PUBLIC WEBSITE
The public site includes no advertising, analytics SDK, or tracking pixel. Your hosting provider may maintain access logs. External destinations have their own policies.
AUTHENTICATION
When configured, Discord handles identity sign-in through Supabase. The browser stores an authentication session needed to keep you signed in. Signing out removes the active local session. Cosmic does not collect your Discord password.
PORTAL RECORDS
The backend stores your user ID, display name, account access role, application answers, review feedback, and application workflow history. Supabase Auth may also hold profile or email information supplied by Discord. Do not enter passwords, payment details, or unnecessary real-world personal information into an application.
DISCORD APPLICATION REVIEWS
Submitted application answers, your display name, verified Discord user ID, application status, and staff feedback are shared with authorized reviewers in a private Cosmic Discord channel. Drafts are not sent to Discord. Staff can approve, deny, or request changes there; their feedback is visible to you in the portal. Discord stores a separate copy of the review message and attached answers. Withdrawing an application does not erase its history, and deleting database records does not automatically remove the Discord copy.
DEPARTMENT WORKSPACES
Internal departments store notices, roleplay employee names, ranks, call signs, divisions, and duty statuses. Each employee is linked to the verified Discord account used for the application, with a username and user ID visible to department members. Current Discord server roles determine access. Scheduled membership checks archive employees who leave the Discord server. Command members can edit this content, and changes keep an audit history identifying the editor. Archived entries remain stored and can be restored. Department records are separate from your profile export; contact the community team for assistance with them.
ACCESS, EXPORT & DELETION
Your profile page can export your profile and application records. Staff can review application data only through authorized backend access. Deletion is a staff-assisted request in this release, not an automatic deletion button. The owner must publish an accessible contact route and document record retention before launch.
NO HIDDEN PRIVATE FILES
Public HTML and repository files are not private storage. Member and staff resource content belongs in the access-controlled database. External documents and files must have their own appropriate access controls.
