Privacy policy draft.

A data overview for the development build. The final privacy policy will be published before launch.

Draft. This is not a finalized privacy policy. Operator details, contact information, retention periods and applicable rights still need to be established.

Local storage.

The plugin uses Studio’s plugin settings to save chats, preferences, provider API keys and sign-in session data on the device.

AI requests.

To answer a request, Shard processes relevant conversation and tool content through its infrastructure and the selected AI provider. Tool content can include script source, object information and Studio Output. API-key connections send the provider key with the request.

Connected-account and hosted-model routes can involve additional relay services. Local storage does not mean local-only processing.

Website account.

When you sign in on this website, your session is saved in your browser’s local storage until you sign out. If you connect a Roblox account, Shard saves your Roblox user ID, username and display name with your Shard account. Roblox access tokens are not kept after the connection is made.

Accounts and diagnostics.

The current backend includes account authentication, usage records and diagnostic events. Metadata and error-redaction mechanisms are present, but this draft does not make a universal no-retention promise.

Code execution.

RunCode executes model-written Luau at plugin identity in Studio. Its isolation measures do not make it a complete security boundary: code can access plugin GUI services, and background or external effects may persist.

Before launch.

The final policy must identify the operator, processors, purposes, retention, contact route and user rights. Those details are not finalized here.

Read the development data overview.