Legal

Privacy Policy

Last updated: July 13, 2026

Effective Date / Last Updated: July 13, 2026.

This Privacy Policy (the "Policy") explains how AW AntiCheat ("AW AntiCheat", "we", "us", "our") collects, uses, discloses, and protects information in connection with (a) the AW AntiCheat web panel, including accounts, license management, the configuration editor, billing, and support tickets (the "Panel"), and (b) the AW AntiCheat server-side anticheat resource that customers install and operate on their own FiveM / GTA V roleplay game servers (the "Resource", and together with the Panel, the "Service").

This Policy forms part of a single agreement set together with the Terms of Service, the Refund & Billing Policy, the End User License Agreement, and the Acceptable Use Policy, each of which may be cross-referenced by name and each of which is incorporated by reference. By registering a Panel account, purchasing or activating a license, deploying the Resource on a server you control, or otherwise using the Service as a Customer, you acknowledge this Policy and agree to be bound by the agreement set; if you do not agree, you must not register, purchase, or deploy. As to Players (defined below), this Policy is provided for transparency and information only, as described in the section "Scope and Who This Policy Covers".

Capitalized terms not defined in this Policy have the meanings given to them in the Terms of Service.

1.Scope and Who This Policy Covers

This Policy applies to two distinct categories of individuals. First, it applies to "Customers": persons who register a Panel account, purchase or manage licenses, configure the Resource, open support tickets, or otherwise interact directly with us. Second, it describes — for transparency only — how the Resource processes information about "Players": individuals who connect to a Customer's FiveM game server on which the Resource has been deployed. Players are not our customers, do not hold accounts with us, and have no direct contractual relationship with us. Players do not become party to the agreement set, acquire no rights under it, and are not intended third-party beneficiaries of it; as to Players, this Policy is informational only.

In addition, and as described in the section "Validation, Audit, and Activity Logs", we process limited technical data relating to any party or server that attempts to validate a license key against our systems, whether or not that attempt is authorized. This Policy constitutes notice of that processing.

Nothing in this Policy grants any right, license, or entitlement beyond what is expressly stated in the agreement set. Where this Policy and mandatory applicable law conflict, this Policy applies to the maximum extent the law permits, and the remainder continues in full force.

2.Our Roles and Responsibility for Data

For personal data relating to Customers — Panel account data obtained through Discord OAuth, billing and order records, support tickets and attachments, license records, and validation, audit, and activity logs — we act as the data controller. We determine the purposes and means of that processing as described in this Policy.

Player data collected, generated, or acted upon by the Resource is processed locally, on and for the Customer's own game server infrastructure, under the Customer's deployment decision and per-license configuration in the Panel (including chosen detections, punishments, bypass rules, optional modules, and webhooks). In the ordinary operation of the Service, that Player data is not transmitted to, received by, hosted on, or accessible from our systems, and we are neither the controller nor the processor of it. The Customer — the server owner — is the sole controller of Player data processed on the Customer's server and is solely responsible for establishing a lawful basis for that processing, for informing Players of it, and for honoring Players' rights, as further described in the sections "Server Owners' Obligations to Their Players" and "Your Rights and How to Exercise Them" below.

Limited exception. Certain Player data can reach our systems only because a Customer places it there: Player identifiers that a Customer enters into Panel configuration (for example, whitelists and bypass rules) and Player data that a Customer includes in support tickets or attachments. We store and process that data solely on the Customer's documented instructions — given through the Customer's Panel configuration and submissions — and solely to provide the Service to that Customer. This Policy, together with the Terms of Service, constitutes the data processing terms governing that limited processing within the agreement set.

We do not control, and expressly disclaim responsibility for, how any Customer configures the Resource, what punishments a Customer applies to Players, which optional modules a Customer enables, or what a Customer does with logs delivered to the Customer's own Discord webhooks. All such determinations are made by the Customer in the Customer's sole judgment, and the Customer indemnifies us for them as set out in the Terms of Service.

