Stormy Ac
← Back to home

Privacy Policy · Stormy Ac

Last updated: 7 October 2026

This translation is provided for convenience. The German version is legally binding.

Stormy Ac is a consent-based, read-only integrity scanner for FiveM servers. This page explains what data the scanner client collects, what it is used for, how long it is stored and what rights you have.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

Marian Kraus
Hainerweg 146
60599 Frankfurt am Main
Germany
Telephone: +49 163 3518898
Email: [email protected]

The provider identification under §5 DDG can be found in the legal notice.

2. Who this policy applies to

Stormy is operated from Germany. The General Data Protection Regulation (GDPR) therefore applies directly and in full to the processing, not merely as a voluntary commitment.

3. What the scanner collects

The scan only runs after explicit consent requested in the client. Before consent, the client shows the currently active checks, the destination address and this policy.

CategoryWhat exactly is collectedPurpose
Hardware/systemCPU, BIOS and drive serial numbers, number of network adaptersDetection of HWID spoofing tools
Processes & tasksNames of running processes, suspiciously named scheduled tasksDetection of known cheat and automation software
Game processSignature check of the DLLs loaded into GTA5/FiveM, a memory scan for known cheat signatures, the layout of the process memory in search of injected code, and translucent windows on top of the gameDetection of unsigned/tampered modules and active cheats in the game
FilesProgram files (EXE, DLL, ASI, SYS) in the FiveM folder, in Temp, in the Downloads folder and on the desktop: file names, hashes, size, compile time, signature and content, compared against the detection rules. Only files that match a rule or a search term are transmitted; the remaining contents of these folders never leave the computerDetection of known or suspiciously packed cheat files
Network tracesThe DNS cache, compared exclusively against known cheat and licensing services. Visited addresses are not transmitted, only matchesDetection of licensing services used to unlock cheats
Program memoryThe memory of Windows Explorer, of selected Windows services (DNS client, Diagnostic Policy Service, Program Compatibility Assistant) and of running web browsers (Chrome, Edge, Firefox, Opera, Brave, DuckDuckGo), compared only with search terms of known cheats and those of the server operator. Search terms with sexual content are not permitted. Only which cheat or search term matched is transmitted, never the memory content, the pages you visited or your browsing historyDetection of cheat shops, cheat downloads and launch traces of cheats that were deleted before the scan
System stateDriver signing settings (test signing, driver verification, kernel debugger, Secure Boot, memory integrity), the names of loaded kernel drivers and the state of the Windows services that record execution tracesDetection of the prerequisites for cheats with a kernel driver
Kernel driversThe registered kernel drivers and driver files (SYS) in Temp, Downloads, on the desktop and in AppData: Authenticode checksums, version information (original name, version) and signature, compared with Microsoft's list of vulnerable drivers, and whether Windows blocks these drivers. Only drivers on this list are transmitted, with path, name and signerDetection of vulnerable drivers through which cheats load their own code into the core of the system
Windows securityDefender status, the exclusions configured there (folders, file extensions, processes), the state of the firewall, tamper protection, User Account Control and SmartScreen, and the PowerShell execution policyDetection of disabled protection mechanisms
Event logsSelected entries from the period examined: cleared logs, newly installed services and drivers, changed start types of services, driver signatures rejected by Windows, drivers blocked by a Windows policy, changes to and detections by the antivirus. For each entry the time, event number, level, source, log, the program involved (file name only) and a short message, at most 400 entries; the server operator sees them in the dashboard. No complete logs are transmitted, and of PowerShell script blocks only the features, never the textDetection of cheat drivers and of traces removed afterwards
Firewall rulesThe stored rules and the hosts file. Only rules and entries are reported that cut the game or its protection system off from the network or redirect its servers, match a stored search term or concern a program in a volatile folder; the rest of the hosts file never leaves the computerDetection of rules intended to prevent findings from being reported
USB device historyVendor and product IDs of all USB devices ever connected, with timestamps. Storage sticks are only counted, unless one was unplugged in the hour before the scan: then its model name and the time are transmitted. Listed individually are input devices built from components that can move the mouse on their own and devices made to alter input, such as the Cronus ZenDetection of hardware that alters input before it reaches the game, and of devices unplugged shortly before the scan
Jump listsThe lists of recently opened files. Only paths that match a stored search term or concern deleted executables from Temp, Downloads or the desktop are transmitted. The rest of your file history is not transmittedDetection of cheats that were deleted after use
Traces of multiple identitiesWhether Discord, Steam, Rockstar Games and FiveM have left traces in several Windows profiles or on several drives of this computer, and how many Steam account IDs occur. Only counts are transmitted. User names, account names and account IDs never leave the computerIndication of a second account on the same device
Diagnostic dataThe Windows diagnostic database (DiagTrack), compared against the stored search terms. Only matches and programs used from volatile folders are transmitted, never the content of the databaseDetection of program launches whose other traces were removed
Traces of known cheatsWhether files and folders created by known cheats (such as configuration and login files) exist in specific locations, the key bindings in the FiveM configuration and the names of crashed programs from the Windows crash reports. Only matches are transmittedDetection of cheats by the traces they leave themselves
Input devices and macrosWhether the macro and profile files of the manufacturer software exist and when they were changed, as well as Lua scripts in Logitech G HUB. Of a script, only whether it moves the mouse by itself is transmitted, never its contentDetection of recoil macros
PowerShell recordsPowerShell script blocks recorded by Windows, compared against characteristics of triggerbots and evasion techniques. Only the characteristics are transmitted, never the script textDetection of triggerbots and deleted traces
PCI devicesThe list of PCI devices, including previously connected ones, checked for programmable chips and known DMA cardsDetection of hardware that reads game memory from outside
Running programsA snapshot with path, parent process, start time and signature. Of the command line, only which obfuscation characteristic occurred in it is transmitted, never its contentDetection of disguised programs and covertly started processes
Execution historyShimCache, Amcache, Prefetch, BAM and NTFS journal entries, entries of the Program Compatibility Assistant, launch records in the registry and in the memory of the Diagnostic Policy Service (DPS), the contents of the recycle bin and the recently opened files. Of these, only what matches a known signature or references a since-deleted file from your FiveM or Temp folder is transmitted. The rest of your PC's program history is not transmitted.Detection of cheats deleted before the scan
Antivirus logsThe logs of Microsoft Defender: cloud lookups for unknown files with their hashes, and the names of programs that were started, compared against the hashes and file names of known cheats. Only matches are transmitted, never the logsDetection of cheats whose other traces were removed
System informationCPU and GPU model, amount of RAM, Windows versionContext for support, no risk assessment
Steam IDYour locally signed-in Steam account (from Steam's own local configuration file, not via Steam's servers)Assignment of the report to your account
Discord IDOnly your Discord ID, your user name and the identifier of your profile picture, collected exclusively via the official Discord login on our website and never by reading local Discord data on your PC. The profile picture itself is not stored; your browser loads it from DiscordAssignment of the report to your Discord account

