Last updated: [DATE]
Who we are#
Shard is a Roblox Studio plugin run by [OPERATOR NAME / ENTITY], [COUNTRY]. Contact: [CONTACT EMAIL].
Shard is not made by, or affiliated with, Roblox Corporation.
The short version#
- Your chats and API keys are saved on your computer, in Studio’s plugin settings.
- To answer you, Shard sends your messages through our server to the AI provider you choose.
- We do not store the text of your chats or your API keys on our server.
- We store your account, your usage counts, and usage and error events that help us fix bugs.
What stays on your computer#
Stored by Studio in the plugin’s settings on your device:
- your chats, including messages and the results of tools Shard ran (script text that Shard read is kept only for your current session and not saved with the chat);
- the API keys you enter;
- your settings (theme, model, provider and similar);
- your Shard sign-in session;
- a random install ID created on first use.
We cannot see this data. Uninstalling the plugin or clearing its settings removes it. [Check: Studio may keep plugin settings after uninstall; confirm and describe.]
What we receive and why#
1. Messages you send to the AI.#
Each request includes your conversation, the tool results the model needs (for example the text of a script it read, search results, Output logs), your model choice, and your API key if you use one. Our server adds Shard’s own instructions and tool list before forwarding it.
- We use it only to pass the request to the provider and return the answer.
- We do not store the conversation text or your API key.
- Your API key is forwarded to the provider you chose and is not saved on our server.
2. Account data (if you create an account).#
Username and/or email address, and your password. Passwords are handled by our authentication provider (Supabase Auth) and stored hashed, not in plain text. We also store your plan and your credit balance. Credits can’t be bought yet; for now only Shard can grant them.
- Accounts made with a username get an internal placeholder email; we never email it.
3. Network address (IP address).#
We store your IP address to:
- count guest usage (guests are counted per network);
- limit how many accounts can be created from one network (currently 2);
- rate-limit requests to protect the service.
4. Usage records.#
For each request we record counts such as messages and web searches or page reads used, for your account or (for guests) your IP address. For signed-in users we keep a per-chat usage summary: token counts, model, provider and cost. It contains no message text. For Shard hosted models we record token usage and cost to bill credits.
5. Usage and error events (diagnostics).#
The plugin sends events such as: plugin opened, chat created or sent, tool started or finished, provider or model selected, setting changed, sign-in attempted, update shown, and errors. Each event can include: install ID, session ID, plugin and Studio version, your account ID if signed in, chat, run and request IDs, provider, model, tool name, outcome, duration, HTTP status and error codes. Error events can include an error message and stack trace, filtered to remove keys, tokens, email addresses and file paths before storage and cut to a fixed length. They can still contain names of scripts or objects in your place. Events do not include your message text, script source or API keys. Our server also logs each request it handles (function name, status, timing, error code, IDs above). [There is currently no setting to turn diagnostics off. Decide whether to add one before launch; some laws may require it.]
6. Feedback.#
When you send a message with Contact us in Settings, we store your message, its category, your Roblox user ID and Roblox username, your Shard account ID if you are signed in, your install ID, session ID and plugin version.
7. Polls and notices.#
When you answer an in-plugin poll we store your choices and any comment. When you close an in-plugin notice we store that you closed it. Both also store your name: the name you set in Settings, or otherwise your Roblox username. These are linked to your account, or to your IP address if you are a guest.
8. Connected accounts (Codex and Claude Code).#
- Codex (ChatGPT): you sign in to OpenAI with a device code. Your OpenAI login session is kept in a separate worker for your account on a relay server run by Shard.
- Claude Code: you paste a token created by
claude setup-token. We store the token on the relay server run by Shard so it can make requests for you. - You can disconnect at any time in Settings. Disconnecting Claude Code deletes the stored token from the relay. Disconnecting Codex signs out of OpenAI, stops your worker and deletes its saved login.
Who we share data with#
We only share data needed to run Shard:
- The AI provider you choose (for example OpenAI, Anthropic, Google, xAI, Groq, OpenRouter, Amazon Bedrock, Z.AI, Moonshot, Meta, or the provider behind a Shard hosted model). They receive your request and handle it under their own terms and privacy policy.
- Web lookups: when Shard browses the web, the search terms and page addresses are sent to Firecrawl, and docs lookups go to Roblox’s documentation site.
- Supabase, which hosts our server, database and sign-in. [Region: fill in.]
- Relay hosting for Codex and Claude Code. Requests reach the relay through Cloudflare Tunnel, so they pass through Cloudflare. [Name the relay host machine or provider.]
We do not sell your data. We do not use it for advertising. [Confirm: we do not use conversations to train models. Shard never stores them, but the chosen provider’s own policy applies.]
How long we keep data#
- Account data: until you ask us to delete your account.
- Usage counts and summaries: [PERIOD].
- Diagnostics and request logs: [PERIOD].
- IP-based records: [PERIOD]. Note: the account-per-network count is currently kept without an end date.
- Feedback and poll answers: [PERIOD].
Your choices and rights#
- Use Shard as a guest to avoid creating an account.
- Use your own API key if you prefer your provider’s terms.
- Disconnect Codex or Claude Code in Settings.
- Ask us to access, correct or delete your data: [CONTACT EMAIL]. There is no delete-account button in the plugin yet; we handle it by request.
- [Add jurisdiction-specific rights (GDPR, UK GDPR, CCPA) after legal review.]
Children#
Roblox Studio can be used by people under 18. [Decide the minimum age and parental-consent approach with legal counsel. Consider COPPA and similar laws, since email addresses and IP addresses are collected.]
Security#
Connections to our server use HTTPS. Server-only data is not readable with the public app key. Test code that Shard runs in Studio is sandboxed from your login and API keys. No system is perfectly secure.
Changes#
We will post changes here and update the date above. For important changes we will also tell you in the plugin.
For a plain-words walkthrough of what goes where, see Privacy and data in the docs. See also the Terms draft.