Privacy Policy
Preamble, Scope, and Definitions
This Privacy Policy (hereinafter, the "Policy," "Agreement," or "Document") is issued by The epic cake (hereinafter, "The Company," "TECIA," "we," "us," or "our"), a corporate entity organized and operating under the laws of the Commonwealth of Puerto Rico, United States of America, and constitutes a legally binding instrument governing the collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction of information (collectively, "Processing" or "Data Processing"), as those terms are understood under applicable law and as further elaborated in Sections 1 through 9 hereof.
Universal and Unconditional Applicability. This Policy applies universally, without limitation or exception, to all natural persons, legal entities, representatives, administrators, agents, or automated systems (individually and collectively, "User," "Data Subject," "You," or "Your") that, in any manner whatsoever — whether directly, indirectly, actively, passively, intentionally, or incidentally — access, install, configure, interact with, benefit from, or are exposed to any component of the Covered Products and Services (as defined below).
Definition — Covered Products and Services: For all purposes of this Policy, "Covered Products and Services," "Services," and "Ecosystem" shall mean, individually and collectively, without limitation: (a) all Discord bot applications developed, operated, maintained, or distributed by The Company, including but not limited to Cosmos+, Cosmos+ Networks and all of its sub-systems and modules (including but not limited to verification systems, moderation modules, analytics engines, and premium feature sets), Cosmos+ Shield, ARAID, Helper+, and any and all past, present, and future bot applications released under The epic cake brand or any associated brand; (b) all web properties, landing pages, control panels, and dashboards operated by The Company or its designees; (c) all public and private APIs, SDKs, webhooks, and developer tools; (d) all digital and physical goods, merchandise, and downloadable assets sold or distributed by The Company; (e) any promotional, support, or community infrastructure (including official Discord servers, documentation portals, and ticketing systems); and (f) all present and future products developed, acquired, or operated by The Company or by Cosmos+ Networks as a product line, regardless of whether such products exist at the time this Policy was last revised. All of the foregoing are governed by this single, unified Policy. See also Terms of Service, §§ 1–2; EULA, § 1; DPA, § 1.
Consent and Constructive Notice. By accessing or using any Covered Product or Service — or by continuing to use any such product or service after the date of any revision to this Policy — you expressly, irrevocably, and unconditionally acknowledge that: (i) you have read and understood this Policy in its entirety; (ii) you agree to be legally bound by all terms herein; (iii) you consent to all forms of Data Processing described herein; and (iv) you waive any right to claim ignorance of the terms of this Policy. If you do not agree to this Policy in its entirety, you must immediately and permanently discontinue all use of the Covered Products and Services. Continued use following any amendment (see Section 8) constitutes renewed consent. This Policy should be read in conjunction with, and is incorporated by reference into, our Terms of Service, End-User License Agreement (EULA), Data Processing Agreement (DPA), Law Enforcement Policy, Sales Policy, and Vulnerability Disclosure Policy, each of which forms part of the complete legal framework governing your relationship with The Company.
1. Categories of Personal and Non-Personal Information Collected
Subject to and consistent with the Scope defined in the Preamble above, The Company collects, processes, and retains, across all Covered Products and Services (including all Cosmos+ Networks sub-systems and modules), a comprehensive range of personal data (as defined under applicable law) and non-personal operational data, as reasonably necessary and proportionate to operate, maintain, secure, improve, develop, and expand the Ecosystem and its underlying Artificial Intelligence infrastructure. The enumeration of data categories below is illustrative and not exhaustive; the absence of a specific data type from this list does not preclude its collection, as further reserved in Section 1.9 (Forward-Looking Collection Reserve) and Section 2.3 of the Terms of Service. Each category of data described below may be collected across any and all Covered Products and Services simultaneously, including through automated, passive, or background mechanisms that do not require affirmative user action.
- 1.1 Identification and Account Data: Discord User IDs, Server (Guild) IDs, usernames, display names, avatar hashes, account creation dates, roles, server join dates, and any email address voluntarily provided or collected through verification processes.
- 1.2 Usage, Behavioral, and Telemetry Data: Given the scale of our Ecosystem, we collect comprehensive telemetry and operational metadata, including but not limited to: executed command logs with full timestamps, message counts and frequency, session durations, feature configuration states, dashboard navigation flows, click-stream data, interaction patterns, API request logs, error reports, response times, and granular user behavioral analytics.
- 1.3 Voice and Multimedia Activity: Voice channel membership records, the duration of voice sessions, join and leave timestamps, and any metadata associated with multimedia features of the Services.
- 1.4 Verification and Security Data: Internet Protocol (IP) addresses and email addresses collected exclusively through our Web Verification and anti-abuse systems (e.g., Cosmos+ Verify). This data is classified as Restricted Data and is subject to enhanced security protocols as described in Section 6.
- 1.5 Web Session and Network Data: Hashed IP addresses, User-Agent strings, browser fingerprints, session tokens, login timestamps, last-active timestamps, and Cloudflare-processed connection metadata from users who interact with our web-based properties.
