UDON SABER Hub Privacy Policy
UDON SABER Hub Privacy Policy
Effective date: June 6, 2026
Last revised: September 8, 2026
Web initial registration (September 8, 2026)
When Web registration is enabled, Discord login requests identify and guilds.members.read. For new players, the Service checks membership and completion of rules screening in the configured Hub server. The result and a suggested Discord nickname are held in server memory for up to 10 minutes, tied to the current Hub session, to authorize initial registration. The Discord nickname is only a suggestion. You choose a display name freely and can change it in Edit Profile. Your existing scores remain associated with the same account. Discord access tokens are used temporarily on the server and are not retained with this result, in the database, or in the browser. This check is not ongoing membership monitoring for registered players.
Google login and account connections (September 5, 2026)
You may link Google after signing in with Discord or a /web-login link. Google login opens the same Hub account and does not create a separate player profile. A Google account cannot be connected to multiple Hub accounts. Discord remains connected as the owner identifier for existing player records.
For Google login, the Service requests the openid and profile scopes. It stores Google's stable account identifier (sub), the connection time, and the association with an internal Hub account ID. A Google display name may be kept temporarily in server memory for the connection confirmation screen, for up to 10 minutes. Google email addresses and profile images are not stored or used to match accounts.
Authorization codes, ID tokens, and access tokens are used temporarily on the server for verification and are not saved to the database or logs. Refresh tokens are not requested. Temporary state, nonce, and PKCE values protect the login flow. Hub session records include the login method and authentication / Discord verification times.
You can unlink Google in Account connections after Discord verification when required. This removes the active Google identity connection and revokes every Hub session created through Google. Player records stay with the same Hub account. Past backups follow the existing backup retention policy; restoring an older backup may restore the older connection state. Disconnecting in Hub does not change your Google account settings. You may also review Hub access in your Google Account's third-party connections.
Google authentication information is used for account verification and connection management, not advertising, sale, or public profile display. For account deletion or data correction, contact an administrator with the Admin role as described below.
This Privacy Policy explains how information is collected, used, stored, published, and deleted in connection with the Discord server “UDON SABER Hub,” the “UDON-SABER Bot,” and the “UdonSaber Leaderboard.”
These are collectively referred to below as the “Service.”
Please review this Privacy Policy before using the Service.
Article 1 — Basic Policy
The Service handles information about users only to the extent necessary to register, aggregate, display, and manage UDON-SABER play records.
The operator will use collected information only as necessary to provide, operate, improve, secure, and support the Service, and will endeavor to avoid unnecessary collection.
The Service is an unofficial service operated by an individual, not by a company or public institution.
Article 2 — Information Collected or Stored
The Service may collect or store the following information.
Discord information:
- Discord user ID
- Discord display name and username
- Discord avatar URL or information needed to retrieve the avatar
- Discord user identification information obtained during web login
- Discord server ID, channel ID, and message ID
- Information required to execute Bot commands
- Role and permission information
- Content sent during registration or inquiries
VRChat and registered-name information:
- VRChat name
- Player name registered with the Bot
- Information related to registered-name changes
- Association between the Discord account and registered name
Submitted images:
- UDON-SABER result screens
- Screenshots submitted for score registration
- Images analyzed by OCR
- Backup images used for record verification, fraud checks, or incident response
- Image submission time
- Identifiers linking images to play records
Song and chart information:
- Song title
- Artist
- Mapper
- Difficulty
- Stars
- BPM
- NPS
- Note count
- Wall count
- Song duration
- Metadata needed to identify charts
- Association with registered Discord servers
Play-result information:
- Score
- Accuracy
- Rank
- Combo
- Hit and Total
- PP and total PP
- Ranking position
- Submission time
- Comparisons with previous records
- Per-song and per-player aggregated information
Settings information:
- Private Score Mode status
- Web login session creation time, last-used time, expiration time, and revocation status
- Upload channels
- Administrator notification channels
- PP notification channels
- Other settings needed to operate the Service
Access information:
The standard features of the web server, tunnel service, Discord, Google, or other external services may record:
- IP address
- User-Agent
- Browser
- Device or OS information
- Access time
- Requested URL
- HTTP request information
- Errors or communication failures
- Random anonymous browser identifier
- Random anonymous visit/session identifier
- Current page category, visit count, page-view count, and concurrent-viewer statistics
The anonymous identifiers are generated by the browser and are not linked by this Service to a Discord account, VRChat name, IP address, User-Agent, or other profile information. Standard infrastructure logs may still contain IP addresses or User-Agent information even when the operator is not actively collecting them for analytics.
