Privacy Policy
Last updated ·
This Privacy Policy explains what personal data Wroud Foundation LLC collects when you use pixly, why we collect it, who we share it with, and the choices you have. It applies in addition to the Terms of Use and the Acceptable Use Policy.
§1. Who We Are
Wroud Foundation LLC ("Wroud", "we", "us", "our") is a limited liability company organized under the laws of the State of Wyoming, United States of America. We operate the pixly managed Minecraft Java Edition server hosting service (the "Service"). For the purposes of the EU General Data Protection Regulation, the United Kingdom GDPR, and similar laws, Wroud is the data controller of the personal data described in this Privacy Policy.
§2. Scope of this Policy
This Privacy Policy applies to the personal data we process when you visit the pixly website, sign up for or use the Service, contact us, or otherwise interact with us. It does not cover data processed by third parties whose services you choose to use through the Service (such as Mojang/Microsoft, Google, AWS, Modrinth, or the Third-Party Payment Processor) under their own privacy policies.
§3. Personal Data We Collect
Account data (from Google OAuth). When you sign in with Google, Google provides us with your name, email address, profile picture URL, and a Google-issued subject identifier. We do not receive your Google password.
Service usage data. When you use the Service, we automatically record server identifiers and metadata, region selection, instance type, server runtime and version, configuration changes, runtime hours, status events (start, stop, sleep, wake), modpack identifiers you choose to install, and player lists you configure (whitelist, operator list, ban list).
Billing data. We record top-up events, debit and credit events against your Wallet, monthly settlement records, the AWS-cost basis for each billing event, refund records, and chargeback records. We retain a token returned by the Third-Party Payment Processor that lets us reference your past payment, but we do not receive or store your full card number, CVV, or bank credentials — those are handled entirely by the Third-Party Payment Processor.
Server content. Your User Content — including world saves, server.properties, datapacks, mods you upload, and the contents of your in-game whitelist, operator, and ban lists — is stored on the storage volumes we provision for your Server and in the daily backups described in the Terms of Use. To the extent any of that User Content contains personal data about you or other people, we process it on your instructions as part of providing the Service.
Technical data. We log connection metadata such as IP address, approximate geolocation derived from IP, user agent, request timestamps, and request paths, for security, fraud prevention, abuse mitigation, and debugging purposes.
Communications. When you contact us at our support email addresses or via in-product channels, we retain the messages you send us and the responses we send you.
§4. How We Use Your Personal Data
- To provide the Service: authenticate you, provision and operate your Servers, deliver backups, process top-ups and debits, and respond to your support requests.
- To bill you: calculate hourly usage, settle your Wallet against monthly AWS cost data, prevent involuntary debt accumulation, and apply refunds or chargebacks.
- To secure the Service: detect and prevent fraud, abuse, account compromise, denial-of-service attacks, and other unauthorized activity.
- To communicate with you: send transactional emails about your Account, your Servers, your Wallet balance, scheduled maintenance, and changes to these legal documents.
- To improve the Service: analyze aggregate usage trends, debug errors, and develop new features. Where reasonably practical we use only aggregated or pseudonymized data for these purposes.
- To comply with the law: meet tax, accounting, anti-money-laundering, sanctions, consumer protection, and other legal obligations, and to respond to lawful requests from government authorities.
§5. Legal Bases (EEA / UK Users)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction that requires us to identify a legal basis for processing your personal data, we rely on the following legal bases:
- Performance of a contract (GDPR Art. 6(1)(b)) — to provide the Service and bill you for it.
- Legitimate interests (GDPR Art. 6(1)(f)) — to secure the Service, prevent fraud, improve the Service, and conduct internal analytics. We balance these interests against your privacy rights and stop processing if your interests outweigh ours.
- Compliance with a legal obligation (GDPR Art. 6(1)(c)) — to meet tax, accounting, sanctions, and other regulatory obligations.
- Consent (GDPR Art. 6(1)(a)) — for any processing we describe as based on your consent (for example, marketing emails if and when we offer them). You can withdraw consent at any time.
§6. Who We Share Personal Data With
We do not sell or rent your personal data. We share personal data only with the categories of recipients listed below and only for the purposes described:
- Cloud infrastructure providers — primarily Amazon Web Services, Inc. ("AWS"), which hosts our compute and storage. AWS acts as our processor and is contractually bound to use the data only on our instructions.
- Authentication provider — Google LLC, which authenticates your sign-in via OAuth. Google operates as an independent controller for the underlying Google account.
- Third-Party Payment Processor — which handles top-ups on our behalf. The processor is an independent controller for your payment instrument data and follows its own privacy policy.
- Modpack metadata providers — primarily Modrinth, when you choose to install a modpack identified by a Modrinth project ID. We send Modrinth the project ID and standard HTTP request metadata; we do not send personally identifying information about you.
- Professional advisors — lawyers, auditors, accountants, and insurers, where reasonably necessary and under confidentiality obligations.