3.Account Data Collected via Discord OAuth

The Panel supports sign-in exclusively through Discord OAuth. When you authenticate, we receive from Discord and store: your Discord user ID, your Discord username, your Discord avatar, and the email address associated with your Discord account. We do not receive your Discord password and we do not request Discord scopes beyond those needed to operate your account.

We use this data to create and maintain your Panel account, associate licenses, orders, configurations, and support tickets with you, communicate with you inside the Panel, and enforce the agreement set. Our administrators may, in our sole discretion, ban or restrict accounts for breach, suspected abuse, fraud, chargebacks, reverse engineering, leaking, or to protect the Service; identifying data associated with banned accounts may be retained to prevent ban evasion and re-registration.

Your use of Discord itself is governed by Discord's own terms and privacy policy, over which we have no control.

4.Billing and Order Data

Purchases are one-time charges completed through card and PayPal-style checkout flows operated by third-party payment processors. There is no auto-renewal. Payment instrument details (such as full card numbers) are handled by the applicable payment processor under its own terms and privacy policy; we receive and retain transaction outcomes and references rather than full payment credentials.

We maintain billing history and order records for each account, including order identifiers, the license or plan purchased (monthly, quarterly, yearly, or lifetime — "lifetime" refers to the operational lifetime of the Service, not the lifetime of the purchaser; see the Terms of Service), amounts, timestamps, and order state (pending, paid, failed, refunded, or granted). We use these records to deliver purchases, manage license entitlements and renewals, investigate and contest fraud and chargebacks, apply the Refund & Billing Policy, and satisfy accounting and legal obligations. Determinations regarding order states, fraud, and chargebacks are made by us in our sole discretion and are final, subject only to mandatory applicable law.

Where an order enters the refunded state or becomes subject to a chargeback or other payment reversal, the associated license and entitlements may be immediately suspended or revoked without further notice, in accordance with the Refund & Billing Policy and the Terms of Service, and the related records are retained as described in the section "Data Retention" to prevent abuse and evasion of enforcement measures.

5.Support Tickets and Attachments

The Support (tickets) section inside the Panel dashboard is the only official support and contact channel for the Service. When you open a ticket, we collect the ticket content, any image attachments you upload, associated account identifiers, and timestamps. We use this data to respond to your request, diagnose issues, maintain a record of communications, and enforce the agreement set.

You are responsible for the content of your tickets and attachments. Do not upload data you are not entitled to share, and avoid including unnecessary personal data of third parties (including Players) in tickets or screenshots. Where a ticket or attachment contains Player data, we hold it on your instructions as described in the section "Our Roles and Responsibility for Data". We may retain ticket histories after resolution for quality, security, dispute-handling, and enforcement purposes.

6.Validation, Audit, and Activity Logs

Each license activates exactly one FiveM server and binds to the first server that successfully validates. A license may be unbound and rebound through the Panel, subject to frequency limits, cooldowns, and other anti-abuse controls we may impose, and we may refuse, delay, or reverse a rebind — and deny validation — in our sole discretion where logs indicate key sharing, leaking, resale, or other abuse. The Resource revalidates with our servers periodically (approximately every five minutes) and receives HMAC-signed configuration and verdicts. To operate and protect this licensing system, we automatically collect validation logs, which include the connecting game server's IP address, its hostname, the license key attempted, and the resulting verdict, together with timestamps.

By activating a license, the Customer instructs and authorizes us to deliver signed configuration, verdicts, plugins, and updates to servers bound to that license as an integral part of the Service. The Customer remains responsible for testing and for the effects of the Customer's configuration choices on the Customer's server.

Validation logs may include data of any party or server that attempts to validate a license key, whether or not that attempt is authorized. We process this data on the basis of our legitimate interests in securing the Service, preventing unauthorized use, and enforcing our rights, and this Policy constitutes notice of that processing.

We also maintain audit and activity logs of actions taken in the Panel (for example, configuration changes, license binds and unbinds, and administrative actions). We use validation and audit logs to authenticate license usage, detect and prevent key sharing, leaking, tampering, unauthorized use, and fraud, to troubleshoot the Service, and to establish evidence for enforcement of the agreement set. These logs are a core security function of the Service. We retain them for no longer than necessary for the security, licensing-integrity, and enforcement purposes described above, determined by criteria including the license's active status, ongoing or reasonably anticipated disputes or investigations, and applicable limitation periods.

