Privacy Policy
What we collect, why we collect it, how long we keep it, and who else sees it. Written against the actual database, not a template.
Effective 14 September 2026
Contents
01Two kinds of data, two different roles
Thorium is sold to the people who run game servers, not to the people who play on them. That makes the distinction below the most important thing on this page.
Account data is the information about you as a Thorium customer: your email address, your organisation, your billing. We decide what to do with it, so under the GDPR we are the controller and this policy governs it.
Player datais the information Thorium sees about people playing on a customer’s server. We only ever handle it on that customer’s instruction. They are the controller; we are the processor. If you are a player and want your data removed or explained, the server operator is who you ask — we cannot lawfully act on their data without them.
02What we collect about customers
When you create an account and use the dashboard, we store:
- Identity: email address, username, display name, optional first and last name, optional phone number.
- Credentials:a hash of your password — never the password itself — plus two-factor settings and lockout counters.
- Discord link, if you connect one: your Discord user ID, username, avatar and the OAuth tokens needed to keep the link working.
- Sessions: for each sign-in, the IP address, user agent, device name, and the country and region derived from that IP, with timestamps. This is what powers the active-sessions list and lets you revoke a session you do not recognise.
- Organisation and billing: organisation name, members and their roles, plan tier, and the customer identifier issued by our payment provider.
- Audit trail:a record of security-relevant actions in your organisation — who invited whom, who changed a role, who deleted a server.
We do not see or store card numbers. Checkout happens on PayNow’s infrastructure and all we receive back is a customer identifier, a plan and a subscription status.
03What we process about players
When a server operator installs the Thorium plugin, the plugin sends us gameplay telemetry from that server. For each player we may hold:
- Identifiers: the in-game username and the platform account ID (for Minecraft, the account UUID).
- Connections: when each session began and ended, the IP address the player connected from, and whether the session ended in a kick and why.
- Gameplay telemetry: movement, rotation, combat interactions, block changes and inventory actions, as the server itself observes them.
- Detections: which checks flagged the player, with a confidence score and a violation level, plus a short recording of the movement around the detection kept as evidence so an operator can review a flag instead of trusting it blindly.
- Moderation state: flags, bans, ban reasons and a trust score, where the operator uses those features.
What the plugin never does:it does not run on the player’s computer. It has no client-side component, reads no files, inspects no memory, takes no screenshots and enumerates no processes. Everything above is derived from packets the game server already receives.
04Why we process it, and on what legal basis
- To provide the service— running detections, showing dashboards, delivering alerts. Performance of our contract with the customer.
- To keep accounts secure— session records, rate limiting, audit logs, brute-force lockouts. Legitimate interest in securing the platform.
- To bill you— plan and subscription state. Performance of contract and legal obligation for tax records.
- To improve detection accuracy— aggregate statistics about false positive and true positive rates. Legitimate interest; we do not need to identify anyone to do this and the data is aggregated.
- To email you about your account: confirmation, password resets, invitations, billing. Performance of contract.
06How long we keep it
- Account data: for as long as the account exists. Delete the account and we remove it, except records we must keep for tax and accounting.
- Sign-in sessions: until they expire or you revoke them.
- Player data and detections:for as long as the customer’s organisation keeps them. When an organisation is deleted, its player data goes with it.
- Evidence recordings: kept alongside the detection they belong to and deleted with it.
- Operational logs (application and infrastructure logs used for debugging): 14 days.
- Audit logs:retained for the life of the organisation, because their purpose is to answer “who did this and when” long after the fact.
07Your rights
If you are in the UK, EU or another region with comparable law, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to another provider. You can also complain to your data protection authority.
For account data, email privacy@thorium.ac and we will respond within 30 days.
For player data, contact the operator of the server you played on. They decide what is collected and how long it is kept; we act on their instructions. If they pass the request to us, we will carry it out.
08How we protect it
- Everything in transit runs over TLS. The origin is not reachable except through Cloudflare.
- Passwords are hashed. We cannot read them and neither can an attacker who takes a database copy.
- Platform credentials are encrypted at rest and never stored in source control.
- Access to production is limited to the people who operate it, and privileged actions are audited.
- Two-factor authentication is available on every account and we recommend turning it on.
09Where the data lives
The platform is hosted in the United States. Cloudflare and Discord operate globally. If you are in the UK or EU, that means your data is transferred outside your region; those transfers rely on the UK/EU Standard Contractual Clauses or an equivalent safeguard with each provider.
10Children
Thorium accounts are for server operators and are not offered to anyone under 16. Players on a customer’s server may be younger; where they are, the server operator is responsible for having a lawful basis to process their data and for telling them about it.
11Changes and contact
If we change this policy in a way that materially affects you, we will email the address on your account before it takes effect. The date at the top always reflects the current version.
Thorium Anti-Cheat Solutions — privacy@thorium.ac. Our terms of service are at /terms.