Modsmith · Legal
Privacy Policy
This Privacy Policy explains how Modsmith, the developer and operator of the Modsmith software and of modsmith.app (“Modsmith”, “we”, “us”), handles information when you visit the website at modsmith.app (the “Website”), use the Modsmith desktop software (the “Software”), hold an account (the “Account”) or use the paid assistant services (the “Services”; together with the Website, the Software and the Account, the “Products”). We are the controller of the personal data described here. Contact details are at the end.
The short version: the Software keeps your data on your computer. It sends something over the network only when you use a feature that needs to, and it says so. There is no telemetry, no analytics and no advertising, in the Software or on the Website. An Account and a subscription add the minimum we need to run them.
1. What stays on your computer
The Software keeps the following in its data folder under your Windows user profile (%LOCALAPPDATA%\Modsmith), or in a library folder you choose:
- your mod library: the unpacked mods themselves, and archives you downloaded;
- backups of the original game files it replaced, and the journal that describes how to put them back;
- versioned backups of game configuration files and plugin lists it has written;
- a local database with mods, versions, profiles, load order, notes and settings;
- native files held back from mods in quarantine;
- application logs;
- your Nexus Mods API key, encrypted with Windows DPAPI for your user account;
- if you sign in, your session with the identity provider, encrypted the same way.
None of this is uploaded, synchronised or backed up by us. Deleting the data folder removes it, including the backups that make a rollback of your game folder possible.
2. What leaves your computer, and when
The Software makes network requests only in the following cases. Each request goes directly from your computer to the service named.
Nexus Mods. When you connect a Nexus Mods account and download mods, the Software talks to the Nexus Mods API on your behalf using your own API key. What you download, when, and from which IP address is visible to Nexus Mods under their own privacy policy. Your API key is sent only to Nexus Mods, never to us.
Load-order sorting. When you sort, the Software downloads the community LOOT masterlist from its public repository on GitHub. Your mod list is not sent anywhere; sorting happens on your machine. The repository host sees ordinary requests for the file and its current branch.
Game stores. To find your game the Software reads local files and registry entries written by Steam, GOG or Epic. It does not contact those stores.
Application updates. At start-up and when you check for updates, the Software asks our release feed whether a newer version exists and, if you choose, downloads it. The request carries the version you run, your Windows architecture and the update channel, and nothing about your setup. The feed is served by our hosting provider, which sees the request as it would any web request.
Sign-in, account and subscription. When you sign in, your browser talks to the identity provider (section 4), and the Software then exchanges a one-time code for a session from your computer. While you stay signed in, the Software refreshes that session with the identity provider and, if you have a subscription, checks in with our service to confirm it and to record the device. Buying, changing or cancelling a subscription opens the payment partner’s pages in your browser (section 6).
Assistant requests. When you use a model-backed feature of the Services, the Software sends a request to our service (section 5). This happens only on your explicit action, after the Software has shown you what will be sent and you have agreed. It never happens in the background.
No other kind of request is made. In particular, the Software sends no telemetry, usage statistics, crash reports or diagnostics to us.
3. The Website
The Website is static. It sets no cookies of its own, runs no analytics and loads nothing from third-party domains. Downloads and the update feed are served from our own domain.
The Website and the release feed are hosted by Cloudflare, Inc. As with any web request, Cloudflare processes your IP address, user agent and the address requested in order to deliver the page and to protect against abuse, keeps short-lived logs for that purpose under its own privacy policy, and may set strictly necessary security cookies when its protection is triggered. We do not add tracking of our own to those logs.
If you email us, we keep the correspondence for as long as needed to handle your request and for our records.
4. Accounts
An Account is needed only for the Services. Everything else works without one.
Sign-in is provided by Supabase, Inc., our identity provider, which processes your email address, your sign-in credentials and any factors you enable, and session tokens. We never see or store your password.
On our side, we keep for an Account: an opaque account identifier, your email address, the creation date, the status and history of your subscription, the devices signed in (an identifier the Software generates and the last time each checked in), and usage counters for the current and past billing periods. Counters record how many operations of each kind were used, not their content.
You can delete your Account from the Software. Deletion removes your identity from our service and from the identity provider; records we must keep for accounting or legal reasons are retained for the period the law requires and then deleted.
5. Assistant requests and their content
When you use a model-backed feature, the Software builds the request from a fixed allowlist of fields and shows it to you. For a crash diagnosis it contains the logger type, the game version, the exception code, the faulting module, up to a fixed number of call-stack frames, the names and versions of loaded modules, and the names and load-order indices of your plugins. Other features send the data they need in the same way: mod names, plugin names, the text to translate, the description you typed. Requests do not contain file-system paths, your Windows account name, raw log text, your saves, your Nexus Mods key, or the contents of mods, except for text you deliberately submit.
