VLRNT Crosshair
Privacy Policy
This page explains what happens to your data when you use VLRNT Crosshair. The short version: the site is a public database and asks for very little. If you add a crosshair, we save the name and code you enter. If you create an account, we also keep a username, an email address and a hashed password. Nothing else is requested.
What we collect
Like almost every website, our web server records standard access information when you load a page: your IP address, the page you requested, the date and time, and your browser's user agent. We use it to keep the site running, to find errors and to protect it from abuse. It is kept only as long as needed for those purposes.
If you use the search box, your search words are sent to our server as part of the page address, so they appear in those same server logs.
Crosshairs you submit
Anyone can add a crosshair on the Submit page. The name and the code you enter, and the date you added them, are saved and shown publicly on the site. Please do not put personal information in the name.
To limit spam, each submission is stored together with a one-way hash of your IP address: a scrambled value made with a secret key that cannot realistically be turned back into the address. We use it only to enforce the limit of one submission every 15 minutes and to block senders who abuse the site, and it is not shown anywhere. A submission is kept for as long as the crosshair stays on the site. To have a crosshair you submitted removed, contact us (see Contact below) and tell us which one it is.
Reports
If you report a crosshair, we save the reason and any note you write, together with the same kind of one-way hash of your IP address. We use the hash only to stop the same person reporting a crosshair twice and to limit mass reporting. Reports are kept while we review them and for as long afterwards as we need them to deal with abuse. They are never shown publicly.
Messages you send us
If you write to us on the Contact page, we save your message, the topic you chose and the time, together with the same kind of one-way hash of your IP address (to limit spam), and your name and email address only if you type them. Only the people who run the site read them. They are never shown, they are used only to answer you and to deal with abuse, and we keep them while we deal with your message and as long afterwards as we need them for that. To have a message deleted, write to us again on the same page and say so.
Comments
Anyone can read comments, and anyone can write one, with or without an account. A comment is saved with the text you write, the time and the crosshair it belongs to, and it is shown publicly. Comments are plain text; please do not put personal information in them, because anyone can read it.
As a member your comment is linked to your account and shown with your username. This is the one place your username appears even when your public profile is off, so write a comment only if you are fine with that. As a guest (no account) you may type a name, which is shown with a “guest” label; if you leave it empty you show up as “Guest”. A guest comment is saved together with the same kind of one-way hash of your IP address as a submission (a scrambled value made with a secret key that cannot realistically be turned back into the address). We use it only to limit how often one address can comment and to block senders who abuse the site; it is never shown. Writing a guest comment sets no cookie and stores nothing on your device except, if you like, the name you typed, which your browser keeps locally so you do not have to type it again.
To stop spam, members are limited by account and guests by that hash; we also check the hash to refuse comments from blocked senders (for a member that hash is not stored with the comment). Only members can report a comment: we save the reason together with the account so one person cannot report the same comment twice. Reports are only seen by the people who run the site.
A member can delete their own comments at any time with the Delete link under them: the text is erased at once. A comment that other people have already replied to stays as an empty “This comment was removed” line so the replies still make sense. When a member deletes their account, their comments go with it, and so do the replies other people wrote under them. A guest has no account to sign in to, so a guest cannot delete a comment afterwards: contact us (see Contact below), tell us which comment it is, and we will remove it. We can also hide or remove any comment that breaks the rules.
Copy counts
When you copy a crosshair code with the copy button, the site counts it, so we can show how popular a crosshair is. Every copy is counted. To spot automated flooding, we store a one-way hash of your IP address (the same kind as described above) next to each counted copy for up to 30 days. It is used only to limit abuse, is never shown, and cannot realistically be turned back into your address.
Crosshair Generator and Sensitivity Converter
Both tools do their work in your browser. The settings you choose in the Crosshair Generator while you build a crosshair, and the numbers you type into the Sensitivity Converter, are not sent to our server. The finished generator code is also written into the page address (after ?c=) so you can bookmark or share it. That address appears in the access logs only if you open such a link. If you click “Add to database”, the code is only carried over to the Submit page and is stored once you submit it there.
