Privacy Policy

Last Updated: August 30, 2026

Website accounts and Leaves — updated 30 August 2026

Website sign-in and staff permissions now use the CraftCorps account service at login.craftcorps.net. We retain old website profiles, content and references and link a profile only after ownership is verified through its old password or unique connected Discord identity. A matching name or email alone is not proof.

For migration, we retain an eligible old bcrypt password hash for up to 90 days from import, deleting it when the profile is claimed or the retention period ends. It does not replace your CraftCorps account password. Unsupported or conflicting profiles stay unclaimed pending review. Contact support for account recovery or coordinated access, export and deletion requests.

The website uses a random session cookie for up to seven days and encrypted server-side credentials; it no longer authenticates using the old website JWT session. The account service has a separate session of up to 30 days. Signing out or revoking that account session invalidates linked website access.

Leaves public text chat is relayed between Minecraft, Discord and YouTube. CraftCam camera participation is separately off by default: /broadcast on opts in, /broadcast off opts out. Participating activity and nearby proximity speech may appear in the public broadcast; private messages and private voice groups are excluded. The public map shows terrain and builds. Public messages and broadcasts may be retained by the receiving platforms.

1. Introduction

CraftCorps Nicolas Palomino (NIP: 8952259152), based in Wrocław, Poland, is committed to protecting your privacy. This policy explains how data is collected, used, disclosed, and protected when using the CraftCorps platform, including the launcher application, game servers, websites (craftcorps.net, battleroyales.net, craftclient.net), and Discord services (collectively the "Service").

As a business registered in the European Union, we comply with the General Data Protection Regulation (GDPR) and applicable Polish data protection laws.

2. Data We Collect

2.1 Account Data

2.2 Gaming Data

2.3 Payment Data

2.4 User-Generated Content

2.5 Technical Data (Collected Automatically)

2.6 On-Device Only (Android launcher)

2.7 Data We Do Not Collect

3. How We Use Your Data

We use collected data for the following purposes:

Legal basis (GDPR): We process data based on (a) contractual necessity (account and service operation), (b) legitimate interest (anti-cheat, fraud prevention, service improvement), and (c) consent (optional telemetry, marketing communications).

4. Data Sharing

We do not sell, rent, or trade your personal data. We share data only with:

5. Data Retention

6. Data Security

We implement industry-standard security measures including:

While we take reasonable precautions, no internet service can guarantee absolute security.

7. Cookies

The website uses minimal cookies for essential functionality. See our Cookie Policy for details.

8. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided personal data, contact us for deletion. Users aged 13–18 require parental or legal guardian consent as outlined in our Terms of Service.

9. Your Rights (GDPR)

As a data subject under GDPR, you have the right to:

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Polish data protection authority (UODO — Urząd Ochrony Danych Osobowych) at uodo.gov.pl.

10. International Data Transfer

The Service is hosted on servers in Singapore and uses Cloudflare's global network. Data may be processed outside the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Cloudflare's and Stripe's compliance with EU data protection standards.

11. Third-Party Links

The Service may contain links to third-party websites (Discord, YouTube, TikTok, Instagram, Facebook, GitHub). We are not responsible for their privacy practices. We encourage you to review their privacy policies.

12. Policy Changes

This Privacy Policy may be updated periodically. Significant changes are communicated via the website and Discord server. Continued use of the Service after changes indicates acceptance of the updated policy.

13. Data Controller

The data controller responsible for your personal data is:

14. Contact

For privacy questions, data access requests, or complaints: