Docs / Reference
Privacy and data
DRAFT FOR REVIEW. This page was written from the plugin and server code, not by a lawyer. It is not a privacy policy. Items marked TODO (owner) need a decision or a check before this goes live.
In short: your conversation and whatever Shard reads from your place go to the AI provider you picked. Shard’s server passes them along, and keeps usage metadata (who, when, which model, how many tokens, errors), not your messages or code.
What goes to the AI provider#
Every time Shard asks the model something, it sends:
- your messages and the conversation so far (or its summary, after compaction);
- what Shard’s tools returned during the chat: script source it read, object names and properties, Output lines, web results;
- Shard’s instructions and its list of tools.
Shard doesn’t upload your place. The model only sees what a tool read during the chat. Shard also doesn’t send your selection or open scripts unless it calls GetStudioState.
How it travels depends on the provider:
| Provider type | Path |
|---|---|
| Your own API key | Studio → Shard’s server → the provider (OpenAI, Anthropic, Google, etc.), using your key. |
| Codex / Claude Code | Studio → Shard’s server → Shard’s relay → OpenAI or Anthropic, using your connected account. |
| Shard-hosted | Studio → Shard’s server → the company that runs the model, using Shard’s own account. |
What the provider does with your data is covered by their terms and privacy policy.
What Shard’s server receives and keeps#
Shard’s server runs on Supabase. TODO (owner) name the hosting region.
Passed through, not stored (based on the code; TODO (owner) confirm that no server logs contain them):
- your messages, conversation and tool results;
- your API key for your own-key providers. It’s sent with every request so the server can call the provider, and it isn’t written to the database.
Stored:#
| What | Why | Details |
|---|---|---|
| Your account | Sign-in | Username, email, password (handled by Supabase Auth), plan, credit balance. |
| Usage counters | Limits | How many messages and web browses you’ve used in the current day and month. Guests are counted by IP address. |
| Request records | Billing, usage reports, debugging | For each request to a model: IDs for the request, chat and task; provider and model; plugin version; reasoning and prompt-caching settings; timing; result; error codes; token counts. The code states that “free-form errors, HTTP bodies/headers, tool arguments, code and model text are never recorded.” |
| Chat usage summaries | The Chat details → Usage tab | Token and cost totals per chat, for signed-in users. |
| Plugin diagnostics | Finding bugs | See below. |
| IP addresses | Abuse protection | Used for per-minute limits and guest limits. The IP used to create an account is stored with the account ID, to enforce the 2-accounts-per-network limit. |
| Support messages | Answering you | The text you send from Settings → Support, with your Roblox user ID and username, and random install and session IDs. |
| Poll answers | Feedback | Your choices, your comment, your display name (your Roblox name, unless you set another one), and your account ID (or, for guests, your IP address). Closing a notice is also recorded. |
TODO (owner) how long each of these is kept, and how to ask for deletion.
Plugin diagnostics#
The plugin collects events about how it’s used and sends them to Shard in batches, about every 5 minutes. Each event has:
- a random install ID (made on first run, not linked to your Roblox account) and a session ID;
- plugin and Studio version;
- the event name, like
chat.sent,tool.finished,theme.changedorapi_key.saved; - IDs for the chat and request, the provider, model and tool name, how long it took, the result, and error codes;
- for errors only: the error message and stack trace, scrubbed first. The plugin removes things that look like keys and tokens, emails, web-address queries and file paths before sending.
For api_key.saved, only whether saving worked is sent, never the key.
There is no setting to turn diagnostics off in this version. TODO (owner) decide whether to add an opt-out, and say so here.
Codex and Claude Code relay#
- Codex: you sign in on OpenAI’s own page. The resulting session is kept on Shard’s relay, in a private folder for your Shard account, so the relay can use it when you chat. Shard never sees your ChatGPT password.
- Claude Code: the token from
claude setup-tokenis sent to Shard’s server and saved on the relay, in a private folder for your Shard account. - Your conversation passes through the relay to OpenAI or Anthropic.
- Disconnect in Settings → AI removes the connection.
TODO (owner) say where the relay runs, how tokens and sessions are protected at rest, and how long relay sessions are kept.
Web browsing#
- RobloxDocs lookups go from Shard’s server to Roblox’s documentation site.
- Search and Scrape go from Shard’s server to Firecrawl, a web search and scraping service. Your search words or the page address are sent to them.
What stays on your computer#
Studio keeps these in Shard’s plugin settings on your computer:
- your chats (messages, tool results, agent reports). Script sources that Shard read are not saved, only kept while Studio is open;
- your API keys and settings (provider, model, theme);
- your sign-in tokens;
- diagnostics that haven’t been sent yet.
Log Out removes your sign-in from this computer. Your chats and API keys stay. To remove a chat, delete it from the sidebar. TODO (owner) explain how to remove saved API keys (there is no “remove key” button; you can only replace one).
Roblox#
Shard reads your Roblox user ID and username from Studio, to show your name and avatar, and to attach them to support messages.
The formal privacy policy draft is on the Privacy page, and the terms draft on the Terms page.