KuroHosting
Plans Calculator Compare hosts Customizemods, plugins & datapacks
Events Streamers FAQ Log in Start →
your data, your business

Privacy Policy

Last updated: August 7, 2026. KuroHosting is hosted in the Netherlands and follows the GDPR. Here's exactly what we collect and why.

Contents
  1. TL;DR
  2. Who we are
  3. What we collect
  4. Why we collect it
  5. Who we share it with
  6. Cookies
  7. Where data lives
  8. How long we keep it
  9. Your rights (GDPR)
  10. If something goes wrong
  11. Minors
  12. Contact & complaints
Friendly note:

No ad networks, no tracking pixels, no data sold. Ever.

1. TL;DR

We collect the absolute minimum to run a Minecraft host: your email and the bare technical stuff your server needs. There's no payment processing built into the site yet, so the site doesn't take or store card details. We don't sell anything to anyone, we don't run ad trackers, and you can ask us to wipe your data at any time. Hosted in the Netherlands.

The short list:
  • Email + password (hashed, never readable)
  • Server names, IPs, subdomains, and your server's files
  • A log of actions taken in the panel (restarts, file changes, whitelist changes)
  • No analytics trackers, no ad pixels, no Facebook SDK

2. Who we are (the data controller)

KuroHosting is run by one person as a sole trader based in the Netherlands, and that business — KuroHosting — is the "data controller" for everything described on this page. In plain terms: I decide what gets collected and why, so I'm the one responsible for it.

Business registration: KvK registration is in progress; this page will list the number once it's issued.

You can reach me directly at info@kurohosting.com, or through the privacy request form if you prefer.

3. What we collect

Account info: the display name, email, and password hash you submit at signup. Optionally your Twitch handle (so we can verify partner perks).

Payment info: none in our database. Payments aren't wired up on the site yet, so there's nothing here for the site to collect — no card numbers, no card tokens, no last-4 digits, no billing addresses, no invoice history. There are no payment fields in our database at all.

Server data: server names, allocated RAM, IPs and subdomains assigned to you, plugin and mod lists, and your actual world/config files on disk. Backups are .tar.gz archives, and copies go to Google Drive — encrypted on our own machines first, so Google only holds ciphertext (see section 5 for the details and one honest caveat about older backups).

Logs: a log of actions taken in the panel — restarts, file writes, whitelist and collaborator changes, backups — recording who did it, what it was, and when. It can include email addresses, server and file names, and the in-game usernames of players you whitelist, op, ban, or kick. Kept for 90 days. We don't record login timestamps, and the site itself doesn't write web access logs.

Optional integrations: none. There is no third-party sign-in — accounts are email and password only, and we hold no third-party account IDs, access tokens or refresh tokens. The Twitch handle above is free text you type yourself; we never check it against Twitch or fetch anything from them. There is no Discord login either; the Discord in our footer is just a link to the server.

Things that end up public: the subdomain we create for your server is a public DNS record, and it's built from the server name you pick. Your server's MOTD, icon, version, and who's online can be read by anyone who pings the address — that's how Minecraft's server list works, not something we add on top.

4. Why we collect it

Every bit of data here exists for a specific reason — and the GDPR asks us to name the legal basis for each one, so here they are:

  • Email & account info: log in, recover password, reply to your messages, warn about outages. Legal basis: performance of our contract with you (Art. 6(1)(b)).
  • Server files: obviously — that is the product. Legal basis: contract (Art. 6(1)(b)).
  • Panel action log & abuse detection: work out what changed on a server and when, and spot abuse. Legal basis: our legitimate interest in keeping the platform secure and accountable (Art. 6(1)(f)).
  • Twitch handle: verify streamer perk eligibility (and only that). Legal basis: contract (Art. 6(1)(b)) — it's part of the perk you're asking for.
  • Invoices & tax records: none exist yet, since billing isn't wired up. Once it is: legal basis: legal obligation — Dutch tax law (Art. 6(1)(c)).
  • Optional product-update emails: only if you opt in, and you can opt out any time. Legal basis: consent (Art. 6(1)(a)).

We don't profile you. We don't try to predict what other services you might want. We don't have a marketing automation funnel.

5. Who we share it with

A short list of "sub-processors" — services we use to actually run KuroHosting:

  • OVH (network relay) — a VPS in London, UK that forwards player connections on to your server over an encrypted tunnel. It doesn't run your server or hold your worlds. It also runs our off-site uptime monitor, which is sent each server's internal panel ID (not the name you gave it), its port, on/off state, and a partly-masked email address of whoever last started or stopped it.
  • Cloudflare (DNS + website proxy) — runs DNS for kurohosting.com and creates the A and SRV records for your server's subdomain. This website and the control panel sit behind Cloudflare, so it terminates HTTPS for them and your dashboard and panel traffic passes through it. Your Minecraft subdomain is DNS-only, so actual game traffic goes straight to us and never touches Cloudflare.
  • Resend (transactional email) — sends account email like verification links and password resets, and delivers contact-form messages to us. So Resend receives your name, your email address, the full text of anything you send through the contact form, and any files you attach to it.
  • Google Drive (backup storage) — server backups and our own nightly site backups are uploaded here. That includes your world and config files, and in the nightly site backup, our account database. Since August 2026 we encrypt every archive on our own machines (public-key encryption with age) before it's uploaded, so Google only ever stores ciphertext it can't read; the decryption key never leaves us and is never sent to Google. Server world backups pick up the same encryption as this rollout finishes on the backup machine — new world backups switch over within days of this update, and anything uploaded before then sits on Drive as a plain archive until it ages out. We don't control which region Google stores the files in, which matters a lot less now that they're encrypted.
  • Modrinth (mod & plugin catalogue) — we fetch mod listings and files from Modrinth. Mod icons load straight from their CDN in your browser, so they see your IP address when you browse the mod list.
  • Mojang / Microsoft (Minecraft accounts) — when we look up a player's skin or UUID we send that Minecraft username to Mojang. We do it from our server, so your browser never talks to them directly.

