Privacy Policy
This Privacy Policy explains how Xavier Studio handles information when you use our website, developer tools, account features, license services, and integrations with third-party platforms such as Roblox, Google, and Discord.
1. Information we process
Depending on the features you use, Xavier Studio may process account identifiers and profile information provided through authorized sign-in or OAuth flows.
- Roblox: Roblox user ID, username, display name, profile/avatar information, and the OAuth authorization state required to connect your account. The Xavier Roblox OAuth integration requests only openid profile for identity linking.
- Google: account identity information used for your Xavier Account, such as email address, display information, and profile image where provided by Google.
- Discord: Discord user ID, username/display name, avatar, and server-membership verification where you choose to use Discord verification.
- Xavier Studio records: product ownership, licenses, account links, tool settings, verification status, and security/access logs required to operate the service.
- Technical information: request metadata and limited diagnostic/security information used to prevent abuse and troubleshoot service failures.
2. Roblox credentials and developer keys
Xavier Studio does not accept your Roblox password or .ROBLOSECURITY cookie on Xavier servers as an account-linking method. Roblox account connections use Roblox's official OAuth flow.
The Xavier Spoofer tool may provide a local cookie field for authenticated Roblox asset operations. In that flow the .ROBLOSECURITY value is sent only to a localhost worker on the user's own device and is not transmitted to Xavier Studio, Railway, Discord, Supabase, or analytics. The Spoofer server rejects Roblox cookies and user Open Cloud API keys if they are accidentally submitted to its job API.
Some developer tools may allow a creator to provide a Roblox Open Cloud API key for an operation they explicitly request. For Xavier Spoofer, that key is client-local and is used by the localhost worker / desktop app. Other tools may have their own clearly described handling. Users remain responsible for the permissions and security of keys they create in Roblox Creator Dashboard.
3. Why we use information
We process information to authenticate Xavier Accounts, connect a user's Roblox identity, verify community membership where applicable, match existing product licenses, deliver developer tools and purchased/free assets, provide support, prevent abuse, maintain security, and comply with legitimate platform or legal requirements.
4. Lawful and authorized use
Xavier Studio tools are built for legitimate creator and developer workflows. They are not intended to bypass Roblox authentication, security controls, platform permissions, paid-content restrictions, or third-party ownership rights. Users must only upload, process, publish, or manage content and assets they own or are authorized to use.
5. Sharing of information
We do not sell personal information. Information may be processed by infrastructure and database providers that are necessary to operate Xavier Studio, and by third-party platforms such as Roblox, Google, or Discord when you intentionally use their integrations. We may also disclose information where required by applicable law or necessary to protect the service from abuse or fraud.
6. Data retention and account linking
Account and license records may be retained while needed to provide Xavier Studio services, maintain ownership history, prevent abuse, or satisfy legitimate operational requirements. Temporary OAuth state and verification data are kept only as long as needed for the relevant flow. You may disconnect your Roblox or Discord account from Xavier Studio where that option is available.
7. Security
We use HTTPS/TLS, official OAuth flows, server-side credential handling, access controls, and other reasonable safeguards appropriate for a developer platform. No online service can guarantee absolute security, so users should also protect their own third-party accounts, sessions, and developer keys.
8. Children's privacy
Xavier Studio does not knowingly use Roblox OAuth to collect more profile information than required for the service. Use of third-party services remains subject to their own age requirements and policies. If information is believed to have been provided inappropriately, a deletion request may be submitted through the Xavier Studio support channels.
9. Your choices and deletion requests
You may disconnect linked providers where supported, stop using Xavier Studio, or request review/deletion of personal account data through the support/contact methods published on the Xavier Studio website or official Xavier Studio community channels. Some limited records may be retained where reasonably necessary for fraud prevention, security, license history, or legal obligations.
10. Changes to this policy
We may update this Privacy Policy as Xavier Studio features or legal/platform requirements change. The latest version will remain published at https://www.xavierstudio.my.id/privacy with an updated effective date.
11. Contact
Questions about this policy, account data, or deletion requests can be submitted through the contact/support methods made available on xavierstudio.my.id and Xavier Studio's official community channels.