Privacy

1. Who this covers

Enderbeam hosts websites for Minecraft servers. A server owner installs our plugin, and it sends data about their server to us so their website can show it.

That means there are four kinds of people in this notice, and they are affected very differently:

  • Server owners, who create an account with us and install the plugin.
  • Players, on a server that uses it. Most will never visit enderbeam.com — so the parts of this notice about them are the parts that matter most.
  • Visitors, who read a site we host without signing in to anything.
  • Members, who have an account on a site we host and post on it.

Where something applies to only one of those groups, this notice says so.

2. What a server sends us

There are five kinds of data here and they follow different rules. The difference is how much of a decision each one is, and whether anybody outside the server ever sees it.

Public — sent for every player, and not something a player can remove themselves from:

  • Server status — who is online now or only how many, plus version, message of the day and tick rate. The same thing you get by typing /list, or by joining and looking. A player vanished by SuperVanish, PremiumVanish or EssentialsX is left out of the list and the count.
  • Town, faction, land and party directories — the group's name, how many people are in it, its claims and its nation. Numbers and place names, with nobody named. Who leads one is a person, so that is in the next list rather than this one.
  • Permission groups — which ranks a player holds. A server assigns these and writes them in front of a name in chat, so they are already shown to anyone who logs in. A site can turn one into a badge, and pass it on to a Discord role if its owner has pointed it at one.
  • Staff lists, which are the same thing shown as a page: whoever holds a rank the owner named as staff, or a badge they granted by hand. This was listed under the consent block until 8 September 2026, which was wrong in the reassuring direction — a staff page is not gated on the box in section 3, and it would be a poor staff page if it emptied itself as staff declined to share their playtime. What you can control is whether your Minecraft account is shown beside your name at all, which is its own switch on your profile.
  • Player-count history — one reading a minute of how many were online and the tick rate. No names.
  • The server's icon, and its address if the owner set one.

Sent for every player and shown only to the server's own staff — punishments: everyone currently banned, with their name, UUID, reason, who issued it and when it expires. This has its own paragraph because it is none of the other three: sent for everybody like the list above, and shown to nobody outside the server's own staff. It is not published on a site and has not been since the public page was removed; it is shown in the creator app to that project's collaborators, and the reason only to its admins. The UUID here is held and never published — what a site sends a browser is a code that means something only to us, which section 9 describes.

Shown only if you asked for it — leaderboards, rankings, and being named as a group's leader. A server sends these for every player it has seen. We publish none of them for anybody who has not signed in here, linked their Minecraft account, and turned it on:

  • Where you rank on this server's boards, and the number the board ranks by: how long you have played, how many advancements you have earned, how much in-game money you hold, your kill, death and block-breaking counts, how many times you have voted for the server, and your levels in mcMMO, Jobs, AuraSkills and Quests.
  • Your Minecraft username, your rank on the server, and when you first joined and were last seen.
  • Your name beside the town, faction or party you lead.

This used to work the other way round: everybody was published and could ask to leave. That is a defensible way to run a leaderboard for adults and a poor way to run one for children, and a great many Minecraft players are children. So the basis is now your permission rather than our judgement about what you would probably not mind — and permission is something we can only take from somebody old enough to give it, which is what the account and the age question in section 6 are for.

What it means in practice: a server can send us ten thousand players and we store the handful who asked. Nothing is held about the rest — not a name, not a number, not a row waiting to be filtered. A board on a new site is empty until people opt in, and that is the intended state rather than a fault.

It also means we no longer work out where any player is. There used to be a stricter default for players in the United Kingdom, and the plugin read the address a player connected with to decide who that applied to. Everybody now has the stricter default everywhere, so there is nothing left to decide and nothing left to read.

You can change your mind either way. Turn it off on the website, or type /enderbeam hide in game, which needs no account and no permission. We act on it the moment it reaches us; your name is off the site within a minute, which is how long the server takes to send its next update.

Shown only if you agreed — a little more of you in the players list:

  • Your playtime, when you first joined, and your mcMMO level, beside your name in a site’s list of members. Without this it shows your name and your rank.