That's it. No ad networks, no data brokers, no "we may share with our partners". If we ever add a new sub-processor, we'll update this page and email you at least 30 days before they go live. One we've removed: Google Fonts. This site used to load its fonts from Google's servers, which meant Google saw your IP address on every visit. The fonts are now hosted by us, so your browser no longer talks to Google when you load a page here.

Not sharing, but you should know it anyway: as the person who runs KuroHosting, I have admin access to every server on the platform. That means I can open your live console, run console commands, read, upload and delete files, download your backups, and see server secrets like your RCON password. It exists so I can fix things and deal with abuse reports, not to browse your world. Changes I make from the admin side are written to the action log — and since August 2026, so are reads: opening your console, listing or reading files, downloading a file or a backup, and viewing your startup settings (where those secrets live) all leave an entry when done from the admin side. The log records what was accessed (file names and paths, never the contents) and is kept for 90 days like the rest of the action log, so you can ask what I looked at and get a real answer.

6. Cookies

We use a tiny set of first-party cookies, all essential:

  • kuro_session — keeps you logged in. Required. Marked HttpOnly, Secure, and SameSite=Strict, which is also what protects your account from cross-site request forgery — no separate tracking token needed.
  • Your cookie-banner choice is remembered in your browser's local storage, not a cookie.

No Google Analytics. No Facebook Pixel. No "consent management platform" because there's nothing to consent to beyond the cookies the service literally cannot function without.

7. Where data lives

All Minecraft servers, backups, and user data are physically hosted in the Netherlands, inside the EU — so none of it leaves the bloc by default. Backups are the exception: they're uploaded to Google Drive, and we don't control which region Google keeps them in — though as explained in section 5, those archives are encrypted before they leave our machines. Email is sent through Resend — your email address, the content of your message, and anything you attach to the contact form go through them, but never your worlds or login credentials.

International transfers. Some of the sub-processors in section 5 sit outside the EU, so a few slices of data legally "transfer" out of the bloc. Here's the coverage for each: Google (US — encrypted backups) and Cloudflare (US — website/panel traffic) are both certified under the EU-US Data Privacy Framework; Resend (US — email) is covered by the EU Standard Contractual Clauses; and OVH (UK — the network relay) is covered by the European Commission's adequacy decision for the United Kingdom, which says UK data protection is essentially equivalent to the EU's.

8. How long we keep it

Data typeKept for
Account & profile infoWhile your account exists, deleted within 30 days of account closure
Server worlds & configsWhile your subscription is active, then 30 days after cancellation
BackupsSet per server — by default 7 daily and 4 weekly copies. Our own nightly site backups go to Google Drive (encrypted, see section 5) and aren't automatically deleted there yet — an honest gap we're working on.
Invoices & tax recordsNone exist yet — billing isn't wired up on the site. Once it is: 7 years (Dutch tax law requirement)
Panel action log90 days
Support tickets & emails2 years

9. Your rights under GDPR

Because we're an EU-based business (a sole trader based in the Netherlands — see section 2), you get the full set of rights under the GDPR — no matter where you live:

  • Access: ask for a copy of everything we have on you. We'll send it within 30 days.
  • Correction: change anything that's wrong (most things are editable from the dashboard directly).
  • Deletion: ask us to delete your account. We will — there's no invoice history to withhold today since billing isn't wired up yet. Once it is, we'd keep only what Dutch tax law requires, per the retention table above.
  • Portability: download a full backup of your server — worlds, configs and all — from the dashboard at any time. It comes as a .tar.gz archive. For a copy of your account data, use the access request above.
  • Object to processing: you can opt out of optional things (like product update emails) without losing service.

To exercise any of these, email info@kurohosting.com or use the privacy request form. We don't charge for any of it.

10. If something goes wrong (data breaches)

If we ever suffer a data breach that puts your rights or freedoms at risk, we'll report it to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of it, where the GDPR requires that. And if the breach is likely to put you at high risk — say, your email and password hash leaked — we'll notify the affected users directly, without undue delay, telling you plainly what happened, what data was involved, and what we're doing about it. No burying it in a changelog.

11. Minors

You need to be at least 16 to make an account on your own. If you're younger, a parent or guardian needs to set the account up and supervise it. We don't knowingly collect data from anyone under 13 — if we find out we have, we delete it immediately.

12. Contact & complaints

For privacy questions, data requests, or anything else, email info@kurohosting.com or use the privacy contact form. Flag it as urgent if you need a fast reply.

If you're not happy with how we handled a privacy concern, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Their contact info is at autoriteitpersoonsgegevens.nl. But honestly — email me first, we can almost always sort it out.

Read the Terms → Back to signup
KuroHosting

Built by a streamer, for streamers.

Plans

  • Cozy
  • Standard
  • Modded
  • Community
  • Realm
  • Compare hosts
  • Calculator

Resources

  • Add-ons
  • Modded hosting
  • UK & EU hosting
  • Event hosting
  • Streamer perks
  • FAQ
  • Status page

Hangouts

  • Discord
  • Twitch
  • Twitter / X
  • Email
  • Terms
  • Privacy
© 2026 KuroHosting · not affiliated with Mojang or Microsoft v0.1