Privacy Notice
What we know, and why.
Last updated 20 August 2026
This Notice explains how the independent operators of NeverLose use personal data when you visit the website, sign in with Discord, redeem a licence, authorise Loader, save a cloud configuration or ask for support.
NeverLose is the controller for this processing. It is an independent two-person operation trading as NeverLose, not a registered limited company. Contact us at legal@soraa.lol.
1. Scope
This Notice covers the NeverLose website, account access, licence and device services, software delivery, cloud configurations and support. Discord, Roblox, payment services and other third-party platforms control their own processing under their own privacy notices.
2. Personal data we use
Discord and account data
When you sign in with Discord, we receive the basic profile information needed to link and display your account, such as your Discord user ID, username, display name and avatar. We do not receive your Discord password and do not request your Discord email.
Licence and entitlement data
We keep the licence identifier, product or plan, issue and activation information, expiry where applicable, current status and account association. This lets us provide purchased access and resolve support or payment questions.
Device, Loader and session data
We use a pseudonymous device identifier, application version, status and relevant timestamps to enforce the purchased device allowance and support authorised resets.
We also process short-lived sign-in and session records needed to authorise access, complete requested actions and protect accounts.
Network and security data
We process IP addresses and request or security metadata to protect the Service, investigate abuse and keep it available. Hosting and security providers may also process IP addresses, routing information, requested URLs, timestamps and similar request metadata.
Cloud configurations
If you choose cloud saving, we store the configuration name, protected settings and basic record information such as update time. Saved settings are protected at rest. You can delete individual saved configurations from the authenticated client.
Purchases and support
Purchase and support arrangements currently take place through Discord or the payment method identified before purchase. We may receive a transaction reference, amount, currency, payment state, purchased plan and correspondence needed to issue access or resolve a dispute. Do not send full card details, passwords or active sign-in credentials to us. The repository does not contain a card-processing integration, and we do not store full payment-card details on the NeverLose website.
3. Why we use personal data
| Purpose | Main data | UK lawful basis |
|---|---|---|
| Provide account access, licence and device management, software delivery and cloud configurations | Discord, account, licence, device, session and configuration data | Performance of our contract with you |
| Prevent fraud, licence sharing, attacks and unauthorised access | Account, device, network and security records | Our legitimate interests in operating and protecting the Service |
| Issue access, handle refunds, disputes and support | Licence, transaction reference and correspondence | Contract, legitimate interests and legal obligations |
| Comply with tax, accounting, court or regulatory requirements | Relevant transaction, account and correspondence records | Legal obligation and establishment or defence of legal claims |
We do not use your NeverLose account data for behavioural advertising and do not sell it. We do not currently use browser analytics or advertising trackers on the authored website.
4. Automated service rules
Routine service checks determine whether an account, licence and device are eligible to use a requested feature. A failed check can deny or pause access. These are service-security decisions, not profiling for advertising. Contact support if you believe a decision is wrong and a member of the team can review the relevant records.
6. Aggregated statistics
The homepage may show a rounded total of activated accounts. It is created from private account records and does not disclose names, account identifiers, device identifiers or individual activity.
7. International processing
Discord, Google and Cloudflare operate internationally, so personal data may be processed outside the UK or your home country. Where data protection law requires it, we rely on the provider’s contractual safeguards, recognised adequacy arrangements or another lawful transfer mechanism. Provider locations and subprocessors can change over time.
8. How long we keep data
- Temporary sign-in, activation and delivery records are kept only briefly and for as long as needed to complete the request, protect the Service and complete routine deletion.
- Session records are kept for the active session and for a reasonable security or audit period after expiry or revocation.
- Licence, account, Discord mapping and device records are kept while needed to provide purchased access, enforce device limits and maintain an audit trail.
- Cloud configurations remain until you delete them or the associated account data is removed, subject to backup and integrity requirements.
- Security, support and transaction records are kept for as long as reasonably necessary to prevent abuse, resolve disputes, meet tax/accounting duties and establish or defend legal claims.
Some records do not yet have an automatic age-based deletion rule. We use the purposes above to decide when they are no longer needed. We may keep a minimal suppression or transaction record after a deletion request where needed for security, fraud prevention or legal compliance.
9. Security
We use administrative and technical safeguards appropriate to the data and risks involved, and we restrict access to people who need it to operate the Service. No online system is completely secure, so keep your Discord account and device protected and contact us if you suspect unauthorised access.
10. Cookies and browser storage
We use necessary first-party cookies for sign-in and requested authenticated features. We do not currently use authored advertising or behavioural-analytics cookies. Details are in the Cookie Notice.
11. People under 18
The Service is intended only for people aged 18 or older. We do not ask for a date of birth through NeverLose and do not knowingly provide the Service to children. If you believe we hold data about somebody under 18, contact us so we can investigate and take appropriate action.
12. Your privacy rights
Depending on where you live and the reason for processing, you may have rights to access, correct, erase, restrict or receive a portable copy of personal data, and to object to processing based on legitimate interests. You may also complain to your local data-protection regulator.
Send a request to legal@soraa.lol from or with reasonable proof that the request relates to you. We may ask for limited additional information to verify identity. Deleting the identifiers required to authenticate a lifetime licence may make us unable to continue providing that access; we will explain the effect before completing the request.
UK users can raise a concern with the Information Commissioner’s Office at ico.org.uk. We would appreciate the opportunity to address the issue first.
13. Changes and contact
We may revise this Notice when the Service, providers or law changes. Material changes will be highlighted on the website or Discord where practical. Questions and privacy requests should be sent to legal@soraa.lol.