Server HostPlaceholder name

Server Host Privacy Policy

Last updated Oct 7, 2026

Draft. Not legal advice. A lawyer checks these pages before we take payments.

We know many of our players are kids, so we keep as little as we can. This page says exactly what we collect, why, how long we keep it, who else sees it, and how to get a copy or have it deleted.

The short version

  • We collect only what a feature needs.
  • We do not show personalized ads and we do not sell your information.
  • Our website counter uses no cookies and collects no personal details.
  • We never store chat. The one exception is a line a player reports.
  • You can download your data and delete your account.

Server Host is NOT AN OFFICIAL MINECRAFT PRODUCT and is not connected to Mojang or Microsoft.

Who this is about

  • Owners have an account. You must be 13 or older to make one (see the Terms of Service). We do not ask your age when you sign up, so we cannot check it. We do not knowingly collect personal details from children under 13. If you are a parent and think your child under 13 made an account, write to [privacy email] and we will delete it. [Open item for the lawyer: is this enough? See README.md.]
  • Players do not need an account. They join a server with their Minecraft account, and we keep only a little (below).
  • Parents: you can ask what we hold about your child, ask us to delete it, or tell us not to collect more. Write to [privacy email]. There is no special parents page: use the contact form or email.

What we collect, and why

Owners (account holders)

WhatWhyHow long
Email addressSign in, verify you, send account emailsUntil you delete your account
Password (kept only as a one-way scrambled hash)Sign inUntil you delete your account
Discord sign-in ID (if you sign in that way)Sign inUntil you delete your account
Two-factor secret (stored encrypted) and recovery codesSafer sign-in, if you turn it onUntil you turn it off or delete your account
Minecraft name and ID, if you link your Minecraft accountOwner powers in game, daily-login credits, getting back into your accountUntil you unlink or delete your account
A usernameShown to your team. It comes from your email or Discord, or you pick it. We do not ask for your real nameUntil you delete your account
Sessions and connected AIs (when last used)Let you see and end themUntil you end them or delete your account
When you accepted the Minecraft EULA for each serverRequired to start a serverAs long as the server exists
Credit balance, credit history (purchases, spends, earned credits, gift codes, admin grants) and purchase recordsRun credits, support, taxes and refund checks[to confirm, tax rules may need longer]
Days you played on the network, and invitesEarned credits (daily streaks, invite-a-friend)Until you delete your account
Your email choices (product news is off unless you turn it on)Send only what you asked forUntil you delete your account
Feedback you send in the panel (and, only if you agree, the server ID and recent errors with a bug report)Fix bugs and plan features[to confirm]
Device and network signals (for example IP address)Spot likely extra accounts or abuse, for a person to review. Never an automatic ban[to confirm]

Your servers

  • Your worlds, settings, plugins, files and snapshots, so we can run and back them up for you. If you delete a server, a last snapshot stays for 30 days in case you change your mind, and then it is gone.
  • Audit log: a record of actions taken through the panel and the AI connector (who or which AI, what, when, which server). Kept for 1 year.
  • Console logs: the raw server console. Kept for 14 days.
  • Chat is never stored by us. Your AI cannot read it unless you switch that on for a server.
  • Team members: if you invite people to help run a server, we keep their role and what they do in the audit log.
  • Archived servers: when a free server is unused for 30 days it moves to cold storage. We do not delete archived servers. See "Your choices" for what happens when you close your account.
  • Owners and player information: your server's players page shows you, for that one server, who is online, their playtime there, their punishments and your notes about them. There are no profiles that follow a player from one server to another.

Players (no account)

  • Minecraft ID (UUID) and name, which our proxy sees when you join. This is how Minecraft works, and we need it to let you in.
  • Network address (IP address): needed to connect you. [How long we keep it, if at all, is to confirm.]
  • Jump back in: the hub remembers your last few servers, by Minecraft ID only. No name history.
  • Votes: one vote per player per server per day. We keep the Minecraft ID and the day, nothing else.
  • Friends, parties and messages (hub only): we keep Minecraft IDs for friend lists, parties and blocks. Private messages go through the same chat filter as the hub chat, can be reported and blocked, and are for friends only unless you change that. We do not store the text of messages. [Open item for the lawyer: the lead chose to keep these hub features although they are a COPPA risk. See README.md.]
  • Hub chat is filtered (bad words, links, spam and personal details like phone numbers and addresses are blocked). We do not store it.
  • Reports: if you use /report or /report-server, we keep the reported line and its context so staff can look at it. This is the only chat we keep.
  • Hub moderation: if staff mute, kick or ban someone in the hub, we keep a record of it.
  • Cosmetics and tags that owners unlock are shown in our hub only.
  • Counts of where joins come from (our list, the hub, a direct address) are only totals. We do not follow individual players.

The AI help bot

  • If you ask the help bot a question on our website or docs, we send it to the bot. A visitor who is not signed in gets answers about the product and the docs. To diagnose a server you must sign in.
  • If you are signed in, the bot remembers your past chats, so it can help better next time. You can see and clear that memory in your account settings. It is deleted when you delete your account, and it is part of your data export. Chats of visitors who are not signed in are not remembered.
  • We limit how many questions each person and each network address can ask, to stop abuse.

