Privacy policy
Last updated 19 August 2026. This describes data processed by the CommunityM website and companion desktop app.
Who we are
CommunityM is operated independently (not by Rockstar or Cfx.re). Privacy requests can be sent through the site operator (see the admin / support channel published on this site).
Data we store
- Account: name, email, password hash (never the raw password), role, ban status.
- Optional OAuth identifiers if you sign in with GitHub or Discord.
- Profiles, resources, forum posts, reviews, issues, reports, notifications.
- Uploaded screenshots stored on this host (or disabled via configuration).
- Invite one-time passwords stored only as hashes, with an expiry time.
- Server logs (IP, user agent) as needed to run and secure the service.
Why we process it
To provide the community (accounts, catalog, forums), to moderate abuse, to send in-app notifications, and to authenticate the desktop app against the public API. Legal bases typically include contract (providing the service you signed up for) and legitimate interest (security and moderation).
Sharing
We do not sell personal data. Content you publish is public by design. Payments for paid scripts are handled by Tebex, not by us. Hosting/database providers process data as processors to run the site.
Retention
Account and public posts stay until you delete them or we remove them for policy reasons. Invite hashes are cleared when you set a password or when they expire. Backups may lag behind deletions.
Your rights
Depending on where you live you may request access, correction or deletion of your account data. Use the in-site settings where available, or the contact above. You can also export what you posted by copying it from public pages.
Cookies
We use an essential session cookie for authentication. We do not use advertising trackers on CommunityM itself.
Also see Terms, Privacy, DMCA and Content policy.