- Successors — in the context of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, in which case we will require recipients to honor this Privacy Policy.
- Government authorities and other third parties — where we believe disclosure is necessary to (i) comply with applicable law, regulation, legal process, or governmental request; (ii) enforce our agreements, including investigation of potential violations; (iii) detect, prevent, or otherwise address fraud, security, or technical issues; or (iv) protect against harm to our rights, property, safety, our Users, or the public.
§7. International Data Transfers
Wroud is based in the United States of America and the Service runs on AWS infrastructure in the region you choose. Personal data may therefore be transferred to and processed in countries outside your country of residence, including the United States of America. Laws in those countries may differ from those in your country.
Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum / Swiss equivalent, as applicable), to ensure your personal data continues to be protected.
§8. How Long We Keep Personal Data
We keep personal data only for as long as needed for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. In particular:
- Account data: for the duration of your Account, plus a short period after closure to handle final billing and disputes.
- Server User Content: primary copies for the lifetime of the Server; daily backups for seven (7) days, after which they are permanently deleted.
- Billing and tax records: typically retained for up to seven (7) years after the relevant transaction, to comply with tax and accounting laws.
- Security and audit logs: typically retained for up to twelve (12) months, longer where required for an ongoing investigation.
- Support communications: typically retained for up to twenty-four (24) months after the support matter is resolved.
§9. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights with respect to your personal data:
- the right to know what personal data we hold about you and to receive a copy;
- the right to have inaccurate or incomplete personal data corrected;
- the right to have personal data deleted ("right to be forgotten");
- the right to restrict or object to certain processing, including processing based on our legitimate interests, and to opt out of "sale" or "sharing" of personal data;
- the right to data portability, where applicable;
- the right to withdraw consent at any time, where processing is based on consent;
- the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you (we do not currently make such decisions);
- the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or place of alleged infringement.
To exercise any of these rights, email privacy@pixly.gg from the email address associated with your Account, or contact us via in-product channels. We may need to verify your identity before acting on a request. We will respond within the time required by applicable law (in most cases, no later than thirty (30) days; we may extend the period for complex requests as permitted by law).
§10. Your California Privacy Rights (CCPA/CPRA)
This section supplements the rest of this Privacy Policy and applies to personal information of California residents that Wroud processes as a "business" under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA/CPRA"). Terms in quotation marks below have the meanings given to them in the CCPA/CPRA.
Categories of personal information we collect. In the preceding twelve (12) months, we have collected the following categories of personal information about California consumers. The specific items are described in Section 3 of this Privacy Policy.
- Identifiers (name, email address, Google-issued subject identifier, IP address, account identifier).
- Customer records (billing data, transaction history, refund and chargeback records; we do not receive or store full card numbers).
- Commercial information (records of Services purchased or considered, top-up history, usage tied to billing).
- Internet or other electronic network activity (server identifiers, region selection, runtime hours, configuration changes, request metadata, user agent, request paths).
- Geolocation (approximate geolocation derived from IP, used for security, fraud prevention, and the region your Service runs in).
- Inferences drawn from the above to characterize preferences and detect fraud.
We do not knowingly collect "sensitive personal information" as defined by the CCPA/CPRA. We do not collect biometric information, precise geolocation, or government-identifier numbers.
Sources. We collect the categories above from you directly when you sign up, configure a Server, top up your Wallet, or contact us; from your interaction with the Service when you use it; from Google when you authenticate; and from the third-party payment processor when you make a payment.
Business or commercial purposes for which we collect personal information. The purposes described in Section 4 of this Privacy Policy. In summary: to provide the Service, to bill you, to secure the Service, to communicate with you, to improve the Service, and to comply with the law.
Categories of recipients to whom we disclose personal information for a business purpose. Cloud infrastructure providers (primarily AWS), the third-party payment processor, our authentication provider (Google), modpack-metadata providers, professional advisors, and government authorities or other parties where disclosure is necessary. The full list is in Section 6 of this Privacy Policy.
No "sale" or "sharing" of personal information. Wroud does not sell personal information and does not share personal information for cross-context behavioral advertising, in each case as those terms are defined in the CCPA/CPRA. We have not sold or shared personal information of California consumers in the preceding twelve (12) months, and we do not have actual knowledge that we sell or share the personal information of consumers under sixteen (16) years of age.
Retention. We retain each category of personal information only for as long as needed for the purposes described in this Privacy Policy. The general retention periods we apply are in Section 8 of this Privacy Policy.