7.Player Data Processed by the Resource on Game Servers

The Resource is deployed, operated, and configured by the Customer on the Customer's own game server infrastructure. Depending on the Customer's configuration, the Resource processes the following categories of Player data on and for the Customer's server, with the Customer acting as controller:

  • Player identifiers exposed by the FiveM platform, which may include the Rockstar license identifier, Discord ID, Steam ID, Xbox Live identifier, Microsoft Live identifier, FiveM account identifier, and IP address.
  • Hardware tokens associated with the Player's machine, as provided by the platform.
  • Player display names.
  • Detection events, including the detection type, points assigned, and the action taken (such as warn, kick, or ban) under the Customer's configured punishment rules.
  • Ban records created by the Customer's configuration, consisting of Player identifiers and hardware tokens.
  • Rate and event monitoring data used to identify abnormal or abusive event traffic.
  • Optional chat-author verification data, where enabled by the Customer.
  • An optional Discord account-age check, which is decoded locally on the server from the Discord snowflake ID itself; no call is made to any Discord API for this check.
  • An optional Steam account-age check performed server-side using the Customer's own Steam Web API key, as described in the section "Owner-Configured Integrations" below.
  • Where the Customer enables the optional OCR screen layer, screen text processed locally on the Player's machine (never transmitted) and a transmitted match / no-match watermark flag, as described in the section "The Optional OCR Screen Layer" below.

Exception: Player identifiers that a Customer enters into Panel configuration (for example, whitelists and bypass rules) and Player data that a Customer includes in support tickets or attachments are stored on our systems; we hold these on the Customer's instructions, as described in the section "Our Roles and Responsibility for Data", and retain them only while the relevant license, configuration, or ticket requires.

Which of these are processed, what thresholds apply, which Players are whitelisted or covered by bypass rules, and what punishments follow a detection are all decided by the Customer. We make no representation that the Resource will detect all cheats or cheat software, and we do not guarantee the absence of false positives; detection outcomes and punishment decisions are configuration-dependent and are the Customer's responsibility.

8.The Optional OCR Screen Layer

The Resource includes an optional on-screen OCR layer that the Customer (the server owner) may enable for their server. Because of its nature, we describe it precisely. When enabled, the OCR layer captures the Player's game frame locally on the Player's own machine and reads visible text locally, using Tesseract running inside the game's NUI environment. The recognized text is matched, still locally, against a list of known cheat-menu watermarks, and the text is then discarded. The OCR layer is designed and intended to operate so that no screenshot, frame, image, or recognized text leaves the Player's machine; the only data element it is designed to transmit is a match / no-match flag indicating whether a watermark from the list was detected. Actual behavior on any given machine can be affected by the Player's own software and system environment and by the Customer's server environment, for which we are not responsible.

The OCR layer is disabled or enabled solely by the Customer. A Customer who enables it is solely responsible for determining that its use is lawful in the relevant jurisdictions, for clearly disclosing it to their Players before or at the time of connection, and for obtaining any consent that applicable law requires. We do not receive or store Players' screen content, the layer is not designed to give us access to it, and we disclaim all liability arising from a Customer's decision to enable the OCR layer or from a Customer's failure to disclose it.

9.Owner-Configured Integrations

Customers may configure Discord webhooks for their license so that detection logs, ban logs, and join logs generated on their server are delivered to Discord channels in the Customer's own Discord server. The destination, content routing, and downstream handling of webhook messages are controlled entirely by the Customer and by Discord; once delivered to the Customer's Discord server, that data is outside our systems and outside this Policy. Webhook URLs are treated as server-only secrets: they are stored server-side and are never sent to game clients.

Where the Customer enables the optional Steam account-age check, the Customer supplies their own Steam Web API key. That key is used server-side only, is never sent to game clients, and is used to query Steam for account information relevant to the check. The Customer's use of the Steam Web API is subject to Valve's applicable terms, and the Customer is responsible for their own compliance with them.

