This Privacy Policy explains how the operator of PharoGames ("we", "us", "our") collects, uses, shares, and protects your personal information when you use the PharoGames network.
PharoGames is a cloud-native Minecraft minigames network operated by an individual based in Canada. PharoGames is not a formally registered company; legal references to a controller mean the operator of PharoGames. Our hosting and processing infrastructure is a self-hosted Kubernetes cluster located in the United States, so your data is stored and processed in the US.
This policy covers the entire PharoGames network:
- Website — pharogames.net (accounts, forums, store, support).
- Game servers — Java IP
play.pharogames.net. - Discord —
discord.gg/pharogames(as it relates to account linking).
NOT AN OFFICIAL MINECRAFT SERVICE. NOT APPROVED BY OR ASSOCIATED WITH MOJANG OR MICROSOFT.
Privacy contact: For any privacy question or data-rights request, email privacy@pharogames.net. For general or billing help, email support@pharogames.net.
2. Information We Collect
We collect only what we need to run the network, secure it, and process purchases. Below is a complete, honest inventory by category.
2.1 Account & Login
| Data | Notes |
|---|---|
| Email address | Used for login, verification, and transactional email. |
| Password | Stored only as a bcrypt hash (cost factor 10). We never store or see your plain-text password. |
| Internal user UUID | Our internal identifier for your account. |
| Roles / permissions | Determines your access level (player, staff, etc.). |
| Created / updated timestamps | Account lifecycle metadata. |
2.2 Social Login (OAuth) — only if you choose it
If you sign in with a social provider, we receive and store:
- Google —
sub(subject) id; GitHub — numeric account id; Discord — snowflake user id. - The email address and display name supplied by that provider.
- The linked-at timestamp.
Your password and login credentials for these providers stay with the provider — we never see them.
2.3 Minecraft & Discord Linkage
- Minecraft UUID and username, and short-lived one-time link codes used to verify the link.
- Discord user id and username when you link Discord.
2.4 Gameplay & Profile
Your player profile may include:
- Per-game stats (kills, wins, deaths, etc.), XP, Coins, Gems.
- Owned cosmetics, owned/selected kits, ranks, battle-pass progress, max killstreaks, vote stats.
- An optional display nickname ("nick" / disguise).
- Join and last-played timestamps.
2.5 Match History
- Per-match records of games you play.
2.6 Leaderboards
- Leaderboards are computed in Redis and are ephemeral — they are derived rankings, not a durable personal record.
2.7 Community
- Forum threads and posts — these are public and are searchable.
- Poll votes.
- Support tickets and their messages — these may contain whatever personal information you choose to type.
- In-app notifications.
- Friend relationships, blocks, and online/offline presence.
About presence and social data: Your online/offline presence is transient, real-time state — we surface it live to other users (for example, to your friends) and do not maintain it as a historical log. In-app notifications, friend relationships, and blocks are kept with your account until you delete it (see Section 7).
2.8 Moderation & Audit
- Moderation records — bans, mutes, kicks, warnings, and player reports, including reason text and the identities of both the target and the moderator.
- Audit events — a security/admin event log of sensitive web actions (login, password reset, account linking) and staff/moderator actions, including the actor's IP address.
About IP addresses: Security audit events are the only place we store an IP address. Our website page counts use your IP address — they combine it with your browser's user-agent string and a secret to produce the short-lived daily code described in Section 2.12 — but the address itself is discarded in the same operation and is never stored, never logged, and never sent anywhere. We do not collect or log IP addresses for ordinary in-game connections.
2.9 Purchases & Payment
- Order records — internal user id, Minecraft UUID, gift-recipient Minecraft UUID (for gifts), items purchased, amounts, currency, coupon code, status, and timestamps.
- Processor identifiers — Stripe checkout session id, payment-intent id, subscription id and refund id, or the equivalent PayPal order, capture, subscription and refund ids.
- Refund requests — reason, your message, and admin notes.
Card data is handled solely by our payment processors. Full payment card and payment-instrument data is processed exclusively by Stripe or PayPal under PCI-DSS and never touches PharoGames servers. Your billing email is given to that processor and is not stored by PharoGames.
2.10 Chat, Direct Messages & Voice
Text chat & direct messages. To keep the community safe and enforce our rules, in-game text chat and direct messages may be logged, retained, and reviewed — including by automated and AI-assisted moderation systems. We may use this content to detect and act on abuse, harassment, cheating, and other rule or legal violations, and to handle reports and appeals.
