Privacy policy
This policy describes what ServerRoam processes, why, and on what legal basis. It reflects what the application actually stores.
Last updated:
Controller
The operator named in the imprint is the controller for this website. Use the contact address there for any data protection request.
Visiting the site
Our hosting infrastructure records technical request data such as IP address, time, requested address, referrer and browser identification. This is needed to deliver pages and to detect abuse. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a secure, functioning service. These records are kept only for a short operational period.
Signing in with Discord
Sign-in is optional and only needed to manage listings. If you use it, Discord sends us your Discord account identifier, display name, email address and avatar address. Access and refresh tokens are stored encrypted. We never post on your behalf and request no further Discord permissions. Legal basis: Art. 6 (1) (b) GDPR.
Session cookie
After sign-in we set one strictly necessary cookie holding a session token, and store that session's IP address, browser identification and expiry so it can be listed and revoked. We set no analytics, advertising or tracking cookies, so no cookie banner is required.
Listing content
Text and addresses you enter for an organisation, community or server are stored as your private draft. Once a listing is approved it becomes publicly visible, including its name, description, tags, region, language and connection address. Do not enter personal data you do not want published.
Ownership verification
To verify that you control a server, we store a hashed one-time token and, at your request, make a single outbound request to exactly the address you entered. We record the time, result and address of that attempt. No other connection to your server is made and no gameplay data is collected.
ServerRoam Connect
When enabled, our worker retrieves aggregate player counts from the public Cfx listing for the configured join code. Cfx receives that code and the worker’s network address, not your browser address through this feature. Counts and retrieval times are public: individual observations are retained for 30 days, hourly aggregates for up to 90 days. Optional txBridge connections send signed status and restart events. We retain only the selected status fields, event identifiers and content digests; no player identities, resource inventories or administrative payloads are stored. Event identifiers and digests remain for the lifetime of the connection to prevent duplicate processing. Connection secrets are encrypted. Changing the source hides its previous history until it expires; replacing the bridge removes its old receipts, and revoking it clears the secret.
Moderation record
Approval, rejection and suspension decisions are recorded with the deciding account, the time and the stated reason. This record keeps moderation accountable and reviewable. Legal basis: Art. 6 (1) (f) GDPR.
Reviews, invitations and developer access
Reviews store your rating, text, display name and moderation status; edits require another moderation decision. Reports record the subject, reason and decision. Organization owners can invite a verified email address and manage membership roles. Invitation and API credentials are stored as hashes and their plaintext is displayed only once. API keys grant read access to published catalogue data and can be revoked. A shared per-account request budget protects the service.
Votes and saved servers
If you vote for a server we store your account identifier, the server, the time, and a shortened, salted hash of your network address, so that one vote per account per server per 24 hours can be enforced. The hash covers a whole network rather than a single address, cannot be reversed back to one, and is cleared after 30 days; the vote itself is kept only as a number and is never published with your name. A saved server is visible to you alone and is counted nowhere. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a directory that automated voting cannot distort.
Abuse protection on the vote control
Where it is configured, the vote control loads Cloudflare Turnstile from challenges.cloudflare.com. Cloudflare then receives your IP address and technical browser data in order to tell a person from a script, and returns only a pass or a fail to us. It is loaded on that control alone, never on the rest of the site, and it sets no advertising or analytics cookie. Legal basis: Art. 6 (1) (f) GDPR.
What we do not do
No web analytics, no advertising, no profiling, no sale of data, and no automated decision-making producing legal effects. The only third-party code we load is the abuse challenge described above, and only on the vote control.
Recipients
Hosting and Cloudflare process delivery data. Cloudflare R2 stores uploaded images in private quarantine and serves approved images publicly. Cloudflare Turnstile checks voting challenges. Discord receives data when you sign in. Public profile content, approved reviews and author display names are visible to visitors and through the public catalogue API.
Retention and deletion
Account settings provide a personal-data export and deletion after a recent sign-in. Organization owners must transfer ownership first; moderators and recorded verification actors contact the operator for deletion review. Deletion removes sessions, linked provider credentials, favorites, votes and authored reviews. Audit references remain for accountability. Rejected review bodies and decided reports are removed after 90 days. Invitation codes expire after seven days and old invitation records are removed after another 90 days. Deleted media is removed by the worker with retries; public caches can retain copies for up to 60 seconds after removal.
Your rights
You have the right to information, correction, deletion, restriction of processing, data portability and objection under Art. 15 to 21 GDPR. Write to the contact address in the imprint.
Supervisory authority
You may lodge a complaint with a data protection supervisory authority. The authority responsible for the operator is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.