There used to be a page here as well, and there is not any more. Two of them, in fact: one at /player/yourname keyed by your Minecraft name, and a Minecraft section on your own profile, both gathering your playtime, balance, advancements, statistics and skill levels under your name in one place. Both were removed on 8 September 2026. What is on a leaderboard is a name and one number in a ranking you are competing in; a page collecting all of it is a different thing, and a great many of the people it would be about are children. So the figures live on boards and nowhere else, and this box now governs three fields in a list rather than a page about you.

Shown only if you turned it on, and only to people who are signed in — where you are on a server’s live map. Some servers run EnderMap, a live web map of their world, and some of those have us host it on their site. Nobody appears on a hosted one unless they signed in here, linked their Minecraft account, and turned on “Show me live on this server’s map” on their profile for that server. For those who did, it shows:

  • Your in-game name and your skin.
  • Where you are in the game, updated about ten times a second, which way you are facing, and how you are moving — sneaking, swimming, gliding and so on.
  • What you are holding and what armour you are wearing.
  • Which of the server’s worlds you are in.
  • Animals and monsters near you. They are nobody’s data, but they move with you, so they say where you are.

The server owner can show less than that — no names, no skins, no gear, positions rounded to the block or to the 16-block chunk, or everything a few seconds late — but not more. The map calls you by a code that means something only on that server, not by your Minecraft account’s identifier, which the server sends us so we can check your answer and which we remove before anybody sees the map.

Only people signed in with an Enderbeam account that has a Minecraft account linked see anybody on it, and not somebody that community has banned. Everybody else sees the world and nobody in it. That is deliberate: a live map anyone can watch is one a stranger can use to learn when a particular player is online and where to go to meet them, and a great many players are children.

The map’s sidebar also lists who is online, by name only, to everybody who opens it. That is the same list as the public one above, and it adds nothing to it: a player who has not turned the live map on appears there as a name, with no position and no world, exactly as they already do on the site’s list of who is online. A vanished player is in neither list and is never drawn on the map.

This is where you are in the game, not in the world. Nothing about it tells us, or anybody, where you are in real life.

And nothing is kept. Each update goes to whoever is watching at that moment and is then forgotten, so there is no history of where you have been and no record of where you were last. If nobody is watching, the server does not send players at all.

What the map is drawn with is kept: its pictures of the world, and the textures they are made from, so it opens quickly and still opens while the server is off. Those are pictures of blocks rather than of anybody, though a build can spell out a name. Your skin is not among them — we pass it on to the person watching and do not store it. Section 7 says how long the pictures stay.

4. What you give us directly

Server owners provide an email address and password to create an account, or sign in with Discord. Payment is handled by Stripe; we never see or store card details.

Everybody who creates an account, either kind, also leaves a record of it: which version of the terms they agreed to, when, and the minimum age that applied where they signed up from. It holds the threshold and not your date of birth — “at least this old” rather than the day you were born, which we ask for on the form and do not keep.

Members of a hosted community site provide a username and email address, and may link a Discord account or a Minecraft account. Linking Minecraft is done by running a command in game — Mojang has already established who they are, so we never ask anyone for a Minecraft password, and could not use one if it were given to us. There is a second route built for signing in with Microsoft, which would prove the same thing through Microsoft rather than through the server; it is switched off and nothing on the site offers it. If it is ever turned on, this paragraph changes before it does.

Anything a member writes on a site — forum posts, comments, wall messages, poll votes, live chat, images they attach, and which posts they reacted to — is stored so that site can show it. Editing a forum post keeps the previous version for a while, so a community can see whether an argument was changed under it; section 7 says how long.

Buying something from a project’s shop needs no account here at all. You type the Minecraft username the purchase is for, we pass it to Tebex to open a basket in that name, and the checkout happens on Tebex’s own pages. We hold nothing from it: no card, no billing address, no email, and no record that you bought anything. What we do briefly hold is your IP address, in memory, to stop a script opening thousands of baskets in a shop owner’s dashboard — it is counted and not stored. The basket’s identifier is kept in your own browser so your basket survives a page reload; see sections 5 and 9.

