Privacy Policy
D3D9 Community
1. Operator and purposes
D3D9 processes personal data needed to provide linked accounts, the forum, public integrated chat, the game server and related tools. Additional purposes or disclosures require an appropriate legal basis and procedure.
Privacy and rights-request contact: D3D9 operator
Email: [email protected]
2. Data, collection and retention
We process information you provide through linking, posts, chat or email; profile data returned by Microsoft/Xbox/Minecraft authentication; data relayed by the game server/Bridge; and technical information generated when accessing the service. Microsoft passwords and refresh tokens are not stored in the operator's user database. Web authentication tokens are used transiently during authentication.
| Category | Data | Purpose | Retention |
|---|---|---|---|
| Account linking | Minecraft UUID/name, creation/last-login time, restriction status | Identity, linking and abuse prevention | While linked; processed upon unlinking/deletion request |
| Forum | Author UUID/name, category, title, body and creation time | Display posts and operate the community | Until post deletion or service closure; authored data is removed when account deletion is requested |
| Public integrated chat | UUID/name, content, time and delivery status | Relay web/game messages and display conversations | 30 by default days; expired records deleted by scheduled cleanup |
| Web server status | Online player UUID/name and update time | Live status and player count | Overwritten by the next update; stale player lists cleared by scheduled cleanup |
| Game server/admin tools | UUID/name, join time, play time, world, coordinates and game-save data; connection details in server logs | Game operation, player administration and security | Live data during the session/server operation; game saves during server operation or until a deletion request is processed; connection logs normally within 30 days |
| Security/session | Session ID, transient authentication data, rate-limit identifiers and Bridge replay-protection values; IP/time/path/browser details in server logs | Authentication, access control and incident response | 24-hour login validity; 24-hour rate-limit data; about 2-minute Bridge replay records; connection logs normally deleted within 30 days; any necessary legal/incident preservation is separately explained |
| Local launcher cache | Microsoft refresh token, app ID, cached player name, preferences and game files | Refresh sign-in, launch the game and retain settings | Token cache until logout or user deletion; other local files until deleted by the user |
| Email requests | Sender email, request content and voluntarily supplied attachments | Support and rights requests | Within 90 days after completion; any necessary legal/dispute preservation reason and period explained separately |
Expired information is removed by cleanup tasks. Information legally required to be preserved is separated and retained only as necessary. Game worlds/player saves are separate from the web account database; deletion requests are assessed for scope and effects on shared worlds.
3. Public disclosure and other sharing
Player names and content posted to chat/forum are visible to other users. In-game global chat is relayed to the public web channel. Online-player details and play status are processed in server status or administrator tools. Do not include sensitive information or others' personal data in public content.
We do not sell personal data or share it for advertising. Separate third-party disclosure is not made except at your request, with consent or on an applicable legal basis. Legal requests are assessed for validity and necessity.
4. External services, processors and overseas processing
The website uses Cloudflare, Inc. for network/security services. IP addresses, request details, headers and transmitted data may be processed when requests are delivered/protected. Processing is subject to the Cloudflare Privacy Policy and contractual terms. Contact: [email protected].
Authentication uses Microsoft/Xbox/Minecraft services. Data processed by Microsoft while you use its sign-in pages/services is governed by the Microsoft Privacy Statement; consult its contact section for inquiries. Downloading from Fabric/Modrinth is also subject to those providers' access-data practices.
External services may process data on servers outside your country. Actual destination countries, recipients, data, timing/method, purpose, retention and legal basis depend on the service contracts/settings in use. Request specific overseas-transfer details and refusal options from [email protected]; the operator will provide verified information. You may stop linking and request unlinking if you do not wish to use overseas processing, but features requiring those network/authentication services may become unavailable.
5. Deletion and your rights
Email [email protected] to request access, correction, deletion, restriction of processing, withdrawal of consent or unlinking. The operator verifies you or an authorized representative using minimal necessary information and responds under applicable legal procedures/time limits. If a request must be refused or restricted, the reason and options will be explained. Passwords or tokens are not requested.
Electronic records are deleted from databases/files. Deleted data is not restored for ordinary service use; processed deletion requests are reapplied if a backup is restored. If backups are used, ordinary backups are rotated within 7 days; processed deletion requests are not restored for ordinary use. Connection logs are normally rotated/deleted within 30 days. Necessary legal/incident preservation is separately explained.
Changes to the original Microsoft/Minecraft profile name must be made through those services. Signing out removes the launcher's local account cache. Copies retained by browsers, game clients or other users may require a request to the relevant holder.
6. Cookies and local storage
The D3D9MC session cookie maintains login with Secure, HttpOnly and SameSite settings. It is a browser-session cookie; login validity is 24 hours. d3d9-theme stores your display-theme preference in browser local storage.
The supplied website code contains no advertising-tracking cookies or advertising-analytics scripts. External services such as Cloudflare may use technical identifiers for security. You can delete/block cookies and site data, but features such as sign-in may be restricted.
7. Security and children
Controls include HTTPS, secure session cookies, origin/CSRF checks, rate limits, signed Bridge messages and access restrictions. Launcher refresh tokens are protected with Windows DPAPI. The operator manages permissions/secrets and responds to incidents under applicable law.
Linked-account features target users aged 14 or over; a parental-consent process is not currently provided. If account data of a child under 14 is identified, appropriate verification and protective/deletion measures are taken.
8. Contact, remedies and changes
Privacy contact: D3D9 operator · [email protected]
You may seek assistance from Korea's Personal Information Infringement Report Center, the Personal Information Dispute Mediation Committee, or relevant local authorities.
Changes will be published with their substance and effective date; any required consent will be obtained separately. Korean and English versions are provided. Differences are explained by reference to the Korean text without restricting statutory rights.
Effective: 1 October 2026 · Document version: 1.0