Privacy Policy
Last updated: 16 September 2026
CivCentral is a community hub for Minecraft civilization events. To run it we store a small amount of information about you — chiefly an email address and a password. This page says exactly what we hold, why, who can see it, and how to get it back or get rid of it.
Who is responsible
CivCentral is operated by the CivCentral archivists, who act as the data controller for everything described here. Privacy questions and requests go to an archivist — see the FAQ for how to reach the team.
What we collect, and why
Your account
- Username. Required, public. It appears on everything you submit. Pick one that isn't your real name if you'd rather not be identifiable.
- Email address. Optional to register, required to contribute. We use it for one thing: sending a verification link that proves the address is yours, which keeps the review queue free of throwaway spam accounts. It is never shown publicly and never sold, rented, or shared with advertisers.
- Password. Stored only as a bcrypt hash. We cannot read it, recover it, or tell you what it was — and neither can anyone who obtains the database. Never reuse a password from elsewhere.
- Discord account. Only if you sign in with Discord or link it later. We store your Discord user ID, display handle, and avatar URL so the account can be matched on future sign-ins. We never receive your Discord password. You can unlink it at any time from your account settings, once you have set a password.
- Profile picture and bio. Optional, public, and entirely up to you. Uploaded images are held in object storage.
What you post
Entries, revisions, evidence links, comments, votes, event ratings, and stars are stored against your account. Apart from your individual vote and rating, they are public. Revision history is kept deliberately: an archive that can be silently rewritten is not an archive.
Hosting and requests
If you ask to become an event host, or propose a server or event, we keep that request, its outcome, and any note the reviewing archivist left — so a decision can be explained later rather than being a shrug. If you opt in to hear about a server's new events, we store that interest so the Discord bot can notify you.
Technical data
- Session cookie. One cookie holding a signed token that says which account you are. It is strictly necessary to keep you logged in, so it is set without a consent banner, and it carries no tracking identifier.
- Theme preference. Kept in your browser's local storage. It never reaches our servers.
- Rate-limit counters. Short-lived counters keyed by IP address, used to stop sign-up, login, comment, and report floods.
- No analytics, no advertising, no third-party trackers. We do not profile you, and there is no automated decision-making.
Moderation data
If you report content or another member, we store the report with your account, the reason, and anything you wrote. Reports are visible to archivists only — never to the person you reported. If your account is suspended or banned we store that status, when it lifts, and the archivist's action in the moderation log.
Our legal basis
- Contract. Running the account you asked us to create.
- Consent. Sending verification email to the address you gave us, and Discord notifications you opted into. Withdraw either by removing the address, opting out, or deleting the account.
- Legitimate interests. Keeping the site usable and free of abuse — rate limiting, moderation, reports, and the moderation log.
Who else sees it
We use a small number of processors, and share nothing beyond what each one needs:
- Our hosting and database provider — Runs the site and stores the data behind it.
- Resend — Receives your email address solely to deliver verification messages.
- Cloudflare R2 — Stores images you upload, such as an avatar or evidence screenshots.
- Discord — Only if you sign in with Discord or opt into event notifications, and only as part of those features.
Beyond that we disclose personal data only when the law requires it. We do not sell it under any circumstances.
How long we keep it
Where a row says data is cleared “opportunistically” rather than on a schedule, that is a deliberately honest description of how the cleanup actually runs — we would rather state the real behaviour than promise a bound the code does not enforce.
Your rights
Wherever you live we will honour these; if you are in the UK, EU, or EEA, the GDPR gives them to you outright.
- Access. Ask for a copy of what we hold about you.
- Correction. Change your email, avatar, or bio from your account settings at any time.
- Deletion. Delete your account from account settings. We remove your email, password hash, Discord link, and avatar.
- Objection and restriction. Tell us to stop processing your data for a given purpose, and we will unless we have an overriding reason — which, for a community site, is usually just abuse prevention.
- Portability. Every entry can be exported as Markdown from its own page, and we can supply the rest on request.
- Complaint. If we handle this badly you can complain to your local data protection authority.
What deletion does not remove
If you never published anything, deleting your account removes the record outright. If you did publish, we keep the row but strip everything that identifies you — username replaced, email, password, Discord link and avatar cleared — so the entries, revisions and discussions other people built on stay coherent. Tell us and we will also remove specific posts.
The moderation log survives account deletion. It stores names rather than account links precisely so it can outlive the content it describes; it is the record of what archivists did, which is the part that has to remain checkable.
Security
Passwords are bcrypt-hashed. Session tokens are signed and set HttpOnly, SameSite=Lax, and, in production, Secure, so page scripts cannot read them. Verification links are stored only as hashes and expire. Discord sign-in only links an existing account when both sides have verified the same email address, so nobody can claim your account by registering on your address first. Traffic runs over HTTPS.
No system is perfect. If we discover a breach affecting your data we will tell you and the relevant authority without undue delay.
Age
You must be at least 13 to hold an account. If we learn an account belongs to someone younger, we delete it.
Changes
If we change this policy in a way that affects you, we will say so on the site rather than quietly swapping the text. The date at the top always reflects the current version.
See also the Terms of Use.

