Privacy policy
What we collect, why we collect it, and what we do not do with it.
What we collect
Account data: your email address and a hashed password. Billing data: handled by Stripe; we store a customer reference and subscription status, never your card number. Server data: the worlds, configs and files you upload. Operational logs: connection and error logs needed to run and secure the platform, including the outbound connection log described below. That includes failed sign-in attempts: the address they came from and when. Too many from one address in a short time and that address is blocked from the control panel for an hour or so. It is how we stop somebody working through a list of stolen passwords against your account, and the record ages out with the rest of the web logs.
Outbound connections from your server
When your server opens a connection to the internet, we record the time, the destination address and port, and which of your servers it came from. We keep that for 14 days and then delete it.
We record that a connection happened, not what was sent. There is no interception of your traffic and no inspection of its contents; the connection is not decrypted, and we could not read it if we wanted to.
This exists so that when someone reports abuse coming from our network we can tell which server was responsible, instead of suspending the wrong customer or all of them. It is used for that and for keeping the platform running. It is not used for anything else, and it is not shared except where we are required to respond to a valid legal request or a specific abuse complaint.
What we do not do
We do not sell your data. We do not run third-party analytics or advertising trackers on this website. Nothing on this website loads from anyone else at all — no analytics, no advertising, no font or script CDN — so browsing it does not tell any other company that you were here. We do not read your server files, and nothing scans their contents — we look at them only if you ask us to for support, or if we are investigating a specific abuse report.
Why we process it
To provide the service you asked for, to take payment, to prevent abuse and to keep the platform secure. Where we rely on legitimate interests, meaning security and abuse prevention, you may object.
Who else touches your data
We use a small number of third parties to run the service, and only for that: OVHcloud, who provide the physical machine in Virginia that your server runs on, and therefore hold your data on their disks in their datacentre; Stripe for payments, which handles card details directly so we never hold them; Cloudflare, through which all traffic to this site and the control panel passes; and Resend to send account email such as password resets. Each sees only what it needs to do its job. We do not share your data with anyone else, and we do not sell it.
One more, and only in one place: the sign-in form on the control panel uses Google reCAPTCHA to tell a person apart from a script trying passwords. When that box is on screen your browser talks to Google and Google sees your IP address. It runs on the control panel login only — not on this website, and not once you are signed in. We would rather have it than not: without it, guessing passwords against our customers gets a great deal cheaper.
Where your data is stored
In the United States, in an OVHcloud datacentre in Virginia. Your server files, the database behind your account, and our backups all live there. We do not copy your data to other countries. If you are outside the US, that means your data is processed there — and if that matters for your situation, it is better that you know before signing up than after.
How long we keep it
Account and billing records are kept while your account is active and for as long as tax and accounting rules require afterwards. Outbound connection logs are kept for 14 days. Other operational logs are kept for a limited period and then rotated away.
Server data is deleted after the retention window following cancellation. Backups take longer: we keep encrypted copies so that a hardware failure does not lose your world, and a deleted server can persist in those until they age out — currently within a few weeks. Backups are encrypted before they leave our machine, and are never used for anything except restoring the service.
Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal data, and to complain to a supervisory authority. Ask via the contact page and we will respond.
Sub-processors
OVHcloud (hosting infrastructure, United States), Stripe (payments), Cloudflare (network and DNS), Resend (transactional email) and Google (reCAPTCHA on the control panel sign-in form only). Any further processors will be listed here before they are used.
Contact
Privacy questions go to our contact page.
Last updated: draft, unpublished.