Privacy policy
Updated 29 September 2026Privacy policy
Who is responsible
The controller for the personal data described here is LuvvSum, an individual operating the Unfckd project from the Netherlands. You can reach the controller at luvvsum@aethrastudios.com. A postal address is available on request at that same address.
This policy follows the General Data Protection Regulation (GDPR) and the Dutch implementation of it. See also the legal notice.
What this policy covers
This policy covers two things.
- The website at unfckd.dev. A set of static pages with no login, no forms, and no comment box.
- unfckd-lite. The scanner you download and run yourself.
It also covers the Unfckd dashboard, which is in development. Signups are closed, so it holds no accounts beyond our own testing, but the account handling described below is what it does today. A section near the end covers what is still to come.
unfckd-lite sends nothing anywhere
unfckd-lite runs entirely on the machine you install it on. It reads manifest files in the resources folder you point it at and prints a report to your own console. It creates no account, opens no connection to us, and transmits no data about you, your server, your players, or your resources.
We therefore receive nothing when you run it, and we hold no personal data as a result of you using it. The source is published under GPL-3.0 at https://github.com/unfckd/unfckd-lite, so you can verify this rather than take our word for it.
What the website collects
Unless you accept analytics, the website collects nothing itself. It sets one cookie to remember your answer to the cookie banner, contains no tracking pixel, and requests no file from any other domain. The fonts are compiled into the site at build time, so your browser never contacts Google to load them. If you accept analytics, the section below applies as well.
Our hosting provider does keep standard server logs, which is unavoidable for any website. Those logs can include the following.
- Your IP address
- The page you requested and when you requested it
- Your browser user agent string
- The referring page, where your browser sends one
An IP address counts as personal data under the GDPR, so we treat it as such.
Why we are allowed to process it
The legal basis is our legitimate interest under Article 6(1)(f) GDPR. The interest is keeping the site online, delivering it to you, and detecting abuse such as denial of service attacks. We do not use these logs to build a profile of you, to advertise, or to identify you as an individual, and we do not combine them with anything else.
How long it is kept
Log retention is set by our hosting provider rather than by us. Their current retention period is described in their own documentation, linked below. We request no extended retention and we export nothing from those logs. Current retention as configured for this project is [CONFIRM RETENTION WITH VERCEL].
Analytics, if you accept it
The public pages use Google Analytics 4 to count visits and see which pages people read, so we know what to improve. It runs only if you accept it in the cookie banner. Until then the script is not loaded and your browser sends nothing to Google.
If you accept, Google Analytics records the following about your visit.
- The pages you view, when, and for how long
- The page that sent you here, where your browser reports one
- Your browser, operating system, device type and screen size
- Your approximate location at country and city level, which Google works out from your IP address
- A random identifier stored in a cookie, so repeat visits from the same browser can be counted as one visitor
According to Google, Google Analytics 4 does not log or store IP addresses. It uses the address to estimate your location and then discards it.
We keep it narrow on purpose.
- The dashboard is never tracked. Analytics does not run on any dashboard page, whatever you chose, so nothing about your account or your servers reaches Google.
- No advertising. Google signals and ad personalisation are switched off, so the data is not linked to your Google account and is not used for ads.
- No identity. We send no name, email or account identifier to Google, and we do not combine analytics with your dashboard account.
Why we are allowed to process it
The legal basis is your consent under Article 6(1)(a) GDPR, which Article 11.7a of the Dutch Telecommunications Act also requires before anything is stored on your device. You can withdraw it at any time from Cookie settings in the footer. Withdrawing stops analytics straight away and deletes its cookies. It does not affect processing that happened before you withdrew.
How long it is kept
Google keeps the analytics data for the retention period we set in Google Analytics, which is [CONFIRM GA4 DATA RETENTION, 2 OR 14 MONTHS]. The cookies themselves last 13 months from your last visit, as the cookie policy lists.
Dashboard accounts
If you have a dashboard account, we hold the following.
- Your email address and name. Used to identify the account and sign you in.
- A hash of your password. Never the password itself, so we cannot read it or recover it for you.
- Session records. A random session identifier, when it expires, and the IP address and browser user agent that created it, so you can be signed out everywhere if a session is stolen.
- Your avatar, if you choose one. A small square image, either one you upload or a copy of your Discord or Google picture. It is stored with your account and shown only to you. Choosing initials instead deletes it.
- The servers you add. The name, platform and environment you pick, plus a connect address and notes if you choose to add them. All of it is yours to choose and need not identify anything real, and we never connect to the address.
- A server activity log. When a server was created, renamed or changed, and when its keys were made or revoked, so you can see what happened to it. It is deleted with the server.
- API keys. Stored only as a hash, with a short readable prefix so you can tell one key from another.
