Privacy Policy
Effective: July 21, 2026
Who we are
MCTotem (mctotem.app) provides Minecraft server diagnostics. It is independently operated and based in Quebec, Canada. Contact for anything in this policy: [email protected].
The person responsible for the protection of personal information at MCTotem is its operator, reachable at the same address.
What we collect
- Account data: email address, display name, a salted hash of your password (never the password itself), and, if you sign in with Discord, your Discord user ID.
- Log Doctor pastes: the log content you submit. IP addresses, player names and UUIDs are removed before storage. The redacted result is stored at a public permalink (see the Terms), together with the automated diagnosis.
- Connected-server telemetry: if you install the agent plugin or connect a Pterodactyl panel: filtered log lines (warnings/errors only, redacted on your server before transmission and again on ours), crash reports (redacted), performance metrics (TPS, memory, player counts, never player identities), your plugin list with versions, and hashes of plugin config files (never the file contents). Raw log lines are kept in a rolling window of at most 48 hours or 20 MB per server, then deleted.
- Server connection address: if you use the test player, the address and port you tell us players use, plus the network address your agent plugin last connected from. We compare the two to check that you are pointing the test player at your own server. This is server infrastructure, not a visitor address.
- Test player results: for each test we store what the bot did, whether each step passed, how long the join took, and readings about the world around it: position, dimension, health, food level, time of day, the number of players online, the types of nearby entities, and the item held. No player names or identities are recorded in these readings. If a test checks for a message in chat, the matching line is stored, with player names and IP addresses removed first. Test results are deleted after 30 days.
- Linked Minecraft accounts: if you link a Minecraft account for the test player, you sign in directly with Microsoft. We never receive or store your password. We store the resulting access token encrypted at rest, together with the account's Minecraft username and UUID. Removing the account from MCTotem deletes the stored token, and you can revoke our access from your Microsoft account settings at any time.
- Discord integration: for linked channels we store the Discord server and channel IDs; feedback votes made via Discord buttons store a salted hash of the voter's Discord ID (not the ID itself).
- IP addresses: used transiently to enforce rate limits and de-duplicate feedback votes, stored only as salted hashes. We never store raw visitor IPs.
- Billing: payments are processed by Paddle, our merchant of record; we store your Paddle customer and subscription IDs, never card or PayPal details.
- Cookies: one essential, httpOnly session cookie for signed-in users. No advertising or analytics cookies.
AI processing
To generate diagnoses, redacted excerpts of logs (never full raw logs) together with your plugin list and server version are sent to Anthropic's API (Claude models). Validated diagnoses are stored in an anonymous, shared knowledge base keyed by a fingerprint of the error. It contains no server or user identifiers.
The test player uses the same API in two places. When you describe a test in your own words, that description and your server version are sent so it can be turned into a sequence of steps. When a test finishes, the step results are sent so a plain-language report can be written. Those results can include a chat line, which has already had player names and IP addresses removed before it is stored or sent.
Who we share data with
Service providers only, each for one job: Anthropic (AI diagnosis of redacted excerpts and test reports), Paddle (billing, as merchant of record), Discord (message delivery to channels you linked), Microsoft (sign-in when you link a Minecraft account), and Cloudflare (network proxying/TLS). These providers are located outside Quebec, mainly in the United States. We do not sell data or share it for advertising.
Retention & deletion
- Raw server log lines: at most 48 hours / 20 MB per server, pruned automatically.
- Test player results, including any chat line: 30 days, pruned automatically.
- Linked Minecraft account tokens: kept encrypted until you remove the account, which deletes them.
- Log Doctor pastes: retained as public pages; contact us to remove one.
- Metrics, events and diagnoses tied to your servers: kept while your account exists.
- On request we delete your organization or account, which removes its servers, events, raw logs, metrics, linked Minecraft account tokens and Discord links. Anonymous entries in the shared error knowledge base are not linked to you and are retained.
Your rights
Wherever you live, you can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Write to [email protected] and we will respond within 30 days. Deletion is handled by us on request; there is no self-serve delete button yet.
As a Canadian business we handle personal information under Canada's federal private sector privacy law (PIPEDA). If you believe we have mishandled your information, you can complain to the Office of the Privacy Commissioner of Canada.
Security
All traffic is encrypted in transit (TLS). Credentials are stored as salted hashes; server agent tokens, linked Minecraft account tokens and third-party API keys are hashed or encrypted at rest. The agent plugin is outbound-only and never grants us access to your machine. The test player is the one part of the service that connects to your server, and only to the address you give us, only when you have enabled it.
Changes
We will announce material changes to this policy on the dashboard at least 14 days before they take effect.
NOT AN OFFICIAL MINECRAFT PRODUCT. NOT APPROVED BY OR ASSOCIATED WITH MOJANG OR MICROSOFT.