- 1.6 User-Generated Content (UGC): Any content created, submitted, or transmitted through our Services, including but not limited to: confessions (including the associated User ID), server suggestions, embed templates, custom bot configurations, and message content temporarily or permanently processed to fulfill a specific Service function.
- 1.7 Economy, Virtual Asset, and Gaming Metrics: Virtual currency balances (e.g., "Planets"), complete transaction histories, casino wagering records, win/loss ratios, behavioral play styles (e.g., risk tolerance classifications), and any other data generated through our virtual economy or simulated gaming systems.
- 1.8 Artificial Intelligence Interaction Data: All inputs, queries, prompts, feedback, ratings, and outputs generated through interactions with any AI-powered features of our Services. This data is used to operate, evaluate, and continuously improve our Artificial Intelligence and Machine Learning (AI/ML) models.
- 1.9 Future and Expanded Data Categories (Forward-Looking Collection Reserve): The Company explicitly and irrevocably reserves the right to collect new, additional, or expanded categories of metadata, telemetry, and interaction data not presently enumerated in this Policy. Such future collection shall be authorized if deemed reasonably necessary to: (a) deliver new functionalities; (b) enhance security and anti-abuse systems; (c) conduct research and development; (d) train, fine-tune, or operate AI/ML models; or (e) generate advanced analytics. Continued use of the Services following any such expansion constitutes your express consent to the modified collection practices.
2. Tracking Technologies and Cookies
The Company deploys cookies, pixel tags, web beacons, local storage objects, and similar tracking technologies on its web properties, sourced from both proprietary tools and trusted third-party providers, including but not limited to Google Analytics, Cloudflare, and our internal analytics infrastructure. These technologies are used to:
- Analyze traffic patterns, audience demographics, and behavioral trends.
- Maintain the integrity, security, and continuity of user sessions.
- Measure the reach and effectiveness of marketing and promotional campaigns.
- Support fraud detection and bot-traffic filtering mechanisms.
Users may exercise control over cookie preferences through their browser settings. However, disabling certain categories of cookies may degrade or limit the functionality of our Services. The Company's use of cookies does not override the terms set forth in this Policy.
3. How We Use Your Information
The Company uses all collected data across the following authorized purposes. Access to user data for internal operational purposes is strictly limited to individuals formally employed by or officially contracted with The epic cake (collectively, "Authorized Personnel"). This expressly excludes all third-party Discord server administrators, server staff, community moderators, or any other persons not directly employed or formally contracted by The epic cake as a Company.
- 3.1 Service Delivery and Infrastructure: To operate, maintain, and continuously improve the technical infrastructure powering the Services.
- 3.2 Activity and Gamification Systems: Usage and behavioral data is used to power XP and Leveling systems, Leaderboards, Server Analytics dashboards, and related gamified features.
- 3.3 Security and Anti-Abuse Enforcement: IP addresses and email addresses collected during verification are processed exclusively by Authorized Personnel for the purposes of preventing account evasion, mitigating server raids, and enforcing our global blacklist and ban systems.
- 3.4 Artificial Intelligence Training and Development: User data, including behavioral telemetry, UGC, and AI interaction data, may be processed by The Company's Authorized Personnel and designated AI infrastructure providers (as listed in Section 5.2) to train, evaluate, and continuously improve our proprietary and integrated Artificial Intelligence and Machine Learning systems.
- 3.5 Quality Assurance and Internal Analysis (Authorized Personnel Only): Authorized Personnel of The Company are expressly permitted to access, review, analyze, and process any and all user data held within our systems for purposes of quality control, technical debugging, service improvement, moderation investigation, and compliance auditing. This right of internal access is exclusively reserved for persons formally employed or contracted by The epic cake as a corporate entity. Under no circumstances shall Discord server staff, guild administrators, community moderators, premium license holders, or any other non-Company personnel be granted access to raw user data, verification logs, IP addresses, or email addresses. All Authorized Personnel are bound by strict internal confidentiality agreements and data handling protocols.
- 3.6 Premium Analytics Features (Non-Sensitive, Aggregated): Non-sensitive, aggregated activity metrics (e.g., server-level leaderboard data, command usage counts) may be made available to server administrators through Premium dashboard features. The scope of such data is strictly ring-fenced to non-sensitive, public-activity-type information and does not include raw personal data, IP addresses, email addresses, or verification records.
- 3.7 Legal Compliance and Law Enforcement: Data may be disclosed to competent governmental or judicial authorities when required by a valid, legally binding court order, subpoena, or applicable law, as further detailed in our Law Enforcement Policy.
- 3.8 Research, Development, and Commercial Analytics: Aggregated and pseudonymized data may be used for internal research and development (R&D), statistical modeling, and business intelligence purposes.
4. Data Retention Policy
The Company maintains a perpetual data retention framework. User data collected in connection with the Services is retained indefinitely, unless a valid data subject deletion request is submitted and honored in accordance with applicable law. The perpetual retention of data is justified under the following legitimate interests:
- Long-term security auditing and anti-abuse tracking across our global Ecosystem;
- Continuous training, fine-tuning, and improvement of Artificial Intelligence and Machine Learning models;
- Preservation of historical analytics for infrastructure optimization and business intelligence;
- Compliance with legal hold obligations or governmental preservation requests;
- Prevention of account evasion by previously banned or blacklisted users.