5. Visitors, downloads, and what we measure about ourselves

We count unique visitors per site, per day. To tell one visitor from another we work out a short code from their IP address, their browser’s user agent and the site’s own identifier, and keep that code with the date rather than the address. It is worked out on our side and never sent to your browser: it is not a cookie, it is not shared, and it is not used for advertising or combined with anything else. We run no third-party analytics on hosted sites.

That is about this code specifically, and not a claim that a site stores nothing on your device. A site with a shop keeps the identifier of your open basket in your browser’s storage, so the things you added are still there when you come back — see section 9. It is only that, it stays on the device that made it, and clearing your browser data removes it.

The code is made with a secret that is generated at random each day and never written down anywhere. That is what stops it being reversible: without the secret, holding the whole table and a list of candidate addresses gets you nothing, and the secret for any past day no longer exists. This paragraph used to say the opposite — that somebody with the table could work out whose code was whose — which was true before the secret was added and stayed on the page after it was.

What the code still does, because it is the point of it, is tell two visits apart on the same site on the same day. Codes are deleted after 30 days and used for nothing but a count.

This paragraph used to end by offering to exclude you if you asked, and that was a promise the design makes impossible to keep — the same failure as the sentence corrected just above it, in the sentence immediately after. There is no list to add you to and no way to build one: the secret your code was made with no longer exists by the next day, so we could not find your rows to leave out, and giving you a code that lasted would mean creating exactly the durable identifier this is built to avoid. What we can tell you honestly is that we hold nothing here that could be traced back to you.

We also count downloads of the plugin from enderbeam.com, per jar, so we know which platforms people install on. A repeat download by the same person on the same day is counted once, using a code made the same way — but with a secret we throw away and replace every midnight, so a download cannot be linked to the same person on a different day. Those codes are deleted within a day.

Servers running the plugin report their Enderbeam version and their Minecraft version on each check-in, and we keep the date each one was last seen, plus one row a day recording that it was running, for three years. That tells us how many servers are on which build, which is how we know when it is safe to stop supporting one. It is about the server, not about its players.

Do Not Track and Global Privacy Control. Some browsers send a signal asking not to be tracked across sites. We do not change what we do when we receive one, and the honest reason is that there is nothing to change: we do not track anybody across sites, we run no advertising and no third-party analytics, and the only thing we count is described above — a per-site, per-day code made with a secret that no longer exists by the next morning. California law asks us to tell you how we respond to that signal, so this is us telling you: we do not act on it, because there is no behaviour it would switch off.

Ordinary server logs record requests, including IP addresses, for security and to keep the service running, and they are not read except when something is being diagnosed. There are two copies and this paragraph described one of them. The system journal is capped at 200 MB and rotates, which at our traffic is a few weeks. The server also keeps a second copy in its own log files, rotated weekly with four kept — so the outside limit on a request log is about five weeks rather than the size cap alone. There was no period stated here at all before that, which in effect meant forever.

6. What we never collect

We do not read anything on a server beyond what section 2 lists. There is no connection into a server: every request is made by the plugin, outward, over HTTPS. There is no port to open and no database credential to give us, and nothing on our side can start a conversation with a server.

A hosted map is the one place we ask a server for something, and it is still the server that connects. The Enderbeam plugin, which the server already runs for its site, opens a connection to us on the map’s behalf and keeps it open; over it, when a visitor needs a file of the map’s that we have not been sent before, we ask for that file. It answers for the map and nothing else.

We never receive in-game chat. Enderbeam once had a feature that published it, and we removed it rather than making it optional: republishing what players typed in a game to anyone with a URL is not something a switch makes comfortable. There is no setting that turns it back on, and no version of the plugin that still sends it.

We do not collect Minecraft passwords, payment details, or where anybody is in the real world. This sentence used to say “precise location”, which stopped being the whole truth with the live map: section 2 describes a map that shows where a player is inside the game, many times a second, if they turned it on. That is a position in a game world, not a place anybody lives, and it says nothing about where they are sitting — but it is location of a kind, and a notice that said we never touch location would now be wrong.

One thing arrives without anybody meaning it to, so it is worth saying what we do about it. A photograph taken on a phone has the coordinates it was taken at written inside the file, and those coordinates are usually somebody's home. Nothing here asks for that and nothing displays it, but a picture attached to a forum post is served from a public website, so it would have been there for anyone who looked. We now remove the embedded information — location, camera, date, and anything else the file was carrying — from every JPEG, PNG and WebP as it is uploaded, before it is stored, on every route: page images, avatars and forum attachments alike. The picture itself is untouched and is not re-compressed.

One format we used to accept, AVIF, we no longer do — we could not clean it, so we stopped taking it rather than store photographs we knew we could not strip. Three things still pass through untouched, and this paragraph called video the only one until 8 September 2026.

  • Video. An MP4 can carry a location too, and rebuilding one is a different piece of work, so videos are stored as they were sent. Only a project’s own team can upload video.
  • GIF. There is nothing to remove: the format has no Exif container, so a GIF cannot carry the coordinates this is about. It is the harmless one of the three, and it was still wrong to describe it as cleaned.

There is a third case, and it applies to one format and is a refusal rather than an exception. A WebP keeps its location information after the picture rather than before it, so cleaning one means holding the whole file — and above 32 MB we will not. Instead of storing one we could not clean, we decline it and say so, which is the same answer AVIF got. JPEG and PNG have no limit at all: they can be cleaned as they are read, however large they are, which is what matters because a camera produces a JPEG. A phone photo is a few megabytes and comes nowhere near any of this.

A visitor attaching a picture to a forum post is on the same route as everybody else, with the same three exceptions.

Signing up asks for your date of birth. It is used once, in your browser, to work out whether you are old enough — and then it is gone. It is never sent to us, we have nowhere to put it, and what we keep is a single number meaning "said they were at least this old". We ask for a date rather than showing you an age to agree to, because a form that tells you the answer is not really asking.

What counts as old enough depends on where you are, in a box of its own rather than bundled with agreeing to these documents. What counts as old enough varies: Article 8 of the GDPR sets 16 and lets a country lower it to 13, and countries have chosen differently — so the form asks for the figure that applies where the request came from, and for 16 wherever that cannot be established. We work that out from the country your connection appears to be in, which our CDN tells us; we do not store it and we do not ask you.

That governs holding an Enderbeam account and nothing else. Playing on a server whose site we host needs no account, so the players in section 2 include children and we know it. That is why the way off a leaderboard needs no account, no permission and no explanation, and why we would rather you told us about a child on a board than assumed we already knew.

