password (stored as a bcrypt hash, not plain text).
- 02Technical Data. Your IP address, assigned port number, subdomain, and connection logs.
- 03Usage Data. Last seen timestamps, uptime statistics, and service usage patterns.
- 04Security Logs. Failed login attempts, detected attack patterns, account lockout events, IP addresses, and geolocation data (only when security events are triggered).
- 05Discord Account Data (optional). If you link your Discord account or log in to the 3DXChat Prelauncher with Discord, we store your Discord ID, username, display name and avatar URL.
- 06Prelauncher Cloud Sync (optional). If you log in to the 3DXChat Prelauncher with Discord, we store your play sessions (start, end, duration), your total playtime and the time of the last sync. A sophey.vodka account is not needed.
- 07Prelauncher Update Check. Since version 1.5.5, the 3DXChat Prelauncher sends only its version, the platform and the day of its previous check when it looks for updates, never an ID. A fresh install reports itself once as new. From these checks we keep daily totals per version. Older versions are counted differently, see Data Retention.
- 08Profile Data. Bio, social media links, genres, location, profile images, banner images, custom CSS, and widget preferences.
- 09Profile Views. When someone visits your public profile, we log their IP address and timestamp for analytics and abuse prevention.
- 10Contact Form and Email. If you write to us through the contact form, we receive your name, email address, message and IP address. Emails to our @sophey.vodka addresses arrive with sender, subject and text. Both are delivered to a private Discord channel that only the site operator reads (see Third-Party Services); the contact form keeps no other copy.
- 11Page Visits. When you open a page on sophey.vodka or one of its subdomains, we record the page address, the page you came from, your browser type (user agent), the time and an anonymous visitor key. Your IP address is not stored. See Cookies and Tracking.
- 12Streaming Statistics. Session history, total streaming time, average session length, peak streaming times, and listener data.
- 13Guestbook Entries. Author names and messages posted on your profile (publicly visible).
- 14Schedule Data. Your streaming schedule including time slots, recurring events, and timezone preferences.
- 15Notification Data. Notification preferences, read status, and notification history.
How We Use Your Information
We use your data to:
- 01Provide and maintain our tunneling services and desktop application.
- 02Monitor service performance, uptime, and connection quality.
- 03Prevent abuse, detect security threats, and protect our infrastructure.
- 04Send you important account notifications (like password resets, security alerts, guestbook entries, or admin announcements).
- 05Display your public profile and manage profile features (guestbook, schedule, etc.).
- 06Generate analytics and statistics for your streaming activity and profile views.
- 07Count visits per page, so we can see which pages and tools are actually used.
- 08Show your own playtime statistics on every PC where you log in to the 3DXChat Prelauncher with Discord.
- 09Count active 3DXChat Prelauncher installations per day and version; since version 1.5.5 this needs no ID at all.
- 10Comply with legal obligations and enforce our Terms of Service.
Data Retention
We keep your data longer than your last bender — specifically, as long as your account is active.
- 01Account Data. Retained as long as your account is active. Deleted when you delete your account.
- 02Guest Accounts. Automatically deleted after 24 hours or when the tunnel disconnects.
- 03Playtime Data. Kept until you remove it with "Delete cloud data" in the 3DXChat Prelauncher, ask us to delete it, or delete your account.
- 04Prelauncher Update Checks. We keep only daily totals per version. Versions before 1.5.5 are counted with a daily hash of the IP address and the user agent the app sends, made with a key that changes every day; these hashes are deleted after 2 days.
- 05Profile Data. Retained as long as your account is active. Public profiles are removed when you disable them or delete your account.
- 06Guestbook Entries. Retained as long as your profile is active. You can delete individual entries at any time.
- 07Streaming Sessions. Session history is retained for analytics purposes as long as your account is active.
- 08Profile Views. View logs are retained for 90 days for analytics and abuse prevention.
- 09Security Logs. Retained for 90 days for abuse prevention purposes.
- 10Messages. Contact form messages and emails stay in the private Discord channel until we delete them. The contact form accepts at most 3 messages per hour from one address.
- 11Page Visit Statistics. Kept without a fixed deletion date. They contain no IP address: the visitor key is made from your IP address and user agent with a key that changes every day and is deleted when that day is over, so it can neither be turned back into your IP address nor linked to your visits on other days. Entries from before September 27, 2026 were converted the same way.
- 12Server Logs. The web server keeps technical access logs (IP address, time, requested address, browser) for 14 days to run the service and to fend off attacks, then deletes them.
Data Security
We take security seriously. Your data is protected with:
- 01Industry-standard bcrypt password hashing.
- 02End-to-end encrypted SSH tunnel connections.
- 03HTTPS/TLS for all web traffic.
- 04Rate limiting and brute-force protection.
- 05PostgreSQL database with secure access controls.
- 06Regular security monitoring and automated threat detection.
Discord OAuth Integration
If you choose to link your Discord account, we use Discord's OAuth 2.0 service to authenticate and retrieve your Discord information:
- 01Data Collection. We ask Discord only for the identify scope and store your Discord ID, username and avatar URL. We do not receive your email address, your server list or your messages.
- 02Purpose. Discord linking enables features like 3DXChat Prelauncher Cloud Sync and profile enhancements.
- 033DXChat Prelauncher. The Prelauncher logs in through the sophey.vodka Discord app and asks only for the identify scope: your Discord ID, username, display name and avatar. No email address, no server list. A sophey.vodka account is not needed; if your Discord is already linked to one, the Prelauncher syncs into that account.
