Ulises LicensesUlises Licenses
FeaturesPricingAPIChangelogs
Discord
Dashboard

Data Protection

Privacy Policy

Governance and data processing specifications for Citymoon Dynamics SRL and the Ulises Licenses platform. Learn how we handle account credentials, Discord identifiers, and runtime telemetry.

Effective Date: October 1st, 2026|Last Revised: September 3rd, 2026|Hosting: USA Only (No Overseas Servers)
Policy Sections
01. Data Controller & Scope02. United States Server Hosting03. Categories of Data Collected04. Legal Bases & Processing05. HWID & License Telemetry06. Cookies & Session Storage07. Third-Party Sub-processors08. Technical Security Measures09. Data Retention & Deletion10. Data Subject Rights (GDPR / CCPA)11. International Transfers12. Protection of Minors13. Amendments & Official Contact

Related Legal Agreements:

View Terms of Service
01.

Data Controller & Scope

This Privacy Policy outlines how Citymoon Dynamics SRL ("we", "us", or "our"), operating as the data controller, collects, utilizes, discloses, and safeguards personal data and technical telemetry through the Ulises Licenses platform (uliseslicenses.xyz).

We operate in compliance with the General Data Protection Regulation (GDPR - EU 2016/679), the California Consumer Privacy Act (CCPA/CPRA), and international privacy standards.

This policy applies to all developers, software vendors, and administrative users accessing our website, dashboard, Discord bot, UlisesLib integration libraries, and license validation REST API endpoints.

02.

Exclusive Server Hosting in the United States (USA)

All physical and cloud computing infrastructure supporting Ulises Licenses is located exclusively within the United States of America.

Primary database instances, license validation API edge nodes, and file processing systems are deployed in secure data centers within the United States.

We do not operate validation servers, intermediate compute nodes, or database replicas outside of the United States. All data processing described in this policy occurs on United States infrastructure.

If you access the Service from outside the United States, you acknowledge that your information is transmitted directly to and processed in the United States.

03.

Categories of Data Collected

We collect technical and personal data strictly necessary to provide dependable licensing infrastructure, mitigate software piracy, process payments, and authenticate developer sessions.

The following structured table outlines the categories, operational purposes, and retention criteria for all collected data elements.

Developer Identity & Account Data

Purpose: Authentication, dashboard provisioning, user profile resolution, and communications.

Retention: Retained during active account lifecycle; deleted within 30 days upon verified request.

Scope of Data Collected:
  • Discord unique identifier (Snowflake ID)
  • Discord username and discriminator
  • Discord avatar hash and avatar CDN URL
  • Verified email address provided via Discord OAuth2 consent

License Validation & Hardware Telemetry

Purpose: Runtime license validation, anti-piracy enforcement, IP quota caps, and HWID binding.

Retention: Active license bindings retained until reset; historical validation logs retained for 90 days.

Scope of Data Collected:
  • Hardware Identifiers (HWID hashes: CPU, motherboard, and system UUID fingerprints)
  • Public IP addresses of client hosting environments executing licensed plugins
  • Validation timestamps, request latency (ms), and HTTP client metadata
  • Plugin status (active, expired, revoked, or bound)

Software Products & Binary Metadata

Purpose: Managing product catalogs, auto-update distributions, and bytecode watermarking.

Retention: Retained while the product exists in the account; temporary binaries purged after injection.

Scope of Data Collected:
  • Product titles, descriptions, and semantic version strings
  • SHA-256 cryptographic checksums of compiled JAR binaries
  • Custom class paths designated for watermark token injection
  • Uploaded JAR archives processed in memory or ephemeral storage during watermarking

Billing & Subscription Metadata

Purpose: Facilitating plan upgrades, managing active subscriptions, and satisfying accounting standards.

Retention: Transaction reference logs retained for 7 years to satisfy statutory tax obligations.

Scope of Data Collected:
  • PayPal order identifiers and transaction references
  • Subscription renewal dates, plan tier (Free vs. Pro), and purchase timestamps
  • Note: We never process or store raw credit or debit card numbers.

Audit & Operational Security Logs

Purpose: Investigating administrative abuse, tracing license resets, and forensic defense.

Retention: Retained for 180 days in audit storage.

Scope of Data Collected:
  • Administrative action records (license creation, key revocation, HWID resets)
  • Originating IP addresses and User-Agent headers of dashboard sessions
  • Support ticket inquiries and ticket response histories
04.

Legal Bases for Data Processing

Under GDPR Article 6, we process data only when supported by a legitimate legal basis:

Performance of a Contract (Art. 6(1)(b)): Processing account credentials, verifying licenses in real-time, executing HWID and IP bindings, distributing updates, and providing access to purchased Pro tier features.

Legitimate Interests (Art. 6(1)(f)): Detecting software leaks via bytecode watermarks, preventing malicious API flood attacks, enforcing quota limits, investigating fraud, and ensuring infrastructure stability.

Compliance with Legal Obligations (Art. 6(1)(c)): Retaining billing transaction records, tax reporting, and responding to lawful requests from judicial authorities.

Consent (Art. 6(1)(a)): Where explicitly provided, such as opting into informational product updates or connecting external services.

05.

HWID Binding & License Telemetry

A core function of Ulises Licenses is preventing unauthorized software distribution through Hardware Identification (HWID) and IP address binding.