In-game voice is always recorded. When you use in-game voice chat, all of your voice transmissions are recorded — automatically and for every speaker, not only when a report is made. We record voice for two purposes: (1) moderation — to investigate reports of harassment, threats, hate speech, and other rule violations, and (2) match replay — so audio can be aligned with a match for review. Recording is on by default whenever voice chat is active; if you do not want to be recorded, do not transmit on in-game voice.
Voice is transcribed to text for moderation. Recorded voice is converted to text by an automated speech-to-text system, and that text is checked by the same automated moderation that reviews in-game chat. Two things follow from this, and we want to be direct about both. First, the audio is sent to a GPU compute provider to be transcribed — Runpod or DeepInfra, both listed in Section 6.1 — with no account, email, Minecraft, or Discord identifier attached, so the provider receives audio and a meaningless random reference. Which of the two handles a given clip does not change what is sent. The audio is still a recording of your voice, and anything said aloud in it travels with it. That transcription copy is held for up to 7 days so a failed run can be retried, then deleted automatically; it stays unlinked to your identity for as long as it exists, and it does not extend how long the original recording is kept. Second, the resulting transcript is sent to OpenAI for safety classification, exactly as your text chat already is. See the sub-processor table in Section 6.1.
A human decides. Automated flagging does not by itself punish anyone. A flagged transcript is put in front of a human moderator, together with the audio it came from, and a person decides what happens. You are not subject to a decision based solely on automated processing that produces a legal or similarly significant effect.
No biometrics. We do not generate, store, or use a voiceprint or any other biometric identifier from your audio. We do not use voice recordings to identify, profile, or track you beyond the moderation and replay purposes above. Transcription converts what was said into text; it does not analyze or model who is speaking from the sound of their voice.
Retention. Voice recordings are kept on a defined schedule:
- Ambient recordings (ordinary captured audio not tied to a report or action) are retained for about 21 days, then automatically deleted.
- Transcripts are retained on the same schedule as the recording they came from, and are deleted with it. A transcript of ambient audio does not outlive the 21-day window; a transcript attached to a case follows the evidence timeline below.
- The copy prepared for transcription — speech audio with no identifier attached, sent to a GPU compute provider (Section 6.1) — is held for up to 7 days so a failed run can be retried, then automatically deleted. It never outlives the ambient window and does not extend it.
- Evidence — voice clips or segments attached to a player report, moderation action, or appeal — are retained longer, for up to about 366 days, so we can act on them, defend appeals, and meet our legal obligations. They are deleted once they are no longer needed for those purposes.
We do not use the content of your messages or voice for advertising, and we do not sell it. In-game voice chat runs on the game servers, which anyone with a Minecraft account may join — it does not require a PharoGames website account (see Section 9). You must be at least 13 to transmit on in-game voice. We do not knowingly record a child under 13; if we learn that we have, we delete that audio promptly. If you are a parent or guardian and believe your child under 13 has been recorded, contact privacy@pharogames.net and we will remove the recordings.
2.11 Creator Channel Linking (Twitch & YouTube)
If you connect a streaming channel to earn the in-game Media rank, we collect and store only:
- YouTube — your YouTube channel ID, channel title, and the linked-at timestamp. We obtain these once, at link time, by calling the YouTube Data API
channels.listwith your authorization, solely to confirm you own the channel. We do not retain any Google or YouTube access or refresh token — the authorization is used once and discarded. We then periodically read your channel's public subscriber count using a server-side API key to keep your eligibility current. - Twitch — your Twitch user id (and login), used the same way to read public viewership statistics.
We use this data for one purpose: to automatically grant or revoke the cosmetic Media creator rank based on public channel size. When you unlink a channel — or delete your account — we delete the stored channel identifier promptly (within 7 days). See Section 12.1 for the YouTube API Services disclosures, including how to revoke access.
2.12 Website Analytics
We count page views on pharogames.net so we can see which pages people actually use, where visitors come from, and whether the site is fast. It runs on our own servers. There is no Google Analytics, no ad pixel, no third-party analytics service, and no tag from anyone else.
What we record for each page view
- The page, as a route pattern rather than the address you visited — a player profile is recorded as
/stats/[username], never as the username. - A session identifier that exists only in the memory of the open page. It is a random number, it is not written to your device, and it disappears when you close the tab or reload.
- A daily visitor code (see below).
