Skip to content
romsns.xyz Switch Archive

Legal

Privacy

What this host actually writes down when you browse, submit a form, comment, or rate a listing. The audience copy is written for a United States reader. There is no visitor account and no self-service export button.

Who operates this site

The public organization name in markup is romsns.xyz. The site-pack does not name a separate corporation, registered agent, or data-protection officer. This page therefore does not invent one. Copyright mail goes to the address printed on DMCA.

Ticket and issue forms

The ticket form stores the title name, optional Title ID, optional format (NSP, XCI, or either), optional notes, and the email you type. The issue form stores the listing URL or title, optional issue type, optional format, the “what failed” text, and the email you type.

Email is stored as submitted. It is not hashed. The connecting address is stored only as a SHA-256 hash so repeat floods can be limited (five accepted messages per form type per hour from one address). A hidden “website” field is a honeypot: if it is filled, the request is dropped and nothing is written.

Rows land in a site inquiry table when that table exists; otherwise they are written as JSON files on the application disk. There is no promised reply, no mailing list, and no automatic account from the address you leave.

Comments on game pages

When a game page shows a guest comment form, a submit stores the display name, email, and comment body, plus a hashed address used for rate limits. Guest comments wait for moderation. Email is not printed as a public byline. Empty or bot submissions (honeypot, instant submit) are discarded before a row is created.

Ratings and download counts

When a game page shows stars, a vote stores the score against that listing together with a hashed visitor cookie and a hashed address, so the same browser or address cannot keep stacking scores. The first-party cookie name is aic_eng. It is set when you vote, not because you opened this Privacy page.

A Get click can increment a download counter on that listing. Repeat increments from the same address are rate-limited. The counter is not a personal file history and is not tied to an account.

Cookies on ordinary page views

This host is a Laravel app. A first-party session cookie and an XSRF-TOKEN cookie are set so posted forms can be checked. They are not advertising pixels. Cloudflare (the edge in front of this origin) may also set its own cookies; those are the edge’s, not application features we configured as a marketing stack.

Visit script

The layout can print a first-party page-view script from /wp-content/themes/nsw/js/hit.js when a website id is set in the server environment. The cabinet hostname is never written into public HTML. Google Analytics and Google Tag Manager are not loaded.

On this response the website id is set, so that first-party script is included.

Server and edge logs

The web server and the CDN in front of this origin keep ordinary request logs (time, path, status, user agent, connecting address). This page does not invent a retention calendar or a deletion SLA for those logs. We do not sell lists of visitors.

What this page does not claim

  • No user registration, billing profile, or “do not sell” toggle exists on this host.
  • No automated GDPR / CCPA export or erasure portal is wired. Saying we “respond in 30 days” would be a process we did not build.
  • Search queries on /find/ are handled as ordinary requests. They are not turned into public profiles.

If you need a stored ticket, issue, or comment removed, write enough detail to find it: the email you used, the approximate day, and the listing URL. Use the issue form or the mailbox on DMCA. There is no promised turnaround.