Privacy Policy
Last updated: July 16, 2026
1. Overview
Sinkly (“we”, “us”) provides a staff console for Roblox communities. This policy explains what information the Sinkly Roblox OAuth 2.0 application collects when you choose to connect your Roblox account, how that information is used, and how it is stored.
2. Information we collect
When you authorize Sinkly via Roblox OAuth 2.0, Roblox returns the following to us based on the scopes you approve:
- Your Roblox user ID, username, and display name.
- Your Roblox profile URL and avatar image.
- An OAuth access token and refresh token issued by Roblox.
We do not receive your Roblox password. We do not access private messages, purchases, or payment information.
3. How we use it
- To confirm your Roblox identity inside the Sinkly console.
- To associate your Roblox profile with the community staff account you use.
- To let community owners verify staff identity across Roblox and Discord.
4. Storage and security
Roblox profile data and OAuth tokens are stored in our managed database with row-level security so that each record is only readable by the user it belongs to and by Sinkly server processes. Tokens are never exposed to the browser or to other users.
5. Sharing
We do not sell your data. We do not share Roblox profile data with third parties other than the infrastructure providers required to run Sinkly (hosting and database). We may disclose information if required by law.
6. Revoking access
You can disconnect Sinkly at any time from your Roblox account security settings, or by deleting your Sinkly account. Once revoked, the stored tokens are no longer usable and are removed from our database.
7. Children
Sinkly is a tool for community staff. It is not directed at children under 13. If you believe a child has connected their account, contact us and we will remove the record.
8. Contact
Questions about this policy: hello@sinkly.cc.
