Privacy & Data Protection

Your trust is important to us. Learn how we protect your personal information.

Encrypted

All passwords are bcrypt hashed

No Tracking

We don't sell or track your data

Your Control

Access, modify, or delete anytime

Data We Collect

Account Information

  • Username: Your chosen display name
  • Email Address: Used for account recovery and notifications (optional)
  • Password: Securely hashed using bcrypt encryption
  • Minecraft Username: Linked to your in-game identity (optional)

Usage Information

  • Posts and Comments: Your social posts, forum threads, and replies
  • Private Messages: Encrypted communications between users
  • Server Activity: Basic gameplay statistics and online status
  • Profile Data: Bio, avatar, and other voluntary profile information

How We Protect Your Data

Encryption

  • Passwords: Bcrypt hashed with salt rounds before storage
  • Transmission: HTTPS/TLS encryption for all data in transit
  • Database: Secure connections with encrypted credentials

Access Control

  • Role-Based Access: Strict permission system (User, Moderator, Admin)
  • Session Management: Secure tokens with automatic expiration
  • API Protection: Rate limiting and authentication for sensitive endpoints

Infrastructure Security

  • Environment Variables: Sensitive configuration stored securely
  • Input Validation: All user inputs are sanitized and validated
  • SQL Injection Prevention: Parameterized queries using Drizzle ORM
  • XSS Protection: Content sanitization and CSP headers

What We DON'T Do

Sell Your Data: Never to third parties
Share Without Consent: Your data stays private
Track Extensively: Only essential data
Store Payment Info: No financial data
Read Private Messages: Your DMs are private
Use Tracking Cookies: No behavioral profiling

Your Rights

Access: View all data we store about you
Modify: Update or correct your information anytime
Delete: Request complete account and data deletion
Export: Download your data in a portable format (coming soon)
Opt-Out: Disable optional features and data collection

Exercise Your Rights: Visit your profile settings to access, modify, or request deletion of your data.

Third-Party Services

We use minimal third-party services to enhance functionality:

Minecraft Server Status

  • Service: mcstatus.io API
  • Purpose: Real-time server status and player counts
  • Data Shared: Server IP addresses only (no personal data)

Authentication

  • Method: NextAuth.js (self-hosted)
  • Storage: Session data in our secure database
  • Control: Fully under our management

Compliance

We strive to comply with:

GDPR: General Data Protection Regulation (EU)
CCPA: California Consumer Privacy Act
COPPA: Children's Online Privacy Protection
OWASP: Security best practices

Questions About Your Privacy?

Have concerns or questions about your data or privacy? We're here to help.

Response Time: We aim to respond within 48 hours

Support: Contact us through our community channels

Transparency: We're committed to open communication

Last Updated: October 13, 2025

Your trust is important to us. We continuously work to improve our security measures.