Legal
Privacy Policy
How Ocean Anti-Cheat collects, uses and protects your data.
Este texto legal é publicado apenas em inglês. A versão vinculante é o texto em inglês abaixo.
Last updated 02 Mar, 2026
DATA CONTROLLER
Ocean Anticheat
To provide our services effectively and maintain the integrity of our platform, we collect and process certain types of data. Our data collection is guided by principles of transparency, necessity, and security.
Represented by: Gaston Dallavalle
Angelo de Peredo 2673, Córdoba, Argentina
Email: contact@anticheat.ac
EU/EEA & UK GDPR Representatives (Article 27)
If you are located in the EU or UK and have questions or concerns regarding your personal data, you may contact our appointed GDPR representatives:
EU Representative
Euverify Ltd (Ireland)
Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland
UK Representative
Euverify Ltd (UK)
3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom
To submit a Data Subject Access Request (DSAR), data deletion request, or any other GDPR-related inquiry, please use our secure portal: https://gdpr.euverify.com/verify/c0e9c62b-0d75-4c0d-9146-df73801cfdb2
1 — COLLECTION
Types of Data we Collect
Account and Platform Data
User Registration Information
- Email address: used for account verification, required for communications, encrypted storage, retained for account duration.
- Discord ID: service integration, support communications, community features.
- Nametag: public identification, community interaction, user recognition.
Authentication Data
- IP Addresses: login security, fraud prevention, 90-day retention.
- User-Agent: browser identification, system compatibility, security verification.
Transaction Information
- Payment processing: payment-related data is processed securely through our Merchant of Record, Lemon Squeezy (https://www.lemonsqueezy.com/privacy). Secure transmission with no local financial data storage on our servers.
- Transaction records: purchase history, service activation, compliance records.
Third-Party Platform Data (Discord Tracking)
- Server Metadata & Activity: identifiers for servers categorized as cheating communities; join dates and “last seen” timestamps within these servers.
- User Roles: current roles and permission levels; historical logs of any role modifications.
- Message History: content, context, and timestamps of messages posted within tracked servers.
Anti-Cheat & Scan Data
- Historical Scan Records: dates, times, and specific parameters of previous scans; final detection outcomes and system telemetry.
- Centralized Database Access: query access for authorized customers; visibility of historical scan results across the Ocean Anticheat network.
Ocean Scanner Technical Data
- VPN Detection: connection analysis, security verification, temporary storage.
- Operating System: version information.
- Hardware Identifiers: device-specific hashes including CPU, GPU, and motherboard models for unique identification. Encrypted storage, access controls, data minimization.
- Process Analysis: Windows process and service initialization timestamps; specific process memory data for integrity verification; system startup execution records.
Game and Visual Data
- User account identifiers for scan history tracking.
- Active game process captures for integrity verification.
- Full-screen desktop screenshots: captured during scan initialization to visually verify the legitimacy of the scan, detect debugging or tampering attempts, and validate the integrity of the environment. This capture may include windows or content unrelated to the game, but is used solely for security and integrity verification purposes.
By accepting our Terms of Service and initiating the scan, you explicitly agree to this necessary data collection.
2 — USAGE
Data Usage and Processing
We process collected data for the following purposes:
- Service delivery and enhancement
- User experience optimization
- Security and anti-cheat system improvement
- Technical issue resolution
- Compliance with legal obligations
We maintain strict data sharing policies and do not share personal information with third parties except when required by law, necessary for service provision, or as part of a business transaction (with prior notification).
3 — RETENTION
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements.
Important: When you are banned from our services, data deletion is paused solely for the duration of the appeal period (21 days). Unless a legal dispute or chargeback is active, data will be automatically deleted after this timeframe.
4 — SECURITY
Data Security
We implement industry-standard security measures to protect your data, including encryption protocols, access controls, regular security assessments, and secure data storage systems.
Full-screen screenshots are never used for monitoring general user activity or unrelated personal content; they are processed only as needed to verify scan integrity and detect debugging, tampering, or evasion attempts.
5 — STORAGE
Data Storage Location & International Transfers
Our services operate from secure servers located in the United States and Argentina.
For EU/EEA/UK Users: We ensure your data is protected by implementing Standard Contractual Clauses (SCCs) approved by the European Commission, or by ensuring our third-party US hosting providers are certified under the EU-U.S. Data Privacy Framework.
6 — EXTERNAL LINKS
Links to Other Sites
Our service may contain links to external websites. We are not responsible for the privacy practices or content of these sites and encourage users to review their respective privacy policies.
7 — CHILDREN
Children's Privacy
The Service is primarily intended for users 18 years or older.
