Apfel Mod Hosting

Privacy Policy

Last updated: 2026-09-28

1. Who is responsible

apfelmagnet32
Contact: contact@apfelserver.net
Based in Germany

This is a personal, non-commercial project run by a private individual, not a company. The operator is the data controller for everything described below, and the address above reaches them directly about anything in this policy.

2. What data is collected

DataWhyLegal basis
Username, email address, password (stored as a bcrypt hash, never in plain text)To create and secure your accountNecessary to provide the service you asked for (Art. 6(1)(b) GDPR)
Projects, versions, and files you upload, plus any text you write (descriptions, disclosures, changelogs)To publish and host your content on the platformNecessary to provide the service (Art. 6(1)(b) GDPR)
A session cookie (a random token, not linked to tracking)To keep you signed inStrictly necessary for the service to function — no consent banner needed

That's it. There is no analytics, no advertising, no third-party tracking scripts, and no data is sold or shared with advertisers.

3. Where your data goes

There is no analytics or advertising, and nothing is sold or shared with advertisers. Two infrastructure providers process data on the operator's behalf, purely to run the Service:

  • Neon hosts the database (accounts, project metadata, messages).
  • GitHub stores the actual uploaded files (mod jars, resource packs, etc.), in a private repository the operator controls.

Server logs may briefly include IP addresses, used to debug faults and to enforce the rate limits that keep the Service usable. The basis for this is the operator's legitimate interest in a working, non-abused service (Art. 6(1)(f) GDPR). These logs stay with the hosting provider and aren't shared beyond that.

Processing outside the EU

Neon, GitHub and the hosting provider are US-based companies, so your data may be processed outside the EU/EEA. Transfers like these are covered by the European Commission's standard contractual clauses and, where the provider is certified, the EU–US Data Privacy Framework. US law gives their authorities access powers that EU law does not, which is a risk you should be aware of before uploading anything sensitive — though nothing here asks you for sensitive data in the first place.

4. How long data is kept

Your account and content are kept until you delete your account or ask for it to be deleted.

If a registration is rejected, the account and everything stored about it are deleted automatically about ten minutes after that decision — no request needed. Until then you can sign in to read the decision, and delete the account yourself straight away if you prefer.

While a registration is still awaiting a decision, you can sign in and delete the account at any time. An account that was never approved is not held hostage by that: signing in works purely so the account can be identified, and nothing else on the site is reachable until it is approved.

Uploaded files are removed from the app immediately on deletion. Because of how the underlying storage works, the file's raw bytes may continue to exist, inaccessible to the app or anyone else, on the storage provider's infrastructure for a limited additional period (on the order of weeks) until its own routine cleanup reclaims the space — this isn't something the operator can force to happen sooner.

Addresses barred from registering

If an address is barred from signing up again — usually after a registration was refused — it is kept in a separate list, and kept indefinitely, since that is the whole point of it. It is stored as a one-way hash rather than as the address itself: the list can be checked when someone registers, but not read back, and the operator only sees enough of an address (s•••••r@example.com) to tell entries apart. Nothing else about the account is kept. To ask for an entry to be removed, email contact@apfelserver.net.

5. Your rights

Under GDPR, you can ask the operator to:

  • Tell you what data is held about you (access)
  • Correct inaccurate data (rectification)
  • Delete your account and data (erasure) — or delete your own account yourself in Account settings
  • Give you a copy of your data in a portable format (portability) — or download it yourself as a JSON file under "Your data" in Account settings
  • Stop processing your data in certain cases (restriction/objection)

Erasure and portability are self-serve in Account settings. For anything else, email contact@apfelserver.net. You also have the right to complain to your local data protection authority.

6. Children

This service isn't directed at children. Under GDPR Art. 8, the age for consenting to data processing on your own in Germany is 16; below that a parent or guardian has to agree. Note that agreeing to the Terms of Service is a separate question with its own age rule — see section 2 of the Terms of Service.

There's no automated age check — registration relies on what you tell the operator. If it turns out an account belongs to someone under 16 without a guardian's agreement, the account and its data are deleted. A parent or guardian who believes their child signed up without their agreement can ask for the same at contact@apfelserver.net, and the account will be removed.

7. Changes to this policy

If what data is collected or how it's used changes, this page will be updated with a new "last updated" date.

Terms of ServicePrivacy Policy

All rights reserved.