- Your referrer's website name only —
google.com, not the search you typed or the address you came from. - Campaign labels (
utm_source,utm_medium,utm_campaign,utm_content) when a link carries them, and a yes/no flag for whether the link came from a paid ad click. The advertising click id itself is discarded without being read. - Your device type (desktop, mobile or tablet), browser family, operating system family, primary language and window width.
- Three named actions: copying the server IP, clicking a Discord invite, and starting a store checkout.
- Page speed measurements (the standard Core Web Vitals) and how long the page was in the foreground.
The daily visitor code, described honestly. To count how many different people visited on a given day without identifying anyone, we combine your IP address, your browser's user-agent string, our site name and a secret that changes every 24 hours, and keep only a short code derived from that. The IP address and the user-agent string are discarded immediately and are never stored next to the code.
This is a pseudonym, not anonymity, and we would rather say so than overstate it. We hold the secret, so we could in principle recompute a past day's code. What is true is that the code changes every day, that it is not stored alongside the information it came from, that it is deleted with the rest of the raw records after 90 days, and that it is never linked to your account, your email, your Minecraft UUID, your Discord id, or anything else about you. There is no key that would let us join these records to your player profile, and we do not create one.
What we never record here
- No cookie, and nothing in
localStorage,sessionStorageor any other browser storage — we neither write to nor read from your device. - No IP address, and no user-agent string.
- No full web address and no query string. We keep only the allowed campaign labels above; everything else in a link, including the tokens our password-reset and email-verification links carry, is discarded without being read.
- Nothing at all from the pages where you would be typing something personal: /admin, /staff, /appeal, /support/tickets, /profile and /auth are excluded entirely, on both the page and the server.
- No account id, email, Minecraft UUID, Discord id or username.
- No location, no advertising profile, no cross-site tracking, no session recording or heatmaps.
Who sees it. Nobody outside PharoGames. These records are stored on our own infrastructure and are not shared with, sold to, or processed by any third party.
How long we keep it. Individual records are deleted automatically after 90 days (page speed measurements after 30 days). What remains after that is daily totals — counts only, with no session identifier, no visitor code and nothing about an individual — which we keep so we can compare one month with another.
Turning it off. If your browser or an extension sends a Global Privacy Control or Do Not Track signal, we record nothing at all. See Section 8.
3. How We Use Your Information
We use your information for the following purposes, and only these:
| Purpose | What it involves |
|---|---|
| Authentication | Creating and securing your account, verifying email, signing you in (including via social login). |
| Running the games | Operating game servers, tracking stats/XP/currencies, managing kits, cosmetics, ranks, battle pass, leaderboards, and match history. |
| Processing payments | Completing purchases through Stripe, recording orders, and managing auto-renewing Rank subscriptions. |
| Delivering & restoring purchases | Granting purchased items, ranks, gems, and cosmetics, and restoring them on your account. |
| Moderation & safety | Enforcing rules via bans, mutes, kicks, warnings, and player reports to keep the community safe. Includes automated screening of chat, direct messages, and voice transcripts, with human review before any punishment (see Section 4). |
| Security, fraud prevention & audit | Detecting abuse, preventing ban evasion and payment fraud, and keeping a tamper-evident audit log. |
| Transactional email | Sending verification, password-reset, and notification emails. |
| Support | Responding to support tickets and refund requests. |
| Website analytics | Counting page views on our own servers to see which pages and features are used, where visitors arrive from, and whether the site is fast — described in full in Section 2.12, with the legal basis in Section 4 and the opt-out in Section 8. |
4. Legal Bases for Processing (GDPR / UK-GDPR)
If you are in the EU or UK, we rely on the following legal bases for each purpose:
- Performance of a contract — to create and secure your account, run the games you play, process purchases and auto-renewing Rank subscriptions, and deliver the services you request. Social login is also processed on this basis: when you choose to sign in with Google, GitHub, or Discord, that identity check is part of providing the account you asked for. (If you withdraw a social-login connection, that sign-in method will stop working and you may need an email/password login to keep access — the account itself does not rely on ongoing consent.)
- Legitimate interests — to secure the network; moderate the community; prevent fraud, payment abuse, and ban evasion; maintain audit logs; understand how our own website is used through the storage-free, aggregate page counts in Section 2.12; and retain anonymized order and ban records after account deletion for chargeback defense, fraud prevention, and ban-evasion prevention. We balance these interests against your rights. For the website analytics specifically, the balance rests on it storing nothing on your device, building no profile, and being switched off entirely by a Global Privacy Control or Do Not Track signal (Section 8).
