Privacy Policy
Last Updated: September 25, 2026
This is the privacy contract for NAVCOM-ID, NAVCOM-Bot, and navcom.ai. It is written for people, not as pretend EU establishment text. We are a United States operator and we do not claim an EU establishment we do not have.
Who operates this
NAVCOM-ID, NAVCOM-Bot, and navcom.ai are operated by Wild Knight Squadron in the United States — the same operator named in the site footer and terms. This is a community project, not a Cloud Imperium Games product. We do not list a street address on this site; we will not invent one here.
Questions: use the public contact already on the site — Discord (the invite you get when you add the bot) or Buy me a coffee. Do not look for a helpdesk URL on this page; there is not one. For the SENTRY website, API, or Overlay, use the SENTRY Contact Us page.
What we store
- Discord id if you link Discord or sign in with Discord (plus Discord OAuth tokens we need to keep that link working).
- Email if you provide and verify one. Hashed password if you set one. Short-lived hashed email OTP codes.
- Account email is delivered through Mailgun.
- RSI handle and verification state when you complete bio proof (portal or Discord
/verify). - OAuth grants — which apps you allowed, which scopes, and issued tokens (hashed refresh material, not raw secrets in logs).
- Sessions so you can sign out or revoke devices under Account.
- TOTP / WebAuthn as hashes or public keys only. We never store authenticator seeds in the clear.
- Guild/bot configuration you set (roles, welcome, voice, action logs).
What we never store
- Phone numbers. No SMS. No phone verification.
- Government ID.
- Payment cards. Donations go through Buy Me a Coffee; we do not keep card numbers.
- Google or Twitch accounts. We do not offer those logins and we do not collect those identities.
We do not sell data. We do not run ad pixels or third-party analytics trackers on navcom.ai.
RSI data
RSI profile facts come from public RSI pages via SENTRY (player and org encyclopedia). Bio proof means you put a code on your public RSI profile so we can see you control that page. It is not Cloud Imperium game login and we never receive your RSI password.
Hidden or redacted org memberships are not in SENTRY public data and are not shared with Sign in with NAVCOM apps.
SENTRY Overlay and Game.log
If you sign in to the SENTRY Overlay with NAVCOM-ID, the Overlay forwards lines from your local Star Citizen Game.log to SENTRY (same operator) while Game.log tailing is running, together with your handle and Overlay version. This verbose log forwarding is currently on for all signed-in Overlay users. It is temporary: it will become an opt-in setting once Game.log parsing is satisfactory. Game.log can contain other players' handles, ship names, locations, and local file paths. SENTRY uses it to improve parsing and contact detection and to diagnose problems, and keeps it for up to 1 year. To stop it, sign out of the Overlay or turn off Game.log tailing. Details: https://sentry.wildknightsquadron.com/privacy.html
Email we send
navcom.ai sends account email through Mailgun, our email delivery provider: email verification, password reset, and one-time sign-in and email-link codes. Mailgun receives your email address and the message content in order to deliver it. navcom.ai has no public contact form. Developer support requests submitted at /developers/support are stored in the NAVCOM database. The SENTRY Contact Us form is covered by the SENTRY privacy policy (it also uses Mailgun).
OAuth / Sign in with NAVCOM
- Apps receive only consented scopes. Required scopes must be granted or login stops. Optional scopes can stay off.
- Discover (reverse Discord↔RSI lookup) is off by default. It only works if you turn it on under Account and the app holds both
rsianddiscord. - Discord ids never appear in tokens without the
discordscope and discover on for reverse lookup. - You can revoke apps, sessions, and RSI under Account. Download a ZIP of your account fields via Download my data (no hashed passwords, no live OAuth tokens).
How to request deletion
On Account you can revoke RSI, unlink Discord (when you have a verified email), revoke sessions, and revoke apps. For full account deletion, request it from Account (see the deletion note there) or via the same public Discord / contribute contact. Removing the bot from a Discord server deletes that server’s configuration.
Why no Google / why no phone
NAVCOM-ID is Discord + email + passkeys (headline) / TOTP. We do not collect phone numbers and we will not add SMS. We do not add Google or Twitch login. That is a product choice: fewer identity brokers, no phone graph, no bulk-access client credentials.
Children
NAVCOM is not for children under 13. We do not knowingly collect their data. If we did, tell us through the public contact above and we will delete it.
Changes
Updates land on this page with a new “Last Updated” date. The public URL is https://navcom.ai/privacy (the old /privacy-policy path still works).