Legal

Privacy policy.

What we collect, why we collect it, and how to make us forget. Minimal data, no creepy tracking, no ads — promise.

01

Information We Collect

We collect data, not hangovers. Here's what information we gather when you use Pika Radio, the 3DXChat Prelauncher and our other services:

  • 01
    Account Information. Username, email address, and password (stored as a bcrypt hash, not plain text).
  • 02
    Technical Data. Your IP address, assigned port number, subdomain, and connection logs.
  • 03
    Usage Data. Last seen timestamps, uptime statistics, and service usage patterns.
  • 04
    Security Logs. Failed login attempts, detected attack patterns, account lockout events, IP addresses, and geolocation data (only when security events are triggered).
  • 05
    Discord Account Data (optional). If you link your Discord account or log in to the 3DXChat Prelauncher with Discord, we store your Discord ID, username, display name and avatar URL.
  • 06
    Prelauncher Cloud Sync (optional). If you log in to the 3DXChat Prelauncher with Discord, we store your play sessions (start, end, duration), your total playtime and the time of the last sync. A sophey.vodka account is not needed.
  • 07
    Prelauncher Update Check. Since version 1.5.5, the 3DXChat Prelauncher sends only its version, the platform and the day of its previous check when it looks for updates, never an ID. A fresh install reports itself once as new. From these checks we keep daily totals per version. Older versions are counted differently, see Data Retention.
  • 08
    Profile Data. Bio, social media links, genres, location, profile images, banner images, custom CSS, and widget preferences.
  • 09
    Profile Views. When someone visits your public profile, we log their IP address and timestamp for analytics and abuse prevention.
  • 10
    Contact Form and Email. If you write to us through the contact form, we receive your name, email address, message and IP address. Emails to our @sophey.vodka addresses arrive with sender, subject and text. Both are delivered to a private Discord channel that only the site operator reads (see Third-Party Services); the contact form keeps no other copy.
  • 11
    Page Visits. When you open a page on sophey.vodka or one of its subdomains, we record the page address, the page you came from, your browser type (user agent), the time and an anonymous visitor key. Your IP address is not stored. See Cookies and Tracking.
  • 12
    Streaming Statistics. Session history, total streaming time, average session length, peak streaming times, and listener data.
  • 13
    Guestbook Entries. Author names and messages posted on your profile (publicly visible).
  • 14
    Schedule Data. Your streaming schedule including time slots, recurring events, and timezone preferences.
  • 15
    Notification Data. Notification preferences, read status, and notification history.
02

How We Use Your Information

We use your data to:

  • 01
    Provide and maintain our tunneling services and desktop application.
  • 02
    Monitor service performance, uptime, and connection quality.
  • 03
    Prevent abuse, detect security threats, and protect our infrastructure.
  • 04
    Send you important account notifications (like password resets, security alerts, guestbook entries, or admin announcements).
  • 05
    Display your public profile and manage profile features (guestbook, schedule, etc.).
  • 06
    Generate analytics and statistics for your streaming activity and profile views.
  • 07
    Count visits per page, so we can see which pages and tools are actually used.
  • 08
    Show your own playtime statistics on every PC where you log in to the 3DXChat Prelauncher with Discord.
  • 09
    Count active 3DXChat Prelauncher installations per day and version; since version 1.5.5 this needs no ID at all.
  • 10
    Comply with legal obligations and enforce our Terms of Service.
03

Data Retention

We keep your data longer than your last bender — specifically, as long as your account is active.

