CLOTHING COURSE / PRIVACY
Private lessons.
Clear data rules.
Effective September 20, 2026 · Nitya Studios
How the protected course verifies students, records activity, and handles leak investigations.
Scope and access
This policy covers the private Nitya Clothing Course, its Discord sign-in, protected lessons, downloads, and access enforcement. It is separate from the main Studio and free-course policies. Access depends on a qualifying role in an approved Discord server and a verified email on your Discord account. Horizon Customs role holders must also submit a request and receive approval before lessons unlock.
Discord information
On sign-in, we receive your Discord user ID, username, verified email, and membership or role information needed to check access. We use an OAuth access token to verify membership; it is stored encrypted with your session. Discord processes sign-in under its own privacy policy. We do not receive your Discord password.
Horizon Customs access requests
If you request access through the Horizon Customs Discord command, we receive the email, payment method, proof or transaction reference, Roblox username when relevant, typed signature, submission time, and the reviewer’s decision and reason. Authorized course reviewers in the first server can see those details. A declined request may lead to an account, email, and known IP restriction; Discord itself does not give us your IP address, so only IPs observed when you visit the site can be blocked.
Sessions, devices, activity, and reviews
We record a session ID, sign-in and expiration times, terms acceptance, IP addresses observed during access, role-check times, lesson starts, asset requests, and attempts to unlock password-protected lessons. A long-lived security cookie assigns an opaque ID to a browser. We store its hashed token, general device label, a hash of the browser user-agent, first and last use times, recent IP, trust status, and reviewer information. The first browser may be trusted automatically; another browser may keep video access while asset downloads wait for staff approval. If an account changes from a recently trusted IP address, we may create a network review containing the Discord account, verified email, session ID, previous IP, new IP, and detection time. These records help enforce access, troubleshoot issues, and investigate unauthorized sharing.
What appears on videos
Each video displays a moving watermark with your Discord username and ID, verified email, session ID, full IP address observed by the site, and current viewing time. Anyone who sees a screenshot or recording may also see these details. Your IP can change between connections. The watermark is intended to deter sharing and help investigate a leak; it cannot stop screen recording or guarantee identification of every copy.
Bans and access restrictions
Access may be revoked for a Discord account or verified email, and known IP addresses associated with that account may be blocked. A restriction can remain in effect until an administrator lifts it, including indefinitely. The system may retain a case ID, reason, decision time, administrator, and affected identifiers to enforce and review the decision. A shared IP may affect another person; network-only visitors see a general notice rather than another student's account details.
Retention of records
Routine clothing-course session and access-event records are subject to a 30-day cleanup on successful sign-ins, so older records may remain longer if no cleanup runs. Active ban identifiers are kept while a ban is in force. Lifting a ban removes its stored identifier snapshot; the case record can remain for accountability. Other data may be retained where needed for security, disputes, or legal duties.
Security alerts and personalized downloads
Protected videos and files are served only after same-site access checks, sessions expire, and only one session remains active after a new sign-in. Role changes are rechecked periodically. Rapid lesson starts or asset downloads can create a staff security alert containing the account, session, trusted-device reference, IP, counts, and time. Downloaded assets receive a personalized filename containing the Discord identity and a unique trace ID; we store the trace ID, item, filename, session, device, IP, and time. Filenames can be changed and metadata can be removed, so tracing does not guarantee that every copy can be identified. Hourly limits may temporarily pause unusually high activity. These controls reduce casual sharing but cannot prevent screen recording, photography, or copying a permitted download. No online system is perfectly secure.
Requests and appeals
Email orders@nitya.xyz to request access, correction, or deletion of information we hold, or to appeal a restriction. Include your Discord ID and any case ID shown on the restriction page. We may verify identity and keep records required for security or law. Do not email your password.
Policy updates
We may update this policy when course tools, access controls, or legal requirements change. The date above identifies the version currently published.
Need to get in touch?
Email orders@nitya.xyz. For a course access decision, include your Discord ID and case ID if one is shown. Please do not send passwords or payment card details by email.