Privacy Policy
1. Who is responsible
apfelmagnet32
Contact: contact@apfelserver.net
Based in Germany
This is a personal, non-commercial project run by a private individual for a small, invite/ approval-gated group of users — not a company, and not offered to the general public. A full legal name and home address (the kind a commercial "Impressum" needs) generally isn't required for a non-commercial, access-gated project like this; GDPR itself only asks for enough identity and contact info for someone to reach the controller about their data, which a name/handle plus an email address satisfies.
2. What data is collected
| Data | Why | Legal basis |
|---|---|---|
| Username, email address, password (stored as a bcrypt hash, never in plain text) | To create and secure your account | Necessary to provide the service you asked for (Art. 6(1)(b) GDPR) |
| Projects, versions, and files you upload, plus any text you write (descriptions, disclosures, changelogs) | To publish and host your content on the platform | Necessary to provide the service (Art. 6(1)(b) GDPR) |
| A session cookie (a random token, not linked to tracking) | To keep you signed in | Strictly necessary for the service to function — no consent banner needed |
That's it. There is no analytics, no advertising, no third-party tracking scripts, and no data is sold or shared with advertisers.
3. Where your data goes
There is no analytics or advertising, and nothing is sold or shared with advertisers. Two infrastructure providers process data on the operator's behalf, purely to run the Service:
- Neon hosts the database (accounts, project metadata, messages).
- GitHub stores the actual uploaded files (mod jars, resource packs, etc.), in a private repository the operator controls.
Server logs (which may briefly include IP addresses for debugging/abuse prevention) are kept by the hosting provider and not shared beyond that.
4. How long data is kept
Your account and content are kept until you delete your account or ask for it to be deleted. If an account is rejected during moderation, its data is removed.
Uploaded files are removed from the app immediately on deletion. Because of how the underlying storage works, the file's raw bytes may continue to exist, inaccessible to the app or anyone else, on the storage provider's infrastructure for a limited additional period (on the order of weeks) until its own routine cleanup reclaims the space — this isn't something the operator can force to happen sooner.
5. Your rights
Under GDPR, you can ask the operator to:
- Tell you what data is held about you (access)
- Correct inaccurate data (rectification)
- Delete your account and data (erasure) — or delete your own account yourself in Account settings
- Give you a copy of your data in a portable format (portability)
- Stop processing your data in certain cases (restriction/objection)
To exercise any of these, email contact@apfelserver.net. You also have the right to complain to your local data protection authority.
6. Children
This service isn't directed at children. If you're under 16, you need a parent or guardian's consent to create an account, in line with GDPR Art. 8.
7. Changes to this policy
If what data is collected or how it's used changes, this page will be updated with a new "last updated" date.
