Privacy Policy
Last updated: October 08, 2026 · Effective Version 2.4
01. Scope & Research Mandate
The Austronesian Localization System (operating at karyain.net) is an independent Natural Language Processing (NLP) research and fan-preservation initiative dedicated to delivering high-fidelity Austronesian language assets (Indonesian, Malay, Tagalog/Filipino) for interactive video game narratives.
We operate strictly under a non-commercial, non-profiling philosophy. We do not sell user data, do not display third-party advertisements, and do not monetize browsing behavior or personal telemetry.
02. Universal Patcher Desktop Application (Zero Telemetry)
The Austronesian Universal Patcher desktop executable (AustronesianPatcher.exe) is engineered with client-side isolation:
- 100% Offline Execution: Once the executable and your target
.karyainpackage are downloaded, the patching workflow executes entirely offline without requiring an active internet connection. - No Background Telemetry: The desktop client does not phone home, does not collect analytics on user hardware or playtime, and does not monitor keystrokes, background applications, or personal documents.
- Local In-Situ Processing: Game archives, binary injectors, dialogue strings, and automatic backups (
*.bakaryain) are created and stored exclusively on your local disk drive. No game files, source scripts, or modified data are transmitted over the network. - Diagnostic Logging: Technical diagnostic logs (
log-*.txt) generated during patching operations are saved locally beside the executable. These logs contain only local stream offsets, container fingerprints, and error codes to assist in user troubleshooting, and are never automatically transmitted.
03. Web Authentication & Supporter Verification
Access to public areas of our website (project catalog, progress trackers, community manual, request board) requires no account creation or personal data submission.
For administrative personnel and active community supporters accessing the VIP Lounge and Cloud Catalog, authentication is provided through Google OAuth 2.0 (including the OAuth 2.0 Device Authorization Grant flow for desktop sign-in):
- Collected Attributes: We collect only the user's primary Google account email address, display name, and unique Google account subject identifier.
- Purpose of Collection: The email address is cross-referenced in real-time against authorized administrator lists and verified public Trakteer supporter records to grant VIP access.
- Zero Password Storage: Authentication is handled entirely by Google Identity Services. We never view, request, or store your Google account password.
- Device Flow Token Security: For desktop patcher sign-in, user verification codes expire automatically after 15 minutes, and persistent tokens are stored in secure local configuration files.
04. Nintendo Switch & Console Data Boundaries
The platform explicitly disclaims the collection, storage, or transmission of console-specific cryptographic material:
- We do not collect or store Nintendo Switch system keys (
prod.keys,title.keys), certificates, device certificates, or console serial numbers. - The automated patcher feature for Nintendo Switch is currently not publicly available. Any manual experimentation requiring users to dump ROM contents operates exclusively on the user's own computer; no ROM dumps or extracted assets are uploaded to our servers.
05. Server Infrastructure & Security Logging
To defend against automated denial-of-service (DDoS) attacks, brute-force exploits, and unauthorized API abuse, our web hosting infrastructure and Cloudflare edge proxies record standard HTTP request headers:
- Client IP address and geographic country code (derived at the edge).
- Browser User-Agent header, referring URL, and requested URI path.
- Timestamp and HTTP response status code.
These server logs are retained in secure, access-restricted database tables solely for security diagnostics, rate-limiting, and error tracking, and are automatically pruned on a rolling schedule.
06. Cookies & Local Browser Storage
Our web portal uses minimal, strictly functional cookies:
PHPSESSID: Standard temporary session cookie for managing authenticated session state.karyain_premium_session: Encrypted, HMAC-SHA256 authenticated cookie for persistent 7-day VIP supporter login.chrono-theme/manual_lang: Local browser storage items preserving user theme (dark/light) and manual language (EN/ID) preferences.
07. User Rights & Data Deletion
You have the absolute right to control your personal information. You may at any time:
- Revoke Google OAuth account access via your Google Account Security Dashboard.
- Request the immediate removal of your supporter email address from our authentication database.
- Clear your browser cookies and local storage tokens to terminate all active sessions.
08. Contact & Governance
For questions regarding our privacy practices, requests for authentication data removal, or security disclosures, please reach out to the project maintainers via our community Discord or email contact provided on the community portal.