- Legal obligation — to retain order and tax-related records for the period required by law and to respond to lawful requests.
- Consent — for the limited cases where the law requires it (for example, optional features you choose to enable). Where consent is the basis, you may withdraw it at any time.
PIPEDA (Canada): For Canadian users, we collect, use, and disclose personal information based on your consent (express or implied, as appropriate) and for purposes a reasonable person would consider appropriate in the circumstances. By using PharoGames you consent to the practices described in this policy. Cross-border handling of Canadian personal information is described in Section 10.
Automated processing and human review (GDPR Article 22). We use automated systems to screen chat, direct messages, and transcripts of in-game voice for content that may break our rules. These systems flag content; they do not decide your punishment. A flagged item is reviewed by a human moderator, who sees the content in context and makes the call. We do not subject you to a decision based solely on automated processing that produces legal effects or similarly significantly affects you.
One narrow exception, so this is not overstated: an automated system may remove or withhold a single message before a human sees it. That is reversible, it does not restrict your account, and it does not end your access to the service. Every actual punishment — a mute, a kick, or a ban — is issued by a person. You can contest any moderation outcome by appealing in-game or emailing support@pharogames.net, and you may ask for a human to look again.
5. Cookies & Similar Technologies
PharoGames uses only three cookies, all strictly necessary:
| Cookie | Purpose | Notes |
|---|---|---|
next-auth.session-token | Your signed login session | httpOnly |
next-auth.csrf-token | Cross-site request forgery (CSRF) protection | — |
discord_oauth_state | Short-lived CSRF protection for Discord account linking | Temporary |
We use no analytics cookies, no advertising or marketing cookies, and no third-party tracking pixels or technologies.
Our website analytics is cookieless and storage-free. The page counting described in Section 2.12 runs on our own servers. It sets no cookie and reads no cookie. It writes nothing to localStorage, sessionStorage, IndexedDB or any other browser storage, and it reads nothing from them either — including any preference of yours, which is why the opt-out in Section 8 is a signal your browser sends rather than a setting we store on your device. Its session identifier exists only in the memory of the open page and is gone when you close the tab.
Because every cookie we set is strictly necessary to deliver the service you request, and because our analytics neither stores information on your device nor gains access to information stored there, no cookie consent banner is required under EU/UK rules — there is still nothing optional to consent to.
6. How We Share Information
We do not sell or share your personal data for advertising or cross-context behavioral purposes. We share data only with the service providers (sub-processors) needed to run PharoGames, and only the minimum required. Otherwise, we disclose personal information only where necessary to comply with the law, enforce our terms, or protect the safety of our users and the network.
6.1 Sub-Processors & Data Recipients
| Recipient | What they receive | Why |
|---|---|---|
| Stripe, Inc. | Line items, amounts, billing email, order metadata, and all card data | Payment processing; handles all card data under PCI-DSS. |
| PayPal | Line items, amounts, billing email, order metadata, and all payment-instrument data | Payment processing for PayPal, wallet methods (Apple Pay, Google Pay) and local methods (iDEAL, Bancontact, BLIK, eps, Przelewy24); handles all payment-instrument data under PCI-DSS. |
| Google / Discord / GitHub | OAuth identity assertion (provider id, email, display name) | Identity providers — only if you choose social login. |
| Google — YouTube API Services | A one-time channel-ownership authorization (your YouTube channel id and title) | Confirming you own the YouTube channel you link, to grant the Media rank — only if you connect YouTube. No Google token is retained. |
| Twitch | Your Twitch user id and login | Confirming channel ownership and reading public viewership stats — only if you connect Twitch. |
| Resend | Recipient email address and the contents of transactional messages, which may include your username, verification and password-reset links/tokens, and notification text | Transactional email delivery (verification, password reset, notifications). |
| Mojang / Microsoft API | Minecraft username and/or UUID | Resolving Minecraft username ↔ UUID. |
| mc-heads.net | Your Minecraft UUID (embedded in image URLs) | Rendering Minecraft player skins/heads for display. |
| Cloudflare | Voice recordings, match replay files, maps, and resource packs, stored as encrypted objects | Object storage for large media. This is where voice recordings and replays physically live (see Section 6.2). |
