Reverb Script Hub – Privacy Policy
Last updated: 27 July 2026
This Policy explains how Reverb collects and uses personal data through rbxreverb.com, key.rbxreverb.com, loader.rbxreverb.com, the Reverb loader, scripts, purchases and support (the “Service”). For UK data-protection purposes, Reverb is the controller of the information it decides to collect and use. A legal controller name and service address will be added when finalised. Contact: reverbsupport@proton.me.
1. Information collected
Store and purchase data: email address, customer and invoice identifiers, purchased product/variant, price, currency, payment status, delivery and refund information, and fraud or support records supplied through SellAuth and payment providers. Reverb does not receive full card details.
Key and security data: key identifiers and hashes, key tier, creation/activation/expiry dates, configured device allowance, device or installation identifiers converted into security hashes, Roblox account identifiers or hashes, validation attempts, device/account changes, security flags and administrative actions. Reverb does not need to store the plaintext value of device identifiers for validation analytics where a hash is sufficient.
Usage and analytics data: session and installation identifiers; Roblox user ID, username and display name; source/campaign; game, place and universe identifiers; hashed server identifier; selected script and version; loader version; executor and platform; Free or Premium tier; feature usage; timestamps, heartbeat/activity and diagnostic or error information.
Checkpoint and website data: Linkvertise or Work.ink provider, one-time completion-token hashes, checkpoint progress, issued-key references, essential cookies, cart/currency/affiliate preferences stored by the storefront, IP address, browser/device information and security logs normally generated by hosting and storefront providers.
Support and community data: information you send by email, SellAuth tickets or Discord, including identifiers and attachments you choose to provide.
2. Why information is used and lawful bases
Contract: to process purchases, deliver and activate keys, provide the purchased plan, validate access and provide support.
Legitimate interests: to operate and improve Reverb, understand reliability and feature usage, diagnose errors, measure traffic sources, secure keys, enforce device allowances, prevent sharing, fraud and abuse, and maintain necessary business records. Reverb balances these interests against user privacy and uses hashed identifiers where reasonably possible.
Legal obligation: to maintain records, respond to lawful requests and meet tax, accounting, consumer-protection and data-protection duties.
Consent: where consent is legally required, including optional non-essential cookies or marketing. Consent may be withdrawn without affecting earlier lawful processing.
3. How information is shared
Information may be processed by service providers needed to run Reverb, including SellAuth and payment providers for storefront, orders and payments; Supabase for database and key/analytics storage; Vercel and domain/security providers for hosting and delivery; Linkvertise and Work.ink for free-key checkpoints; Discord for optional community and support; and professional, regulatory or law-enforcement recipients where reasonably necessary or legally required.
Each independent service may process data under its own privacy terms. Reverb does not sell personal data. Data is not shared for unrelated third-party advertising by Reverb.
4. International transfers
Some providers may process information outside the United Kingdom. Where UK data-protection law applies, Reverb relies on an applicable adequacy regulation, contractual safeguards used by the provider, or another lawful transfer mechanism. You may contact Reverb for more information about relevant safeguards.
5. Retention
Reverb keeps information only for as long as reasonably needed for the purpose collected, including providing active or Lifetime access, security and fraud prevention, resolving disputes, enforcing device allowances and complying with legal obligations.
Expired free-key records are normally removed after a short operational period; the current key service is configured to remove qualifying expired keys after approximately seven days. Purchase, payment and tax records may be retained for the period required by applicable law. Analytics and security records are reviewed against their operational value and may be deleted or de-identified when no longer needed. Records connected to fraud, disputes, bans or legal claims may be retained for the applicable limitation period. Reverb will document and refine fixed retention schedules as the Service develops.
6. Cookies and local storage
The storefront and Reverb checkpoint pages use essential cookies or similar storage for sessions, security, carts, currency, affiliate attribution and checkpoint progress. Some preferences may be kept in local storage. Essential storage is used because the requested feature cannot work properly without it. Optional analytics or marketing storage will be used only with any consent required by law. Third-party checkpoint and payment pages have their own cookie practices.
7. Automated security decisions
Key validation automatically checks key status, expiry, device allowance and configured account/device rules. Access may be temporarily refused when those checks fail. Security flags may help identify possible sharing or fraud, but users may contact Reverb to request review of a decision affecting paid access.
8. Your rights
Depending on the processing and applicable law, you may have rights to access your personal data; correct inaccurate data; request deletion; restrict processing; object to processing based on legitimate interests; receive certain data in a portable format; withdraw consent; and request human review of a qualifying automated decision.
To make a request, email reverbsupport@proton.me and provide enough information to locate the relevant purchase, key or Roblox identity. Reverb may need to verify identity and may retain information where a legal exemption or overriding obligation applies. You may complain to the UK Information Commissioner’s Office at https://ico.org.uk/.
9. Children
The Service is not intended for children under 13. Users aged 13–17 should involve a parent or guardian, particularly for purchases and privacy requests. Reverb does not use loader analytics for behavioural advertising. If you believe information about a child under 13 has been collected, contact reverbsupport@proton.me.
10. Security
Reverb uses measures including restricted administrative access, server-side secrets, hashed key/device/account identifiers and encrypted storage where appropriate. No system can be guaranteed completely secure. Keep keys private and do not send passwords or full payment-card details to Reverb support.
11. Changes and contact
This Policy may be updated when the Service, providers or law changes. The current version and date will be published here. Material changes will be highlighted where reasonably practicable.
Operator/trading name: Reverb
Email: reverbsupport@proton.me
Discord support: https://discord.gg/xKh6WsgJem