7. How long it is kept

  • Players who have not logged in for about thirteen months are dropped — 400 days exactly. The plugin stops sending them and we delete them. Nobody has to ask, and nothing has to be running for it to happen.
  • Player-count history is kept for 90 days.
  • Live chat between members on a website keeps its last 20 messages, and nothing older than 7 days. That is people typing on the website, and is not connected to anything in game.
  • Punishments are kept until the server owner removes them, because a lifted ban is part of a server's record. They are not published on a site — see section 2.
  • The written reason for a ban goes 90 days after that ban ends, whether it expired or was lifted. Who was banned, when, by whom and whether it was lifted all stay; the sentence explaining it does not. A ban still in force keeps its reason for as long as it is in force.
  • A warning, mute or ban given on a website follows the same rule and the same 90 days — counted from when it ended, or, for a warning, from when it was given, since a warning has nothing to expire. The community keeps who, what and when; the sentence explaining it goes. A mute or ban still in force keeps its reason while it is in force. The moderators’ own log of what was done loses its reasons on the same clock.
  • When we act on an account or a project ourselves — restoring one somebody deleted, or making one free — we record who did it, to what, when and why, and keep that for three years. It is how the question "why is this account like this" gets an answer long after everyone has forgotten, including when the person asking is you.
  • The live map keeps nothing. Each update is passed to whoever is watching and then forgotten, in memory and nowhere else — not in a database, not in a file, not in the logs, and so not in the backups either. Your skin is passed on the same way and not stored by us; the browser of the person watching may keep it for up to an hour, the way it keeps any picture.
  • A hosted map’s pictures of the world are kept as a cache: up to 1 GiB per server on the free plan and 10 GiB on Premium, and when that is full the ones nobody has looked at for longest go first. A picture goes as soon as that part of the world changes, and all of them go when the server changes its textures.
  • Visitor codes are deleted after 30 days, and download codes within a day. See section 5.
  • If you write to support, that conversation is deleted 90 days after the ticket is closed — every message with it. An open one is never touched, and replying to a closed one reopens it and starts the clock again. It is 90 rather than 30 days because this is also how you ask us to delete or hand over your data, and the record of us having done that is the conversation itself.
  • Account data and most of what a member wrote is kept until the account or the content is deleted. These have a clock of their own, and are deleted whether or not anybody asks:
  • The previous version of an edited forum post goes after 60 days. The point of keeping it is that a community can see whether an argument was changed under it, and that question is settled within days; after that it is somebody's deleted words sitting in a table. The “edited” marker on the post itself is permanent.
  • An application or build submission that has been decided goes 60 days later, and takes the staff notes and votes on it with it. One nobody has decided is never swept, however long it has been waiting — a queue that emptied itself would hide exactly the staff who are not reading it.
  • Notifications go after 30 days.
  • A report goes 90 days after it is closed, as section 8 says. One nobody has answered is never deleted.
  • The snapshot of a server’s leaderboards that we hold so a restart does not blank every site goes 30 days after that server stops sending. So does a queued request asking a server to re-send one player, after 7 days, if the server never answers it.
  • A server's connect address, if its owner sets one, is kept for as long as that server is registered. It is meant to be the public address players type in, but a server run from somebody's home is their home connection, so it is treated as personal data and goes when the server or the project does.
  • An invitation to collaborate on a project holds the email address it was sent to. Declining deletes it, and so does deleting the project. Accepting does not: the address stays as that collaborator’s address of record for as long as they are on the project. This said “until it is accepted” until 8 September 2026, which was wrong in the direction of promising more than we do. See section 9.
  • Everything above describes the live system. Behind it we take one whole-system backup a day, between 4am and 8am UTC, and keep seven. A backup cannot be edited from the inside, so something deleted today is still in the backups taken before it went — and gone from all of them within seven days. They are only ever used to restore the whole system after a failure.

Deleting a project deletes everything held for it, including its players, punishments and history, and a hosted map’s cached pictures and our record of the map. After that the map’s address shows only that it is offline.

A player who withdraws is deleted straight away, without waiting for any of the above.

8. Your choices

Players: everything about you on a site is there because you asked for it, so the way to stop it is to say so — untick the box on your profile on that site, or type /enderbeam hide in game. Either deletes what is held for that server. The live map has its own switch, on your profile and in the site’s Live map block, and no command in game; there is nothing to delete for it, because nothing was kept. Section 3 has the detail.

What you cannot remove yourself is the public list in section 2: whether you are online. There is no switch for it because the answer comes from the server every minute — take it off the site and the next update puts it back — so the change has to happen at the server, which is why asking them is the direct route. That is a fact about where the data comes from and not a statement that it is nothing to do with us: we are joint controllers of this along with the server owner, the same as everything else in section 2. If they will not help, or you cannot reach them, write to us. You do not need an account, you do not need that server's permission, and we will not send you back to them.

A punishment on your record is not on a site at all any more. It is visible to that server's own staff, and the reason only to its admins, so the person to ask about it is the server that issued it.

Linking a Minecraft account claims a player on a site as yours, and is what makes the box in section 3 available. Unlinking gives that claim up and takes you off every board, out of every players list and off every live map, everywhere, not only on the site you unlinked from — disclaiming the account is not a statement about one community. Your refusal is recorded rather than forgotten, so linking again does not re-agree on your behalf; you would tick the box again.

