Skip to main content
LEGAL

Privacy Policy

How the City of Indiana Roleplay community collects, uses, stores, and protects your personal data across our website and game server.

Last updated: August 15, 2026

01

Introduction

This Privacy Policy explains what personal data the City of Indiana Roleplay community ("we", "our", "us") processes when you visit our website at www.cityofindiana.com, use our online dashboard, or participate in the game community. This policy applies to the website and to community features tied to it; the in-game experience itself is provided through RedM and is governed by the terms of the Red Dead Redemption 2 / RedM platforms.

We are a non-commercial community project operated by volunteers. We do not sell or rent your personal data to anyone. By creating an account and using our services, you agree to the practices described in this policy. Where we ask for your consent before processing particular data, you can withdraw that consent at any time using the methods described in Section 9.

02

Information We Collect

We collect only the information needed to run the community. The categories of data we process include:

Account data (via Discord)

To sign in you must authorize through Discord OAuth. With your authorization we receive your Discord user ID, username, display (global) name, avatar, and email address, as well as your Discord guild memberships and roles where used for community access control.

Onboarding & character data

When you complete onboarding we ask for your date of birth (day, month and year), your character (outlaw) name, and a Discord age verification. Character details and in-game statistics such as level, playtime, money, gold, inventory, and bank balances are read from the game database and shown to you on your dashboard.

Whitelist & job applications

To gain access to the server you complete a written whitelist examination. Your exam answers are submitted along with your character name and character date of birth. If you apply for a job, we may ask for your real name, age, location, hours available per day, and a short biography.

User-generated content

You may upload images — an avatar, photographs for the community gallery, or newspaper articles. These images are stored with our image hosting provider. Gallery and newspaper content is displayed publicly with your author name unless you choose to hide it.

Preferences & settings

We store your account preferences, including whether your profile is public, whether your financials are shown, whether your inventory is hidden, and whether you receive Discord notifications about application updates.

Technical data

Like most websites we receive standard technical information from your browser, including your IP address (used transiently for rate limiting and abuse prevention and not stored), and we place small browser storage entries described in Section 6 and in our Use of Cookies page. We do not use analytics SDKs, advertising trackers, fingerprinting, or geolocation.

03

How We Use Your Information

  • To provide the service — authenticating you with Discord, verifying your eligibility, creating and managing your account and character.
  • To process whitelist and job applications — your exam answers and application details are used to evaluate your application and are reviewed by staff and, for whitelist exams, evaluated by an AI assistant.
  • To operate community features — powering community galleries, newspapers, and your dashboard.
  • To communicate with you — sending you Discord messages about application updates and community notices.
  • To protect the community — rate limiting, abuse prevention, detecting violations, and enforcing our server rules.
  • To maintain security and reliability — securing the website, debugging, and keeping the service operational.
04

How We Share Your Information

We do not sell or rent your personal data. We share data only with the services required to operate the community:

  • Discord — for OAuth sign-in, sending you application-update messages, and posting summaries of whitelist and job applications into our staff Discord channels for review. Discord processes this data under Discord's Privacy Policy.
  • OpenRouter (AI) — your whitelist exam answers are sent to the OpenRouter AI service for automated evaluation of your written answers. We do not share your real name, email, or other identifying data with the AI service.
  • ImgBB — uploaded avatar, photograph, and newspaper images are stored with our image hosting provider.
  • Hosting & infrastructure — the website is deployed on Vercel and data is stored in a MySQL database managed by our hosting provider.
  • Asset delivery — Google Fonts and a Font Awesome CDN load styling assets; your browser contacts these providers to fetch the resources.

We may disclose personal data where required by law, or to protect the rights, property, or safety of the community, our members, or the public. We do not otherwise share your data with third parties.

05

Public Information & Privacy Choices

Some community features are public by design. Photographs and newspapers you publish are visible to other players. We provide controls so you can limit what is shown:

  • Toggle your profile between public and private.
  • Hide your financials (money and gold) from public directories.
  • Hide your inventory.
  • Disable Discord notifications about your applications.
  • Delete your own photographs or articles from the galleries.

These options are available from your account dashboard. If you choose a public profile, the information you publish (such as a photograph with your character name) is visible to other members of the community.

06

Cookies & Similar Technologies

Our website uses a small number of first-party cookies and browser storage entries, described in detail on our Use of Cookies page. In summary:

  • session_token — keeps you signed in (expires after 7 days).
  • discord_oauth_state — a temporary security token used during Discord sign-in (expires after 15 minutes).
  • coi_admin_token — used only for staff members to keep an admin session (expires after 12 hours).
  • localStorage / sessionStorage — small entries that remember dashboard preferences, whether you have read the rules, and the outcome of your whitelist exam within your current session.
These cookies and storage entries are set only by our own site; we do not use third-party advertising or tracking cookies. You can clear them at any time through your browser settings. If you delete the session_token cookie you will be signed out.
07

Data Security

We take reasonable measures to protect your data, including serving the site over HTTPS, signing session tokens, marking session cookies as HttpOnly and Secure where supported, using parameterized database queries, and restricting access to staff members who need it to operate the community. Access to the administrator panel is limited to authorized staff.

No method of transmission or storage is completely secure. While we work to protect your personal data, we cannot guarantee its absolute security, and any transmission to us is at your own risk.

08

Data Retention

We retain your personal data for as long as your account is active and your character exists on the server, or as long as needed to provide the service and enforce our rules. We have no automated deletion schedule: your data remains stored until you request deletion, you leave the community and we clean up your records, or we remove it for a rule violation.

Game-server records (such as your character, statistics, and any warnings or bans) are part of the community's operational data and may be retained separately from your website account records.

09

Your Rights & Choices

  • Access — view the personal data associated with your account on your dashboard.
  • Correction — update your settings, preferences, character details, and application information at any time.
  • Deletion — use the “Delete Application Data” option in your dashboard to remove your website account records.
  • Portability (data export) — use the “Export My Data” option in your dashboard to receive a machine-readable JSON copy of the personal data we hold about your account. The file is delivered to your Discord DMs.
  • Restrict public display — hide your profile, financials, and inventory as described in Section 5.
  • Consent withdrawal— disable Discord notifications or revoke our access to your Discord account at any time through Discord's settings.
You can request an export of your data at any time from your account dashboard (“Export My Data”). The JSON file contains your profile, settings, character records, applications, published content, and moderation history, and is delivered privately to your Discord DMs. Deleting your application data removes the records we hold on the website side. It does not automatically delete game-server character records, does not revoke the Discord authorization you granted, and does not remove content you have published in public galleries. If you would like a wider deletion, contact us using the details in Section 14 and we will review your request.
10

Children's Privacy

Our community is intended for adults. We require confirmation that you are at least 13 years old during onboarding, and our Terms & Conditions and server rules set an 18+ standard for participating in the roleplay. We do not knowingly collect personal data from children under the age of 13. If you believe a child under 13 has provided us with personal data, contact us so we can delete it.

11

International Data Transfers

Our community serves players from different countries, and the services we rely on — including Discord, OpenRouter, ImgBB, and Vercel — are operated by providers located primarily in the United States. Your personal data may therefore be processed in countries outside your country of residence. By using our services you understand that your data may be transferred internationally to the providers listed in Section 4.

13

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page and, where appropriate, notify you through the community. Continued use of the website or community after changes take effect constitutes acceptance of the updated policy.

14

Contact Us

If you have questions about this Privacy Policy, wish to exercise any of your rights, or would like to request deletion of your data, you can reach us at: