Legal

Privacy Policy

Effective 2026-07-13

This policy explains what Pico's Task Force ("PTF") collects through picostaskforce.org and the org's Discord bot, why, and who can see it. It is written for the people it actually affects: org members who sign in to the terminal with Discord. The short honest summary is that this is a hobby site run by volunteers - we collect what the org needs to function, we show it to fellow members by design, and we do not sell or advertise with any of it.

1. What we collect

Discord account. Signing in uses Discord OAuth. We store your Discord ID, username, display name, avatar, the email address on your Discord account, and your roles in the PTF server (which drive rank and permissions).

RSI identity. If you verify your RSI handle through the bot, we store the handle and public details from your RSI profile (citizen record, moniker, main org, enlistment date).

Sign-in and security records. Sign-ins, sign-outs, and permission checks are logged with your IP address and browser user-agent. Active sessions store the same. Your accept/decline decision on the site terms is recorded the same way. These are audit records that let us investigate anything odd.

Site analytics. Page views are counted using a random first-party visitor cookie. Our server receives your IP address, browser information, the page visited, and the referring page. To estimate rough geography (city, region, country, ISP) we send the IP over an encrypted connection to ipwho.is; a hashed form of the IP is then used only as the key in our own local geolocation cache. Selected analytics events - approximate location, page, device, and, if you are signed in, your Discord identity, but not your raw IP - may be shown to authorized officers in a restricted Discord channel. There are no third-party analytics scripts, no ad networks, and no cross-site tracking.

Org service records. The terminal exists to keep these: operation signups and attendance, awards, commendations, promotions and nominations, in-game treasury contributions and related ledgers, your callsign, your ship list and wishlists, and reports you write or appear in.

Problem reports.When you send a problem report from the terminal, it includes what you typed, any screenshot you choose to attach, plus technical context captured automatically in your browser: recent JavaScript errors, failed requests to this site (addresses only, never contents), the pages you moved between, your browser and screen size, and the site version. You can review exactly what is attached under "Technical details" before sending. Reports never include cookies, login tokens, form contents, or anything you typed outside the report itself. The technical context and any screenshot are deleted 90 days after your report is resolved; the report text itself is kept as part of the site's maintenance history.

2. The Discord bot

The org's Discord bot operates inside the PTF server and shares a database with this site. Within the server it processes and logs member activity: messages and reactions in org channels, voice channel presence, and interactions with the bot itself. In specific voice channels where its listening feature is enabled, speech is transcribed on our server so the bot can detect its wake phrase ("hey pico"); the bot posts a visible notice in the channel when it starts listening. Only speech aimed at the bot (a wake match) is stored - ordinary voice chat is transcribed in memory to check for the wake phrase and then discarded. This happens in the org's own server, under rules set by org leadership.

3. AI-assisted features

Some features send text to a third-party AI provider (Anthropic) for processing: polishing report drafts, generating operation follow-ups, and the bot's chat and voice responses. Treat those features like any third-party service - do not put sensitive personal information into report drafts or bot conversations.

4. Cookies

  • Session cookie - keeps you signed in after Discord OAuth. Removed on sign-out.
  • Visitor cookie (ptf_vid) - a random first-party identifier used only for the site's own visit counting.

These are the persistent first-party cookies we set. Discord OAuth may also use short-lived cookies needed to complete sign-in securely. We use no advertising or cross-site tracking cookies.

5. How we use it

  • Running the terminal: sign-in, rank-based permissions, and the org records above.
  • Recognition: attendance, awards, promotions, and contribution history are the point of the system.
  • Security: audit logs and session records to spot abuse.
  • Understanding site traffic with our own analytics.

6. Who can see it

The terminal is a shared org record, so fellow members see your service record by design: roster identity, attendance, honors, fleet, and treasury contributions. Some areas (audit logs, recruitment, command tools) are restricted to officers by rank-based permissions. Beyond the org, data lives with the infrastructure that hosts the site and database, and flows to the services named above - Discord, RSI's public site, Anthropic (AI processing), and ipwho.is (approximate geolocation) - only as described. We never sell personal data and run no advertising.

7. Retention

Org records are the org's history, so they are kept while you are a member and, as history, after you leave (a departed member still appears in past operation rosters and award records). Security logs and analytics are kept only as long as they are useful for their purpose.

8. Your choices

  • Ask leadership on Discord for a copy of what the org holds about you, or to correct it.
  • Ask for your personal data to be removed. We will honor it, with the caveat that shared org history (like an operation report that mentions you) may be anonymized rather than deleted.
  • Decline the site terms at sign-in - you will simply be signed out, and your Discord membership is unaffected.

9. Children

The site is not directed at children under 13, and Discord's own minimum age (and your country's, where higher) applies to signing in at all. Having a Discord account is not proof of age. If leadership learns that someone below the minimum age is using the terminal, we will remove or restrict their access and data.

10. Changes

When this policy or the Terms of Service change in a way that matters, the revision date above is updated and the terminal asks every member to accept the new version at their next sign-in.

11. Contact

Privacy questions and requests go to org leadership on the PTF Discord.

© 2026 Pico's Task ForceTermsPrivacyBeta v0.8.5.1

This is an unofficial Star Citizen fan site. Pico's Task Force is not affiliated with, endorsed by, or sponsored by the Cloud Imperium group of companies. All content on this site not authored by its host or users is property of its respective owners. Use of Star Citizen materials is in accordance with the Fankit and Fandom Policy and Fan Film and Machinima Policy.