| OpenAI | The text of in-game chat, direct messages, and transcripts of in-game voice, plus images posted to moderated surfaces | Automated content moderation. Text and transcripts are submitted for classification only — we ask whether content violates a safety category and receive scores back. We do not use OpenAI to generate content about you or to make an automated decision that has a legal or similarly significant effect (see Section 4). |
| Runpod | Audio only. Speech audio is sent for transcription with no account, email, Minecraft, or Discord identifier attached — each clip is labelled with a random job-local reference that is meaningless outside our systems. The audio is still a recording of your voice, and anything said aloud in it travels with it | GPU compute for speech-to-text. The copy of the audio prepared for transcription is held in our storage for up to 7 days so a failed or incomplete run can be retried, then automatically deleted. We attach no identifier to it while it is there. |
| DeepInfra | Audio only. Speech audio is sent for transcription with no account, email, Minecraft, or Discord identifier attached — each clip is labelled with a random job-local reference that is meaningless outside our systems. The audio is still a recording of your voice, and anything said aloud in it travels with it | GPU compute for speech-to-text, doing the same job as Runpod, and what we send is identical either way. The reference → account mapping stays in our database and is never sent. DeepInfra states that input to its inference API is not stored to disk and exists in memory only while the request is being processed, and that it generally does not log the content of requests. It also reserves the right to log a small portion of requests when necessary for debugging or security purposes, so a small sample of the audio we send may be retained by DeepInfra for that purpose. DeepInfra also states that it does not use data submitted to its APIs to train models, except when Google or Anthropic models are used. The speech-to-text model we run there is neither, so that exception does not apply to your audio. Any copy of the audio we prepare for transcription is held in our storage for up to 7 days so a failed run can be retried, then automatically deleted. |
These recipients act as our service providers/processors: they process the data only to perform the service we have engaged them for, not for their own independent purposes.
6.2 Internal Infrastructure
The following components run on our own US Kubernetes cluster and process data on our behalf — they are part of PharoGames, not independent third-party recipients:
- MongoDB — primary data store.
- Redis — ephemeral state and leaderboards.
- NATS — internal messaging.
One exception worth naming plainly: large media — voice recordings, match replay files, maps, and resource packs — is not stored on that cluster. It is stored as encrypted objects with Cloudflare, listed as a sub-processor in Section 6.1. Everything else described in this policy is on our own infrastructure.
6.3 Legal & Safety Disclosures
We may disclose information when we reasonably believe it is necessary to comply with a legal obligation, enforce our terms, investigate fraud or abuse, or protect the rights, property, or safety of our users, the public, or PharoGames.
7. Data Retention
We keep personal information only as long as needed for the purpose it was collected, then delete or anonymize it. Concrete limits:
| Data | Retention |
|---|---|
| Match history | 90 days, then auto-deleted |
| Audit events (including IP addresses) | 30 days, then auto-deleted |
| Voice recordings — ambient (not tied to a report/action) | ~21 days, then auto-deleted |
| Voice transcripts | Same schedule as the recording they came from; deleted with it |
| Voice audio copy prepared for transcription (no identifier attached) | Up to 7 days, then auto-deleted |
| Voice recordings — evidence (tied to a report, action, or appeal) | Up to ~366 days, then deleted when no longer needed |
| Website analytics — page views, named actions and visit records (Section 2.12) | 90 days, then auto-deleted |
| Website analytics — page speed measurements | 30 days, then auto-deleted |
| Website analytics — daily totals (counts only; no session identifier, no visitor code, nothing about an individual) | Retained indefinitely |
| Email verification token | 24 hours |
| Password reset token | 1 hour |
| Account-link codes | ~5 minutes |
| Leaderboards | Ephemeral (Redis) |
| Online/offline presence | Transient real-time state; not kept as a historical log |
| Account, player profile, forum content, support tickets, moderation records, in-app notifications, friends, blocks | Retained until you delete your account (subject to legal-minimum retention) |
| Order / payment records | Retained longer (tax, chargeback defense, fraud prevention); kept in anonymized form after account deletion |
| Ban records | Retained longer (ban-evasion prevention); kept by Minecraft UUID in anonymized form after account deletion |
When you delete your account, we erase your personal data and keep only the legal minimum described above.
8. Your Rights & Choices
Depending on where you live, you have some or all of the following rights. We honor these rights for all users wherever practical.
- Access & portability — request an export of the personal data we hold about you. Your export includes time-limited download links for any voice recordings we still hold for your account, and any transcripts of them.
