Version of 1 October 2026.
1. Who we are
Playkeeper is run by CIYA TECHNOLOGIES LTD, Pyrrou 11, 4105 Limassol, Cyprus ("Playkeeper", "we"). We decide how the personal data in this policy is used, except where section 5 says we handle it for a store. Write to us at me@siya.digital.
This policy covers:
- playkeeper.io, its live demo and its install script;
- the Playkeeper software, where you run it yourself, but only what it sends us or the services it uses;
- free names under playkeeper.me;
- Playkeeper Cloud, where we run the machines, including for stores on Whop that sell through it;
- sellers who connect Playkeeper Cloud to their Whop business.
2. playkeeper.io
- Counting visits, without cookies. Every page but the template share page (
/t) loads OpenAnalytics, an open-source visit counter we run on our own server. It records the page you're on and the page that sent you, any campaign in the address, your device and browser type, how fast the page loaded, a sample of clicks and scrolls, and a few things you do, such as copying the install command, opening the live demo or using a free tool. It never stores your IP address. It may work out your country and city from it, on our server. It counts you by a code made with a key that changes every night, so after a day nothing it kept can be tied back to you. In your browser it keeps a visit's ID in session storage, gone when you close the tab, and any events it couldn't send yet. It records nothing if your browser sends Global Privacy Control or Do Not Track. - Counting copies of the install command. When you copy it, your browser tells our stats service that it was copied, and which campaign's command it was, and nothing else: no cookie, no referrer. We keep hourly counts for 400 days. Your browser sends nothing if it sends Global Privacy Control or Do Not Track.
- Downloading the install script. When a machine fetches it from playkeeper.io, we log the time, the address it came from (its IP address), the script it asked for and its user agent. The logs are deleted after 30 days. They count installs and help us stop abuse.
- GitHub's star count. Your browser asks GitHub how many stars Playkeeper has, so GitHub sees your IP address. The number is kept in your browser for an hour.
- Kept only in your browser: the address of your own dashboard, for Open in my dashboard, and the live demo's state. These never reach us.
- No forms, and no ads. Nothing on the site asks for your email address, and no advertising pixel or cookie is on any page.
3. The Playkeeper software, when you run it yourself
Your server's data stays yours. Your players, worlds, backups and logs stay on your machine. You decide what happens to them, and we don't receive them. The software sends us only the following.
- Usage stats, which you can turn off. A random ID made on your machine, not linked to you; the Playkeeper version, your operating system and its version, and your CPU type; how Playkeeper got onto the machine, and which campaign's command, if any; whether the machine runs the dashboard or joined another; and how the install went, and the step that failed, if one did. Then, a minute after it starts and twice a day after that, the kind of address the machine has (a free name, your own domain or an IP address) and how many servers it has and runs. Never an IP address, a host or server name, or anything about players. Our stats service uses the IP address a report comes from only to limit how often it's sent, in memory, and doesn't log it. It forgets a machine 400 days after its last report. To turn them off, set
DO_NOT_TRACK, setPLAYKEEPER_USAGE_STATS=off, or use Settings › Playkeeper › Usage stats. - Update checks. About every 30 minutes, your machine asks playkeeper.io, then GitHub, for the latest release, saying only that it's "playkeeper-updater". They see its IP address. You can turn automatic checks off in Settings.
- Free names under playkeeper.me. If you take one, our names service keeps the name; your machine's public key, whose private half stays on your machine; its public IPv4 and IPv6 addresses; when it was claimed and last refreshed; and the records for your servers' ports. The name and its address are published in public DNS, through Cloudflare, as any address is. A name not refreshed for 30 days stops working, and 60 days later anyone can take it. A name you release is held from others for 30 days.
- Certificates. Your machine gets its certificates from Let's Encrypt, with no email address unless you set one.
- Other services your machine uses: for normal running, Docker Hub, PaperMC and Mojang, for server software, and Mojang for players' faces and to check the names you invite; when you browse add-ons, Modrinth and Hangar, and CurseForge; when you set up your own domain, Cloudflare's and Google's DNS lookups; and only if you connect them, Discord, Hetzner, Whop and backup storage elsewhere. Crash reports stay on your machine, and the software turns off Paper's own usage reporting (bStats).
4. Playkeeper Cloud
Here we run the machines, so we hold what running your servers needs.
- Your account: your username, and a password stored only as an argon2id hash; your two-factor secret, and recovery codes stored only as hashes; and the tokens you give AI agents, stored only as hashes. A session cookie,
__Host-playkeeper, keeps you signed in, for up to 12 hours idle and 7 days in all. - The audit log: who did what and when, such as starting a server or changing a setting. It keeps no IP address, and entries are deleted after a year.
- If you bought through Whop: your Whop user ID and username, the store you bought from, and your plan and its state. Signing in with Whop asks Whop only who you are and your username. We don't read or keep your email address, or Whop's sign-in tokens. We keep the messages we send you in the store's Whop chat for 30 days after they're sent.
- Payments, for stores that sell through Playkeeper Cloud: each payment's ID, the buyer's Whop user ID, the plan, the amount, any refund and Playkeeper's share, and the fee lines Whop shows us, to check our share was paid. When your account is deleted, your payments stay in the store's accounts without your Whop user.
