Skip to content

Legal

Privacy Policy

What we collect, why, how long we keep it, and how to get it deleted.

Effective 2026-09-15

The short version

We collect the minimum needed to run your servers and stop abuse. We do not sell your data, we do not run advertising, and we do not track you across other websites.

Our AI assistant runs on our own hardware. What you type into it is not sent to any third-party AI provider.

What we collect

When you hold an account we store:

  • Your email address, used to identify your account, verify it, reset your password, and send service notices.
  • A cryptographic hash of your password. We never store the password itself and cannot recover it.
  • The IP address you signed up from. We use this to enforce our one-account-per-connection limit and to investigate abuse.
  • A display name, if you provide one.
  • Your Discord user ID and email, if you choose to sign in with Discord. We do not read your messages or servers.
  • A Stripe customer identifier, if you subscribe to a paid plan.
  • Details of the servers you create: names, games, hostnames, plans and activity timestamps.

What we do not collect

  • Card numbers. Payments are handled entirely by Stripe; we never see or store them.
  • The contents of your game worlds, chat, or player data — beyond storing them so your server runs.
  • Advertising or cross-site tracking identifiers. We do not use third-party advertising or analytics trackers on the hosting site.

Why we are allowed to hold it

We process this data to perform our contract with you (running your servers and billing you), to comply with legal obligations, and for our legitimate interest in keeping the service secure and free of abuse.

Where we rely on consent — for example optional emails — you can withdraw it at any time.

Who we share it with

We use a small number of processors, and share only what each needs to do its job:

  • Stripe — payment processing and subscription management.
  • Cloudflare — DNS and protection of our public endpoints; it processes connection metadata including IP addresses.
  • Brevo — sending transactional email such as verification and password resets.
  • Discord — only if you choose to sign in with Discord.

Where your data lives

Account data and game server data are stored on hardware we own and operate in the United States. Our processors may handle data elsewhere under their own terms.

Our AI assistant runs locally on our own hardware. Your conversations with it are not sent to OpenAI, Anthropic, Google, or any other external model provider.

How long we keep it

  • Account records: while your account is open, and up to 90 days after closure.
  • Game server data: deleted when the server is deleted. Free servers may be removed after a prolonged period of inactivity.
  • Signup IP addresses: up to 12 months, for abuse prevention.
  • Billing records: as long as tax and accounting law requires, typically seven years.
  • Operational logs: typically 30 days.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, or restrict how we use it. Email [email protected] and we will respond within 30 days.

Depending on where you live you may have additional rights under the GDPR, the UK GDPR, or US state privacy laws such as the CCPA. We apply these rights to everyone rather than only where legally required.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Deleting your account deletes your servers and their contents. That cannot be undone.

Cookies

We use one essential cookie to keep you signed in, and a token to protect forms against cross-site request forgery. Both are necessary for the service to work and neither is used for tracking or advertising.

We do not use advertising or analytics cookies on the hosting site.

Children

The service is not directed at children under 13 and we do not knowingly collect their personal information. If you believe a child under 13 has given us data, contact us and we will delete it.

Security

Passwords are hashed with a modern memory-hard algorithm. Sessions are held server-side so they can be revoked. Traffic is encrypted in transit, and game servers are isolated from each other and from our internal network.

No system is perfectly secure. If you find a vulnerability, please report it to [email protected] and give us a reasonable chance to fix it before disclosing it publicly. We will not pursue legal action against good-faith security research.

Changes and contact

We will post changes here and, where they are material, email account holders.

Privacy questions and data requests: [email protected]

Questions? Email [email protected]. To report abuse on a server we host, email [email protected].