Article 3 — How Information Is Collected
The Service mainly collects information when:
- A user runs a Discord command
- A user submits a result image
- A user enters a registered name
- A user uses Bot buttons, menus, or forms
- A user authorizes web login through Discord OAuth2
- Necessary information is obtained from the Discord API
- Images are analyzed with Google Cloud Vision API
- A user accesses the website or public API
- An administrator registers or corrects information
- The system automatically calculates PP, rank, or other values
Article 4 — Purposes of Use
Collected or stored information is used to:
- Analyze UDON-SABER result images
- Register scores and other play results
- Associate players with Discord accounts
- Securely maintain the user's authenticated web session
- Manage registered names
- Calculate PP and total PP
- Create and display rankings
- Display player profiles
- Display song- and chart-specific rankings
- Provide the website and public API
- Compare result images with registered records
- Check and correct OCR errors
- Investigate fraudulent records, fabrication, or impersonation
- Organize duplicate charts or records
- Provide Private Score Mode
- Investigate Bot or website problems
- Respond to security issues
- Enforce the Terms of Service
- Respond to inquiries
- Improve, maintain, and add features
- Back up and restore data
- Carry out other purposes necessary for proper operation
Article 5 — Information Made Public
For ordinary users, the following information may be made public through Discord, the website, or public APIs:
- Registered name or player name
- Discord avatar
- Score
- Accuracy
- Rank
- Combo
- Hit and Total
- PP and total PP
- Ranking position
- Played songs and charts
- Per-song rankings
- Player profile
- Submission time
- Song and chart metadata
The website and public APIs may be viewed by people who are not members of the Discord server.
By registering a score, the user acknowledges that the above information may be made public.
Article 6 — Handling of Result Images
Submitted result images may be stored for:
- OCR analysis
- Verification of registered data
- Correction of recognition errors
- Investigation of fraudulent records
- Handling user inquiries
- Responding to system failures
- Backup and restoration
Images are generally retained unless a deletion request is approved, the Service ends, storage devices fail, an accident occurs, or another circumstance requires deletion.
Images are generally viewable only by the operator and administrators with the Admin role.
However, unintended display cannot be completely ruled out because of Bot or website configuration, bugs, or human error.
When a deletion request is approved, the related result image will also be deleted where reasonably possible.
Data may remain temporarily in backups, caches, logs, or external-service storage.
Article 7 — Google Cloud Vision API
The Service uses Google Cloud Vision API to analyze text in submitted result images.
Accordingly, submitted images or information derived from them are sent to Google servers for OCR processing.
Google handles the information under its own terms, privacy policy, data processing terms, and other rules.
The operator cannot fully control Google’s systems, storage periods, processing methods, or security.
By submitting an image, the user acknowledges that it will be sent to Google Cloud Vision API to the extent necessary for OCR.
Article 8 — Discord API
The Service uses the Discord API for Bot operation, user identification, avatar display, server and channel identification, permission checks, and related purposes.
For web login, the Service exchanges a Discord OAuth2 authorization code on the server and verifies the user's Discord user ID. The authorization code and Discord access token obtained during this process are used temporarily for login verification and are not stored in the Service database.
After login, a random session identifier is stored in the browser as an HttpOnly Cookie. The Service stores only its hash, expiration time, and usage state on the server.
Information obtained through the Discord API is handled under Discord’s terms, privacy policy, and developer policies.
The Service does not seek to obtain Discord account passwords or email addresses.
The operator cannot fully control Discord’s specifications, storage methods, or outages.
Article 9 — Private Score Mode
For users with Private Score Mode enabled, all or some of the following are hidden from normal public display:
- Score
- PP and total PP
- Accuracy
- Rank
- Combo
- Hit and Total
- Detailed player profile
- Detailed per-song ranking information
- Result images
- Detailed public API information
- Other records designated as private by the operator
The registered name or player name remains visible even when Private Score Mode is enabled.
Private Score Mode is therefore not an anonymization feature.
In a dedicated administrator-approved channel, the user or authorized users may be able to view private records through Bot functions.
Complete deletion or hiding of information published before the setting was enabled, past Discord posts, notifications, caches, screenshots, and related information cannot be guaranteed.
To request Private Score Mode, contact an administrator with the Admin role in the relevant Discord server.
Article 10 — Sale to Third Parties and External Services
The operator does not sell collected user information to advertisers, data brokers, or other third parties.
The Service may use external services as necessary, including:
- Discord and Discord API
- Google Cloud Vision API
- Web servers
- Communication or tunnel services
- DNS, hosting, or network services
- Backup or storage services
- Other services necessary for operation
Information may be disclosed where required by law, necessary to protect life, body, or property, or needed to respond to abuse or security issues, to the extent permitted by law.