- 04Discord's Privacy Policy. When you link Discord, you also agree to Discord's Terms of Service and Privacy Policy. We recommend reviewing their policies at discord.com/privacy.
- 05Unlinking. You can unlink your Discord account at any time through your account settings. In the 3DXChat Prelauncher, "Log out" stops syncing on that PC and "Delete cloud data" removes your playtime from our servers.
3DXChat Prelauncher
Cloud sync in the 3DXChat Prelauncher is optional and runs only after you log in with Discord. Without it, your playtime stays on your PC.
- 01Data Collected. Your Discord ID, username, display name and avatar URL, and when you first and last logged in; your play sessions (start, end, duration); your total playtime and the time of the last sync.
- 02Purpose. To show your own playtime statistics on every PC where you log in.
- 03Who Can See It. You, in your Prelauncher, and the site administrator in an internal view. There is no public leaderboard.
- 04Deletion. "Delete cloud data" in the Prelauncher settings removes your playtime from our servers and logs you out; the playtime on your PC stays. You can also email us.
- 05Update Check. Since version 1.5.5 the app sends its version, the platform and the day of its previous check, never an ID, and we store daily totals per version. For older versions see Data Retention.
- 06Anonymous Playtime (discontinued). Versions before 1.5.5 could send playtime without a login under a random ID. We no longer accept it; the 2,877 stored sessions were deleted on September 25, 2026.
- 07Token Guard. Runs only on your PC and sends nothing to us or anyone else.
- 08Discord Status. Shows "Playing 3DXChat via Prelauncher" in Discord through the Discord app on your PC. It goes to Discord, not to us, and you can turn it off in Settings.
- 09Data Accuracy. We rely on the Prelauncher application to report accurate data. We reserve the right to remove suspicious or manipulated statistics.
Profile Data and Public Content
Your profile page is publicly accessible and may contain various types of information:
- 01Public Information. Your profile bio, social links, genres, location, images, and schedule are publicly visible when your profile is enabled.
- 02Guestbook Entries. Messages left on your profile are publicly visible. You can moderate and delete entries.
- 03Profile Views. We track when someone visits your profile (IP address, timestamp, geolocation) for analytics and abuse prevention. This data is not publicly visible.
- 04Custom CSS. If admins add custom CSS to your profile, it is publicly visible. You cannot control this directly.
Profile View Tracking
When someone visits your public profile, we collect the following information:
- 01IP Address. Collected for analytics and abuse prevention.
- 02Timestamp. When the profile was viewed.
- 03Purpose. To provide you with profile analytics and detect abuse (e.g., spam views, bot traffic).
- 04Retention. View logs are retained for 90 days and then automatically deleted.
Note: We do not collect geolocation data for profile views. Geolocation is only collected when security events are detected (e.g., attack attempts, suspicious activity) for security monitoring purposes.
Third-Party Services
We integrate with the following third-party services:
- 01Discord OAuth. When you link your Discord account, we use Discord's OAuth 2.0 API. Discord may collect certain information as part of the OAuth flow. See Discord's Privacy Policy for details.
- 02Discord (messages and alerts). Contact form messages and emails to our @sophey.vodka addresses are delivered to a private Discord channel instead of a classic mailbox. Security alerts go to a separate private channel; they contain the IP address, network and requests of blocked attackers. Discord is operated by Discord Inc. in the USA. See discord.com/privacy.
Your GDPR Rights
If you're in the EU (or just like privacy rights), you have the following rights under GDPR:
- 01Right to Access. Request a copy of all personal data we hold about you.
- 02Right to Rectification. Ask us to correct any inaccurate or incomplete data.
- 03Right to Erasure. Request deletion of your account and all associated data ("Right to be Forgotten").
- 04Right to Data Portability. Receive your data in a structured, machine-readable format.
- 05Right to Object. Object to certain types of data processing (e.g., marketing, though we don't do that anyway).
- 06Right to Restriction. Request that we limit how we process your data.
To exercise any of these rights, email legal@sophey.vodka with your request. We'll respond within 30 days as required by GDPR.
International Data Transfers
Our servers are located in Germany (EU). One service we use is based outside the EU: Discord (USA) receives contact form messages, emails to our addresses and security alerts. Such transfers rely on the safeguards the provider offers for data from the EU, such as the EU–US Data Privacy Framework or the EU Standard Contractual Clauses.
Cookies and Tracking
We use minimal cookies — just session cookies for authentication (JWT tokens). No third-party tracking, no analytics spyware, no creepy ad networks. We respect your privacy.
Our own server does count page visits. Most pages on sophey.vodka and its subdomains include a small script from this server that reports the page you opened and the page you came from to/api/track (never the part after a ? or #). The admin panel and a few internal tools do not include it. It sets no cookie, stores nothing on your device and sends nothing to anyone else. We store the details listed under Page Visits, with an anonymous visitor key instead of your IP address. This also covers the free tools other people publish here, such as Gifty and Profilly.
Legal basis: our legitimate interest in knowing which pages are used (Art. 6(1)(f) GDPR). You can object at any time by email to legal@sophey.vodka, or block /api/track in your browser.
Children's Privacy
Pika Radio is not intended for users under 18. We don't knowingly collect data from minors. If you're a parent and believe your child has provided us with personal information, email legal@sophey.vodka immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we'll update the "Last updated" date at the top. Continued use of the service means you accept the updated policy.
Contact
Questions about privacy? Want to exercise your GDPR rights? Need clarification on our data practices? Email legal@sophey.vodka and I'll be happy to help.