Privacy notice
Last updated: 15 September 2026
1. Controller and contact
AFKSystems is the controller for personal data processed by this service. AFKSystems is operated outside Germany. Privacy requests may be submitted through a support ticket in the panel, by email to [email protected], or through the AFKSystems Discord linked on the website. Exercising a data protection right is free of charge; proof of account ownership may be requested to prevent disclosure to an unauthorised person.
2. Data we process
- Account and profile data: email address, username, password only as a cryptographic hash, language and settings. Optionally, the details that belong on a receipt: legal name, company, VAT identification number, billing address, phone number, a separate address for receipts, and the time zone. These are not required to use the service; without them a receipt carries only the account name.
- Sign-in data: session identifier, time, IP address and shortened browser/device information. Session identifiers are held in an HttpOnly cookie and cannot be read by JavaScript.
- Linked services: when used voluntarily, the account ID, name, email address, avatar and Discord membership status supplied by Discord or Google. AFKSystems never receives the password used with those providers.
- Minecraft operations: account name and UUID, destination server, version, bot settings, commands, macros, connection states and technical logs. Microsoft accounts use Microsoft's device sign-in flow; credentials are not requested in the browser.
- Communications: ticket contents, participants, status, Discord mapping, chat and support messages, and emails sent by the service.
- Billing data: credit movements, plans and add-ons, payment amount, method, reference and status. Every settled payment produces a receipt with a sequential number; what is printed on it (address, company, VAT note) is recorded at the moment of settlement and stays unchanged afterwards, because a receipt is evidence about a particular point in time. Card payments and the other electronic payment methods are processed by Stripe (Stripe Payments Europe, Limited) as payment service provider. Card numbers and security details are entered and processed at Stripe only; AFKSystems does not receive them. What is reported back to AFKSystems is the payment identifier, amount, currency, payment status, the payer's email address and which top-up it belongs to. AFKSystems, not Stripe, is the seller of the service.
- Security and operations: audit events, errors, abuse signals, and server or process metrics.
- Reach statistics: page views on the public pages, with the address, country, referring site and whether the request is recognisably automated (a search engine or tool) rather than a human. No cookie is set for this and no IP address is stored; a "unique visitor" is derived from a value recalculated every night that cannot be traced back to a person or device.
3. Purposes and legal bases
Data is processed to provide accounts and booked bot services, handle payments and credits, provide support, diagnose faults and protect the service from abuse. Where the GDPR applies, processing is based, depending on the activity, on performance of a contract or pre-contractual steps (Article 6(1)(b)), compliance with a legal obligation, particularly payment records (Article 6(1)(c)), legitimate interests in secure and reliable operation (Article 6(1)(f)), or freely given consent that may be withdrawn at any time (Article 6(1)(a)).
4. Recipients and external services
Data is available only to people and providers that need it for operation, hosting, support or billing. Depending on features chosen voluntarily, data is sent to Discord, Google, Microsoft or Stripe. Profile pictures may also be loaded from Gravatar; Gravatar receives the MD5 digest of the normalised email address and ordinary request data (in particular IP address and browser information), not the plain-text email address. The account settings can instead pin Discord or Google, or use the entirely local initials image. When a bot connects, the selected Minecraft server necessarily receives information such as Minecraft name, UUID, connection IP address and game actions sent. Email providers process sender, recipient and message contents. Personal data is not sold or disclosed for advertising.
Those providers may process information outside the user's country or outside the EU/EEA. Such transfers are made in accordance with applicable legal requirements and the safeguards offered by the provider. The privacy terms of a selected third-party service also apply.
5. Cookies and local storage
AFKSystems uses no advertising or tracking cookies. An HttpOnly session cookie is necessary for sign-in and a language cookie stores the selected language. Language, colour theme, collapsed navigation and dismissed notices may also be stored locally in the browser. Local values do not leave the browser unless a feature expressly synchronises them with the account.
6. Retention
Account data is generally held while the service is used. If the account is scheduled for deletion in the panel, the services stop immediately; full deletion follows after a grace period of fourteen days and can be cancelled in the panel at any time until then. Sessions end when they expire, the user signs out or they are revoked. Technical logs and security information are kept only as long as reasonably needed for diagnostics, security and abuse prevention. Reach statistics rows are deleted after six months. Ticket and contract data is retained for handling and possible evidence. Payment and accounting records are kept for the periods required by applicable commercial, tax or consumer law. Data is then deleted or anonymised unless an unresolved claim, security incident or legal obligation requires continued retention.
7. Rights
Where applicable law provides, users have rights of access, correction, erasure, restriction, portability and objection. Access and portability can be exercised without asking: Settings → Your data offers the account's complete record as a machine-readable file, and account deletion is started from the same place. Correction likewise happens in the panel, by changing the details. Consent can be withdrawn at any time for the future. A complaint may also be made to the competent data protection authority. Information required by law or needed to perform an active contract may be deleted only after that requirement ends.
8. Security and automated decisions
AFKSystems uses measures including encrypted HTTPS connections, hashed passwords, random revocable sessions, role-based access, input validation, security headers and protected server files. No internet service can promise absolute security. There is no solely automated decision producing legal or similarly significant effects. Automatic plan renewals from an available credit balance and technical security restrictions follow the user's settings or explainable security rules.
9. Changes
This notice is updated when functions, providers or legal requirements change. The current version and its date are published on this page.