  • 01
    Account Data. Retained as long as your account is active. Deleted when you delete your account.
  • 02
    Guest Accounts. Automatically deleted after 24 hours or when the tunnel disconnects.
  • 03
    Playtime Data. Kept until you remove it with "Delete cloud data" in the 3DXChat Prelauncher, ask us to delete it, or delete your account.
  • 04
    Prelauncher Update Checks. We keep only daily totals per version. Versions before 1.5.5 are counted with a daily hash of the IP address and the user agent the app sends, made with a key that changes every day; these hashes are deleted after 2 days.
  • 05
    Profile Data. Retained as long as your account is active. Public profiles are removed when you disable them or delete your account.
  • 06
    Guestbook Entries. Retained as long as your profile is active. You can delete individual entries at any time.
  • 07
    Streaming Sessions. Session history is retained for analytics purposes as long as your account is active.
  • 08
    Profile Views. View logs are retained for 90 days for analytics and abuse prevention.
  • 09
    Security Logs. Retained for 90 days for abuse prevention purposes.
  • 10
    Messages. Contact form messages and emails stay in the private Discord channel until we delete them. The contact form accepts at most 3 messages per hour from one address.
  • 11
    Page Visit Statistics. Kept without a fixed deletion date. They contain no IP address: the visitor key is made from your IP address and user agent with a key that changes every day and is deleted when that day is over, so it can neither be turned back into your IP address nor linked to your visits on other days. Entries from before September 27, 2026 were converted the same way.
  • 12
    Server Logs. The web server keeps technical access logs (IP address, time, requested address, browser) for 14 days to run the service and to fend off attacks, then deletes them.
04

Data Security

We take security seriously. Your data is protected with:

  • 01
    Industry-standard bcrypt password hashing.
  • 02
    End-to-end encrypted SSH tunnel connections.
  • 03
    HTTPS/TLS for all web traffic.
  • 04
    Rate limiting and brute-force protection.
  • 05
    PostgreSQL database with secure access controls.
  • 06
    Regular security monitoring and automated threat detection.
05

Discord OAuth Integration

If you choose to link your Discord account, we use Discord's OAuth 2.0 service to authenticate and retrieve your Discord information:

  • 01
    Data Collection. We ask Discord only for the identify scope and store your Discord ID, username and avatar URL. We do not receive your email address, your server list or your messages.
  • 02
    Purpose. Discord linking enables features like 3DXChat Prelauncher Cloud Sync and profile enhancements.
  • 03
    3DXChat Prelauncher. The Prelauncher logs in through the sophey.vodka Discord app and asks only for the identify scope: your Discord ID, username, display name and avatar. No email address, no server list. A sophey.vodka account is not needed; if your Discord is already linked to one, the Prelauncher syncs into that account.
  • 04
    Discord's Privacy Policy. When you link Discord, you also agree to Discord's Terms of Service and Privacy Policy. We recommend reviewing their policies at discord.com/privacy.
  • 05
    Unlinking. You can unlink your Discord account at any time through your account settings. In the 3DXChat Prelauncher, "Log out" stops syncing on that PC and "Delete cloud data" removes your playtime from our servers.
06

3DXChat Prelauncher

Cloud sync in the 3DXChat Prelauncher is optional and runs only after you log in with Discord. Without it, your playtime stays on your PC.

  • 01
    Data Collected. Your Discord ID, username, display name and avatar URL, and when you first and last logged in; your play sessions (start, end, duration); your total playtime and the time of the last sync.
  • 02
    Purpose. To show your own playtime statistics on every PC where you log in.
  • 03
    Who Can See It. You, in your Prelauncher, and the site administrator in an internal view. There is no public leaderboard.
  • 04
    Deletion. "Delete cloud data" in the Prelauncher settings removes your playtime from our servers and logs you out; the playtime on your PC stays. You can also email us.
  • 05
    Update Check. Since version 1.5.5 the app sends its version, the platform and the day of its previous check, never an ID, and we store daily totals per version. For older versions see Data Retention.
  • 06
    Anonymous Playtime (discontinued). Versions before 1.5.5 could send playtime without a login under a random ID. We no longer accept it; the 2,877 stored sessions were deleted on September 25, 2026.
  • 07
    Token Guard. Runs only on your PC and sends nothing to us or anyone else.
  • 08
    Discord Status. Shows "Playing 3DXChat via Prelauncher" in Discord through the Discord app on your PC. It goes to Discord, not to us, and you can turn it off in Settings.
  • 09
    Data Accuracy. We rely on the Prelauncher application to report accurate data. We reserve the right to remove suspicious or manipulated statistics.
07

