Legal

Privacy Policy

Privacy Policy for Martian Defense

This Privacy Policy explains what information Martian Defense collects, why we collect it, how long we keep it, and what rights you have over it. It covers our websites at martiandefense.org and join.martiandefense.org, including the capture-the-flag range that gates entry to our Discord community.

It does not cover information collected offline, or through channels other than these websites. Your activity inside the Discord server itself is also governed by Discord's Privacy Policy.

Summary

The main public site is a static website: we do not ask you to create an account, and we do not run advertising, advertising networks, or third-party ad trackers on it. The join site is different, because it is a gated range: when you sign in with Discord and attempt challenges, we record who did what, from which IP address, in order to run the range and stop abuse. We never record the text of a flag you submit.

The main site (martiandefense.org)

The main site is static content. Our hosting and CDN providers keep standard server logs of requests, which include IP address, browser type and user agent, referring page, and the date and time of the request. These logs are produced by the infrastructure that serves the site, are used for security and for understanding traffic levels, and are not used to build a profile of you. We do not run advertising networks and we do not sell personal information.

The join site and the CTF range (join.martiandefense.org)

The join site hosts a capture-the-flag range. Admission to our Discord community is earned by solving a challenge. Because that is an access-control system, it is monitored. When you use it we collect and record the following.

WhatWhenWhy
Your IP address, browser user agent, and the country your request appears to come fromEvery request to the range's API, whether or not you are signed inTo detect and block brute force, automated flag guessing, and other abuse, and to troubleshoot faults
Your Discord user id, username (your unique @handle), and display nameOnce you sign in with DiscordTo identify you to the range, add you to the server, and assign your roles. Both names are kept because a display name can be changed at any time, so it does not reliably identify an account
Your Discord OAuth access tokenOnce you sign in with DiscordRequired by Discord to add you to the server on your behalf. It is stored only inside an encrypted, HttpOnly cookie in your browser, and expires after 24 hours
Which challenge you attempted, whether the attempt was correct, and the time of the attemptEvery submissionTo operate and score the range, detect brute force, and confirm that challenges are solvable
Join, role-grant, and sign-in outcomes, including failures and the reason for themOn each such eventTo confirm admission worked and to diagnose failures

What we deliberately do not record: the text of any flag you submit. Only the challenge name and whether the answer was right or wrong are stored. We also never record your Discord password, which we never see, and we do not read your Discord messages. The OAuth permissions we request are limited to identify and guilds.join.

Cookies on the join site

The join site sets two cookies, both strictly necessary for sign-in to function, and neither used for advertising or cross-site tracking:

  • md_sess: your signed-in session, encrypted and HttpOnly, expiring after 24 hours.
  • md_oauth_state: a short-lived value that protects the sign-in flow against cross-site request forgery.

The range also stores your solved-challenge progress in your browser's local storage. That stays on your device and is never sent to us.

Where this information is held

Range events are written to our hosting provider's function logs and to a private channel in our Discord server. They are read through an operator view on the join site, which requires signing in with an approved Discord account. Access is granted two ways and two ways only: a short allowlist of named site administrators, and a single Discord role we designate for the site's operations team. Holding any other role in the Discord server, moderator included, grants no access: community moderators cannot see IP addresses or attempt history unless they are separately named or given that one designated role.

How long we keep it

Hosting and function logs are retained for the period set by our hosting provider, which is a matter of weeks, and then deleted automatically. Range event records in the private staff channel are retained for up to 12 months and then deleted, except where a specific record is being kept for an ongoing abuse or security investigation. Your membership and roles in the Discord server persist until you leave or are removed.

Lawful basis

Where the UK GDPR or EU GDPR applies, we rely on our legitimate interests in securing the range, preventing abuse of an access-control system, and operating the community. Where you sign in with Discord, we also rely on performing the service you asked for, namely admitting you to the server.

Sharing

We do not sell personal information, and we do not share it for advertising. Information is processed by the service providers that run the site on our behalf, namely our hosting and CDN providers and Discord. We may disclose information where we are legally required to, or where it is necessary to investigate abuse or protect the community.

Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive a copy in a portable form. California residents additionally have the right to know what is collected, to request deletion, and to not be discriminated against for exercising those rights; note that we do not sell personal information.

To exercise any of these, contact the moderators in the Discord community or use the contact routes on this site. We aim to respond within one month. Please tell us your Discord username or user id so we can find the right records.

Security

Flags are verified on the server and are never sent to your browser. Session data is encrypted with AES-256-GCM and carried in an HttpOnly, Secure cookie. Our credentials are held as secrets in our hosting provider's configuration and are never exposed to the browser. The range's API endpoints are rate limited at the network edge.

Children's information

Our sites are not directed at children. Martian Defense does not knowingly collect personal information from children under 13, and you must be at least 13, and old enough to use Discord in your country, to use the join site. If you believe a child has provided us with personal information, contact us and we will delete it promptly.

Third-party links

Our sites link to other services, including Discord, Medium, and GitHub. This policy does not apply to them, and we have no control over their practices. We encourage you to read the privacy policy of any third-party service you visit.

Changes to this policy

We may update this policy as the sites change. Material changes to what we collect on the join site will be reflected here. Continuing to use the sites after an update means you accept the revised policy.

Contact

Questions about this policy, or requests about your data, can be raised with the moderators in the Martian Defense Discord community or through the contact routes on martiandefense.org.