The unverified Activity is limited to explicitly invited App Testers and developers.
Privacy / invited tester beta
Privacy without invented records.
HackSim.io processes the limited information needed to host its website, authenticate invited Discord testers, and run live NET-101 sessions. This policy separates current behavior from features that have not shipped.
The MVP does not retain completions, scored outcomes, wins/losses, ranks, belts, or a leaderboard as account records.
We do not sell personal information, run behavioral ads, or collect payment details in this build.
01 / Scope
Who and what this policy covers
This Privacy Policy applies to the HackSim.io website, the hosted HackSim.io Discord Activity, and the APIs used to operate the invited tester beta (together, the Service). “HackSim.io,” “we,” “us,” and “our” refer to the operator of the Service.
Discord independently operates its platform and account systems. Discord's policies govern information it processes for Discord. This policy covers information HackSim.io receives from Discord or processes through the Service.
Current beta boundary. HackSim is an unverified Discord Activity available only to explicitly invited App Testers and developers. The current MVP has no public account-progression, outcome-history, ranking, belt, leaderboard, payment, purchase, prize, or wagering system.
02 / Data
Information we process
Discord identity and Activity context
When you sign in or launch the Activity, HackSim requests Discord's identify scope. Depending on the launch, we process:
- Discord user ID, username, display name, and avatar reference;
- an OAuth access token long enough to authenticate the Activity connection;
- Activity context such as the application instance, channel, or server identifier; and
- Activity participant status returned by Discord. The current MVP does not request, sell, or unlock paid entitlements.
HackSim does not request your Discord password, direct messages, contact list, or the general contents of your Discord servers.
Hosted session and device information
| Category | Examples | Current location |
|---|---|---|
| Limited identity | Discord ID, display name, username, and avatar URL used to authenticate a tester and label a live room. | A limited identity row may be held in Supabase. It is not a curriculum or outcome record. |
| Live room state | Presence, seat, readiness, actions, decisions, explanations, scenario state, handoff, and debrief state. | Carried through Supabase Realtime while a Pair or Duel room is active. The browser may retain a recovery checkpoint on the device. |
| Device data | Theme, interface settings, local operator display values, per-tab identifiers, recovery checkpoints, and limited recent-run display data. | Browser local or session storage. It is device-only and does not become account progression. |
| Discord room invitation | Six-character room code, HackSim invite URL, short session labels, and private or first-come visibility. | Sent to the configured Discord channel through the application bot or a validated Discord webhook. |
The current hosted tester flow does not intentionally retain lesson completions, scored outcomes, wins, losses, match history, rank, belt, or progression as server-side or cross-device account records. An in-session result or device-local recent-run display may remain until the room closes or you clear site data, but it is not synced as progression.
Website analytics and operational data
- Essential cookies: a short-lived OAuth state cookie and a signed, HTTP-only Discord session cookie. The session may last up to 30 days; the Activity cookie is partitioned to the Discord iframe context.
- Vercel Web Analytics: aggregated, cookie-free page-view information and limited events such as a landing-page call-to-action click. Reports may include the page, referrer, approximate location, browser, operating system, device type, and time.
- Operational logs: Vercel, Supabase, and Discord may process IP address, user agent, request time, response status, errors, and security diagnostics while delivering and protecting the Service.
- No website waitlist submission: the current landing page does not send or store an email address or professional-role selection.
Do not submit real credentials, private keys, personal records, malware, exploit payloads, or confidential employer data into a lesson, room, explanation, profile field, invitation, or support request.
03 / Purpose
How we use information
We use the information described above to:
- authenticate the invited Discord tester and sign the current session;
- verify that a user is participating in the expected Discord Activity instance;
- run, synchronize, reconnect, and debrief a live NET-101 room;
- send a private room invitation when requested;
- measure aggregate website use, diagnose errors, and evaluate whether the beta should continue;
- prevent abuse, protect the Service, enforce the Terms, and comply with law.
No advertising or hidden progression profile. We do not sell personal information, share it for cross-context behavioral advertising, use third-party advertising cookies, or convert beta session events into an undisclosed rank, belt, or persistent outcome record.
04 / Providers
Service providers and sharing
| Provider | Role | Information involved |
|---|---|---|
| Discord | Identity, Activity iframe and SDK, participant verification, and requested room invitations. | Discord identity, launch context, session participation, and invite content. |
| Vercel | Next.js hosting, server functions, diagnostics, and Web Analytics. | Requests, operational logs, aggregate analytics, and API payloads needed to handle a request. |
| Supabase | Realtime room transport and optional limited identity storage. | The identity, presence, and live-room data described above. |
We may also disclose information when reasonably necessary to comply with law or lawful process, investigate abuse or fraud, protect users or systems, obtain professional advice, or complete a business reorganization subject to appropriate safeguards.
A room invitation is visible to people who can access its destination Discord channel. It does not make the unverified Activity available to someone who is not an accepted App Tester or developer.
05 / Retention
Storage and retention
- OAuth state: expires after approximately ten minutes.
- Signed Discord session: expires after no more than 30 days unless cleared sooner.
- Browser data: remains until you clear HackSim site data, use an available reset, or the application replaces it.
- Realtime room data: is used for the active room; recovery data may remain on participating devices until cleared.
- Limited identity and operational records: may remain while needed to operate, secure, and troubleshoot the invited beta or meet legal obligations.
- Provider logs and aggregate analytics: follow our provider settings and the provider's applicable retention schedule.
The current MVP does not set a retention period for account progression or outcome history because it does not create those records.
06 / Control
Your choices and privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of personal information and to object to certain processing.
- Clear HackSim cookies and local storage through your browser or Discord webview controls.
- Revoke HackSim authorization in Discord's Authorized Apps settings.
- Ask us to access, correct, or delete a limited Supabase identity record.
- Contact Discord for information Discord controls outside HackSim.
We may request reasonable verification through the connected Discord account before acting on an account-level request. Because we do not sell personal information or use it for targeted advertising, there is no sale or targeted-advertising opt-out required for the current Service.
07 / Safeguards
Security and international processing
Safeguards used for this beta include signed HTTP-only sessions, partitioned Activity cookies, server-side secret handling, Supabase row-level restrictions, HTTPS transport, response security headers, bounded and validated invite input, and Discord server-side participant checks. No system is perfectly secure, and we cannot guarantee that information will never be accessed, lost, or misused.
HackSim and its providers may process information in the United States and other countries with different data-protection rules. Where required, we rely on applicable provider and legal transfer safeguards.
08 / Eligibility
Age requirements
HackSim is not directed to children under 13. You must be at least 13, meet Discord's minimum age for your country, and be able to agree to these terms. If local law requires a parent or guardian's consent, they must approve your use.
If we learn that we processed personal information from someone not permitted to use the Service, we will take reasonable steps to delete it.
09 / Contact
Changes and contact
We will update this policy before materially changing the beta's data practices, including before enabling persistent progression, outcome history, rankings, belts, public distribution, payments, or new providers. We will revise the effective date and provide additional notice when required.
Include the Discord user ID connected to the request and “Privacy Request” in the subject. Do not send a Discord password, OAuth token, private key, active payload, or other secret.