The list of mods and plugins you use can say something about you. That is why these features are off by default, ask before the first request, and show the request body on demand.
Our service forwards the request to the model provider you chose or that the routing preset (role) you chose maps to. Providers currently include Anthropic, Google and OpenAI; the current list is shown in the Software. Each provider processes the request as our processor, under data-processing terms agreed with us. We choose providers whose terms do not permit training on our customers’ requests.
We keep the content of requests and responses for up to 30 days for abuse prevention, debugging, metering and quality review of the Services, then delete it. We may keep the result of a request in a cache keyed by a hash of its content, without your account identifier, so that an equivalent request from another user can be answered from the cache; cached results contain no more than the request and response themselves. We do not use request content to train models of our own.
6. Purchases
Subscriptions are sold through our payment partner, currently Xsolla, which acts as merchant of record and as an independent controller for the payment itself. The partner collects and processes your payment details, billing address, tax information and the amounts paid under its own privacy policy, and keeps the payment and tax records; we never receive your card number. From the partner we receive only what we need to activate and maintain the subscription: a transaction identifier, the plan and period purchased, the status and dates of the subscription and of any refund or dispute, and the email address used at checkout so that the purchase can be matched to your Account. We keep these records for as long as accounting and tax law require.
7. Logs
The Software writes logs in its data folder. Before anything is written, your home folder and Windows account name are replaced with placeholders, and query strings are removed from the URLs the log formatter recognises. Logs still contain drive letters, game folder names and mod names. They are never uploaded. If you send a log to us for support, that is your deliberate action, and we keep it only as long as needed to handle the request.
8. Why we process data, and on what basis
Where data-protection law requires a legal basis, we rely on:
- performance of a contract: providing the Software, the Account, the Services and purchases you request;
- legitimate interests: keeping the Products secure, preventing abuse and fraud, metering usage, improving the Services, and defending legal claims, balanced against your rights;
- consent: sending an assistant request, which you give in the Software and can withdraw there;
- legal obligation: keeping accounting and tax records and answering lawful requests.
9. Who receives data
We share personal data with our processors, each bound by contract to process it only on our instructions: Cloudflare (hosting and delivery), Supabase (identity) and the model providers (assistant requests); and with the payment partner, which processes your payment as an independent controller under its own policy. We may also disclose data when the law requires it, to protect our rights or the safety of others, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to the transferred data.
We do not sell personal data, and we do not share it for advertising. We make no decisions about you with legal or similarly significant effects by automated means alone; automatic rate limits and abuse filters on the Services only delay or refuse a request, and you can contact us about any of them. Organisations that use the Services can request a data processing agreement from us.
10. International transfers
Our processors operate in several countries, including the United States. Where data leaves the region in which you live, we rely on safeguards recognised by the applicable law, such as standard contractual clauses or an adequacy decision, as provided in our agreements with each processor.
11. Retention
- Data in the Software: on your computer, under your control, until you delete it.
- Account data: until you delete the Account, or until we close it for inactivity as the Terms of Service allow, then up to 30 days in backups, except records we must keep for accounting or legal reasons.
- Assistant request content: up to 30 days; cached results without identifiers, until the cache is rotated.
- Purchase records: for the period accounting and tax law requires.
- Support correspondence: for as long as needed to handle the request, and up to two years for our records.
- Hosting logs: short-lived, under Cloudflare’s retention.
12. Security
Secrets on your computer are encrypted with Windows DPAPI for your user account. Requests to our services and to third parties use HTTPS. Our services store the minimum described above, keep secrets out of logs, and are designed so that a breach of our side would not expose your Nexus Mods key, your files or your password, none of which we hold. No system is perfectly secure, and we cannot guarantee that unauthorised access will never occur; if a breach affects you, we will notify you as the law requires.
13. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to receive it in a portable format, to restrict or object to its processing, to withdraw consent, and to complain to a supervisory authority. Residents of California and of other states with similar laws have the right to know what personal information is collected and how it is used, to delete it, to correct it, and not to be discriminated against for exercising those rights; we do not sell or share personal information as those laws define it.
To exercise a right, email [email protected] from the address on your Account, or describe your request in enough detail for us to verify it. We answer within the time the applicable law allows, normally within 30 days. Most of what the Software holds is on your computer, where you can access and delete it directly; Account deletion is available in the Software.
14. Children
The Products are not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this policy
We may change this policy at any time. The current version is published on the Website with its version number and effective date; the Software records which version it showed you. Where a change materially affects how we use data we already hold about you, we will notify you in the Software or by email at least 14 days before it takes effect.
16. Contact
Privacy questions and requests: [email protected]. Other questions: [email protected].