Privacy & Data Protection
Your trust is important to us. Learn how we protect your personal information.
Encrypted
All passwords are bcrypt hashed
No Tracking
We don't sell or track your data
Your Control
Access, modify, or delete anytime
Data We Collect
Account Information
- •Username: Your chosen display name
- •Email Address: Used for account recovery and notifications (optional)
- •Password: Securely hashed using bcrypt encryption
- •Minecraft Username: Linked to your in-game identity (optional)
Usage Information
- •Posts and Comments: Your social posts, forum threads, and replies
- •Private Messages: Encrypted communications between users
- •Server Activity: Basic gameplay statistics and online status
- •Profile Data: Bio, avatar, and other voluntary profile information
How We Protect Your Data
Encryption
- ✓Passwords: Bcrypt hashed with salt rounds before storage
- ✓Transmission: HTTPS/TLS encryption for all data in transit
- ✓Database: Secure connections with encrypted credentials
Access Control
- ✓Role-Based Access: Strict permission system (User, Moderator, Admin)
- ✓Session Management: Secure tokens with automatic expiration
- ✓API Protection: Rate limiting and authentication for sensitive endpoints
Infrastructure Security
- ✓Environment Variables: Sensitive configuration stored securely
- ✓Input Validation: All user inputs are sanitized and validated
- ✓SQL Injection Prevention: Parameterized queries using Drizzle ORM
- ✓XSS Protection: Content sanitization and CSP headers
What We DON'T Do
✗Sell Your Data: Never to third parties
✗Share Without Consent: Your data stays private
✗Track Extensively: Only essential data
✗Store Payment Info: No financial data
✗Read Private Messages: Your DMs are private
✗Use Tracking Cookies: No behavioral profiling
Your Rights
✓Access: View all data we store about you
✓Modify: Update or correct your information anytime
✓Delete: Request complete account and data deletion
✓Export: Download your data in a portable format (coming soon)
✓Opt-Out: Disable optional features and data collection
Exercise Your Rights: Visit your profile settings to access, modify, or request deletion of your data.
Third-Party Services
We use minimal third-party services to enhance functionality:
Minecraft Server Status
- • Service: mcstatus.io API
- • Purpose: Real-time server status and player counts
- • Data Shared: Server IP addresses only (no personal data)
Authentication
- • Method: NextAuth.js (self-hosted)
- • Storage: Session data in our secure database
- • Control: Fully under our management
Compliance
We strive to comply with:
•GDPR: General Data Protection Regulation (EU)
•CCPA: California Consumer Privacy Act
•COPPA: Children's Online Privacy Protection
•OWASP: Security best practices
Questions About Your Privacy?
Have concerns or questions about your data or privacy? We're here to help.
• Response Time: We aim to respond within 48 hours
• Support: Contact us through our community channels
• Transparency: We're committed to open communication
Last Updated: October 13, 2025
Your trust is important to us. We continuously work to improve our security measures.