Notwithstanding the foregoing, if the bot is removed from a server, that server's non-restricted configuration data may be scheduled for routine anonymization or archival. Data classified as Restricted (IP addresses, emails from verification) is subject to the enhanced retention rules described in Section 6. All users retain the right to submit a deletion request as described in Section 7.
5. Information Sharing and Third-Party Providers
5.1 General Principle — No Sale of Data: The Company does not sell, rent, or trade personally identifiable information to third parties for their own marketing purposes. Data is shared exclusively as enumerated below, under strict contractual confidentiality obligations.
5.2 Artificial Intelligence Infrastructure Providers: The Company utilizes advanced Artificial Intelligence and Machine Learning systems to power, enhance, and develop our Services. In connection with these operations, user data (including but not limited to interaction data, telemetry, and user-generated content) may be processed by, transmitted to, or used to train models hosted by the following categories of AI providers, which may include but are not limited to:
- Self-Hosted AI Systems: Proprietary models hosted on our own infrastructure.
- Groq: High-speed inference infrastructure.
- Grok (xAI): xAI's large language model platform.
- Anthropic: Including Claude model family APIs.
- Cloudflare AI: Cloudflare's Workers AI and related AI gateway services.
- Google AI: Including Google Gemini, Vertex AI, and associated Google Cloud ML services.
- OpenAI: Including GPT model family APIs and associated services.
- Future AI Providers: The Company reserves the right to onboard additional AI infrastructure providers without prior notice. Any new provider will be bound by data processing obligations consistent with this Policy.
5.3 Infrastructure and Operations Providers:
- Hosting and Computing: VPS and Dedicated Server Providers.
- Network Security: Cloudflare (DDoS protection, CDN, DNS).
- Web Analytics: Google Analytics.
- Payment Processing: WHOP, Stripe, PayPal.
- Legal Compliance: Competent judicial or governmental authorities, upon receipt of a valid, legally binding court order or subpoena.
5.4 Premium Dashboard Analytics: We reserve the right to expand the types of non-sensitive, aggregated activity metrics made available to server administrators through Premium features (including but not limited to the User Lookup Tool and Analytics Dashboard), without prior notice. By using our Services, you consent to your publicly visible and server-specific activity data being visualized and aggregated within such tools. Highly sensitive data, including IP addresses and verification emails, is strictly ring-fenced and shall never be exposed to server administrators under any circumstances.
6. Cosmos+ Verify and Restricted Data Security
Personal data collected through the Cosmos+ Verify system, including Internet Protocol (IP) addresses and email addresses, constitutes "Restricted Data" under our internal classification framework. Restricted Data is subject to the following protections:
- Restricted Data is stored in encrypted, access-controlled log systems separate from general service databases.
- Access is limited exclusively to Authorized Personnel of The Company (as defined in Section 3.5) and is never disclosed to server owners, server administrators, or any third-party community staff.
- Restricted Data is retained indefinitely to prevent account evasion by previously sanctioned individuals, under the legitimate interest of system security and ecosystem integrity.
7. Your Rights and Right to Be Forgotten
The Company acknowledges that Data Subjects, depending on their jurisdiction, may hold certain rights regarding their personal data, including rights of access, rectification, portability, and erasure ("Right to be Forgotten"). To exercise any such right, you must submit a formal request through our official support channels:
- Discord Support Server: Via our official The epic cake support server.
- Email: support@theepiccake.org
The Company will evaluate all deletion requests in accordance with applicable law. Please note the following material limitations:
- Data that has been irreversibly anonymized or aggregated and can no longer be attributed to an individual Data Subject is exempt from deletion requests.
- Data retained under a legal hold obligation, active investigation, or valid law enforcement preservation request may not be eligible for deletion during the applicable retention period.
- Certain technical and operational data is inherently necessary for the provision of the Service. Deletion of such data may require the termination of your account and all associated Service access.
- Data that has been used in the training of AI models may be technically non-retrievable or non-deletable from trained model weights. We will make commercially reasonable efforts to fulfill such requests to the extent technically feasible.
8. Policy Amendments
The Company reserves the absolute and unilateral right to amend, modify, or replace any portion of this Policy at any time and without prior individual notice. The "Last Updated" date at the top of this document shall reflect the most recent revision. Your continued use of the Services following any such amendment constitutes your unconditional acceptance of the revised Policy. We encourage you to review this Policy periodically.
9. Governing Law
This Policy and all matters arising from or relating to your use of the Services shall be governed by and construed in accordance with the laws of the Commonwealth of Puerto Rico and the applicable federal laws of the United States of America, without regard to conflict of law provisions. By using our Services, you irrevocably agree that any dispute relating to this Policy shall be subject to the exclusive jurisdiction of the courts located in San Juan, Puerto Rico, as further detailed in our Terms of Service, Section 9.