10.Purposes and Legal Bases

Where we act as controller, we process personal data for the following purposes and, where applicable law requires a legal basis, on the following bases:

  • Performance of a contract: creating and operating your Panel account, delivering purchased licenses, binding and validating licenses, delivering signed configuration, verdicts, plugins, and updates to the Resource, providing the configuration editor, and responding to support tickets.
  • Legitimate interests: securing the Service; preventing and investigating fraud, chargebacks, license sharing, leaking, tampering, reverse engineering, unauthorized validation attempts, and other abuse; maintaining validation, audit, and activity logs; enforcing the Terms of Service, Refund & Billing Policy, End User License Agreement, and Acceptable Use Policy; preventing ban evasion; and establishing and defending legal claims.
  • Legal obligations: maintaining transaction and accounting records and responding to binding requests from competent authorities.
  • Consent, where and only where applicable law requires it for a specific processing operation; where consent is the basis, you may withdraw it prospectively, without affecting prior processing.

Where Player data reaches our systems in the limited circumstances described in the section "Our Roles and Responsibility for Data", we handle it on the Customer's instructions. In all other respects, the purposes and legal bases for the processing of Player data are determined by the Customer as controller, and Players should consult the Customer's own privacy notice.

11.Data Retention

We retain personal data for as long as your account is active and thereafter for no longer than reasonably necessary for the purposes described in this Policy, determined by criteria including the status of your account and licenses, ongoing or reasonably anticipated disputes, investigations, or enforcement matters, applicable limitation periods, and legal record-keeping requirements. In particular: billing and order records are retained for the periods required by accounting, tax, and commercial law; validation, audit, and activity logs are retained under the criteria stated in the section "Validation, Audit, and Activity Logs"; support ticket histories are retained for quality, dispute, and enforcement purposes; and records associated with fraud, chargebacks, breach, or banned accounts may be retained after account closure specifically to protect the Service and to prevent evasion of enforcement measures.

Player data processed by the Resource resides on the Customer's own server infrastructure and in the Customer's own Discord servers (where webhooks are configured); its retention is controlled by the Customer as controller, not by us. Exception: Player identifiers that a Customer enters into Panel configuration (for example, whitelists and bypass rules) and Player data a Customer includes in support tickets are stored on our systems; we hold these on the Customer's instructions and retain them only while the relevant license, configuration, or ticket requires, or as otherwise permitted or required by law.

12.Security Measures

We implement technical and organizational measures appropriate to the nature of the Service. These include: HMAC signing of configuration and verdicts delivered to the Resource, designed so that tampered or forged responses can be detected and rejected by the Resource; per-license signing secrets placed in the Customer's server.cfg; and strict separation of secrets, whereby signing secrets, webhook URLs, and API keys are server-only and are never transmitted to game clients. Access to administrative functions is restricted, and Panel actions are recorded in audit logs.

Customers are responsible for securing their own environments, including their server.cfg, license keys, signing secrets, Steam Web API keys, webhook URLs, Discord accounts used for sign-in, and game server infrastructure. No method of transmission or storage is completely secure, and the Service and the Resource are provided "AS IS" and "AS AVAILABLE"; we do not warrant that security measures will be error-free or that unauthorized access will never occur, and our liability in connection with any security incident is limited as set out in the Terms of Service and restated in the section "General Provisions" below.

If we become aware of a personal data breach affecting data for which we are the controller, we will notify affected Customers via the Panel and competent authorities as and when applicable law requires; notice through the Panel constitutes sufficient notice. Customers are responsible for any Player-facing notification obligations arising from incidents on their own servers. Nothing in this section creates notification duties beyond those imposed by applicable law.