If you sign in with Discord or Google
Choosing Discord or Google sends you to them to approve it. They then hand us your email address, your name and the address of your avatar, and we store the same fields listed above plus the account identifier they gave us. If you signed up through them, or later pick their picture as your avatar, our server downloads one copy of it and stores that instead of the address, so your browser never loads anything from Discord or Google while you use the dashboard. We never receive your password for either service, and we ask them for nothing beyond what is needed to create the account.
You can disconnect a provider at any time from your settings, as long as you keep one way of signing in. Disconnecting removes the link and the tokens we hold for it. What Discord or Google keep about the sign-in is governed by their own policies.
We process this to give you the account you asked for, on the basis of the contract between us under Article 6(1)(b) GDPR. Deleting your account deletes all of it, because every record above is tied to your user row and removed with it.
The dashboard sets one cookie, which keeps you signed in, and stores your theme choice in your browser if you pick one. It runs no analytics. The cookie policy describes both.
Who can see your data
The Unfckd project is run by one person, its founder, who holds the owner account. The owner account has exactly the same access as an administrator account and nothing more. An administrator can see a read-only list of every server across every account, which covers the server name and platform you chose, the account email it belongs to, the plan, how many keys are active, and when the server last reported in.
This exists so we can answer a support question without asking you to describe your setup from memory. Three limits apply to it.
- It is read only. An administrator cannot change your servers, create keys on your behalf, or sign in as you.
- Keys stay secret. API keys are stored only as a hash, so nobody can read one, administrator or not.
- Every look is logged. Each time an administrator opens that page it is recorded against their account with a timestamp. Ask and we will tell you what those records say.
Neither the administrator nor the owner role can be granted over the web. There is no route, no form, and no setting that hands them out. They are set directly in the database, which only we can reach.
Who processes data for us
We use the following processors.
- Vercel. Hosts and serves the website and keeps the server logs described above. Vercel Inc. is based in the United States and acts as our processor. See the Vercel privacy policy.
- Google. Provides Google Analytics for the public pages, and only receives data if you accept it. Google Ireland Limited acts as our processor under the Google Ads Data Processing Terms, and data may be processed by Google LLC in the United States. See the Google privacy policy.
- Neon. Hosts the Postgres database behind the dashboard, which holds the account data listed above. The database is stored in the United States, in the us-east-1 region of Amazon Web Services.
Some of this happens outside the European Economic Area. Serving the site can involve a transfer of your IP address to the United States through Vercel. Accepting analytics involves a transfer of the analytics data described above through Google. If you have a dashboard account, your account data is stored in the United States through Neon. Those transfers rely on the Standard Contractual Clauses in each provider's data processing terms, and also on the EU-US Data Privacy Framework for Vercel and Google LLC, which are certified under it.
Links to other services
The site links out to GitHub and to Discord. Those are separate services run by separate companies. We send them nothing about you, and nothing loads from them until you choose to follow a link. Once you do, their own privacy policies apply rather than this one. See the GitHub privacy statement and the Discord privacy policy.
Your rights
Under the GDPR you have the following rights over personal data we hold about you.
- Access. Ask whether we hold data about you and get a copy of it.
- Rectification. Have inaccurate data corrected.
- Erasure. Ask us to delete data, where the law allows it.
- Restriction. Ask us to limit what we do with data while a dispute is resolved.
- Portability. Receive data you gave us in a machine readable form.
- Objection. Object to processing we base on legitimate interest, including the log processing described above.
Write to privacy@unfckd.dev to use any of these. We answer within one month. In practice we hold almost nothing about any individual visitor, so an access request will usually return very little.
If you think we have handled your data badly, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl. You can also complain to the authority in the EU country where you live.
Automated decisions and profiling
We make no automated decisions about you and we build no profiles. Nothing on this site scores, ranks, or categorises visitors. Analytics, where you accept it, is read as totals and trends, not visitor by visitor.
Children
This site is a technical tool for people who run game servers. It is not aimed at children and we knowingly collect no data from them. We ask for no age and we hold no account data that could carry one.
Selling data
We do not sell personal data. We do not share it for advertising. We hold nothing that would be useful for either.
What changes when scan uploads and a CDN arrive
Uploading scan results
The dashboard receives no scan data yet. When it does, the results you choose to upload will be processed to show you your own history, again on the basis of the contract between us. Retention will follow whichever plan you are on, and we will publish the periods and an export and deletion route before that feature opens.
Cloudflare
If we put Cloudflare in front of the site, Cloudflare will process your IP address as a processor in order to route and protect traffic, and its bot management will set a cookie. We will list that cookie in the cookie policy and add Cloudflare to the processor list above before it goes live.
Changes to this policy
We update this policy when what we do changes. The date at the top of the page shows the last substantive change. If a change matters to you, for example because we start collecting something new, we will say so clearly rather than quietly editing the text.
Contact
Questions about this policy go to privacy@unfckd.dev.