When a client application or Minecraft server boots with an integrated UlisesLib plugin, it transmits a cryptographic hash derived from hardware identifiers (such as system UUID, processor ID, and mainboard attributes) alongside the public network IP address.

We do not collect personal file directories, private documents, or unhashed serials. Hardware data is transformed into salted, non-reversible hashes to match against developer-configured license caps.

Hardware identifiers and IP addresses are accessible only to the product developer who issued the license and platform administrators for support resolution.

06.

Cookies & Session Storage

We employ security cookies and minimal local storage to maintain session integrity without behavioral tracking.

Session Cookie ("session"): A cryptographically signed cookie utilizing HMAC-SHA256 with HTTP-only, Secure, and SameSite=Lax flags. It stores session identification to keep you authenticated in the dashboard without exposing raw credentials.

UI Preferences ("db-theme"): A browser localStorage key used exclusively to persist your selected visual theme across page reloads.

Zero Third-Party Advertising Trackers: We do not serve third-party behavioral tracking pixels, marketing cookies, or programmatic advertising scripts.

07.

Third-Party Sub-processors & Service Providers

We partner with infrastructure providers who process data in accordance with strict data processing agreements:

Discord, Inc. (USA): User authentication via Discord OAuth2, bot command interactions, and developer community notifications.

PayPal Holdings, Inc. (USA / Global): Payment processing, subscription recurring billing, and merchant payment security.

Vercel Inc. (USA): Web application hosting, serverless compute, and performance telemetry.

MongoDB Atlas (AWS USA Datacenters): Managed, encrypted database infrastructure for persistent account and license records.

Resend Inc. (USA): Transactional email notifications and team invitation delivery.

08.

Technical & Organizational Security Measures

We implement defense-in-depth security architectures to ensure enterprise data protection:

Encryption in Transit: All public traffic, API calls, dashboard interactions, and webhook events are enforced over TLS 1.3 / HTTPS encryption.

Session Signature Verification: Session cookies are protected against tampering using timing-safe HMAC-SHA256 verification (crypto.timingSafeEqual), preventing signature forgery and timing attacks.

Role-Based Access Controls: Strict segregation between user and admin roles. Developer databases are partitioned, preventing cross-tenant data leakage.

Rate Limiting & Threat Mitigation: Automated rate limiting defends validation endpoints from credential stuffing and denial-of-service attempts.

09.

Data Retention & Disposal Schedule

We retain personal data only for the timeframe necessary to accomplish the purposes specified in this policy:

Active Developer Accounts: Retained while the account is active. Inactive accounts with no active licenses may be archived after 24 months of total inactivity.

License Validation Telemetry: Ephemeral request telemetry is rotated and purged every 90 days.

Bytecode Watermarking Binaries: Binary files uploaded for watermark processing are processed in memory and deleted from temporary storage immediately after download delivery.

Financial Transaction Logs: Preserved for 7 years in compliance with statutory financial and taxation regulations.

10.

Data Subject Rights (GDPR & CCPA)

Under applicable data privacy laws, you hold comprehensive rights regarding your personal information:

Right to Access (GDPR Art. 15): Request confirmation and copies of all personal data held about you.

Right to Rectification (GDPR Art. 16): Update or correct incomplete or inaccurate profile details.

Right to Erasure (GDPR Art. 17): Request permanent deletion of your account and associated license data, subject to legal retention obligations.

Right to Restriction of Processing (GDPR Art. 18): Restrict how we process your information under specific legal circumstances.

Right to Data Portability (GDPR Art. 20): Obtain an export of your product, license, and profile records in a structured, machine-readable format (JSON/CSV).

Right to Object (GDPR Art. 21): Object to processing based on legitimate interests at any time.

To exercise any statutory right, submit a written request to hello@uliseslicenses.xyz. We will verify your identity and respond within thirty (30) days without charge.

11.

International Data Transfers to the United States

Because our infrastructure is located in the United States, utilizing the platform involves direct data transfer to the United States.

Where personal data originating in the European Economic Area (EEA), United Kingdom, or Switzerland is transferred to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, ISO/IEC 27001 certifications of our hosting facilities, and applicable data protection adequacy frameworks.

By using Ulises Licenses, you acknowledge and agree that your data is processed and stored on United States servers.

12.

Protection of Minors

Ulises Licenses provides business and developer infrastructure not targeted at children under the age of 16.

We do not knowingly solicit or collect personal data from anyone under 16 years of age. If we learn that we have inadvertently collected data from a child under 16 without verified parental consent, we will delete that data from our production databases.

If you believe a minor has provided us with personal information, notify us immediately at hello@uliseslicenses.xyz.

13.

Policy Amendments & Data Protection Contact

We may update this Privacy Policy periodically to reflect technological changes, regulatory requirements, or platform updates.

Significant revisions will be announced via our dashboard notices, Discord announcements, or email prior to taking effect. Your continued use of the platform after the revised effective date constitutes acknowledgment of the updated policy.

For privacy questions, data subject requests, or regulatory inquiries, contact our Data Protection Officer:

Citymoon Dynamics SRL

Privacy & Data Governance Officer

Primary Data Hosting: United States of America

Corporate Site: https://citymoon.org

Direct Inquiries: hello@uliseslicenses.xyz

Ulises LicensesUlises Licenses

© 2025-2030 Citymoon Dynamics (citymoon.org). All rights reserved.

TermsPrivacyDiscord