SYNC
LEGAL

Privacy Policy

This policy explains how YugiSMP handles information across the website, accounts, forum, Minecraft network and YugiCore API.

Effective: October 3, 2026 · Last updated: October 3, 2026

1. Scope and operator

YugiSMP is a United States-based Minecraft community. This policy covers yugismp.net, api.yugismp.net, YugiSMP accounts, the Minecraft network, forum and developer services. YugiSMP is not affiliated with Mojang Studios or Microsoft.

2. Information we process

  • Account data: display name, email address, email-verification status, Discord identifier and avatar, linked Minecraft username and account creation time.
  • Security data: a one-way password hash, encrypted authenticator secret when 2FA is enabled, signed session data, verification-code hashes, login/security events and Cloudflare Turnstile verification results. We do not intentionally store plaintext passwords or complete API keys.
  • Community data: forum posts, replies, moderation records, support messages and notifications.
  • Minecraft data: username, UUID, avatar, server presence, gameplay events, achievements, team name and public statistics such as money, gems, kills, deaths, playtime and spawners.
  • Developer data: project descriptions, websites, repositories, requested scopes, API usage, request routes, response status and timestamps.
  • Technical data: IP address, browser information, request metadata, cookies and security logs supplied through normal network requests.

3. Sources

Information comes from you, Discord when you authorize login, YugiSMP Minecraft servers, approved integrations, your browser, API requests and security providers such as Cloudflare Turnstile. Discord and Cloudflare process information under their own policies.

4. Purposes and legal grounds

We use information to create and secure accounts, send verification and security emails, provide the forum and player statistics, review API applications, enforce scopes and rate limits, prevent abuse, operate notifications, troubleshoot failures, moderate content and comply with law. Where a legal basis is required, we rely on our agreement with you, legitimate interests in operating and securing the Services, legal obligations and consent where requested.

5. Public information

Player names, linked Minecraft usernames, selected gameplay statistics, achievements, leaderboard positions, forum content and approved project details may be public or returned through approved APIs. Do not publish private information in public areas.

6. Service providers and disclosures

We may share necessary information with infrastructure, hosting, database, email-delivery and security providers; Discord for Discord login; Cloudflare for human verification; approved API developers according to granted scopes; moderators; and authorities when legally required. SMTP providers process recipient addresses and email content to deliver verification messages. We do not sell personal information or share it for cross-context behavioral advertising.

7. International processing

Services are operated from the United States. Information may be processed in the United States and countries where providers operate, which may have different data-protection laws.

8. Retention

We retain information only as reasonably needed to operate and secure the Services, resolve disputes and meet legal requirements. Sessions expire after seven days. Verification codes expire after ten minutes and are marked consumed after use. Account, forum and project records may remain while the account or content is active. Security and API logs may remain longer when needed to investigate abuse. Backups may retain deleted data for a limited period.

9. Your rights

Depending on your location, you may request access, correction, deletion, portability or restriction, or object to certain processing. California residents may request to know, correct or delete covered information and exercise rights without discrimination. We do not sell personal information. Some records may be retained for security, legal compliance, free expression or the rights of others. Submit requests through the official support channel on yugismp.net or the official Discord; identity verification may be required.

10. Children

The Services are not directed to children under 13. Users under the age of majority should have permission from a parent or guardian. If we learn that information was collected from a child under 13 without valid authorization, we will take reasonable steps to delete it.

11. Security

Safeguards include password hashing, encrypted SMTP, Turnstile and TOTP secrets, signed HTTP-only sessions, hashed API keys, access controls, server-side CAPTCHA validation and request validation. No system is completely secure. Keep passwords, authenticator recovery information and API keys private.

12. Changes and contact

We may update this policy and announce material changes through the Services. Privacy questions and requests can be submitted through the official YugiSMP support channel or official Discord.