Privacy Policy
Last updated: Aug 18, 2026
Overview
Coalstack is a desktop application that manages a Minecraft server running on your own computer. Almost everything it does - starting/stopping the server, editing files, reading the console, installing mods - happens entirely on your machine and never touches our servers at all. The sections below explain exactly which pieces of data do leave your machine, why, and what happens to them - most of it only if you turn on Conduit (our optional remote-management feature) at all.
Account Data
- Email address, and a password if you sign up with email/password (handled entirely by our authentication provider, Supabase - we never see or store your plaintext password, only a salted hash it manages). If you sign in with Google instead, we receive your email address from Google; we never receive your Google password.
- Date of birth, collected once at signup solely to verify you meet the 13+ age requirement (see "Age Requirement" below). We don't use it for anything else.
- Display name, an optional, publicly-unique name you can set for your account - shown in place of your email in the desktop app's remote-admin UI, and (if you submit a review) shown publicly next to that review on coalstack.net.
- Payment data: handled entirely by Stripe. We never see or store your card number. We receive your email, a Stripe customer ID, and subscription status back from Stripe.
- License data: a generated license key tied to your account and subscription tier, used to unlock paid features in the desktop app. The app periodically sends this key to our server to confirm it's still active - nothing else is sent with that check.
- Device tokens: when you log into the desktop app, it's issued a random, unguessable 256-bit token (not your password) that it attaches to every request it makes to our servers afterward. A token expires automatically after one year, and you can revoke every device's token instantly from the website's Security page ("Log Out All Devices") if one is ever lost or compromised.
Conduit: What Gets Relayed When You Turn It On
Conduit is off by default and entirely opt-in, turned on per-server from the app's Settings page. With it off, nothing below this point applies to you - your server's console output, world data, and player activity never leave your machine.
Once you enable Conduit for a server, the desktop app polls our server roughly every 10 seconds and sends:
- Live status: whether the server is running, its CPU/RAM usage, TPS, and the Minecraft loader/version it's running.
- Player list: the names of players currently connected.
- Console output: new console lines since the last check-in (capped at a rolling 500-line buffer per server - older lines are dropped, not archived). This includes chat messages and any commands run through the console, since that's what a Minecraft server's console log normally contains.
- Network address: your server's public IP and port (and custom domain, if you've set one), so the "Connect" info can be shown on your remote dashboard.
- Admin actions: if you invite other Coalstack accounts as admins on a server, every remote action they take (start/stop/restart, console commands, file edits) is written to an audit log tied to their account, visible to you and other admins on that server.
This data is used only to power your own remote dashboard at coalstack.net/servers - to show you (and any admins you've explicitly invited) what's happening on your server from a browser. We don't read it, analyze it, or use it for anything else. See how Conduit is secured for the authentication/authorization model protecting this data in transit and at rest.
Reviews
If you submit a review from your Account page, your display name, star rating, and review text are sent to us and held privately until we approve it. Once approved, all three become publicly visible on coalstack.net's homepage - anyone can read them, including search engines. You can edit or withdraw your review at any time from your Account page; editing it resets it to pending until we review the change again.
What We Don't Collect
We do not collect analytics or tracking data from the desktop app itself. Unless you've turned Conduit on for a specific server (see above), we never see that server's files, world data, or console output - those stay entirely on your own machine. RCON, used internally by the app to talk to your own server, is bound to 127.0.0.1 and never exposed to your network or the internet.
How We Use It
To authenticate you, issue and validate your license key, process billing, power the Conduit remote dashboard (only for servers you've opted in), moderate submitted reviews, and respond to support requests. We do not sell your data to third parties, and we don't use anything you send us - console output included - to train any AI model.
How This Data Is Protected
- All traffic between the desktop app, this website, and our servers is encrypted (HTTPS/TLS).
- Database access is enforced with row-level security policies, not just checks in our server code - so even a bug in our API can't leak one account's server data to another account.
- Login attempts are rate-limited per account and per IP address to slow down brute-force attempts.
- We have not yet had a formal third-party security audit. We welcome anyone who wants to look closely - see our responsible disclosure policy.
Third Parties
- Stripe processes payments and is subject to its own privacy policy (stripe.com/privacy).
- Supabase hosts our database (including any Conduit data you opt into) and handles authentication (supabase.com/privacy).
- Vercel hosts this website and its server functions (vercel.com/legal/privacy-policy).
- Google, only if you choose to sign in with Google (policies.google.com/privacy).
- Resend delivers internal operational emails triggered by the site (e.g. download notifications). No personal data about you is included - just the fact that a download happened (resend.com/legal/privacy-policy).
- Discord (or Slack, if you configure one instead) only if you set up a webhook URL yourself in Settings - crash/status notifications go straight from your own desktop app to that webhook. We never see the content of these messages; they don't pass through our servers at all.
Data Retention
Account data is retained until you delete your account or request deletion. Deleting your account from Settings removes your account, profile, license, submitted reviews, and Conduit server records immediately, and cancels any active subscription; Stripe retains payment records afterward as required by law (PCI-DSS/tax record-keeping).
Conduit's console-output buffer is capped at 500 lines per server and overwritten on a rolling basis - it is not archived beyond that window. Device tokens expire automatically after one year, or immediately if you revoke them. Admin action logs are retained for as long as the server they're attached to exists, so owners can review admin activity history.
International Data Transfers
Supabase, Stripe, and Vercel may process and store data outside your country, including in the United States. Where required (e.g. for users in the EEA, UK, or Switzerland), these transfers rely on Standard Contractual Clauses or an equivalent transfer mechanism provided by each vendor.
Global Privacy Control
We honor the Global Privacy Control (GPC) browser signal as an opt-out of non-essential analytics. If your browser sends GPC, we skip loading page-view analytics for your visit automatically - no need to also click "Reject" on the cookie banner.
Age Requirement
Coalstack is not directed at children. You must be at least 13 years old (or the minimum age for consent to data processing in your region, if higher) to create an account. We ask for your date of birth at signup to enforce this and do not knowingly collect data from anyone younger. If we learn an account belongs to someone under 13, we'll delete it.
Your Rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data (e.g. your display name or email).
- Delete your account and associated data at any time from the Settings page, or by request.
- Turn Conduit off for any server at any time, immediately stopping all data relay for it.
- Withdraw or edit a submitted review at any time from your Account page.
- Receive a copy of your data in a portable format, on request.
- California (CCPA/CPRA): opt out of the "sale" or "sharing" of personal information (we don't sell data; GPC/cookie-reject is treated as this opt-out for analytics) and limit use of sensitive personal information.
- Canada (PIPEDA/Quebec Law 25): access and correct your data, and withdraw consent for any optional processing at any time.
- EEA/UK (GDPR): access, rectification, erasure, restriction, and data portability, and the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights beyond the self-service options in Settings/Account, email [email protected]. We'll respond within 30 days.
Changes to This Policy
If we make a material change to what we collect or how we use it, we'll update the date below and, for significant changes, post a notice on the site.