We deliberately do not collect: email addresses, passwords, message contents, browser history or files outside the folders named above.

This list is extended as further check modules go live. We update this page before a new module is activated.

4. Legal basis

The processing is based on two grounds (Art. 6(1) GDPR):

Without consent, no scan takes place. Without the confirmation being set, the scan cannot be started in the client.

5. Storage period

Scan reports are deleted automatically after 90 days. Manual deletion on request is possible at any time (see Contact).

6. Recipients

Data is transmitted exclusively to the server operator (customer) who requested the scan, to the hosting provider of the infrastructure on which the data is technically stored, and to Cloudflare, through whose network every connection to this website and to the server passes (section 11). It is not passed on for advertising purposes or to any other third parties.

If the server operator uses an Enterprise licence, up to six people work under one shared access. The administrator of this access sees the reports requested by the members of their team; the members do not see each other's reports. The circle of recipients thus remains limited to the customer, but includes several people on their side.

7. No automated decisions

Stormy itself makes no ban or sanction decisions. The scanner produces a technical report with a risk assessment; the decision on any measures is made exclusively by the server operator after a human review of the report.

8. Your rights

9. Contact

For questions or deletion requests: [email protected]. We reply within 14 working days.

10. Language selection on this website

If you choose a language on this website, your browser stores this choice locally (in localStorage, entry “stormy.sprache”). It is not transmitted to us and only serves to show you the site in your language again on your next visit. Without your own choice, the site appears in English. Storing it is necessary for the function you requested (§ 25(2) no. 2 TDDDG). You can delete the entry at any time in your browser settings.

11. Protection and delivery via Cloudflare

This website and the interface to which the scanner sends its report are delivered through the network of Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA). Every connection first passes through a Cloudflare server, which forwards it encrypted to our server. In doing so, Cloudflare processes your IP address, technical information about your browser or program (such as the user agent and language setting), the requested address and time, and the transmitted content, for example a scan report. The purpose is to defend against attacks and automated access, such as overload attacks, and to ensure secure, encrypted transmission.

Before a page is shown, Cloudflare may check whether the request comes from a human; for this you tick a box. Once the check is passed, Cloudflare sets the cookie “cf_clearance” so that you are not asked again on every visit. It is valid only for a limited time and serves this purpose alone. Storing it is necessary for the secure operation of the website (§ 25(2) no. 2 TDDDG). The scanner itself is not checked and receives no cookie.

The legal basis is our legitimate interest in a secure and available service (Art. 6(1)(f) GDPR). Cloudflare processes the data as our processor (Art. 28 GDPR). Data may also be processed outside the EU, in particular in the USA. Cloudflare is certified under the EU-U.S. Data Privacy Framework; the transfer is based on the European Commission's adequacy decision (Art. 45 GDPR) and additionally on standard contractual clauses (Art. 46(2)(c) GDPR). More information is available in Cloudflare's privacy policy.

12. Changes to this policy

We announce significant changes in advance (notice in the client consent screen and an update of the date above). We recommend checking this page again from time to time.