- Your servers: their files, which hold what Minecraft keeps, such as worlds, players' Minecraft names and UUIDs and what they carry, the allowlist, operators and bans, including banned IP addresses if you ban by IP. The console shows the last 2,000 lines, with IP addresses hidden, and servers don't log players' IP addresses; chat does appear in the console and the server's logs. Players' visits, their names, UUIDs and times, are kept 180 days for your server's charts. Players' faces come from Mojang and are reused for 12 hours before they're fetched again. Backups hold worlds, player data and settings, not logs, and are kept as your backup rules say. Copies elsewhere are encrypted before they leave the machine, to storage you choose.
- Friends who ask to join: their Minecraft name, and their network address while the request waits. It's cleared once you answer.
- Your public server page is on unless you turn it off. It shows who's playing only if you turn that on.
- Our alerts: the dashboard posts about our machines and servers in a private channel of the Playkeeper Discord. A post can name your server and its players, a friend asking to join, or a team member whose two-factor sign-in changed.
- When your plan ends, your servers stop, and you can still sign in and download backups. 14 days later the servers are deleted, and a final backup is kept 30 more days. 30 days after your servers are deleted, your account and its records are deleted too. You can ask us to delete your account sooner; if you still have a plan, cancel it on Whop first.
- Who sees what: you and your team; for a store's customers, the store's seller, who sees your Whop username, your plan, since when you're a customer, and your status; and Playkeeper, to run the service. No other seller sees you. If we suspend you, the seller sees only that you're suspended, not why.
- Stores that sell through Playkeeper Cloud. If you bought your plan from another store on Whop that sells through Playkeeper Cloud, that store decides how your data is used, and we handle it for them, as our seller terms set out. Ask the store about your data. If you write to us, we pass your request on and help them answer. We still decide ourselves on what we keep for our own purposes: the payment records that show our share was paid, the audit log, and what keeps the service safe.
5. Sellers who connect Playkeeper Cloud
- About your store: your business's Whop ID, name and address, and your plans and prices.
- Playkeeper's share: Playkeeper is your revenue share partner on Whop.
- Your store's payments: for your earnings, and to check our share.
- Your team: your page inside Whop checks with Whop, each time, that the person looking is on your business's team.
- Accepting our seller terms: who ticked the box (their Whop user), when, and which version, kept with your store's record.
- Your customers' data: we handle it for you, as our seller terms set out.
6. Who we share personal data with
We don't sell personal data. We use:
| Who | For | Where |
|---|---|---|
| Hetzner Online | the servers behind playkeeper.io, its visit counting, the stats and names services, and Playkeeper Cloud | EU |
| Cloudflare | DNS for playkeeper.io and playkeeper.me, and the store sites | USA |
| Whop | payments, sign-in, store data and messages to customers | USA |
| Discord | the alerts in our Discord, and for software you run yourself, only if you connect it | USA |
| GitHub (Microsoft) | releases and the star count | USA |
| Mojang (Microsoft) | server software, players' faces, checking player names | USA |
| Backup storage | only if you connect it | where you choose |
7. Transfers outside the EU
Cloudflare, Discord, GitHub and Mojang are certified under the EU–US Data Privacy Framework. Whop protects transfers with the European Commission's standard contractual clauses.
8. Why we may use it
- To give you what you signed up for: your Cloud account and servers, their backups, messages about them, sign-in and free names, and for sellers, what our seller terms promise.
- Our legitimate interests, which you can object to: counting visits and installs without cookies; keeping the service secure, with the audit log and limits on how often things can be tried; alerts that keep our machines running; and usage stats, which you can turn off.
- The law: records we must keep, such as for tax.
For a store's customers, the store decides why their data is used, and we follow its instructions.
9. How long we keep it
| What | How long |
|---|---|
| Install script logs (IP address, user agent) | 30 days |
| Counts of install command copies | 400 days |
| Visit counting | no IP address; after a day, nothing that can be tied back to you |
| Usage stats | 400 days after a machine's last report |
| A free name, with its IP addresses | until 30 days after it's released, or 90 days after its last refresh |
| Signed-in sessions | 12 hours idle, 7 days at most |
| Audit log | 1 year |
| Messages sent in Whop chat | 30 days after sending |
| Players' visits to a Cloud server | 180 days |
| Players' faces | 12 hours, then fetched again |
| A Cloud server after its plan ends | 14 days, then a final backup for 30 more |
| A Cloud account after its servers are deleted | 30 days |
| Payments | while you're a customer, then without your Whop user |
10. Your rights
You can ask for a copy of your data; have it corrected, deleted or used less; take it elsewhere; and object to what we do for our legitimate interests. Write to me@siya.digital. We answer within a month. You can also complain to Cyprus's Commissioner for Personal Data Protection, or to the authority where you live.
11. Children
Playkeeper Cloud accounts are for people aged 14 or older, and under 18 only with a parent's or guardian's agreement, as Whop's terms also ask. Servers our customers run may have younger players, whose Minecraft names and UUIDs the servers keep, as every Minecraft server does.
12. Keeping it safe
- Passwords are argon2id hashes, and tokens and recovery codes are stored only as hashes.
- Connections use HTTPS.
- Backups sent elsewhere are encrypted first.
- Consoles hide IP addresses.
13. Our channels
We talk about Playkeeper in the Playkeeper Discord and on X. What you post there is seen by us and others there, under Discord's and X's own policies.
14. Changes
We date each version here and say what changed. When it changes, customers and sellers also see a notice on their pages.