- Deletion / erasure — delete your account. We erase your personal data — including your ambient voice recordings and their transcripts — and retain only the legal minimum (for example, anonymized order records for tax and chargeback purposes, ban records keyed to a Minecraft UUID for ban-evasion prevention, and any voice clips already attached to a report, moderation action, or appeal, which are kept in redacted form for as long as needed for that purpose).
- Correction / rectification — fix inaccurate or incomplete data.
- Objection / restriction (GDPR/UK-GDPR) — object to or restrict certain processing based on legitimate interests.
- "Do Not Sell or Share" (CCPA/CPRA) — PharoGames does not sell or share personal data for advertising or cross-context behavioral purposes, so there is nothing to opt out of; we honor the right regardless.
- Opt out of website analytics — see the next paragraph. It takes effect immediately and costs you nothing else on the site.
Website analytics choices, and our Do Not Track disclosure. The page counting in Section 2.12 is switched off completely — nothing is sent and nothing is recorded — when your browser tells us you object. We honor two signals, and they are legally distinct: Global Privacy Control (Sec-GPC), which is a legally recognized opt-out request in California, Colorado and Connecticut, and Do Not Track (DNT), which is a stated preference rather than a legal instruction. We treat either one as a complete opt-out. Most browsers offer GPC natively or through an extension; Do Not Track lives in your browser's privacy settings. We deliberately do not offer a stored opt-out setting instead: saving one would mean writing to and reading from your device, which is the exact thing this design avoids.
How to exercise your rights: Use your account settings for self-serve actions (export and deletion), and/or email privacy@pharogames.net. We respond within 30 days (see Section 8.1 for California's 45-day standard). We will never retaliate or discriminate against you for exercising your rights. If we cannot fulfill a request, we will explain why, and you may appeal by replying to our response or contacting privacy@pharogames.net.
Payment data held by our payment processors. Some payment information — your billing email and your card or PayPal account data — is held by Stripe or PayPal, whichever processed your purchase, under that company's own privacy policy, not by PharoGames. We cannot access, export, or delete data we never store. To exercise rights over that data, please contact that processor directly. We can still act on the order records we keep (described in Section 2.9).
8.1 California Privacy Rights (CCPA / CPRA)
This section provides the disclosures required for California residents and serves as our Notice at Collection.
Categories of personal information we collect. In the past 12 months we have collected the following CCPA categories. For the specific data points in each, see the inventory in Section 2.
| CCPA category | Examples in PharoGames | Collected? |
|---|---|---|
| Identifiers | Email, internal user UUID, Minecraft UUID/username, Discord/Google/GitHub ids, IP address (stored only for security audit; used but not stored to derive the daily analytics code in Section 2.12), the in-memory website session identifier and daily visitor code | Yes |
| Customer records / account info | Password (bcrypt hash), display name, account timestamps | Yes |
| Commercial information | Order records, items purchased, amounts, coupon codes, refund requests, owned items/ranks/cosmetics | Yes |
| Internet / network activity | Login and security-audit events, in-app notifications, forum/poll activity, and first-party website analytics — pages viewed as route patterns, referring website name, campaign labels, device/browser/OS type and page speed (Section 2.12; no cookies, no device storage, no third party) | Yes |
| Geolocation | We do not collect precise geolocation | No |
| Audio / visual | In-game voice chat is recorded for all speakers and transcribed to text (no voiceprint/biometric), and text chat/DMs are logged, for moderation and replay (see Section 2.10) | Yes |
| Professional / employment / education | Not collected | No |
| Inferences (profiles) | We do not build advertising or behavioral profiles. Our website analytics produces daily counts, not a profile of any individual, and is never joined to an account | No |
| Sensitive personal information | Account log-in credentials (email + password hash) | Yes (limited) |
Business / commercial purposes for collection. We use these categories to authenticate you, run the games, process payments and subscriptions, deliver and restore purchases, moderate for safety, prevent fraud and ban evasion, send transactional email, and provide support — as detailed in Section 3.
Sensitive personal information. We use sensitive PI (your login credentials) only for the permitted purpose of providing and securing the service. We do not use or disclose sensitive PI to infer characteristics or for any purpose that would trigger the right to limit beyond these permitted uses, and we do not sell or share it.
