Data inventory
What we process
- Minecraft UUID, current and previous player names, edition/platform capability, session time, playtime, progression, settings, and gameplay state.
- Claims, teams, balances, ledger entries, shops, market listings, trades, portals, homes, death boxes, events, quests, journals, projects, inbox metadata, and related audit records.
- Moderation actions, appeals, private reports, safe evidence references, filter-rule matches, and investigation records.
- Connection-security data. The custom IP-ban system stores salted keyed hashes rather than plaintext IP addresses; infrastructure logs may temporarily contain connection addresses.
- Block and container activity recorded for grief investigation and restoration.
- Basic website request logs produced by DreamHost, such as IP address, timestamp, requested path, browser user agent, and response status.
This website has no advertising trackers, third-party analytics, social pixels, or payment collection.
Adult volunteers
Staff application data
The Community Helper application collects a Minecraft username or gamertag, edition, Discord username, time zone, general availability, relevant experience, scenario responses, motivation, and boolean records showing acceptance of the 18+ attestation and volunteer terms under the displayed policy revision. It does not request a legal name, exact age or birth date, address, phone number, school, workplace, or precise location. Submitted Minecraft and Discord identities are unverified until staff separately confirm account control.
A secure session cookie expires after 30 minutes and holds one-use anti-forgery values plus a bounded attempt counter. The server uses a keyed hash of the direct connecting IP address for bounded abuse limits and a keyed digest of normalized application content for duplicate control. Submitted account identities do not consume identity-based quotas, and the application system does not store plaintext IP addresses in its private rate-limit shards. Bot checks include submission timing, a local challenge, and empty trap fields.
Purpose limitation
Why we use it
- Provide persistent survival gameplay and restore a player's state.
- Protect claims, economy operations, trades, deliveries, and item recovery.
- Enforce rules, investigate reports and grief, prevent evasion, and process appeals.
- Evaluate adult Community Helper applicants, contact selected applicants through their submitted Discord username, verify account control later, and administer volunteer access.
- Diagnose errors, secure infrastructure, enforce queue capacity, manage retries, and recover from failures.
- Publish only approved community information such as completed civic project markers.
Not forever by default
Retention
Persistent gameplay records remain while the world and account state are active. Security, moderation, transaction, and recovery records are retained only as long as needed for integrity, safety, legal obligations, and active restrictions. Rolling backups may preserve deleted data until their finite retention window expires.
Application rate-limit timestamps stop counting after 24 hours and are pruned during later checks. Pending queue content is retried for no more than 14 days before being moved to access-restricted dead-letter storage; cron retention cleanup deletes dead-letter content after 30 days. Successful Slack delivery removes queued application content and leaves a minimal application ID, keyed duplicate digest, and delivery timestamp for up to 180 days. Private application security logs contain event categories rather than application text, account names, or IP addresses; later security-log activity deletes files older than 30 days. Queue, dead-letter, receipt, and log storage all have hard count or byte limits.
The Slack copy follows the owner-controlled workspace's configured retention, which is not currently published here. Records tied to an active investigation or legal obligation may be held longer where deletion is suspended deliberately.
Player choices
Access, correction, and deletion
Players may request an explanation or copy of their custom-plugin profile data, correction of inaccurate account metadata, or deletion where operational and legal obligations allow. Deleting persistent gameplay data may permanently remove builds' ownership links, progression, balances, claims, and recovery rights.
Privacy contact status: a dedicated public privacy contact has not yet been published. Until one appears here, there is no verified website channel for access or deletion requests; applicants who are contacted may ask the contacting staff member to route a request. Do not submit if this limitation is unacceptable. Never submit passwords, private keys, government identification, payment information, or unrelated personal evidence.
Families
Children and supervision
Players under the age required by their local law should join only with parent or guardian permission. PlushSMP does not ask children to publish real names, exact ages or birth dates, schools, addresses, phone numbers, or external social accounts. Families should review platform privacy settings and the family safety guide together. The staff application is only for adults who attest that they are at least 18.