What is collected
- Roblox user id - to bind your authorization to your sessions.
- Granted experience ids - the experiences you chose to authorize.
- An encrypted Roblox refresh token - stored using authenticated encryption; the key is held in the hosting provider's secret store.
- Operation records - what was created or updated, when, and whether it succeeded. Kept 30 days.
- A hashed installation id - to tell your Studio installs apart.
- Hashed session credentials - the plugin's access and refresh credentials for this service, stored only as hashes and never in a usable form. Refresh credentials rotate on every use, and expired credentials are removed during scheduled cleanup.
- Rate-limit counters - a request count keyed on your IP address when you start or complete a connection, used only to limit abuse. These records are retained for roughly 24 hours and then removed during scheduled cleanup.
What is never collected
- Your Roblox password. Authorization happens on Roblox, not here.
- Your place files, scripts, or game data.
- Analytics, advertising or third-party tracking of any kind.
Deleting your data
Disconnect in the plugin to end your sessions. Use Settings → Delete my data in the plugin, or email support@madebyrush.com, to remove the stored authorization and all operation records. You can also revoke this application at any time from your Roblox account settings.
Contact
support@madebyrush.com