Privacy
Plain-language overview for the default SKZLX Chat configuration.
Public content
Public-room messages, usernames, profile cosmetics, levels, message counts, account age and online/last-seen status are designed to be visible to other visitors.
Accounts
SKZLX ID does not require an email address in this build. Passwords are stored as salted password verifiers with a private server-side pepper, not as plaintext passwords.
Sessions
The service uses an HttpOnly secure session cookie so the browser can stay signed in. Password changes invalidate previous sessions.
Network abuse controls
The server can receive a visitor IP from the hosting network, but the default application does not store or show the raw IP. It stores a one-way secret HMAC network fingerprint for registration/login abuse controls and moderation correlation.
Moderation
Moderators can remove messages, mute/ban accounts and delete accounts. Actions are logged in a moderation audit table. Users may report public messages.
Backups
The site owner may create private database backups containing account, chat and moderation data. Those backups should be encrypted and must not be published.
Uploads
Custom image uploads are disabled by default. If the owner enables them, only small PNG/JPEG/WebP profile images are accepted.
This template is not legal advice. The site owner should adapt the privacy notice and age/community rules to the laws and audience that actually apply before a large public launch.