If a server bans you permanently, we stop showing you entirely on that server — off its leaderboards, out of its players list and off its live map, even though you had asked to be there. The reason is that the way off a board is a command typed in game, and somebody who cannot rejoin cannot type it: the person most likely to want off is the one least able to ask. The live map follows the same rule so that a ban means one thing everywhere. If the ban is lifted your own answer applies once more, because you can act on it again.

Unlinking takes the leaderboards with it. Being ranked depends on an account, a linked Minecraft identity and a yes, so saying that identity is not yours withdraws the thing the yes was about — leaving you ranked would mean publishing you on a permission from an account that no longer claims you, with nobody left who could take it back.

Server owners: every integration the plugin reads has a switch in plugins/Enderbeam/config.yml on your own machine, and nothing there is set from our side. What you cannot do from there — or from anywhere — is agree on a player's behalf. Profile data appears for the players who ticked the box on your site and for nobody else. The same goes for a hosted live map: we tell your plugin which players said yes, and check every player it sends us again, whatever it sends.

Members: you can delete your own posts, comments and messages, and your account. Deleting your account removes it and everything you wrote — posts, comments, wall messages, reactions, applications and the staff notes and votes you left on other people's, build submissions, poll answers and your notifications — unlinks your Minecraft account and takes you off every leaderboard and players list — except forum threads and replies, which stay under the byline "Account Deleted" so the conversations other people took part in survive. The earlier versions of any post you edited do go, because nobody replied to those. Delete a post yourself first if you would rather it went with you.

Deleting your account takes you off every leaderboard, because being on one depended on that account. This used to leave you ranked where you had explicitly asked to be, on the reasoning that it was your decision and losing an account is not changing your mind — but a permission with no account behind it is one nobody can withdraw, and that is worse than losing a place you can ask for again.

Two things outlive the account, both with you taken out of them. A warning or ban a community's staff issued against you keeps the fact, the kind and the date on their record, and loses your name and the reason — the decision was theirs to make and is theirs to remember, and the reason is the part that was written about you. The same goes the other way for anything you did as a moderator: the action stays on the log, your name comes off it.

And if you had written to support, every message goes and a shell of the ticket stays — its reference, what it was about, and when it closed — until our ordinary support retention removes it. That is because a request to be erased is very often made through support, and the record of having answered it would otherwise be inside the thing we were erasing. It is closed as your account goes, so the clock on it starts the same day.

If you report something, we keep what you sent — which post, what you picked, anything you typed, and a short copy of the reported text so it still means something after the post is deleted. Your name goes to the site's staff along with it, because a moderator answering a report needs to know who is telling them. Reports are deleted 90 days after they are closed; one nobody has answered is never deleted, because age is not a reason to stop caring about it.

Deleting your account deletes the reports you filed that have been dealt with. One that is still open keeps the fact of it and loses you: your name and anything you typed go, and what is left is the category and the reported content. That is because an open report is a complaint somebody is still acting on — sometimes about a child's safety — and closing your account should not delete a thing somebody else is in the middle of answering.

A report about a site, or about the people running it, is the exception: it goes to Enderbeam and nowhere else. That site's staff never see it and are not told it exists.

If you want something removed and cannot do it yourself, write to us and we will.

9. Who else sees it

A hosted site is public, so anything placed on it is public. That is the point of it, and it is why the choices in sections 3 and 8 matter.

The players on a live map are the exception. They are shown only to people signed in with an Enderbeam account that has a Minecraft account linked — any such account, not only members of that community, unless that community’s staff have banned them. The map itself, the world with nobody in it, is public like the rest of the site. If you watch one, the site hands the map a pass saying which account you are, good for an hour and for that one map; we check it when the map connects and do not keep a record of who watched.