Categories disclosed to service providers (past 12 months). We disclosed identifiers, customer/account information, commercial information, internet/network activity, and audio/visual information to service providers strictly to perform services for us (see the sub-processor table in Section 6.1 — Stripe, PayPal, the OAuth providers, Resend, Mojang/Microsoft, mc-heads.net, Cloudflare, OpenAI, and Runpod). DeepInfra was added to that table on August 19, 2026 for the same speech-to-text purpose and received no data before that date. We disclosed these for the business purposes in Section 3. The website analytics records described in Section 2.12 are an exception in the other direction: they are disclosed to no one, and no recipient in that table receives them.
No sale or sharing. In the past 12 months we have not sold and have not shared (for cross-context behavioral advertising) any category of personal information, and we do not do so. We have no actual knowledge of selling or sharing the personal information of minors under 16.
Your California rights. As a California resident you have the right to:
- Know / access the categories and specific pieces of PI we have collected, the sources, the purposes, and the categories of recipients.
- Delete the PI we have collected from you, subject to legal exceptions.
- Correct inaccurate PI.
- Opt out of the sale or sharing of your PI — though we do not sell or share it.
- Limit the use of sensitive PI — we already restrict it to permitted purposes only.
- Non-discrimination — we will not deny service, charge a different price, or provide a different quality of service because you exercised your rights.
How to submit and verify a request. Email privacy@pharogames.net or use your account settings. We verify your request by confirming control of your account (for example, via your verified email) and matching the request to the information we hold. We will respond within 45 days, and may extend once by a further 45 days where reasonably necessary, with notice to you.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written permission and may still ask you to verify your own identity directly.
9. Children's Privacy (COPPA + PIPEDA)
Anyone of any age may play the Minecraft game servers (Minecraft accounts are managed by Mojang/Microsoft).
Our website — including accounts, forum posting, support tickets, and purchases — is not directed to, and may not be used by, children under 13. You must be at least 13 to create a website account. When you register with an email address we ask for your date of birth and block under-13 sign-ups.
We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you are a parent or guardian and believe your child under 13 has provided us personal information, contact privacy@pharogames.net and we will remove it.
9.1 Minors and Purchases
Users under the age of majority in their jurisdiction must have a parent or guardian's permission to make purchases. Where a Rank is purchased as an auto-renewing subscription (a recurring charge), that permission must cover the recurring charge. A parent or guardian may cancel the subscription at any time through account settings or by contacting support@pharogames.net.
10. International Data Transfers
The operator of PharoGames is in Canada, and your data is stored and processed in the United States on our self-hosted infrastructure. If you access PharoGames from outside the United States — including from Canada, the EU, or the UK — your personal information will be transferred to and processed in the US.
There is no EU or UK adequacy decision covering this transfer, and the operator is not certified under the EU-US / UK-US Data Privacy Framework. We therefore rely on the mechanisms and safeguards below.
10.1 EU and UK Transfers (GDPR / UK-GDPR, Chapter V)
For personal data transferred from the EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs) as our Article 46 transfer mechanism. For personal data transferred from the UK, we rely on the UK International Data Transfer Addendum (IDTA) to the SCCs (or the standalone UK IDTA, as applicable).
We have carried out a transfer impact assessment considering the destination (US) legal environment and the nature of the data, and we apply supplementary technical and organizational measures to protect transferred data, including:
- Encryption in transit (TLS) for data moving between you, our services, and our sub-processors;
- Hashing of credentials (passwords stored only as bcrypt hashes; signed session tokens);
- Strict access controls limiting who can access personal data, and audit logging of sensitive actions;
- Data minimization and short retention windows (see Section 7).
Consent is not our primary transfer mechanism. We may rely on a derogation under Article 49 (such as your explicit consent, or necessity for performance of your contract) only in the limited, occasional cases the law permits, and never as a standing basis for systematic transfers.
You may request a copy of, or more information about, the relevant SCCs/IDTA by emailing privacy@pharogames.net.
10.2 Canadian Transfers (PIPEDA)
Under PIPEDA, transferring personal information to a service provider in another country for processing is a permitted "use," but it does not by itself reduce our accountability. We remain accountable for personal information sent to our US infrastructure, and we use contractual and technical measures to ensure a comparable level of protection while it is processed in the US. Because the data is stored in the US, it may be subject to lawful access by US authorities under US law. If you have questions about this cross-border handling, contact privacy@pharogames.net.
11. Data Security
We protect your data with industry-standard measures, including:
- bcrypt-hashed passwords (cost factor 10) — passwords are hashed at rest; we never store plain-text passwords.
