Files
policies/privacy-policy.md
Anna Hermes 495bcb5f32 Cover both self-hosted and cloud-based AI in policy AI sections
- Restore cloud-based AI as a first-class category (Anna, Madi run on Ollama Cloud)
- Self-hosted moderation AI (ShieldGemma etc.) clearly separated
- Cloud AI covers operational tasks: admin, support, media management, troubleshooting
- Both categories disclosed honestly
2026-08-20 13:23:25 +02:00

13 KiB

Privacy Policy

Last updated: 2026-08-20

This Privacy Policy explains how Majjo Duran collects, uses, stores, and protects data when you use our services. It works alongside our Terms of Service.

We do not sell personal data or use advertising trackers. We aim to collect only what is reasonably needed to operate, secure, moderate, and improve the services.


1. Service Scope

This policy applies to user-facing services covered by our Terms of Service:

  • Plex — media streaming and playback
  • Seerr — media request management
  • Bitwarden (Vault) — password and credential management
  • Slink — image upload, storage, and link sharing
  • Community game servers — including Minecraft and Palworld

Administrative and supporting infrastructure—including reverse proxies, security monitoring, access logging, analytics, media-management tools, dashboards, and AI-assisted administration—may process data behind these services but is not separately offered to users.

2. Data We Collect

Depending on the service you use, we may process:

  • Account and identity data — usernames, email addresses where applicable, Discord usernames used for support or access, roles, and permissions
  • IP and network data — IP addresses, ASN/provider information, VPN/datacenter/proxy classification, and approximate country or region from GeoIP
  • Device and client data — device name, platform, application or browser type, client version, and identifiers supplied by the service
  • Playback and media activity — watch history, media titles and metadata, playback devices, timestamps, bandwidth, transcoding, sessions, and user statistics
  • Request activity — Seerr requests, requester, approval or denial state, requested media, timestamps, and history
  • Vault and authentication metadata — login and session events, known-device checks, failed authentication, and security events where logged; private vault contents and raw credentials are not used for analytics or AI training
  • Slink account and upload data — usernames, account settings, uploaded image files, filenames, image type and size, dimensions, share/privacy/password/expiration settings, upload and deletion times, storage usage, and access activity where logged
  • Game-server data — player names, UUIDs or platform/account identifiers, IP addresses, connection history, chat and command logs where enabled, gameplay and administrative events, moderation actions, inventories, character or player progress, server statistics, and contributions stored in shared world files
  • Access and security logs — IP, host, path, method, status code, timestamp, duration, routed service, user-agent, TLS/router metadata, and traffic volume
  • Enforcement data — warnings, bans, suspensions, blacklists, moderation actions, suspected cheating or exploitation, scanner/probing records, and incident notes
  • Support communications — Discord, email, or other support messages related to access, moderation, content, or service issues

Data is generally collected when you interact with a service, when your client connects, when a public share link is requested, or when security systems observe traffic reaching our infrastructure.

3. How We Use Data

Data may be used to:

  • Operate, maintain, and troubleshoot services
  • Provide uploads, sharing, playback, requests, authentication, multiplayer worlds, and other user-facing features
  • Monitor performance, bandwidth, storage, and resource utilization
  • Secure accounts and infrastructure and detect abuse, cheating, exploitation, scanning, or attacks
  • Moderate user uploads, chat, gameplay, and community conduct
  • Investigate rights complaints, incidents, and Terms of Service violations
  • Restore backups, troubleshoot corrupted game state, and maintain shared worlds
  • Provide support and communicate service changes
  • Train or evaluate internal AI models as described in Section 4

4. AI & Automated Processing

We use AI and automated systems for moderation, security monitoring, abuse detection, service operation, and service improvement. These include both self-hosted AI systems running on infrastructure we control and cloud-based AI providers.

Self-hosted moderation AI: We deploy and operate self-hosted AI models for content moderation and abuse detection. These systems run on infrastructure we control — they do not send your data to external AI providers for moderation. Service data, including user-uploaded content, messages, chat, metadata, and activity associated with your account, may be processed by these internal AI systems to classify content, detect violations, flag suspicious behavior, and support moderation decisions. AI-assisted moderation may classify or flag content automatically. Automated signals are not treated as infallible — context may be reviewed before permanent enforcement where circumstances allow.

Cloud-based AI: We also use cloud-based AI providers for operational tasks such as service administration, support, media management, and troubleshooting. When cloud AI providers are used, data is limited to what is reasonably necessary for the task and is processed under the provider's applicable terms and privacy practices.

Internal AI training: Service data, including user-linked and identifiable data, may be used to train internal AI models. These models are internal-only, access-controlled, and not exposed to users or third parties.

What is never used for AI: Raw passwords, secrets, private vault contents, and credential material are never used for AI processing or training.

Slink content is stored on infrastructure operated by Majjo Duran until deleted, removed, or expired according to the applicable settings and retention limits.

When you create or distribute a share link, anyone who receives or discovers that link may request the image unless you use an available password or other access restriction. Discord and other platforms may automatically crawl, proxy, resize, preview, or cache shared images. Those services may process the image, link, and request metadata under their own terms and privacy policies.

Deleting an upload or share from Slink does not delete copies already downloaded, reposted, captured, or cached by recipients, browsers, Discord, content-delivery networks, search engines, or other third parties outside our control.

