VFX Loom is a plugin for Roblox Studio. This policy describes the data the VFX Loom licensing service processes in order to verify that a Roblox account is entitled to use VFX Loom.

VFX Loom is an independent project. It is not affiliated with, endorsed by, or operated by Roblox Corporation.

When you start or complete a paid purchase, VFX Loom systems may process and store the purchase reference, selected product/price reference, Checkout and payment references, payment/refund/dispute state, currency and amount, webhook event records, and the link between the purchase and the verified Roblox account. For a gift, the service also stores a gift reference, a hash of the Gift Link token, its state and expiry, and the recipient Roblox User ID after redemption. The plaintext Gift Link is not stored in D1. These records are used to create, reconcile, fulfil, refund or revoke the paid licensing state and to keep an auditable purchase history.

Stripe independently processes payment details, including card details, under its own privacy terms. VFX Loom receives the payment lifecycle information needed to fulfil the purchase and handle refunds or disputes; VFX Loom does not receive or store your full card number.

What VFX Loom processes

The licensing service may process and store:

  • Your numeric Roblox User ID.
  • Your entitlement state (whether paid or separately authorized access is currently active or revoked) and its revision number.
  • Activation metadata — when an activation was started, whether it succeeded, failed, expired or was consumed, and when it expires.
  • Hashed activation credential identifiers. The credential itself is not stored; only a hash of its identifier is.
  • Session metadata — issue time, expiry time, last-used time, and revocation state, if revoked.
  • Hashed session identifiers. Session identifiers are not stored in a readable form.
  • The plugin version reported by the client.
  • Timestamps for issue, expiry and last use.
  • Coarse licensing and security events — an event type, an optional user ID, an optional hashed session identifier, a plugin version, a timestamp and a result code.

Optional administrative fields may also be recorded for a separately authorized account, such as a Roblox username or an internal note, where these were provided when access was granted.

Optional Discord linking

If you choose to connect Discord from your VFX Loom account page, VFX Loom may store your numeric Discord user ID, an optional display identity, link and unlink timestamps, and role-sync status such as the last attempt and result. This is used only to synchronize the three VFX Loom server roles on Discord. Discord is an external platform with its own terms and privacy policy. VFX Loom does not store Discord OAuth or bot credentials in the licensing database.

Roblox account verification (OAuth)

VFX Loom uses Roblox OAuth only to verify which Roblox account you are.

  • The verified Roblox account is used to derive your numeric Roblox User ID.
  • Roblox OAuth access, refresh and ID tokens are used during verification and are not retained afterwards.
  • OAuth tokens are never exposed to the Roblox Studio plugin.
  • The authorization flow uses PKCE. The PKCE verifier is stored encrypted for the duration of the activation and is not retained beyond it.

What VFX Loom does not collect

VFX Loom does not collect, transmit or store:

  • Your Roblox password or any Roblox account credentials.
  • Your project files, graph contents, node parameters or presets.
  • Texture pixels, generated VFX, or exported assets.
  • Game or place source code.
  • Hardware identifiers or device fingerprints.
  • Roblox profile data unrelated to identifying your account.
  • Browsing history.

Everything you build in VFX Loom stays in your Studio session and your place.

Why this data is processed

The data above is used solely to:

  • Verify that your Roblox account has a valid VFX Loom entitlement.
  • Create, refresh and expire activations and sessions.
  • Revoke access where an entitlement is revoked.
  • Detect and limit abuse of the licensing service, including rate limiting.
  • Operate paid and separately authorized access.
  • Process and reconcile paid purchases, Checkout returns, refunds, disputes and paid licensing state.
  • If you opt in, synchronize convenience roles on an external Discord server.

The data is not used for advertising, profiling, or analytics, and it is not sold. This website contains no tracking scripts and sets no analytics cookies.

Infrastructure

The licensing service runs on Cloudflare infrastructure (Cloudflare Workers and Cloudflare D1). Cloudflare processes requests on the service’s behalf as its infrastructure provider. This website is served as static files by the configured Cloudflare deployment.

Retention

  • Entitlement records are retained for as long as the entitlement exists, including after revocation, so that revoked access stays revoked.
  • Activation transactions are short-lived and expire as part of the activation flow.
  • Activation credentials expire according to their lifecycle — currently 30 days by default — and are invalidated when the entitlement revision changes.
  • Sessions expire at their recorded expiry time, and are invalidated on revocation or on an entitlement revision change.
  • Coarse licensing and security events are retained for approximately 30 days where event pruning is implemented.
  • Purchase, payment-lifecycle, licensing-handoff and webhook correlation records are retained as needed to fulfil purchases, reconcile provider events, apply refund/dispute transitions and maintain an auditable access history.

Your choices

If you do not want the licensing service to process the data described above, do not purchase or activate VFX Loom.

If you would like your entitlement revoked and your associated account record removed, contact us using the details below. Note that some records may be retained where they are necessary to keep a revocation effective or to prevent abuse.

Changes to this policy

This policy will be updated when the licensing implementation changes. The “Last updated” date at the top of this page reflects the most recent revision.

Contact

For privacy questions or entitlement removal requests, email privacy@vfxloom.com.