Privacy & data transparency

Your data.
No mystery.

This policy explains what Forward Operating Idiots ("FOI," "we," "us") collects through our website, Discord bot, Squad server tools, and connected services; why we use it; and the choices available to you.

01 — Scope

What this policy covers

This policy covers data handled by the FOI website, FOI Discord bots, FOI Squad server tracking, whitelist and progression systems, administrative tools, applications, and ban appeals. It does not replace the separate privacy policies of Steam, Discord, BattleMetrics, Cloudflare, Patreon, YouTube, X, or other services you choose to visit.

We never receive your Steam or Discord password. Steam authentication is handled by Steam. Discord linking requests only basic account identity. The temporary Discord authorization token used during linking is not stored in the FOI database.

02 — Data collected

Information we collect

Steam identity

SteamID64, display name, avatar, public profile URL, linked-account status, and login or profile-refresh timestamps.

Discord identity

Discord user ID, username or display name, server membership, roles, supporter or staff access, and account-link timestamps.

Progression & activity

Rank, XP and XP sources, chat XP totals, voice-channel duration, referrals, FOI join date, applications, rewards, and related audit history.

Squad & seeding

FOI server sessions, playtime, session timestamps, server player counts, seeding minutes, milestones, rewards, Steam Squad hours, and BattleMetrics player references.

Access & moderation

Whitelist entries and reasons, role-based access, Discord or Squad ban status, ban reason and expiration, staff actions, and administrative logs.

Information you submit

FOI applications, referral details, command or form inputs, ban-appeal type, email address, approximate ban date, appeal explanation, decisions, and staff notes.

Support tickets

Ticket category, owner Discord ID, opening and closing times, participating messages, attachments, embed text, and transcript history. Ticket transcripts are shown only to the ticket owner through the Steam account linked to that Discord ID and to authorized staff.

Discord activity

The bot processes events needed to operate the community, such as commands, role changes, message activity used for chat XP or moderation, voice-channel join and leave times, applications, referrals, and moderation events. FOI does not record Discord voice audio. Normal chat XP records are totals and timestamps, not a permanent copy of every ordinary message; however, content involved in moderation, edited/deleted-message logging, applications, tickets, appeals, or staff review may be retained in the relevant Discord channels or logs.

Technical information

Our web host, reverse proxy, and security provider may create routine request logs containing information such as IP address, requested URL, date and time, response status, referrer, and browser or device user-agent. We use this information for delivery, troubleshooting, security, and abuse prevention.

03 — Use

How we use information

  • Authenticate and link accounts so Steam, Discord, the website, and bot recognize the same player.
  • Operate community features including profiles, ranks, XP, leaderboards, supporter features, referrals, applications, achievements, and stat cards.
  • Track Squad and seeding activity and issue whitelist, seeding, rank, supporter, or staff access.
  • Moderate and protect FOI by checking bans, enforcing roles and permissions, investigating abuse, and keeping staff audit history.
  • Process applications and appeals, notify the appropriate staff channels, carry out approved actions, and email appeal decisions.
  • Maintain and improve reliability through troubleshooting, backups, performance monitoring, and security logs.

We do not sell or rent personal information, build advertising profiles, or use FOI data for third-party targeted advertising.

04 — Access & disclosure

Who can access information

  • You and other community members: profile, leaderboard, stat-card, role, or activity information may be visible where a feature is designed to share it.
  • Authorized FOI staff: Admins and Head Admins can access information required for member management, moderation, applications, appeals, whitelist administration, and audits. Access depends on current Discord roles.
  • Connected providers: information is exchanged as needed with Steam, Discord, BattleMetrics, website hosting and security infrastructure, and the configured email provider.
  • Safety or legal needs: information may be preserved or disclosed when reasonably necessary to protect FOI, users, systems, enforce rules, investigate fraud or abuse, or comply with a valid legal obligation.

Appeal details may be posted into restricted FOI staff Discord channels. Approved appeals may trigger automated Discord or BattleMetrics actions using the linked Discord ID or SteamID64.

05 — Cookies

Login cookie

The website uses one essential, signed session cookie named foi_site_session. It keeps you signed in after Steam authentication, is HTTP-only, Secure on the live website, uses SameSite=Lax, and expires after approximately eight hours. The associated session is held in server memory. Signing out clears the browser cookie and invalidates the current session.

FOI currently does not place separate advertising or behavioral-analytics cookies. Steam, Discord, Cloudflare, or sites reached through external links may process cookies under their own policies.

06 — Retention

How long information is kept

Retention depends on why the record exists:

  • Website login sessions normally expire after approximately eight hours.
  • Account links, progression, playtime, rewards, referrals, applications, and membership records are generally kept while needed to operate the community and preserve accurate history.
  • Inactive whitelist records may be removed from active output while a corresponding audit log is retained.
  • Appeal, moderation, ban, and administrative audit records may be retained after a case closes—or after an operational record is removed—to preserve accountability, prevent abuse, and document staff actions.
  • Backups and infrastructure logs may remain for a limited operational or security period before rotation or replacement.
  • Third-party services retain information according to their own policies.

FOI may retain specific information longer when reasonably necessary for safety, dispute resolution, rule enforcement, fraud prevention, or legal obligations.

07 — Your choices

Access, correction, and deletion

You may ask FOI staff to provide, correct, unlink, or delete information associated with your Steam or Discord identity. We will review requests in context and may need to verify that you control the account. Some moderation, security, appeal, transaction, backup, or audit records may be retained where deletion would compromise community safety, record integrity, or a legal obligation.

  • You can sign out to end the current website session.
  • Discord linking is optional, but Discord-specific bans, roles, supporter features, rewards, and appeals may not work without it.
  • You may disable seeding-reward direct messages where that preference is offered.
  • You can control information you provide directly by choosing whether to submit an application, appeal, referral, or optional command.
08 — Security

How information is protected

FOI uses safeguards intended to reduce unauthorized access, including encrypted HTTPS connections, signed HTTP-only session cookies, restricted administrative routes, live Discord-role permission checks, database access controls, and operational backups. No online system can guarantee absolute security, so members should also protect their Steam and Discord accounts with strong passwords and multi-factor authentication.

09 — Connected services

Third-party policies

Connected platforms process information under their own terms. Review their policies for details:

Following a Patreon, YouTube, X, Steam, Discord, or other external link leaves the FOI website and may allow that service to collect information under its own policy.

10 — Contact & updates

Questions or requests

For a privacy question or a request to access, correct, unlink, or delete FOI-held information, contact FOI staff through Discord and ask for a Head Admin. Please do not post sensitive details in a public channel; use a staff ticket or private staff-approved method.

Contact FOI staff

Policy changes

We may update this policy when website, bot, server, or legal requirements change. The effective date at the top will be updated when material changes are published.