6. Game Servers & Third-Party Platforms

Minecraft, Palworld, Steam, Microsoft/Xbox, Mojang, Pocketpair, mod loaders, and third-party mods or plugins may independently process account, device, telemetry, crash, or gameplay data under their own terms and privacy policies. We do not control that separate processing.

Third-party server components may create their own configuration, log, cache, or world data as part of normal operation. We limit access to server files to administration and operational purposes, but cannot guarantee the behavior or security of third-party code.

Game chat and activity occur in a shared multiplayer environment. Other players may see, record, quote, stream, or capture what you say, build, or do. Do not disclose information you do not want other players to receive.

7. Data Retention

We retain data for as long as reasonably necessary to operate, secure, moderate, and enforce the services:

  • Accounts and service activity — retained while the account or service relationship remains active and longer where needed for functionality or support
  • Slink uploads — retained until deleted by the user, expired, removed by management, or deleted with the account, subject to backups and third-party copies
  • Game worlds and player state — retained as part of the active world or server history; individual player data may remain embedded in shared world files and backups
  • Playback, request, and dashboard history — may be retained indefinitely to provide history and service functionality
  • Access and security logs — retained as needed for diagnostics, bandwidth monitoring, abuse prevention, and security analysis
  • Enforcement and moderation data — may be retained permanently where necessary to prevent evasion and protect users and services
  • Support communications — retained as needed for support, moderation, and enforcement

Data connected to suspected abuse, compromise, illegal content, rights complaints, cheating, or security incidents may be retained longer while necessary to investigate, document, or prevent recurrence.

8. Data Storage & International Processing

Primary service storage and most sensitive operational data are hosted on private infrastructure in Stockholm, Sweden.

Limited data may be processed outside Sweden or the European Union when you interact with third-party services or when infrastructure providers are required to deliver the service. In particular, public Slink images and links may be fetched or cached globally by Discord, browsers, recipients, and content-delivery networks. Game publishers, platform providers, email providers, DNS providers, and cloud AI providers may also process limited data in other jurisdictions under their own terms.

9. Data Sharing & Third Parties

We do not sell personal data or voluntarily share it with unrelated third parties. Data may be processed by or disclosed to:

  • Infrastructure, DNS, and hosting providers — traffic metadata and technical information needed for routing, delivery, and security
  • Email providers — data required for email delivery and support communications
  • Discord — messages and usernames used for support or community access, plus shared Slink images and link metadata when users post links to Discord
  • Game and platform providers — such as Microsoft, Mojang, Xbox, Pocketpair, and Steam when their games, accounts, networking, or software are used
  • Cloud AI providers — limited task data when cloud inference is used
  • Legal authorities or rights holders — only where legally required or reasonably necessary to respond to valid legal or rights complaints

10. Cookies & Sessions

Cookies, session tokens, and local storage are used for login sessions, authentication, security, access control, and service preferences. We do not use advertising cookies or unrelated behavioral tracking.

11. Security Monitoring

Security monitoring may log request metadata, classify traffic by ASN/provider or GeoIP, detect suspicious patterns, and automatically rate-limit or temporarily block traffic. Game servers may additionally log connections, commands, chat where enabled, suspicious gameplay, and administrative actions.

Provider or datacenter classification alone is not treated as conclusive proof of abuse. Legitimate platform proxying or caching of public Slink links, including Discord image fetching, may originate from shared cloud or CDN infrastructure.

12. Your Rights

Subject to applicable law, you may request:

  • Access to personal data we hold about you
  • Correction of inaccurate or incomplete data
  • Deletion, subject to Section 13
  • A structured, machine-readable copy where reasonably available
  • Withdrawal of consent where consent is the applicable legal basis

To exercise these rights, contact management using the details below. We may need to verify your identity before fulfilling a request.

13. Data Deletion Limits

Some data may not be immediately or fully removable, including:

  • Security, ban, moderation, and enforcement records required to prevent evasion or protect services
  • Player state or contributions embedded in shared game worlds where separation is not technically reasonable
  • Data in rotated backups until the retention window expires
  • Data required for an active investigation, legal obligation, or rights complaint
  • Copies downloaded, reposted, recorded, or cached by other users or third parties outside our control

Deleting data required to operate an account may result in loss of access. Requests are normally scheduled within 30 days after identity verification.

14. Children's Data

Services are not directed at children under 13. We do not knowingly offer accounts to children under 13. If we learn that a child under 13 provided personal data, we will take reasonable steps to delete it, subject to security, shared-world, backup, and legal limits.

Parents or guardians who believe a child has provided data may contact us below. Third-party games and platforms may impose additional age or parental-consent requirements.

15. Changes to This Policy

We may update this policy periodically. Material changes will be announced by email, through the Discord server's announcement channel, or by another reasonable service notice. Unless a later date is stated, changes take effect upon publication. Continued use after notice constitutes acceptance where permitted by law.

16. Governing Law & Severability

This policy is governed by Swedish law and applicable European Union law. Mandatory privacy rights remain unaffected. If a provision is unenforceable or invalid, it will be limited or removed only to the minimum extent necessary; the remainder stays in effect.


Contact

For privacy questions, access requests, deletion requests, or concerns:

  • Discord: @majjoduran
  • Email: support@majjoduran.xyz