Privacy Policy
Last Updated: September 3, 2026
This is the privacy contract for NAVCOM-ID, NAVCOM-Bot, and navcom.ai. It is written for people, not as pretend EU establishment text. We are a United States operator and we do not claim an EU establishment we do not have.
Who operates this
NAVCOM-ID, NAVCOM-Bot, and navcom.ai are operated by Wild Knight Squadron in the United States — the same operator named in the site footer and terms. This is a community project, not a Cloud Imperium Games product. We do not list a street address on this site; we will not invent one here.
Questions: use the public contact already on the site — Discord (the invite you get when you add the bot) or Buy me a coffee. Do not look for a helpdesk URL on this page; there is not one.
What we store
- Discord id if you link Discord or sign in with Discord (plus Discord OAuth tokens we need to keep that link working).
- Email if you provide and verify one. Hashed password if you set one. Short-lived hashed email OTP codes.
- RSI handle and verification state when you complete bio proof (portal or Discord
/verify). - OAuth grants — which apps you allowed, which scopes, and issued tokens (hashed refresh material, not raw secrets in logs).
- Sessions so you can sign out or revoke devices under Account.
- TOTP / WebAuthn as hashes or public keys only. We never store authenticator seeds in the clear.
- Guild/bot configuration you set (roles, welcome, voice, action logs).
What we never store
- Phone numbers. No SMS. No phone verification.
- Government ID.
- Payment cards. Donations go through Buy Me a Coffee; we do not keep card numbers.
- Google or Twitch accounts. We do not offer those logins and we do not collect those identities.
We do not sell data. We do not run ad pixels or third-party analytics trackers on navcom.ai.
RSI data
RSI profile facts come from public RSI pages via SENTRY (player and org encyclopedia). Bio proof means you put a code on your public RSI profile so we can see you control that page. It is not Cloud Imperium game login and we never receive your RSI password.
Hidden or redacted org memberships are not in SENTRY public data and are not shared with Sign in with NAVCOM apps.
OAuth / Sign in with NAVCOM
- Apps receive only consented scopes. Required scopes must be granted or login stops. Optional scopes can stay off.
- Discover (reverse Discord↔RSI lookup) is off by default. It only works if you turn it on under Account and the app holds both
rsianddiscord. - Discord ids never appear in tokens without the
discordscope and discover on for reverse lookup. - You can revoke apps, sessions, and RSI under Account. Download a ZIP of your account fields via Download my data (no hashed passwords, no live OAuth tokens).
How to request deletion
On Account you can revoke RSI, unlink Discord (when you have a verified email), revoke sessions, and revoke apps. For full account deletion, request it from Account (see the deletion note there) or via the same public Discord / contribute contact. Removing the bot from a Discord server deletes that server’s configuration.
Why no Google / why no phone
NAVCOM-ID is Discord + email + passkeys (headline) / TOTP. We do not collect phone numbers and we will not add SMS. We do not add Google or Twitch login. That is a product choice: fewer identity brokers, no phone graph, no scrape-shaped client credentials.
Children
NAVCOM is not for children under 13. We do not knowingly collect their data. If we did, tell us through the public contact above and we will delete it.
Changes
Updates land on this page with a new “Last Updated” date. The public URL is https://navcom.ai/privacy (the old /privacy-policy path still works).