- RS256-signed session tokens.
- httpOnly session cookies, so session tokens are not exposed to client-side scripts.
- TLS encryption in transit.
- Security headers — HSTS,
X-Frame-Options: DENY,X-Content-Type-Options: nosniff, and a strict referrer policy.
The encryption described above protects data in transit (TLS), and passwords are stored only as bcrypt hashes. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify affected users and any applicable regulators as required by law.
12. Third-Party Links & Services
PharoGames links to and integrates with third-party services — including Discord, Mojang / Microsoft, Stripe, PayPal, and (if you connect a creator channel) Google / YouTube and Twitch — that have their own privacy policies. This policy does not cover their practices; please review the privacy policy of any third-party service you use.
12.1 YouTube API Services
PharoGames' YouTube channel-linking feature uses YouTube API Services. By linking your YouTube channel, you also agree to be bound by the YouTube Terms of Service. Google's handling of your information is governed by the Google Privacy Policy.
What we access and why. When you link YouTube, we make a single authorized call to the YouTube Data API to read your channel's id and title, solely to confirm you own the channel before granting the cosmetic Media rank (see Section 2.11). We do not store any Google or YouTube access or refresh token, and we do not access your videos, comments, watch history, private account data, or anything beyond your channel id and title. Ongoing eligibility checks read only your channel's public subscriber count via a server-side API key.
Limited use. We use information obtained through YouTube API Services only to provide the Media-rank feature described above. We do not use it for advertising, do not sell it, and do not transfer it to third parties except as necessary to provide this feature, to comply with applicable law, or to protect against fraud or abuse.
Revoking access and deletion. You can revoke PharoGames' access to your Google/YouTube data at any time in your Google security settings. Because we never store a Google token, revoking there simply confirms the one-time authorization is gone; to remove the linked channel from PharoGames, use the unlink option in your account settings, which deletes the stored channel id. For any question or complaint about how this feature handles your data, contact privacy@pharogames.net.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice (for example, on the website or by email) before the changes take effect. The "Effective date" at the top reflects the latest version. Your continued use of PharoGames after an update means you accept the revised policy.
Change published August 19, 2026. We added DeepInfra to the sub-processor table in Section 6.1 as a second speech-to-text provider alongside Runpod, and reworded the passages that described our transcription provider in the singular. As of this effective date we have sent DeepInfra no audio. The change takes effect when we first send it audio, and publishing it now is the notice this section promises; we will record that date here. What a transcription provider receives does not change: speech audio labelled with a random reference, with no account, email, Minecraft, or Discord identifier attached, and the mapping from that reference back to an account stays in our database. Transcripts still share the retention of the recording they came from, and still appear in your account export and deletion.
Change made August 19, 2026 — we added website analytics. Until this date this policy said we ran no analytics of any kind, and that was accurate. We now count page views on pharogames.net using our own servers, and Section 2.12 sets out exactly what that records, what it deliberately does not, and how long it is kept. This is a material change, so here is the short version: it uses no cookie and no browser storage, no third party is involved and none receives the data, it builds no profile, it is never linked to your account or your Minecraft UUID, and it collects nothing at all on /admin, /staff, /appeal, /support/tickets, /profile and /auth. Your IP address is used to derive a daily code and then discarded rather than stored. If your browser sends Global Privacy Control or Do Not Track, nothing is recorded (Section 8). We also updated Sections 1, 2.8, 3, 4, 5, 7 and 8.1 so each of them reflects this, and corrected the summary in Section 1 that previously said we ran no analytics.
Corrections made July 31, 2026. We corrected an inaccurate description of who can use in-game voice chat: it runs on the game servers and does not require a PharoGames website account. We also narrowed our description of what our transcription provider receives, added PayPal to the sub-processor table and to every place this policy described payment handling, and clarified that the date-of-birth check at sign-up applies to email registration. None of these change what we collect, who we share it with, or how long we keep it.
14. Contact Us
For privacy questions or to exercise your rights:
- Privacy & data requests: privacy@pharogames.net
- General & billing support: support@pharogames.net
Canadian users may also contact the Office of the Privacy Commissioner of Canada (OPC) if they have unresolved concerns about how we handle their personal information.
EU and UK users may also lodge a complaint with their local data protection authority (DPA).
NOT AN OFFICIAL MINECRAFT SERVICE. NOT APPROVED BY OR ASSOCIATED WITH MOJANG OR MICROSOFT.