Privacy Policy
OMNISIGHT REPORT ("this site") collects only what is needed to confirm that you are entitled to read the member reports. Logging in happens through Discord OAuth or Patreon OAuth only, and no email address and no password is ever requested, collected or stored.
What we collect and store
- Discord login — your Discord account identifier, your Discord username, whether you hold one of the designated community roles, and when that was last checked.
- Patreon login — your Patreon account identifier, whether you hold an active paid tier pledge, when that was last checked, and a refresh token used to re-check that pledge over time. The refresh token is encrypted at rest (AES-256-GCM) and never stored in plain text. Payment details and pledge amounts are handled by Patreon and are not passed to this site.
- OAuth verification records — to prevent request forgery and session swapping, this site processes SHA-256 hashes of the OAuth state and an initiating-browser random value, the provider, the internal return path, and approval/use status as a ten-minute-valid record. The original random values are not stored in the database; expired records are pruned when later sign-ins begin.
- Account key — an internal key combining the login provider name and the account identifier, used only to tell accounts apart. It is never displayed and never used to contact you.
- Sessions — a session identifier, the times it was created, expires, was last seen and was revoked on logout, and the User-Agent string sent by your browser.
- Activity events — the event type and time (for example a page view), the path, the symbol and report identifier where applicable, the referrer, the session identifier, and the account identifier when you are logged in.
This site does not store IP addresses in its own database, although the hosting provider may keep its own access logs.
Why we use it
- To sign you in and keep your session active.
- To confirm eligibility — a designated Discord role, or an active paid Patreon tier — and to re-check it periodically so cancellations and removed roles take effect.
- To prevent abuse and to answer support requests.
- To measure which reports are read, so the service can be improved.
Cookies
- Session cookie — set with HttpOnly, Secure and SameSite=Lax. It carries a signed session identifier only, never personal data or a password.
- Temporary login cookies — a state value protecting against request forgery (CSRF), a random value binding completion to the initiating browser, and the internal path to return to after login. Authentication cookies use HttpOnly, Secure and SameSite=Lax and are cleared when login completes.
- Advertising cookies — this site may use Google AdSense to serve third-party ads. Third-party vendors, including Google, use cookies to serve ads based on prior visits. You may opt out of personalized advertising via Google Ads Settings.
Retention and deletion
- Every session record is given an expiry time when it is created; expired and logged-out sessions can no longer be used to read anything.
- The Patreon refresh token is kept for one purpose only: re-checking whether the pledge is still active.
- To have your account and its records deleted, write to the address below. After verifying the request we delete the account record and the stored refresh token.
- You can revoke the access you granted to Discord or Patreon at any time in each provider's own account settings.
Third parties
- Cloudflare — site hosting, serverless functions, and the member and session database.
- Discord — OAuth sign-in and community role checks.
- Patreon — OAuth sign-in and paid pledge checks.
- Google — AdSense advertising, where enabled.
We do not sell or otherwise share your information beyond the purposes above.
Contact
For access, correction or deletion requests, write to chominsh@gmail.com.