Privacy Notice

What Cronus Zens knows about you, where it came from, who else sees it, how long we keep it, and how to make us delete it.

Who is responsible for your data

Cronus Zens is the data controller for everything described here. If you want to ask about any of it, or exercise any of the rights at the bottom of this page, get in touch on our Discord server.

You can read this whole site, including the catalogue and every script page, without signing in and without us learning who you are. Almost everything below starts only when you choose to sign in or buy something.

What we collect, and where it comes from

From Whop, when you sign in or buy

We use Whop for accounts and payments. When you sign in, Whop tells us your Whop user ID, your name, your username, your email address and your profile picture, and whether your account holds the product you are trying to use. When you buy something, Whop tells us the payment ID, the amount and the currency.

We never see your card details. Those go to Whop and its payment processors and never reach this site.

From Discord, if you connect it

Connecting Discord is how the Club gives you your role and your channels. When you connect it, Discord tells us your Discord user ID, your username, the address of your avatar image and your server tag, and we ask Discord from time to time whether the tag is still on. This information comes from Discord rather than from you, which is why we are telling you about it here.

From you and from your Zen

  • The serial number and firmware version of any Cronus Zen you connect. Where you have bought a product that is locked to one device, we store the serial number in full so we can tell your device from someone else’s.
  • Anything you write in the Club: your posts and your comments.
  • Any script file you upload to compile, and anything you tell us when you ask for help.
  • A timestamp saying you were on the site in the last minute or so, which is what the member and online counts are built from. It is overwritten each time, so it is not a history of your visits.
  • Where something goes wrong, a fault report: what failed, your account ID and username, and details of the device and the step it failed at.

A file you upload is sent to two people

This one deserves its own heading rather than a line in a list. If you are signed in and you compile a .gpc script file that you brought yourself, a copy of that file is sent as a Discord direct message to two members of our team, along with a note naming you: your Discord mention and handle where we have them, otherwise your name, username or account ID.

We do this so we can see what people are trying to run and fix the compiler when it refuses something it should accept. If you would rather that did not happen, do not upload a file you consider private. If a copy of a file of yours has already been sent and you want it deleted, ask us on our Discord server and we will delete it.

Why we use it, and what allows us to

  • To give you what you paid for — signing you in, checking your account holds the product, delivering scripts, running the Club, binding a build to your device. We need this to perform our contract with you.
  • To support you and fix faults — fault reports, upload copies, the support record of a device binding. This is our legitimate interest in running a product that works, and yours in it being fixed.
  • To stop one licence being used by many people — device serial numbers and the record of which account a build belongs to. Our legitimate interest in being paid for what we sell.
  • To run the community — your Discord role, your posts and comments, the presence timestamp. Performance of our contract with you as a member.
  • To keep records we are required to keep — payment and refund records, for tax and accounting. A legal obligation.

Where we rely on a legitimate interest, you can object to it. See your rights at the bottom of this page.

Cookies and what is stored on your device

We set four cookies. All of them are strictly necessary to run the parts of the site you have asked for, all are marked HttpOnly and Secure, and none of them is used for advertising.

  • cz_whop_session — keeps you signed in. It is encrypted, and holds your Whop access and refresh tokens, your name, username, email and avatar, and a short-lived note of whether your account holds the product. It lasts 30 days.
  • cz_discord — remembers the Discord account you connected: its ID, username, avatar address and server tag. It is not encrypted, because it holds a name and a picture rather than anything that grants access. It lasts a year.
  • cz_whop_flow — holds one sign-in attempt together while you are away at Whop. It lasts 30 minutes.
  • cz_oauth_state — the same thing for Discord, and it is what stops someone else starting a connection in your name. It lasts 10 minutes.

We also keep a few things in your browser’s own storage that never reach us: your light or dark theme, your saved Evolve settings, the slots you have staged but not yet programmed, and, in development, a preview switch. None of it identifies you and none of it is sent anywhere.

We do not use analytics, advertising tags or tracking pixels, and we do not track you across other websites. Our fonts are served from our own domain rather than from Google. That is why you are not being shown a cookie banner: storage of this kind does not need your consent, though we are still required to explain it clearly, which is what this section is for.

One third-party script does load, and only in one place. When a signed-in member opens the Support section, we load Whop’s chat component from their servers so the support conversation can be shown on our page. It handles the messages and may store what it needs on your device to do that. It is not loaded anywhere else on the site, and it is not loaded at all for a visitor who is not signed in.

Whop and Discord set their own cookies on their own sites when you sign in or pay, and the Whop checkout runs inside a frame on our page. Those are covered by their notices, not ours. A Club post containing a YouTube link loads that video from YouTube’s no-cookie domain.

Who else sees it

  • Whop — accounts, payments and entitlement. When you open a checkout, your email address is passed to it so you do not have to type it again. Whop also holds the support conversation: everything you write in the Support section is a message in your support channel on Whop, stored by them and read by us there.
  • Discord — your membership of our server, your role, and the direct message described above.
  • Our own library service, at hackclient.com, which holds the database behind this site: your profile, your Club posts and comments, your device bindings, fulfilment records, fault reports and the presence timestamp.
  • Vercel, which hosts this site, and Cloudflare, which runs the compiler. The compiler receives the script text and nothing that identifies you.
  • Anyone we are legally required to disclose to, and an accountant or adviser acting for us under an obligation of confidence.

We do not sell your personal data, and we do not share it for anyone else’s marketing.

What you post in the Club is visible to other members, and your name and picture appear next to it. Your Discord profile is visible to everyone in our server.

Where it goes

Whop, Discord, Vercel and Cloudflare are based in the United States, so using this site involves your data being transferred there. Where we rely on a transfer mechanism, we use either the UK extension to the EU–US Data Privacy Framework, where the recipient is certified under it, or the UK International Data Transfer Agreement.

How long we keep it

  • Your sign-in cookie expires after 30 days and your Discord cookie after a year. Signing out deletes both immediately and tells Whop to revoke the token.
  • Your member profile, posts and comments are kept while your account exists, and until you ask us to remove them.
  • Device bindings and fulfilment records are kept for as long as you hold the product, and afterwards for as long as we may need to deal with a dispute or a chargeback.
  • Payment records are kept for six years, because tax law requires it.
  • Fault reports are kept while they are useful and deleted when they are not.
  • The presence timestamp is a single value that is overwritten, so nothing accumulates.

Your rights

You have the right to:

  • ask for a copy of the personal data we hold about you;
  • have anything inaccurate corrected;
  • ask us to delete it, where we do not have to keep it;
  • ask us to restrict what we do with it while a question about it is resolved;
  • object to anything we do on the basis of a legitimate interest;
  • ask for the data you gave us in a portable form, or ask us to send it to someone else; and
  • withdraw consent at any time, where we relied on consent.

Ask us on our Discord server and we will answer within a month. There is no charge. We may ask you to sign in first, because we would rather not hand your data to somebody claiming to be you.

Today there is no self-service export or delete button on the site. Ask us and we will do it by hand. In the meantime, signing out clears both cookies from your browser, and you can delete your own Club comments yourself.

If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, or to the supervisory authority where you live.

Children

This site is not intended for children. You need a Whop account and a Discord account to buy or to join the Club, and both have their own minimum age. If you believe a child has given us personal data, tell us and we will delete it.

Changes to this notice

If we change how we use your data, we will update this page and change the date at the top. Where a change matters to you, we will tell you rather than rely on you noticing.

The other pages