To see how much the tools are used, the pages tell our server two things: that a tool was used (you changed something) and that you pressed its Copy button. With each of these we store a one-way hash of your IP address (the same kind as described above, never the address itself) together with the day, so we can count how many different people used a tool. When you copy a code you made in the Crosshair Generator, that code is also saved, without anything that identifies you, so we can see which crosshairs people create and may add some of them to the site. A code is not saved if you only copied the untouched default or a code you loaded without changing it. The numbers you type into the Sensitivity Converter are never saved. These usage records are used only for these counts and for fighting abuse, are never shown publicly, and the per-person records are deleted after about 13 months.
Staff sign-in
Only the people who run the site can sign in to the admin area. Signing in sets a session cookie that is limited to the admin area and removed when the browser closes. Visitors never receive it. Admin actions and sign-in attempts, including the IP address they came from, are logged for security.
Accounts
You never need an account to browse, copy or add crosshairs. If you create one, we store:
- the username you choose and your email address. The email is only used to send you a password reset link and is never shown to anyone;
- your password, only as a one-way hash (we cannot read it, and nobody who works on the site can);
- when the account was created and when you last logged in;
- the crosshairs you saved, and which crosshairs you added while logged in, so we can show them in your account;
- the comments you write and the reports you send about other people's comments (see Comments above);
- whether your public profile is on (see below), which is off until you turn it on;
- a temporary record of your login, sign-up and password reset attempts, each with a one-way hash of your IP address (never the address itself), which we use to stop guessing attacks. These records are deleted after about two days.
Logging in with Google or Discord. If you choose “Continue with Google” or “Continue with Discord”, you sign in on their site, not ours: we never see your Google or Discord password. They tell us only your account ID, the email address of that account (only if they have verified it) and your display name. We use the email address and the name to create your account here (the name only suggests a username), and we store the account ID together with a label (your email address or Discord name) so we can recognise you next time and show it in your Settings. We ask for nothing else, such as your contacts or your servers. In return, Google or Discord learn that you signed in to this site; what they do with that is covered by their own privacy policies. You can disconnect a provider in Settings at any time. An account created this way has no password until you set one.
Public profile (optional, off by default). Unless you switch it on, your username is not shown next to the crosshairs you add and there is no profile page for you; the only place it appears without this switch is next to the comments you write (see Comments above). If you turn on “Show my username and my profile page publicly” under Account > Settings, your username is shown next to the crosshairs you add while logged in, and anyone can open your profile page (/u/yourname), which lists those crosshairs and how often they were copied. Search engines are asked not to list profile pages. Your email address is never shown. You can switch the profile off again at any time: the name and the page disappear immediately.
If you tick “Remember me”, we keep a random token (only its hash on our side) so you stay logged in for 30 days on that device. You can end every session by changing your password.
You can delete your account at any time under Account > Settings. That removes your username, email, password hash, saved list, comments (and the replies under them) and tokens. The crosshairs you added stay on the site without any link to you, unless you choose to delete them as well. If you cannot login, contact us (see Contact below) and we will delete the account for you.
The site itself sends email only for a password reset you asked for (one at most per hour for an account). We do not send newsletters or share your address with anyone. If you leave an email address on the Contact page, we may answer you there. Mail goes through our email provider, who handles it only to deliver it.
Cookies and tracking
If you only browse, the site sets no cookies at all. Cookies exist only for logging in, and they are strictly necessary for that: a session cookie while you are logged in (removed when you close the browser), and, only if you tick “Remember me”, a second cookie that keeps you logged in for 30 days. Both are used for nothing else, are not readable by scripts and are removed when you logout. The staff sign-in described above has its own separate cookie.
The site does not use advertising or analytics services. If that changes, we will update this page first and, where the law requires it, ask for your consent.
The site uses your device's built-in fonts and loads its own scripts and styles from its own server, so it does not send your visit to font or script providers.
Links to other sites
The site may link to other services. Once you follow a link, that service's own privacy policy applies.
Your rights
Depending on where you live, you may have the right to ask what data we hold about you, to have it corrected or deleted, or to object to how it is used. Since we collect almost nothing, there is usually little to give, but you are welcome to ask.
Contact
Use the Contact page to reach us, for example to have something removed or to ask what we hold about you. To report one crosshair or one comment, use the Report link next to it.
Changes to this policy
We may update this policy as the site grows. The date at the top shows when it last changed.