Privacy Policy
Last updated 15 August 2026.
Two groups of people appear in our records: our customers, and the console players on their servers. This page separates them, because what we hold about each is very different.
The short version
- We hold your sign-in identity, your server’s address, and operational logs.
- About your players, we hold a gamertag and whether we let them in. Nothing else.
- No world data, no chat, no voice, no location, no gameplay.
- No analytics, no tracking, no advertising, no sale of data. Two cookies, both necessary.
Who is responsible
Helgi T. Johannsson, based in Iceland, is the controller for the data described below. Contact [email protected] about anything on this page.
What we collect, and why
If you are a customer
- Your sign-in identity — an email address, or a Discord or Google account id and display name. Needed to know whose dashboard to show you.
- Your password, if you use email sign-in. Stored only as a scrypt hash; we cannot read it.
- Your two-factor secret, if you enable it.
- Your server’s address, port and settings. Needed to provide the service.
- Operational records — status history, alerts, and sign-in times with the IP address used.
- Payment details. Handled by Paddle and never reaching our servers. We hold only the fact of payment and what it was for.
If you are a player on a customer’s server
- Your Xbox gamertag and XUID, when you add a join account we operate.
- Whether we friended you, and why not if we did not — for example “the account was full” or “on this server’s denylist”. This is what lets a server owner answer “why can’t my friend join?”.
We do not collect your Minecraft world data, your chat, your voice, your location, or anything about how you play.
Lawful basis
- Contract — to provide the service you have subscribed to.
- Legitimate interests — for security, fraud prevention, and keeping the service working. This covers the player records above, which are necessary for the service the server owner has asked for.
- Legal obligation — for accounting records.
How long we keep it
- Player decision history — 90 days, then deleted automatically.
- Current player state — until they stop following the join account, or the customer cancels.
- Customer accounts and server settings — while the account is active, and for 30 days after cancellation, then deleted.
- Operational logs — 30 days.
- Accounting records — 7 years, as Icelandic bookkeeping law requires.
- Backups — encrypted, retained 14 days, then deleted.
Who else processes it
- Hetzner Online GmbH (Germany) — hosting.
- Cloudflare, Inc. — DNS, TLS and traffic delivery.
- Microsoft / Xbox Live — unavoidably, because the service works by operating an Xbox account and interacting with Xbox Live.
- Discord, Inc. — if you sign in with Discord, or if your alerts are delivered to a Discord channel you choose.
- Google LLC — if you sign in with Google.
- Resend — delivery of account emails such as password resets.
- Paddle.com Market Ltd — payments. Paddle is the merchant of record, which means they are the seller on your statement and they account for the tax.
We do not sell personal data, and we do not use it for advertising.
Cookies
We set two cookies, both strictly necessary, so no consent banner is required:
cx_session— keeps you signed in. Signed, and readable only by the server.cx_csrf— prevents another site submitting forms as you.
We use no analytics, tracking or advertising cookies.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict how we use it, or to object to that use. Email [email protected] and we will respond within one month.
If you are a player rather than a customer: you can ask us to delete your gamertag from our records at any time, and you can remove the join account from your friends list yourself, which stops any further processing.
If you are unhappy with how we have handled your data you can complain to the Icelandic Data Protection Authority (Personuvernd) at personuvernd.is.
Where data is held
Our servers are in Germany. Some processors above are based in the United States, and those transfers rely on their standard contractual clauses or equivalent safeguards.
Security
Passwords are hashed with scrypt. Two-factor is available. Each customer’s Xbox credentials are isolated from every other customer’s at the operating-system level. Backups are encrypted with a key that is not stored on the server. Traffic is encrypted in transit.
No system is perfectly secure. If a breach affects you, we will tell you and Personuvernd as the law requires.