Privacy Policy
Last updated: 29 August 2026 · Version 1.3
Read this before you run a scan. GORE PC Check is a forensic tool. It reads records that Windows keeps about programs that have run on the computer it is installed on. If you are being asked to run it by a server or gang administrator, you should understand exactly what it looks at and what is shared — that is what this page is for.
1. Who we are
GORE PC Check ("GORE", "we", "us") is software that helps FiveM and GTA community administrators verify whether a computer shows evidence of known game cheats. This policy covers the desktop application, the website at gore-software.com, and the backend service that supports them.
The data controller is gore-software. Our registered postal address is available on request — write to [email protected] and we will provide it. For any privacy question or data request, use the same address.
2. What the scan reads on your computer
When you run a scan, GORE examines records that Windows already keeps about program activity. How far back those records go is decided by Windows, not by GORE: some are rotated within weeks, while others — the NTFS master file table in particular — index the whole volume and can reach back to when it was formatted. GORE does not impose a time limit of its own. Specifically, it reads:
- Program execution records — the Windows Prefetch folder, the Background Activity Moderator (BAM), UserAssist, Amcache, ShimCache and MUICache. These record which programs ran, when, and how often.
- Resource-usage records — the SRUM database, which records which programs used CPU, disk and network time, and when.
- File system records — the USN change journal (the drive's own log of files created, renamed and deleted), and the file names, paths and timestamps under the folders where cheats are typically staged: Downloads, Desktop, Temp, ProgramData and the Recycle Bin. It reads those names and dates, not the contents of the files.
- The file system index (MFT) — the NTFS Master File Table, which is the drive's own index of file names, sizes and timestamps. GORE reads it to find traces of files that have been deleted, renamed or back-dated. It reads the index, not the contents of your files.
- Windows event logs and registry hives — GORE reads the system event logs and the registry to detect tampering: logs that were cleared, logging that was switched off, or security tooling that was disabled. Copies of these records are written to the scan folder on your own computer so a result can be re-checked; they are never uploaded, and you can delete that folder at any time.
- Live system state — currently running processes and loaded drivers.
- A hardware identifier ("HWID") — a value derived from your computer's hardware, used to lock a licence key to one machine.
What it does not do. GORE does not read the contents of your personal documents, photos, emails or messages, and it does not read your browser history or bookmarks. It does not log keystrokes, capture your screen, use your microphone or camera, or provide anyone with remote control of your computer. It does not run in the background — it runs only when you launch it and start a scan.
3. What actually leaves your computer
This is the most important section. The great majority of what the scan touches is analysed locally on your machine and never transmitted. Only a bounded summary is uploaded:
Flagged findings are encrypted on your computer before they are sent. They are sealed with end-to-end encryption addressed to the review team's keys, so our servers store material they cannot read. See how that works.
| Uploaded | Detail |
|---|---|
| Scan verdict | Whether cheats were found, plus counts: confirmed detections, items needing review, and the total number of artifacts examined. |
| Flagged findings | Up to 80 flagged items only. Each contains a confidence level, a category, the artifact source, the target (typically a file name or path), and a short detail string. |
| Whether the scan was complete | Scans run without administrator rights cannot read some records; this is flagged so a result is not misread as clean. |
| Your computer's name | The Windows machine name — for example DESKTOP-4F2K1A — so one member's report can be told apart from another's. Uploaded in readable form. |
| A behavioural risk score | A number and a band (low, elevated or high) summarising how the activity on the machine scored against patterns typical of cheat use. This is how an unknown cheat with no signature still gets noticed. Uploaded in readable form; a high band also flags your hardware identifier for the repeat-cheat detection described in section 4. |
| Proof the scan is genuine | A one-time challenge value issued by our server, and a signature computed over the counts above, so a result cannot be edited by hand between the scan and the upload. It describes nothing about your files. |
| A reference code per finding | One short, opaque code for each flagged item, so a reviewer can record a decision on an individual finding. The codes are derived on your computer under a secret our servers never receive, and reveal nothing about what the finding is. |
| Your identifiers | Your username/email, your gang (if any), your HWID, and the scan timestamp. |
Everything in that table except the flagged findings is stored in readable form, because the owner dashboard and our anti-fraud checks are built on it. All of it is cryptographically bound to the encrypted findings, so none of it can be altered afterwards — by us or by anyone else — without the findings failing to decrypt.
Items that are not flagged are never uploaded. If a program on your computer does not match a cheat signature, it is not sent anywhere and we never learn it exists.
Please note that a flagged finding may include a file name or file path, and a path can sometimes contain personal information (for example, a Windows username). We keep only what is needed to review a detection. Because these findings are end-to-end encrypted, that information is readable only by a reviewer holding a decryption key — not by our servers, our hosting provider, or anyone who obtained a copy of our database.
4. Account and payment data
- Account — your email address (or username) and a password. Passwords are never stored in readable form; they are salted and hashed with scrypt.
- Licence keys — the keys issued to you, the HWID each key is bound to, and their expiry or revocation status.
- Gang membership — your role (member, gang owner, or staff) and your gang name, where applicable.
- Payments — payments are processed by Stripe. Card details are entered on Stripe's own checkout page. We never see, handle or store your card number. We receive only a confirmation that a payment succeeded, plus the items purchased. See Stripe's privacy notice at stripe.com/privacy.
- Server logs — our backend records the time, method, path, response status and IP address of requests, for security, abuse prevention and debugging.
