KuroHosting
Plans Calculator Compare hosts Customizemods, plugins & datapacks
Events Streamers FAQ Log in Start →
your data, your business

Privacy Policy

Last updated: July 26, 2026. KuroHosting is hosted in the Netherlands and follows the GDPR. Here's exactly what we collect and why.

Contents
  1. TL;DR
  2. What we collect
  3. Why we collect it
  4. Who we share it with
  5. Cookies
  6. Where data lives
  7. How long we keep it
  8. Your rights (GDPR)
  9. Minors
  10. Contact & complaints
Friendly note:

No ad networks, no tracking pixels, no data sold. Ever.

1. TL;DR

We collect the absolute minimum to run a Minecraft host: your email and the bare technical stuff your server needs. There's no payment processing built into the site yet, so the site doesn't take or store card details. We don't sell anything to anyone, we don't run ad trackers, and you can ask us to wipe your data at any time. Hosted in the Netherlands.

The short list:
  • Email + password (hashed, never readable)
  • Server names, IPs, subdomains, and your server's files
  • A log of actions taken in the panel (restarts, file changes, whitelist changes)
  • No analytics trackers, no ad pixels, no Facebook SDK

2. What we collect

Account info: the display name, email, and password hash you submit at signup. Optionally your Twitch handle (so we can verify partner perks).

Payment info: none in our database. Payments aren't wired up on the site yet, so there's nothing here for the site to collect — no card numbers, no card tokens, no last-4 digits, no billing addresses, no invoice history. There are no payment fields in our database at all.

Server data: server names, allocated RAM, IPs and subdomains assigned to you, plugin and mod lists, and your actual world/config files on disk. Backups are ordinary .tar.gz archives — we don't encrypt them ourselves before they're stored, and copies go to Google Drive (see section 4).

Logs: a log of actions taken in the panel — restarts, file writes, whitelist and collaborator changes, backups — recording who did it, what it was, and when. It can include email addresses, server and file names, and the in-game usernames of players you whitelist, op, ban, or kick. Kept for 90 days. We don't record login timestamps, and the site itself doesn't write web access logs.

Optional integrations: none. There is no third-party sign-in — accounts are email and password only, and we hold no third-party account IDs, access tokens or refresh tokens. The Twitch handle above is free text you type yourself; we never check it against Twitch or fetch anything from them. There is no Discord login either; the Discord in our footer is just a link to the server.

Things that end up public: the subdomain we create for your server is a public DNS record, and it's built from the server name you pick. Your server's MOTD, icon, version, and who's online can be read by anyone who pings the address — that's how Minecraft's server list works, not something we add on top.

3. Why we collect it

Every bit of data here exists for a specific reason:

  • Email: log in, recover password, reply to your messages, warn about outages
  • Server files: obviously — that is the product
  • Panel action log: work out what changed on a server and when, and spot abuse
  • Twitch handle: verify streamer perk eligibility (and only that)

We don't profile you. We don't try to predict what other services you might want. We don't have a marketing automation funnel.

4. Who we share it with

A short list of "sub-processors" — services we use to actually run KuroHosting:

  • OVH (network relay) — a VPS in London, UK that forwards player connections on to your server over an encrypted tunnel. It doesn't run your server or hold your worlds. It also runs our off-site uptime monitor, which is sent each server's internal panel ID (not the name you gave it), its port, on/off state, and a partly-masked email address of whoever last started or stopped it.
  • Cloudflare (DNS + website proxy) — runs DNS for kurohosting.com and creates the A and SRV records for your server's subdomain. This website and the control panel sit behind Cloudflare, so it terminates HTTPS for them and your dashboard and panel traffic passes through it. Your Minecraft subdomain is DNS-only, so actual game traffic goes straight to us and never touches Cloudflare.
  • Resend (transactional email) — sends account email like verification links and password resets, and delivers contact-form messages to us. So Resend receives your name, your email address, the full text of anything you send through the contact form, and any files you attach to it.
  • Google Drive (backup storage) — server backups and our own nightly site backups are uploaded here. That includes your world and config files, and in the nightly site backup, our account database. We don't encrypt those archives ourselves, and we don't control which region Google stores them in.
  • Google Fonts (web fonts) — every page on this site loads its fonts from Google, so Google sees your IP address and your browser. It doesn't see which page you're on — this site sends no referrer header, so that part never reaches them.
  • Modrinth (mod & plugin catalogue) — we fetch mod listings and files from Modrinth. Mod icons load straight from their CDN in your browser, so they see your IP address when you browse the mod list.
  • Mojang / Microsoft (Minecraft accounts) — when we look up a player's skin or UUID we send that Minecraft username to Mojang. We do it from our server, so your browser never talks to them directly.