Everyone who visits the website

  • Visitor counter: we run our own cookieless counter (Plausible or Umami) on our own machine. It counts page views and where visitors came from. No cookies, no personal details, and nothing is sent to an outside analytics company. That is why we do not show a cookie banner.
  • Server logs: our web servers keep short-lived technical logs (like IP address and the page asked for) to keep the site safe and fix problems. [How long, to confirm.]
  • Ads: a few public pages may show light ads. They are never personalized and never appear in the panel or in game. We ask the ad company to treat the site as child-directed so it does not use your interests. [Open item: how the ad company handles cookies and IP addresses needs a lawyer's check and may need an extra notice.]
  • Emails to us: if you write to us, we keep your message so we can answer you.

How our own team sees your data

Our staff have roles. Support staff can see servers and reports but not billing, and see email addresses partly hidden. Only admins see billing. An admin or support person can look at your panel as you to help you, and every use of that is logged. We also keep totals about how the service is doing (active servers, paying owners, revenue against costs, how many owners connect an AI). Those are totals, not data about one person.

Who else sees some of it

We use a few other companies to run Server Host. We share only what each one needs.

  • Discord: if you sign in with Discord, it tells us your Discord ID and a verified email. We also use a bot and webhooks to send you notices (for example crashes, approvals waiting, and reports) and for our community server. Discord has its own privacy policy.
  • Google: [if we add Google sign-in later, it will tell us your sign-in ID and email. Not offered yet.]
  • Resend: sends our emails (like verification and password resets). It sees your email address and the message.
  • OpenRouter and the AI model it uses (our help bot): when you ask the help bot a question, your message goes to OpenRouter and the model provider behind it. To help diagnose a problem it may also be given your server's status, recent logs and our docs. Those logs can contain player names. Please do not type secrets into the help bot. The help bot never changes your server. [Check OpenRouter's and the model provider's data and training settings before launch.]
  • Your own AI (for example Claude or ChatGPT): if you connect one, the answers our tools give it are shared with that AI company, under its terms and privacy policy, not ours. You choose which AI to connect, and you can cut it off any time.
  • Payment provider (later): [Tebex or Stripe, to be confirmed] handles your payment and acts as the seller. It sees your payment details and the details it needs for tax. We never see or keep your card number. If a parent pays for an owner under 16 through an "Ask a parent to buy" link, the provider deals with the parent. [Open item: which details it passes to us.]
  • Hosting, protection and storage companies: our website runs behind Cloudflare. Our machines, attack protection and backups (including cold storage) may be run by other companies that store data for us. [Names to be added, including the backup storage company.]
  • Authorities: we may share information if the law requires it, or to protect a child or stop serious harm. We tell you first when we are allowed to. See "Legal requests and child safety". If staff learn of apparent child sexual abuse material, we must report it and keep it as the law requires.

We do not sell your information, and we do not use it to show personalized ads.

Where your data lives

For now we only run machines in the USA. So your data is kept in the USA, including if you are in the EU or UK. We ask the companies that handle it for us to sign the standard EU contract terms for moving data, and we honour your requests to download or delete it. When we open a machine in Europe, EU owners' data will move there. [Open item for the lawyer.]

Cookies

We use only the cookies needed to keep you signed in and keep the site safe. Our visitor counter uses none. [Check the final list of cookies, including any set by ads or sign-in providers.]

Your choices

  • Download your data: in your account settings you can get an export of your account data in a readable file, and a one-click export of your worlds, configs and your own plugins. Our own closed plugins stay behind, but the data they hold for you is included in a readable form.
  • Fix your data: change your email and details in your settings.
  • See and cut off connections: your active sessions and connected AIs are in your settings.
  • Help bot memory: see and clear it in your account settings.
  • Email choices: product news is off unless you turn it on. Account, billing and security emails cannot be turned off, and server alerts only come by email if you choose that.
  • Delete your account: in your account settings. First your servers are archived. Then we remove the account data we do not need to keep, such as your email, sign-in details and settings. [Open item: archived worlds are kept in cold storage and are not deleted. If you want a world erased for good, tell us at [privacy email], and we will [handle it, to confirm].]
  • Players: you do not have an account with us. If you want your Minecraft ID removed from our votes, friends or hub lists, write to [privacy email].
  • Parents: you may ask to see, delete or stop collection of your child's information at any time.

If you are in the EU, UK or another place with more privacy rights (like access, correction, deletion, moving your data or objecting), those rights apply to you, and you can write to us to use them. [Open item for the lawyer: the legal basis for each use, a representative in the EU or UK if needed, and international data transfers.] People in California and some other US states have similar rights.

How we protect it

Passwords are stored as hashes. Two-factor secrets are stored encrypted. Servers run in separate boxes, and every login and file action is logged. Our AI connector uses narrow tools, labels untrusted text, never reveals secrets, and cannot read chat unless you turn that on. No system is perfectly safe, so tell us right away at [security email] if you find a problem.

Changes

If we change this policy in a way that matters, we will tell you on the site or by email before it starts. If we ever want to collect something new from children, we will ask a parent first where the law says we must.

Contact

[privacy email] or [mailing address].