- Repeat-cheat detection (hardware reputation) — if a scan confirms a cheat, or shows a strong evidence-cleanup pattern, we record that the hardware identifier involved was flagged. If the same hardware later appears under a different account or community, our staff can see it was flagged before, to catch cheaters who make new accounts. This signal is visible only to GORE staff — community administrators never see another community's data — and a flag can be cleared. It is based on a hardware identifier, not on your name, browsing, or file contents.
5. Consent and legal basis
A scan must never be run on a computer without the informed consent of the person who uses it. If you are an administrator asking someone to run GORE, you are responsible for obtaining that consent and for pointing them to this page first. If you are being asked to run GORE and you do not consent, do not run it — the decision is yours, and the software will not scan on its own.
Where the UK/EU GDPR applies, we rely on the following legal bases: consent for running a scan and uploading its result; performance of a contract for operating your account and delivering licence keys you have paid for; and our legitimate interests in securing the service, preventing abuse, and improving cheat detection. You may withdraw consent at any time by ceasing to use the software and asking us to delete your data.
6. Who can see your data
- You — you see your own full scan result on your own machine.
- Your gang owner, if you redeemed a key they issued — they see your username, your scan status (no evidence found, needs review, awaiting review, cleared by review, cheats found, incomplete, or never scanned) and the date of your last scan. They see a licence key as "bound" or not; they do not receive your raw hardware identifier.
- GORE staff — our team reviews uploaded scan results in order to confirm or reject a detection and to improve the signature database. Access is limited to accounts with a staff role, and flagged findings can only be read by a reviewer whose device holds a registered decryption key. A staff account alone is not enough, and the server itself cannot decrypt them.
- Service providers — Stripe (payments) and our hosting provider (Railway), which stores the service's data on our behalf.
- Legal — we may disclose data if required by law.
We do not sell your personal data, and we do not use it for advertising or share it with data brokers.
Public listings. Some communities choose to publish a page showing which of their members have a clean scan. Only a display name, a status and a date appear there. Never any findings, paths, or hardware identifiers.
7. How long we keep data
- Scan results — only your most recent one. When a new scan is uploaded it replaces the previous one. We do not build a history of your scans.
- Account data — kept while your account exists, and deleted when the account is deleted.
- Licence keys — kept while valid, and afterwards only as needed for billing and fraud records.
- Sessions — sign-in tokens expire automatically after 30 days.
- Server logs — kept for a short operational period and then rotated out.
8. How we protect it
- Flagged findings are end-to-end encrypted. They are sealed on the member's computer and can be opened only on a reviewer's own device. Our servers, our hosting provider, and anyone who obtained a copy of our database hold ciphertext they have no key for. The scan verdict and counts are stored unencrypted so dashboards work, and are cryptographically bound to the encrypted findings — they cannot be altered without the encryption failing.
- All traffic to our service is encrypted with HTTPS/TLS.
- Passwords are salted and hashed with scrypt; they are never recoverable, even by us.
- Licence keys are locked to one machine and can be revoked by their issuer.
- Access to scan reviews is restricted to staff accounts; cross-account access is blocked at the API.
- The database is backed up on a rolling basis and written atomically to prevent corruption.
No system is perfectly secure. If we ever discover a breach affecting your personal data, we will notify affected users and any regulator we are legally required to inform.
9. Your rights
Depending on where you live (including the UK, EU/EEA, and California), you may have the right to:
- Ask what personal data we hold about you and receive a copy.
- Have inaccurate data corrected.
- Have your data deleted — including your account and your most recent scan result.
- Object to or restrict certain processing, and withdraw consent.
- Not be discriminated against for exercising these rights.
There is no self-service export or delete button in the app or on this site — every request is carried out by a person. To exercise any of these rights, email [email protected] from the address on your account, telling us which right you are exercising. We aim to respond within 30 days. If you are in the UK/EEA and are unhappy with our response, you may complain to your local data protection authority.
10. Age requirement
GORE is not intended for children. You must be at least 16 years old (or the minimum digital-consent age where you live, if higher) to create an account or run a scan. If we learn we have collected data from someone under that age, we will delete it.
10a. Regions we do not serve
GORE PC Check is not marketed or offered to people located in the European Economic Area, the United Kingdom or Switzerland. We do not target those regions. Where we can identify that a request comes from one of them, we refuse account creation, purchases, download-key redemption and scan uploads.
We want to be straight with you about what that check is worth: it relies on country information supplied by the network in front of our service, which is not always present, and which a VPN or proxy can defeat. It is a statement of who we offer the service to, not a technical guarantee that the service cannot be reached from those regions. If you reach us from one of them and we later determine that, we may close the account — and you keep the rights in section 9 either way.
Reading this site and signing in are never blocked. If you already hold an account and are in one of those regions, you can still sign in and reach it. Signing in is not itself an export tool, though: as set out in section 9, the product has no self-service export or delete function, and access, correction and erasure are all handled by hand. Write to [email protected] from the address on your account and we will action the request — including erasing your account and the scan result stored against it — and confirm to you when it is done. We will not cut you off from information you have a right to reach.
11. International transfers & changes
Our service providers may process data in countries outside your own, including the United States. Where required, transfers are covered by appropriate safeguards such as Standard Contractual Clauses.
If we make a material change to this policy we will update the date at the top and, where the change significantly affects you, give notice in the application or by email.
12. Contact
Privacy questions and data requests: [email protected]
General enquiries: [email protected]
See also the End User Licence Agreement, which governs your use of the software.