Two things used to leave without being on this list, and both are worth saying plainly rather than quietly fixing. Every player head shown on a site was drawn by a third-party service, and the address of the picture had the player’s Minecraft account identifier in it — so your browser told that service which player you were looking at, and told it your own IP address by asking at all. And every hosted site loaded its typefaces from Google’s font servers, which meant Google received the address you came from, your browser’s headers and the page you were on, on every single page view of every site. Neither was named here, neither was in our agreement with anybody, and neither was a decision: they were how the first head got drawn and how the first site got its type.

Both now come from us. We draw the heads ourselves and serve the fonts from our own address, so neither Google nor anybody else hears from your browser because of them. The player identifier is no longer in the page at all — what a site sends your browser is a code that means something only to us.

What we cannot promise is that a site never loads anything from anywhere else, because a site is built by its owner and some of the blocks they can place reach out. A video block loads a player from YouTube, Twitch or Vimeo. An embed block loads whatever address the owner typed into it — a booking widget, a form, a map. And a shop loads Tebex: the package pictures come from Tebex’s own servers, and opening the checkout loads a script from js.tebex.io so the payment window can appear on the page rather than sending you away. In each case your browser talks to that service directly, and what it learns is between you and them.

A hosted map is a case of its own. The page is the server owner’s, sent from their server through us, so it is their code running in your browser. It runs sealed off from the rest of the site — it cannot read your sign-in, or anything the site keeps in your browser — which is why it is given a one-hour pass rather than your account.

That last one was our omission rather than an owner’s choice, and this paragraph said the opposite of it until 8 September 2026 — that everything Enderbeam itself puts on a page comes from us. The shop is ours, and it does not.

Two things involve somebody who never came here at all, and both were missing from this notice until now. If a site has a contact form and you fill it in, your name, your email address and your message are emailed straight to that site's owner — we do not store any of it, and there is no inbox for it on our side. Your address is not used as the sender, so the owner sees a message from us carrying your address to reply to. And if somebody invites you to help run their project, your email address is stored from the moment the invitation is sent, before you have any account here, so that the invitation can be matched to you when you open it. Both are done for the project owner rather than for us. Write to support@enderbeam.com if you want either removed and we will do it without asking them.

This is everyone outside Enderbeam who sees any of it. Most are service providers running part of Enderbeam on our instructions and for no other purpose. Three are not, and it is worth naming them rather than counting: Mojang and GeyserMC we simply ask for a skin, the way any program asking a public service would, on nobody’s instruction and under no contract with them. Tebex works on the project owner’s instruction rather than ours — the shop is their account, under their own agreement. We do not sell personal data, and we do not share it for advertising. The current list:

  • Supabase — accounts and sign-in.
  • Cloudflare — three things, and the first is much larger than the other two. Every request to this site, to the creator app, to our API and to a project on its own custom domain reaches Cloudflare's network before it reaches us: the encryption ends there and a second connection carries it on to our server, so Cloudflare sees the address you came from, what you asked for and your browser's headers. It also stores the images and files uploaded to a site and the cached pictures of a hosted map, and serves the plugin downloads. And it is what tells us which country a request came from, which is how the age rule in section 6 knows which figure applies.
  • Resend — email we send you, and email you send to support@enderbeam.com, which they receive and hold for us. That includes anything you send us to report a community, to ask about your own data, or to make a legal complaint.
  • Stripe — payments. Card details go to Stripe directly; we never see or store them.
  • DigitalOcean — the server everything runs on.
  • Mojang (Microsoft) — where a Java player's skin comes from, so we can draw the little head beside their name. We ask them, using the account identifier Mojang issued in the first place, and send the picture on ourselves.
  • GeyserMC — the same thing for a Bedrock player, because Mojang does not hold their skin. A Bedrock player joins through Geyser, and their Xbox identifier is what Geyser knows them by, so that is what we send. This is asked by our server rather than by your browser, so what Geyser learns is which player is being drawn and nothing about who is looking. It was missing from this list until 8 September 2026, and a sentence above claimed Mojang was the only party involved.
  • Discord — where somebody signs in with it, links it to their community profile, or a site’s owner connects a Discord server. Discord is a source and a recipient both: signing in tells us who Discord says you are, linking stores your Discord id, username and avatar, and a role you hold on a site can be pushed to a role in the owner’s Discord if they set that up. A linked member’s avatar is loaded from Discord’s own address, so on a page showing one, Discord sees the visitor’s address. It was missing from this list until 8 September 2026.
  • Tebex — the shop, where a project has one. Two things, and the second was missing from this list until 8 September 2026. If you open a basket we pass the Minecraft username you typed to Tebex so they can open it in that name, and payment happens on their pages rather than ours: we never see your card, your address or your email from a purchase. And your own browser talks to them directly on a page with a shop on it — the package pictures load from their servers, and opening the checkout loads a script from js.tebex.io so their payment window can appear in place. So Tebex sees your address on those pages the way any site you visit does. If the shop chooses to show recent buyers or a top supporter, those names come from Tebex's own store settings, and a shop that would rather not name its customers turns that off there.