That's it. No ad networks, no data brokers, no "we may share with our partners". If we ever add a new sub-processor, we'll update this page and email you at least 30 days before they go live.

Not sharing, but you should know it anyway: as the person who runs KuroHosting, I have admin access to every server on the platform. That means I can open your live console, run console commands, read, upload and delete files, download your backups, and see server secrets like your RCON password. It exists so I can fix things and deal with abuse reports, not to browse your world. Changes I make from the admin side are written to the action log; reads currently aren't.

5. Cookies

We use a tiny set of first-party cookies, all essential:

  • kuro_session — keeps you logged in. Required. Marked HttpOnly, Secure, and SameSite=Strict, which is also what protects your account from cross-site request forgery — no separate tracking token needed.
  • Your cookie-banner choice is remembered in your browser's local storage, not a cookie.

No Google Analytics. No Facebook Pixel. No "consent management platform" because there's nothing to consent to beyond the cookies the service literally cannot function without.

6. Where data lives

All Minecraft servers, backups, and user data are physically hosted in the Netherlands, inside the EU — so none of it leaves the bloc by default. Backups are the exception: they're uploaded to Google Drive, and we don't control which region Google keeps them in. Email is sent through Resend — your email address, the content of your message, and anything you attach to the contact form go through them, but never your worlds or login credentials.

7. How long we keep it

Data typeKept for
Account & profile infoWhile your account exists, deleted within 30 days of account closure
Server worlds & configsWhile your subscription is active, then 30 days after cancellation
BackupsSet per server — by default 7 daily and 4 weekly copies. Our own nightly site backups go to Google Drive and aren't automatically deleted there yet.
Invoices & tax recordsNone exist yet — billing isn't wired up on the site. Once it is: 7 years (Dutch tax law requirement)
Panel action log90 days
Support tickets & emails2 years

8. Your rights under GDPR

Because we're an EU-based business (a sole trader registered in the Netherlands), you get the full set of rights under the GDPR — no matter where you live:

  • Access: ask for a copy of everything we have on you. We'll send it within 30 days.
  • Correction: change anything that's wrong (most things are editable from the dashboard directly).
  • Deletion: ask us to delete your account. We will — there's no invoice history to withhold today since billing isn't wired up yet. Once it is, we'd keep only what Dutch tax law requires, per the retention table above.
  • Portability: download a full backup of your server — worlds, configs and all — from the dashboard at any time. It comes as a .tar.gz archive. For a copy of your account data, use the access request above.
  • Object to processing: you can opt out of optional things (like product update emails) without losing service.

To exercise any of these, use the privacy request form. We don't charge for any of it.

9. Minors

You need to be at least 16 to make an account on your own. If you're younger, a parent or guardian needs to set the account up and supervise it. We don't knowingly collect data from anyone under 13 — if we find out we have, we delete it immediately.

10. Contact & complaints

For privacy questions, data requests, or anything else, use the privacy contact form. Flag it as urgent if you need a fast reply.

If you're not happy with how we handled a privacy concern, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Their contact info is at autoriteitpersoonsgegevens.nl. But honestly — email me first, we can almost always sort it out.

Read the Terms → Back to signup
KuroHosting

Built by a streamer, for streamers.

Plans

  • Cozy
  • Standard
  • Modded
  • Community
  • Realm
  • Compare hosts
  • Calculator

Resources

  • Add-ons
  • Event hosting
  • Streamer perks
  • FAQ
  • Status page

Hangouts

  • Discord
  • Twitch
  • Twitter / X
  • Email
  • Terms
  • Privacy
© 2026 KuroHosting · not affiliated with Mojang or Microsoft v0.1