Profile Data and Public Content

Your profile page is publicly accessible and may contain various types of information:

  • 01
    Public Information. Your profile bio, social links, genres, location, images, and schedule are publicly visible when your profile is enabled.
  • 02
    Guestbook Entries. Messages left on your profile are publicly visible. You can moderate and delete entries.
  • 03
    Profile Views. We track when someone visits your profile (IP address, timestamp, geolocation) for analytics and abuse prevention. This data is not publicly visible.
  • 04
    Custom CSS. If admins add custom CSS to your profile, it is publicly visible. You cannot control this directly.
08

Profile View Tracking

When someone visits your public profile, we collect the following information:

  • 01
    IP Address. Collected for analytics and abuse prevention.
  • 02
    Timestamp. When the profile was viewed.
  • 03
    Purpose. To provide you with profile analytics and detect abuse (e.g., spam views, bot traffic).
  • 04
    Retention. View logs are retained for 90 days and then automatically deleted.

Note: We do not collect geolocation data for profile views. Geolocation is only collected when security events are detected (e.g., attack attempts, suspicious activity) for security monitoring purposes.

09

Third-Party Services

We integrate with the following third-party services:

  • 01
    Discord OAuth. When you link your Discord account, we use Discord's OAuth 2.0 API. Discord may collect certain information as part of the OAuth flow. See Discord's Privacy Policy for details.
  • 02
    Discord (messages and alerts). Contact form messages and emails to our @sophey.vodka addresses are delivered to a private Discord channel instead of a classic mailbox. Security alerts go to a separate private channel; they contain the IP address, network and requests of blocked attackers. Discord is operated by Discord Inc. in the USA. See discord.com/privacy.
10

Your GDPR Rights

If you're in the EU (or just like privacy rights), you have the following rights under GDPR:

  • 01
    Right to Access. Request a copy of all personal data we hold about you.
  • 02
    Right to Rectification. Ask us to correct any inaccurate or incomplete data.
  • 03
    Right to Erasure. Request deletion of your account and all associated data ("Right to be Forgotten").
  • 04
    Right to Data Portability. Receive your data in a structured, machine-readable format.
  • 05
    Right to Object. Object to certain types of data processing (e.g., marketing, though we don't do that anyway).
  • 06
    Right to Restriction. Request that we limit how we process your data.

To exercise any of these rights, email legal@sophey.vodka with your request. We'll respond within 30 days as required by GDPR.

11

International Data Transfers

Our servers are located in Germany (EU). One service we use is based outside the EU: Discord (USA) receives contact form messages, emails to our addresses and security alerts. Such transfers rely on the safeguards the provider offers for data from the EU, such as the EU–US Data Privacy Framework or the EU Standard Contractual Clauses.

12

Cookies and Tracking

We use minimal cookies — just session cookies for authentication (JWT tokens). No third-party tracking, no analytics spyware, no creepy ad networks. We respect your privacy.

Our own server does count page visits. Most pages on sophey.vodka and its subdomains include a small script from this server that reports the page you opened and the page you came from to/api/track (never the part after a ? or #). The admin panel and a few internal tools do not include it. It sets no cookie, stores nothing on your device and sends nothing to anyone else. We store the details listed under Page Visits, with an anonymous visitor key instead of your IP address. This also covers the free tools other people publish here, such as Gifty and Profilly.

Legal basis: our legitimate interest in knowing which pages are used (Art. 6(1)(f) GDPR). You can object at any time by email to legal@sophey.vodka, or block /api/track in your browser.

13

Children's Privacy

Pika Radio is not intended for users under 18. We don't knowingly collect data from minors. If you're a parent and believe your child has provided us with personal information, email legal@sophey.vodka immediately.

14

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we'll update the "Last updated" date at the top. Continued use of the service means you accept the updated policy.

15

Contact

Questions about privacy? Want to exercise your GDPR rights? Need clarification on our data practices? Email legal@sophey.vodka and I'll be happy to help.

© 2026 Sophey. Built with attitude.