Article 11 — Retention Period
Information is generally retained until one of the following:
- A deletion request is received and completed
- Operation of the Service ends
- The information is no longer needed for verification, fraud investigation, or inquiries
- A legally required retention period ends
Result images and records are generally retained unless deletion is requested, the Service ends, an accident occurs, or an SSD or other storage device physically fails.
Backups, caches, logs, and other copies may remain for a period after the primary data is deleted.
If immediate deletion of an individual item from backups is technically difficult, it will be removed when the backup is updated or destroyed.
Article 12 — Deletion, Correction, and Privacy Requests
Users may request:
- Deletion of score records
- Correction of registered names
- Correction of incorrect song or chart information
- Deletion of result images
- Enabling Private Score Mode
- Disabling Private Score Mode
- Other inquiries about their information
Requests should generally be made from the registered Discord account to an administrator with the Admin role in the relevant Discord server.
To prevent unauthorized requests, the operator may verify identity using:
- Whether the request comes from the registered Discord account
- Whether the registered name matches the Discord user ID
- Whether the request matches past submission records
- Other checks considered necessary
If identity cannot be verified, the request may be refused.
Article 13 — Information That Cannot Be Deleted Immediately
The following information may not be completely deleted immediately after a request:
- Backup data
- System logs
- Caches
- Past Discord messages
- Screenshots saved by other users
- Information temporarily retained by external services
- Records needed to investigate abuse or Terms violations
- Information required by law
The operator will make reasonable and technically feasible efforts to delete information but cannot guarantee removal of every copy from the internet.
Article 14 — Security Measures
The operator will take reasonable measures within the scope of individual operation, including:
- Managing Bot tokens, API keys, and other credentials
- Restricting access to administrative functions
- Managing permissions through Discord roles
- Backing up databases and configuration files
- Updating software
- Checking for unauthorized access or abnormal behavior
- Changing passwords or credentials when necessary
- Preventing unnecessary disclosure
- Maintaining Private Score Mode
- Other reasonable measures
The Service does not guarantee perfect security.
Article 15 — Data Breaches and Other Incidents
If a data breach, unauthorized access, malware infection, credential leak, lost storage device, or similar incident occurs, the operator may:
- Investigate the impact
- Temporarily stop the Bot, website, or API
- Change Bot tokens, API keys, passwords, or other credentials
- Block unauthorized access
- Announce the incident in the Discord server
- Contact potentially affected users
- Restore data from backups
- Contact external service operators
- Consult or report to relevant authorities when necessary
- Implement measures to prevent recurrence
For security reasons, not every technical detail may be disclosed.
Article 16 — Cookies, Local Storage, Language Settings, and Anonymous Usage Statistics
The website does not use tracking cookies for advertising or cross-site behavioral tracking.
To display current viewers and cumulative usage statistics, the website stores random anonymous browser and visit identifiers in the browser's Local Storage. These identifiers are used to reduce duplicate counting across tabs, distinguish visits after approximately 30 minutes of inactivity, and aggregate visits, page views, and concurrent-viewer counts.
The Service does not intentionally connect these identifiers to a Discord account, VRChat name, IP address, User-Agent, or advertising profile. Clearing browser storage generates new identifiers; previously aggregated totals may remain in the Service database.
Display language may be determined from browser language settings and may also be stored in Local Storage.
If external services, browsers, proxies, tunnel services, or similar tools use cookies or comparable information, their own terms and policies apply.
Article 17 — Use by Minors
The Service does not impose its own age restriction.
Users must follow the age restrictions, parental-consent requirements, and other conditions of Discord, VRChat, Google, and other external services.
Minors should obtain a parent or guardian’s understanding or consent where appropriate.
Article 18 — Changes to This Policy
The operator may amend this Privacy Policy in response to changes in law, Service content, external services, stored information, public visibility, security, or other circumstances.
Important changes will be announced in the relevant Discord server where reasonably possible.
Continued use of the Service after a change may be treated as confirmation that the updated policy has been reviewed.
Article 19 — Contact
For deletion, correction, Private Score Mode, registered names, public visibility, or other privacy questions, contact an administrator with the Admin role in the relevant Discord server.
There is no dedicated inquiry channel.
Identity verification or additional information may be required.
Article 20 — Operator
Current operation, configuration, data management, server management, and code modifications are handled by U_030D.
The original system on which the Bot is based was created by 0147295.
The original developer does not necessarily handle current personal data, deletion requests, inquiries, Private Score Mode, or other operational matters.