We will name any new one here at least 30 days before it starts. If you run a project and you object to it on reasonable data protection grounds, tell us within those 30 days: we will either propose an alternative or, if we cannot, let you end the affected part of the service and refund the unused portion of anything you have paid. That is section 5 of the data processing agreement, and it was previously only in that document — which is the wrong place for it, since this list is the page you would be watching.

Enderbeam is operated from the United States, so if you are in the UK or the EEA your data is transferred there. We rely on the European Commission's standard contractual clauses of 4 June 2021 and, for the UK, on the ICO's international data transfer addendum. For project owners those clauses are entered into through the data processing agreement, and its section 10 sets out their completed annexes — that document is the instrument rather than a separate signed paper. Read it at enderbeam.com/dpa.

10. Security

Connections are encrypted in transit. Passwords are hashed rather than stored. Access to production data is limited to the people who need it to operate the service.

No service can promise it will never be breached. If one happens and it affects you, we will say so.

11. Who is responsible, your rights, and how to use them

Enderbeam is run by one person rather than a company: Ryan Exner, trading as Enderbeam, 440 N Barranca Ave #1779, Covina, CA 91723, United States. Write to support@enderbeam.com — a person reads it, and you will get a person's reply.

For your account, what you write on a site, our visitor counting and our own product statistics, Enderbeam is the controller and decides those things alone.

For the data your server sends about its players, Enderbeam and the server owner are joint controllers. All of it — the public list of who is online, the town and faction directories, the leaderboards, the players lists, and where a player is on a hosted live map. This used to say “which town somebody is in”, which sections 2 and 8 both contradict: a directory carries a group’s name, size and claims with nobody named, and being named as one’s leader needs the same yes a board does. The owner decides to install the plugin and which integrations to turn on. Enderbeam decides what the plugin can send, how objecting and agreeing work, and what is published by default. Neither of us can honestly say we are only following the other's instructions on those points, so we do not say it. The live map is the clearest case: we decided that players need a yes, that only signed-in people see them and that nothing is kept; the owner decided to run the map and how much of it to show.

A hosted map’s pictures of the world are different. They are the owner’s world, kept on the owner’s instructions, and for those we are the owner’s processor under the data processing agreement rather than a controller.

What that means for you in practice: bring any request to us directly. You do not need an account, and you do not need the server owner's permission. Where a request is about something only the owner can change — a ban they issued, a rank they assigned — we will tell you so and pass it on, and we will take the data off the website in the meantime if you ask us to. You can exercise all of your rights against either of us.

Your rights are access, correction, deletion, restriction, portability, and objection. There is a page about how to use them at enderbeam.com/privacy-request — what to send, what proof we need and when, and what happens then. The short version: email support@enderbeam.com, tell us your Minecraft username, and we answer within one month and usually within a few days. If we hold nothing that identifies you, we will say that rather than nothing.

That address is a mail centre rather than an office, because Enderbeam is one person and the alternative would be a home address. It is a real address that receives real post, including legal process, and it is the one to use for anything formal.

If you are in the UK or the EU, your own data protection law applies to you even though we are in California, and you can complain to your national supervisory authority — in the UK, the Information Commissioner's Office — as well as to us.