13.Sharing and Disclosure

We do not sell personal data, and we do not share personal data with advertising networks or data brokers. We disclose personal data only in the following circumstances:

  • Payment processors, to complete card and PayPal-style checkout transactions, handle refunds, and contest fraud and chargebacks.
  • Hosting and infrastructure providers that store or transmit data on our behalf under contractual confidentiality and data-protection commitments.
  • Competent authorities, courts, or other parties, where we determine in good faith that disclosure is required by applicable law, legal process, or a binding governmental request.
  • Protection of rights: where disclosure is reasonably necessary, in our sole determination, to enforce the agreement set, to investigate fraud, abuse, leaking, tampering, or security incidents, or to protect the rights, property, or safety of AW AntiCheat, our Customers, or the public.
  • Business transfers: in connection with any merger, acquisition, financing, reorganization, or sale of all or part of our business or assets, in which case this Policy will continue to apply to the transferred data until amended in accordance with its terms.

Data delivered to a Customer's own Discord webhooks is a disclosure directed by the Customer, not by us, and is governed by the Customer's controllership as described above.

14.International Transfers

We may process and store data in jurisdictions other than the one in which you reside, including through hosting and infrastructure providers located in multiple countries. Data protection laws in those jurisdictions may differ from those of your own. Where applicable law imposes conditions on cross-border transfers of personal data, we take steps reasonably designed to satisfy them, including the transfer provisions of the data protection law of the Kingdom of Saudi Arabia to the extent applicable. By using the Service, Customers acknowledge that such transfers are necessary for the provision of the Service.

15.Your Rights and How to Exercise Them

Depending on your jurisdiction, you may have rights regarding your personal data, such as the right to access, correct, delete, or receive a copy of it, to object to or restrict certain processing, or to withdraw consent where consent is the basis. We honor such rights to the extent applicable law actually confers them on you.

All rights requests must be submitted exclusively through the Support (tickets) section inside the Panel dashboard, which is the only official contact channel for the Service. If your account is suspended, banned, or terminated, we will maintain access to the Support (tickets) section for the limited purpose of submitting verified privacy rights requests and dispute communications; such restricted access does not reinstate any other Service entitlement. We may take reasonable steps to verify your identity — including verification through your Discord-authenticated account — before acting on a request, and we may decline requests that are unverifiable, manifestly unfounded, excessive, or repetitive. We may retain data notwithstanding a deletion request where retention is permitted or required by law or is necessary for security, fraud prevention, prevention of ban or enforcement evasion, accounting, or the establishment or defense of legal claims, applying the criteria stated in the section "Data Retention".

If you are a Player seeking to exercise rights over data processed on a game server you played on, your request must be directed to the owner of that server, who is the controller of your data. We generally do not hold Player data, cannot identify Players independently, and will refer any Player request we receive to the relevant Customer where feasible.

16.Server Owners' Obligations to Their Players

Every Customer who deploys the Resource agrees, as a condition of the license and of this Policy, to comply with all data protection, privacy, and surveillance laws applicable to the Customer's operation of their game server, and in particular to:

  • Establish and document a lawful basis for all Player data processing performed by the Resource under the Customer's configuration.
  • Provide Players with a clear, accessible privacy notice describing the identifiers, hardware tokens, detection events, and ban records processed, before or at the time Players connect.
  • Expressly disclose the OCR screen layer to Players before enabling it, including that frames are captured and read locally on the Player's machine and that only a match / no-match flag is transmitted, and obtain any consent applicable law requires.
  • Handle all Player rights requests, complaints, and regulator inquiries relating to the Customer's server, and provide us reasonable cooperation where a request implicates the limited Player data we hold on the Customer's instructions.
  • Configure punishments, whitelists, bypass rules, webhooks, and optional modules responsibly and lawfully, and bear sole responsibility for their consequences for Players.

The Customer indemnifies and holds us harmless, as set out in the Terms of Service, against all claims, losses, penalties, and expenses arising from the Customer's servers, the Customer's treatment of Players, the Customer's configuration choices (including punishments, the OCR layer, and webhooks), or the Customer's breach of this Policy or the agreement set. Breach of this section is a material breach entitling us to suspend, revoke, or terminate licenses and access in our sole discretion, without refund.

17.Cookies

The Panel uses only essential cookies and equivalent storage strictly necessary to operate the Service — principally session cookies that keep you signed in after Discord OAuth authentication and protect the security of your session. We do not use advertising cookies, tracking cookies, or third-party analytics cookies of any kind. Because only essential cookies are used, no cookie-consent choice is offered; disabling essential cookies in your browser will prevent the Panel from functioning. If we ever introduce non-essential cookies, we will update this Policy first and obtain any consent applicable law requires.

