Privacy policy
What we collect, why we collect it, and what we do not do with it.
What we collect
Account data: your email address and a hashed password. Billing data: handled by Stripe; we store a customer reference and subscription status, never your card number. Server data: the worlds, configs and files you upload or deploy from a Git repository, and the settings on your server's Startup page, including a bot token, a Git access token or a crash alert webhook if you enter them. Those settings are used only to run your server: the Git token to fetch your repository, the webhook to send crash alerts to the Discord channel you chose, with your bot's recent output (tokens removed) in the message. Operational logs: connection and error logs needed to run and secure the platform, including the outbound connection log described below. That includes failed sign-in attempts: the address they came from and when. Too many from one address in a short time and that address is blocked from the control panel for an hour or so. It is how we stop somebody working through a list of stolen passwords against your account, and the record ages out with the rest of the web logs.
Minecraft waitlist: if you ask on the plans page to hear when Minecraft opens, we keep your email address and the size you had picked. It is used for one email when Minecraft opens, and the list is deleted after that. Ask and we take you off sooner.
Outbound connections from your server
When your server opens a connection to the internet, we record the time, the destination address and port, and which of your servers it came from. We keep that for 14 days and then delete it.
We record that a connection happened, not what was sent. There is no interception of your traffic and no inspection of its contents; the connection is not decrypted, and we could not read it if we wanted to.
This exists so that when someone reports abuse coming from our network we can tell which server was responsible, instead of suspending the wrong customer or all of them. It is used for that and for keeping the platform running. It is not used for anything else, and it is not shared except where we are required to respond to a valid legal request or a specific abuse complaint.
Website analytics
We count visits to this website with Cloudflare Web Analytics: which pages are viewed, how quickly they load, the site that linked you here, and your rough country, worked out from your IP address. It sets no cookies, does not fingerprint your browser, and does not follow you to other websites. We only ever see totals, never an individual visit. Cloudflare already carries all traffic to this site, so this does not add a new company to the list.
What we do not do
We do not sell your data. We do not run advertising trackers or any other analytics on this website, and apart from the Cloudflare analytics script above nothing on it loads from anyone else: no advertising, no font or script CDN. We do not read your server files. Software looks at a few things automatically, and no person sees the contents: once a week a virus scanner compares them against a list of known malware; an hourly check looks at whether our starter bot is still the only code on a new server, to email you setup help; and the status file our startup program writes in .snowservers tells us whether your bot stopped on its own, to email you if it stays down. We look at your files only if you ask us to for support, or if we are investigating a specific abuse report.
Why we process it
To provide the service you asked for, to take payment, to prevent abuse and to keep the platform secure. Where we rely on legitimate interests, meaning security and abuse prevention, you may object.
Who else touches your data
We use a small number of third parties to run the service, and only for that: the hosting providers whose machines your servers run on, and who therefore hold your data on their disks — Discord bots sit in a German company’s datacentre in Vienna, Austria, and Minecraft servers, when they open, will sit in a datacentre in Québec, Canada. We do not print either company’s name here, and we will tell you either one if you ask; Stripe for payments, which handles card details directly so we never hold them; Cloudflare, through which all traffic to this site and the control panel passes; Resend to send account email such as password resets; and Apple, whose iCloud Mail carries anything you send to or receive from our support address. Each sees only what it needs to do its job. We do not share your data with anyone else, and we do not sell it.
One more, and only in one place: the sign-in form on the control panel uses Google reCAPTCHA to tell a person apart from a script trying passwords. When that box is on screen your browser talks to Google and Google sees your IP address. It runs on the control panel login only, not on this website, and not once you are signed in. We would rather have it than not: without it, guessing passwords against our customers gets a great deal cheaper.
Where your data is stored
Discord bots run in Vienna, Austria, in a German company’s datacentre. Your bot's files, its backups, the MySQL database on your plan and the database behind your account all live there. That places them inside the EU, under GDPR, which is the stricter regime rather than the looser one.
Minecraft servers will run in Québec, Canada when they open, because that is where most players are. Canada is one of the countries the EU has decided protects personal data adequately, so an EU customer's data is under equivalent rules there. The world, its backups and its database stay on that machine.
We will tell you which company runs either datacentre if you ask.
We do not copy your data anywhere else. If where your data sits matters for your situation, it is better that you know before signing up than after.
How long we keep it
Account and billing records are kept while your account is active and for as long as tax and accounting rules require afterwards. Outbound connection logs are kept for 14 days. Other operational logs are kept for a limited period and then rotated away.
Server data is deleted after the retention window following cancellation. Backups take longer: we keep encrypted copies so that a hardware failure does not lose your world, and a deleted server can persist in those until they age out, currently within a few weeks. Backups are encrypted before they leave our machine, and are never used for anything except restoring the service.
Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal data, and to complain to a supervisory authority. Ask via the contact page and we will respond.
Sub-processors
Stripe (payments), Cloudflare (network and DNS), Resend (transactional email), Apple (iCloud Mail, which carries support correspondence) and Google (reCAPTCHA on the control panel sign-in form only). Two hosting companies hold the machines: one with a datacentre in Vienna, Austria (Discord bots, their MySQL databases and backups) and one with a datacentre in Québec, Canada (Minecraft servers). We name either of them to anyone who asks; we do not print them here. Any further processors will be listed here before they are used.
Contact
Privacy questions, and any request to access, correct, export or delete your data, go to our contact page, a Discord ticket is the quickest route.
If you would rather not use Discord, or do not have an account, email [email protected] instead. You should never have to sign up to somebody else's service to exercise a right over your own data, so this route exists whether or not you use ours.
Last updated: 16 September 2026.