Privacy Policy
What we store, and why.
Fall operates this website, accounts, downloads, and the Fall software. This policy explains the personal data we process and why.
Short version: we use data to run accounts, verify licenses, secure the service, provide support, and prevent abuse. We do not sell personal data, and we do not use analytics or marketing cookies on this site.
1. Data we collect
- Account data: username, email, password hash, verification state, account status, plan and expiry, creation time, last login, and limited history for support and abuse prevention.
- License and device data: license records, redemption status, HWID hash if provided, last-seen time, and revocation state.
- Discord and support data: Discord ID, username, avatar, email returned by Discord OAuth, and messages you send to support.
- Security data: IP address, user agent, request metadata, rate-limit state, and security events.
We do not intentionally read your scripts, personal files, browser history, or unrelated content on your device.
2. Why we use it
- To create accounts, verify emails, reset passwords, and keep users signed in.
- To redeem keys, validate licenses, and enforce device limits.
- To detect fraud, key abuse, account takeover, bot traffic, and security incidents.
- To operate Discord login, support, and audit trails.
- To enforce the Terms and protect Fall, our users, and the service.
3. Legal bases
Where GDPR-style laws apply, we rely on contract performance for account and license features, legitimate interests for security and fraud prevention, consent for optional features, and legal obligations where records must be kept by law.
4. Cookies
We use essential cookies and local storage for login, preferences, and security. Optional functional storage is used only if you allow it. We do not use analytics or advertising cookies.
5. Sharing
We do not sell your personal data or share it with advertisers. We share data only when needed to operate, secure, or support Fall — including hosting and security providers, Discord OAuth, ad-step providers when you leave our site for those flows, and legal authorities when required.
6. Retention
We keep account and device records while your account is active. If you delete your account, we first disable it for 30 days so you can restore it by signing in. After that, we permanently delete account data unless legal or security records require longer storage. Short-lived tokens typically expire within 60 seconds to 24 hours.
7. Security
We use HTTPS, hashed passwords, rate limits, short-lived tokens, and integrity checks on stored settings. No system is perfectly secure. Never paste commands, cookies, or one-time codes into the browser developer console.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal data. Contact us through Discord; we may need to verify your identity first.
9. Third-party services
We use or link to third-party services such as Discord, Work.ink, LootLabs, and script-hub sources. Their services are governed by their own policies when they process data directly.
10. Children and international use
Fall is not intended for anyone under 13, and we do not knowingly collect data from children under 13. We and our providers may process data in countries other than your own, using lawful transfer mechanisms where required.
11. Changes and contact
We may update this policy by posting a new version on this page. Privacy questions can be sent through Discord. See also the Terms of Service.
Last updated September 2026.