18.Age Requirement

The Service is available only to persons who are at least 18 years of age or the age of majority in their jurisdiction, whichever is higher. We do not knowingly collect personal data from anyone below that threshold, and no one below it may create an account, make a purchase, or use the Panel. If we determine, in our sole discretion, that an account holder does not meet this requirement, we may terminate the account and delete associated data, subject to the retention provisions of this Policy. Age requirements for Players connecting to a Customer's game server are the Customer's responsibility as controller.

19.Changes to This Policy

We may amend this Policy at any time in our sole discretion. The "Last Updated" date above will reflect the current version. Posting the updated Policy in the Panel with a revised Last Updated date constitutes effective notice of the amendment; we will additionally endeavor to highlight material changes in the Panel, but any failure of such additional announcement does not affect the validity or effective date of an amendment. Your continued access to or use of the Service after a change becomes effective constitutes acceptance of the amended Policy; if you do not accept it, your sole remedy is to stop using the Service. Amendments to the other documents in the agreement set are governed by the terms of those documents.

20.General Provisions

Governing law and venue. This Policy and any dispute arising out of or relating to it are governed by the laws of the Kingdom of Saudi Arabia, without regard to conflict-of-laws rules. The competent courts of Riyadh, Kingdom of Saudi Arabia, have exclusive jurisdiction and venue over all such disputes. To the maximum extent enforceable under applicable law, all claims must be brought in an individual capacity only, and you waive any right to participate in a class action, collective action, or other representative proceeding. Where mandatory law of your habitual residence grants you the right to bring or defend proceedings there, or the protection of its consumer rules, nothing in this section deprives you of that right, and the remainder of this section continues to apply to the fullest extent permitted.

Limitation of liability. To the maximum extent permitted by law, our total aggregate liability arising out of or relating to this Policy or any data processing described in it is limited to the greater of (a) the amounts you paid to us in the twelve (12) months preceding the event giving rise to the claim and (b) the amount you paid for the license giving rise to the claim, and we shall not be liable for any indirect, incidental, special, or consequential damages, lost profits, lost data, or lost players or community damage, as further set out in the Terms of Service. Where such limitation is prohibited by mandatory applicable law, our liability is limited to the minimum extent that law permits.

Order of precedence. In the event of a conflict between this Policy and the Terms of Service or another document in the agreement set, the Terms of Service control, except that this Policy controls with respect to the collection, use, disclosure, and retention of personal data.

Severability; survival; entire agreement; no waiver; assignment. If any provision of this Policy is held unenforceable, it will be enforced to the maximum extent permissible and the remaining provisions will remain in full force. Provisions that by their nature should survive — including those on retention, security, disclosure, indemnity, limitation of liability, governing law, and enforcement — survive termination of your account or the Service. This Policy, together with the Terms of Service, the Refund & Billing Policy, the End User License Agreement, and the Acceptable Use Policy, constitutes the entire agreement regarding its subject matter. No failure or delay by us in exercising any right is a waiver of it. We may assign this Policy and our rights and obligations under it, in whole or in part, without notice or consent; you may not assign or transfer any rights under it, and any attempted assignment by you is void.

21.Contact

The only official channel for questions, privacy inquiries, rights requests, and any other communication regarding this Policy or the Service is the Support (tickets) section inside the Panel dashboard. If your account is suspended, banned, or terminated, we will maintain access to the Support (tickets) section for the limited purpose of submitting verified privacy rights requests and dispute communications; such restricted access does not reinstate any other Service entitlement. Communications sent through any other channel are not official, may not be received, and create no obligation on our part. Players who do not hold a Panel account should direct all inquiries to the owner of the game server they played on, who is the controller of their data.

The Terms of Service, Privacy Policy, Refund & Billing Policy, End User License Agreement, and Acceptable Use Policy form one agreement set — read them together. The English text is the governing version.

Questions about these policies? Open a support ticket from your dashboard — it is our only official contact channel.