Global/US (COPPA)
Users between 13 and 17 years old may access the Service under strict conditions with verified parental consent. Users under 13 are strictly prohibited.
EU/EEA/UK (GDPR)
You must be at least 16 years old (or the applicable age of digital consent in your specific Member State) to use our Service. Accounts found to be in violation will be immediately terminated.
8 — YOUR RIGHTS
Your Privacy Rights
Whether you are protected by Argentine law, the GDPR, or the UK GDPR, we guarantee the following rights:
Access Rights
Request information about your stored data and obtain copies.
Data Control
Update, correct, or request deletion of your information.
Data Processing Transparency
Know how your data is being used and structured.
To exercise these rights, please use our Euverify DSAR portal linked at the top of this policy.
9 — LEGAL BASIS
Legal Basis for Processing
We process your data based on:
Performance of a Contract (Art. 6(1)(b) GDPR)
Account creation, scanner tool usage (including visual verification), and technical support.
Legitimate Interests (Art. 6(1)(f) GDPR)
Fraud prevention, service improvement, and security enhancement.
10 — INTERNATIONAL
International Data Protection
While operating under Argentine jurisdiction as the Data Controller, we strictly follow international privacy best practices (GDPR/UK GDPR), implement robust data protection measures, and provide transparent data handling policies.
11 — MEASURES
Data Protection Measures
To protect your data, we implement technical safeguards (end-to-end encryption, secure transmission, security audits) and organizational controls (access control policies, incident response procedures).
12 — BREACHES
Data Breach Procedures
In the event of a data breach, we will notify affected users promptly, investigate the incident thoroughly, take measures to prevent future occurrences, and comply with all applicable breach notification laws.
13 — PROVIDERS
Third-Party Service Providers
We work with trusted third-party providers for payment processing (Lemon Squeezy), analytics services, and cloud storage. All providers are contractually obligated to protect your data.
14 — TRANSFERS
Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your data may be transferred. We will notify you of any change in data controller or changes to the privacy policy.
15 — COPPA
COPPA Compliance
While we are based in Argentina, we respect the Children's Online Privacy Protection Act (COPPA): no collection of data from users under 13, and clear account termination if age violations are discovered.
16 — DISPUTES
Dispute Resolution
Any disputes regarding privacy will be handled according to Argentine law.
Consumer Exception: If you are a consumer residing in the EU, UK, or Switzerland, this governing law clause does not deprive you of the statutory consumer protections afforded to you by your country of residence.
17 — QUESTIONS
Additional Rights and Questions
For any additional privacy-related questions or to exercise your rights, please contact us via email at contact@anticheat.ac, use our support ticket system, or submit a formal GDPR request through our Euverify portal.
18 — SCANNER
Scanner Usage
Regarding security research and scanner usage: Authorized use cases, prohibited activities, and data collection boundaries are strictly defined to protect user privacy while maintaining gaming integrity.
19 — RESEARCH
Security Research Program
We value community contributions to our security. Our recognition program includes responsible disclosure processes, license rewards for verified vulnerabilities, and safe harbor conditions for permitted testing.
20 — IMPROVEMENTS
Service Improvements
We continuously improve our services through user feedback, security research contributions, and technical advancements.
21 — SUPPORT
Contact for Support
- Email: contact@anticheat.ac [Slow Support]
- Discord: https://discord.com/invite/oceanscanner [Fast Support]
By using our services, you acknowledge that you have read and understood this Privacy Policy and agree to our data practices.
22 — COMPARTILHAMENTO DE SCANS
Resumos de scans entre servidores
Quando o mesmo jogador é escaneado em mais de um servidor que usa o Ocean, a equipe com um plano pago pode ver um resumo mínimo dos scans desse jogador em outros servidores, para detectar máquinas limpas entre screenshares.
- O que é compartilhado: a data do scan, o resultado (legítimo, suspeito, cheating ou nenhum), o jogo e como os scans foram associados (HWID, conta do Discord ou HWID vinculado).
- O que nunca é compartilhado: o servidor, a Enterprise, o autor do scan, o PIN, as detecções ou qualquer outro conteúdo do scan. Isso vale também para scans marcados como públicos: os scans de outros servidores são sempre exibidos apenas como este resumo.
Os usuários podem desativar isso em Configurações, e os proprietários ou administradores de uma Enterprise, nas configurações da Enterprise. Quem desativa também deixa de ver os resumos de outros servidores.
Os jogadores escaneados que quiserem remover seus dados de scan podem entrar em contato conosco pelos canais listados em Contato para suporte; essas solicitações são tratadas manualmente.