Your CCPA/CPRA rights. Subject to verification of your identity and applicable exceptions, California consumers have the right to:
- Know what personal information we have collected about you, including categories of sources, business or commercial purposes, categories of third parties to whom we disclose information, and the specific pieces of personal information we hold;
- Delete personal information we have collected from you;
- Correct inaccurate personal information we hold about you;
- Limit use of sensitive personal information to that necessary to provide the Service (not currently applicable as we do not knowingly collect "sensitive personal information");
- Opt out of "sale" or "sharing" of personal information (not currently applicable as we do not sell or share);
- Non-discrimination for exercising any CCPA/CPRA right. We will not deny you the Service, charge you different prices, or provide you a different level or quality of the Service because you exercised a right under the CCPA/CPRA, except as permitted by law (for example, where the difference reflects the value of the data to us, in which case we will tell you).
How to exercise these rights. Email privacy@pixly.gg from the email address associated with your Account, or use the data-rights buttons in your dashboard Account page where available. We will verify your request by matching identifiers in our records and, where appropriate, by confirming your control of the Account via the email associated with the Account. For high-risk requests (such as a deletion request) we may require additional verification.
Authorized agents. You may designate an authorized agent to make a request on your behalf. The agent must provide written authorization signed by you, and we may separately contact you to confirm the agent's authority and to verify your identity directly.
Twelve-month look-back. When you make a request to know, we will provide the information collected, disclosed, sold, or shared (as applicable) in the twelve (12) months preceding the request, unless you ask us to cover a longer period (in which case we may, where feasible and not disproportionately difficult, provide the longer period; we are not required to provide information collected before January 1, 2022).
Complaints. You may file a complaint with the California Privacy Protection Agency. We will not retaliate against you for filing a complaint.
§11. Children
The Service is not directed to children under thirteen (13) years of age, and we do not knowingly collect personal data from children under thirteen (13). In jurisdictions with a higher digital-consent age (such as sixteen (16) in much of the European Economic Area), the Service is not directed to children below that age.
If you believe a child has provided us with personal data without appropriate consent, please contact privacy@pixly.gg and we will take steps to delete the data and close any associated Account.
§12. Cookies & Similar Technologies
We use a small number of strictly necessary cookies and similar technologies. In particular, we set a session cookie named "__Host-mc_session" — an HTTP-only, secure cookie that contains a signed JSON Web Token and expires after seven (7) days — which keeps you signed in to your Account. Without this cookie we could not authenticate your requests, so it cannot be disabled while you remain signed in.
In addition, we use Google Analytics 4 (provided by Google LLC) to measure aggregate use of the Service — for example, which pages are visited and which features are used — so we can improve the Service. Google Analytics sets cookies in your browser (typically prefixed "_ga") that contain a pseudonymous client identifier; we have configured the property without advertising features and we do not use Google Analytics for cross-site advertising, remarketing, or building advertising profiles. The lawful basis for this processing in the EEA and the United Kingdom is our legitimate interest in understanding and improving the Service (GDPR Art. 6(1)(f)); you can object at any time by contacting privacy@pixly.gg or by using a browser-level signal such as Global Privacy Control.
We do not use advertising cookies, cross-site tracking pixels, or third-party marketing cookies. If we add such cookies in the future, we will update this Privacy Policy and, where required, ask for your consent first.
§13. Security
We use industry-standard technical and organizational measures to protect personal data, including transport-layer encryption (TLS) for all communications between your browser and our servers, encryption-at-rest for storage volumes and backups (managed by AWS), least-privilege access controls for internal personnel, audit logging of administrative actions, and the use of Google OAuth so that we never directly handle passwords. No method of transmission over the internet or method of electronic storage is one hundred percent secure, however, and we cannot guarantee absolute security.
§14. Notification of a Data Breach
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and (where required) you, in accordance with applicable law and, where the GDPR applies, generally within seventy-two (72) hours of becoming aware of the breach.
§15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the date of the most recent revision. For material changes, we will give reasonable advance notice as described in the Terms of Use. Your continued use of the Service after the effective date of a change constitutes acceptance of the revised Privacy Policy.
§16. Contact
Privacy questions or rights requests: privacy@pixly.gg. General legal contact: legal@pixly.gg. Postal address and full company details: Contact.
- 2026-06-02 — Updated §12 (Cookies & Similar Technologies) to disclose our use of Google Analytics 4 for aggregate usage measurement, including the cookies it sets, the configuration (no advertising features, no cross-site advertising or remarketing), the lawful basis (legitimate interests under GDPR Art. 6(1)(f)), and how to object. Tightened the residual statement about advertising and marketing cookies.
- 2026-05-26 — Shortened the daily-backup retention window in §8 (How Long We Keep Personal Data) from thirty (30) days to seven (7) days, to match the production retention policy.
- 2026-05-16 — Added new §10 "Your California Privacy Rights (CCPA/CPRA)" with categories collected, sources, business purposes, recipient categories, explicit no-sale / no-share statement, the CCPA/CPRA rights catalog (know, delete, correct, limit, opt-out, non-discrimination), authorized-agent procedure, and twelve-month look-back. Removed the CCPA parenthetical from §9 (now superseded by the dedicated §10). Renumbered §10-§15 to §11-§16. Added this version-history appendix.