Skip to content

Privacy

Last updated 4 October 2026.

You can read everything here without an account. If you sign in, we keep only what the site needs to work, and you can delete it yourself.

Where it is stored

Accounts, posts and uploaded images are kept in one Supabase project (a hosted database with sign-in and file storage) in the United States. Automated tests run against a separate test project that holds only invented test accounts, never members' data.

Some threads, posts, builds, comments, guides and profiles are sample content, written to show how the site works. They belong to sample accounts that can't sign in and hold no one's personal data, and they are tagged Sample. See About.

What we read from Discord

Everyone signs in with Discord. Sign-in asks Discord for three permissions: your identity, your email address, and your member record in the official Citadel server (the guilds.members.read scope).

  • Your Discord ID, username, display name, avatar and email, to make your account.
  • From the Citadel server only: your role IDs and the date you joined it. We never read other servers, your messages or your friends list.

Your roles decide your rank badge, your faction and where you can post. They are re-read when you sign in, when you press "Refresh my roles", and in a regular re-sync of all members. When your roles change, we add a line to your role history (role gained or lost, with the date); that history can't be edited and is deleted only with your account.

The stored Discord token

To keep your rank current without asking you to sign in again, we store your Discord refresh token. It is encrypted (AES-256-GCM) in a table that only our server can read; no page or browser can fetch it. Signing out keeps it, so your rank stays current.

  • Delete my account deletes it at once.
  • Revoking Breacher's Archive in Discord (User Settings, Authorized Apps) stops it working. The next time we try to use it, Discord refuses it and we delete our copy. Your last known roles then show as unverified, and after 7 days they no longer count.

We don't send you email.

What is public

Anyone, signed in or not, can see:

  • Your profile: handle, avatar, cover, bio, signature, links, faction, rank badges and history highs, achievements, Citadel server roles and join date, and when your roles were last synced.
  • Your forum threads and posts, reactions, squad sign-ups, codex and build comments, builds and votes, player guides, and your hangar ships and screenshots.
  • Your trading listings, your completed trades and the trade feedback you give and get. See Trading.
  • Answer edits once they are published, and the answers you marked as checked in game.
  • Roughly when you were last active, for the "who's online" list.

Your in-game callsign, Discord ID, Discord username and email are not shown publicly. Site admins can see your Discord ID and username to sort out role problems. When a trade offer you made or received is accepted, the other player of that trade sees your callsign, Discord username and a link to your Discord profile (see Trading).

If you edit answers, starter guide chapters, codex entries or pages as an editor, each save is kept as a version with your name, which editors can see and restore. Saves by a Citadel developer are marked "by a developer". Earlier versions of a player guide are public, with who made each edit.

Reports you make (a post, comment, profile, guide, build, image, trading listing or feedback comment, or an answer as outdated) are seen by staff, not by the person you reported.

Trading

When you use the trading board, we store:

  • Listings: the items you have and want, their notes, your hub, a picture if you add one, and when it was posted, bumped and closed. Listings are public, also after they close.
  • Offers and counter-offers: the items on each side, the optional short note and whether it was accepted, declined or withdrawn. Only the two players and staff can see them.
  • No private messages. The site has no messaging between players: once an offer is accepted, you arrange the trade in Discord or in game.
  • Trades: what each player gives, the hub, and when each player marked it completed or cancelled. An agreed trade is seen by the two players and staff; once both players mark it completed, it is public with both names, so others can check a player's trading record.
  • Feedback (positive, neutral or negative, and a short comment) is public, with who left it and for which trade.
  • Contact details for a trade: your in-game callsign (from Edit profile) is private. You need one to make or accept an offer, and before you send or accept one the site tells you who will see your details. Once an offer is accepted, the other player of that trade, and only them, sees your callsign, your Discord username and a link to your Discord profile, while the trade is open and after it is completed. No other member or visitor sees them, and a cancelled trade shows them to nobody.

Listings, offers and trades are kept until you delete your account. Staff may hide a listing, offer or feedback comment that breaks the trading rules; you still see your own, marked Hidden by staff. The site never holds items or payments and has no part in what happens in game.

Uploaded images

  • Hangar screenshots and trading listing pictures: JPEG, PNG or WebP up to 10 MB. Avatars and covers: JPG, PNG, WebP or GIF up to 8 MB.
  • Your browser shrinks the picture (and cuts out your crop for an avatar or cover) before sending it. The server then re-encodes it to WebP, which strips all metadata, including camera details and GPS location. Your original file is never stored.
  • New accounts can't upload images in their first 7 days.
  • Uploads are public: anyone with the link can view them. A new avatar or cover replaces the old files.

Cookies and browser storage

  • Session cookies keep you signed in.
  • A theme cookie remembers light or dark mode (one year).
  • An auth_next cookie remembers which page to return to after signing in (10 minutes).
  • Unsent replies, threads, comments and fits are kept in your browser's local storage until you post them. They never leave your browser until then.

No analytics, no ads, no tracking pixels and no third-party cookies.

Deleting your account

Go to Settings, scroll to Delete account, type your handle and choose Delete my account. It takes effect at once and can't be undone. It deletes:

  • your profile, your Discord link, the stored token, your role history and achievements;
  • every image file you uploaded (hangar screenshots, avatar and cover);
  • your builds, hangar ships, codex comments, player guides, reactions, votes, squad sign-ups, reports, answer edits and verifications, starter guide progress, follows, notifications and warnings;
  • your trading listings, the offers you made or received (with their notes), the feedback you left and the feedback left about you. Agreed trades not yet completed are cancelled.

Forum conversations stay readable for everyone else: your posts are kept as [deleted] with their text removed, threads you started stay with the opening post shown as [deleted], and your name and picture become Deleted member everywhere. Other people's replies are not touched. The earlier versions of your posts are deleted too.

Forum answers that staff promoted into the knowledge base stay, without your name.

Completed trades stay on the other player's trading record, with you shown as Deleted member.

If your account is banned, the ban record stays after deletion (your Discord ID, the reason and its dates). See Warnings, timeouts and bans.

Deleted images may take a short time to disappear from caches.

Warnings, timeouts and bans

When staff act on your account, we keep a record of it: what was done, by whom, when and why. You see the reason in your notifications; the record is visible to staff only.

  • Warnings are kept with your account and shown to you until you acknowledge them.
  • Timeouts are stored as an end time on your profile.
  • Bans are tied to your Discord account ID, not just to your site account, so deleting your account and signing in again doesn't lift a ban. If you delete your account while banned, we keep only your Discord ID, the reason and the ban's dates, so the ban still applies. Warnings, timeouts, staff notes and the rest of your moderation record are deleted with your account. The admins' audit log keeps its entries, without your name.
  • Staff can also write private notes about an account. They are seen by staff only.

Every staff and editor action (moderation, content edits, role and setting changes) is recorded in an audit log that only admins can read.

To keep spam out, what you write is checked against a list of blocked words and link domains that staff keep, and new accounts (first 7 days) are limited to 2 links per post or comment and 5 posts an hour. These checks run in our database; nothing is sent to an outside service.

Answers taken from the Citadel Discord

Some answers here are based on things people said in the official Citadel Discord. We paraphrase them and credit the speaker's tier, not their username (developers excepted). If one is based on something you said and you want it removed, contact us.