This Privacy Policy explains how cookiecraftmods handles information when you browse the site, sign in with Discord, download mods, publish or submit content, manage projects, use community features, send mail/contact messages, apply for recruitment, or use staff tools.
The exact information depends on which features you use.
- Account and Discord sign-in data, including Discord ID, Discord username, avatar URL or locally cached avatar image, local user ID, role, permissions, login timestamps, and account status. We request only Discord's
identifyscope and do not request or store your email address. - Profile data you choose to add or edit, including username, profile slug, tagline, pronouns, avatar, banner, bio, location, website, online-status preference, Discord invite, social links, featured projects, profile theme, layout, accent color, notification preferences, and internal-mail preferences. We do not collect profile names, display names, or headlines.
- Community activity, including posts, sections, tags, publication submissions, media, comments, replies, likes, reports, follows, timestamps, and the user associated with those actions.
- Creator and project data, including project ownership, project members, descriptions, metadata, external links, downloads, release channels, changelogs, roadmaps, gallery images, FAQ items, publication status, review status, and related timestamps.
- Uploaded or submitted files and media, including community images, gallery images, mod files, filenames, file paths, file sizes, image titles, alt text, captions, and generated or optimized media versions.
- Mail, contact, and recruitment data, including message subjects, message bodies, participants, read status, staff application answers, application status, admin notes, reviewer information, and timestamps.
- Notification and follow data, including followed creators, followed projects, notification records, notification read state, and notification payload data used to link you to relevant site activity.
- Moderation and administration data, including reports, moderation reasons, muted or banned status, role changes, permission changes, control-panel actions, review notes, activity logs, and staff decisions.
- Session, security, and technical data, including session records, remember-token behavior, IP address where needed for security or administration, user agent, browser/device information, request timestamps, and troubleshooting logs.
- Traffic and download analytics, including page path, route name, visit time, user ID when signed in, hashed session identifiers, hashed IP identifiers, download events, and aggregated download totals.
We use information to run the website and keep its community and creator tools usable.
- Authenticate users with Discord, maintain sessions, recognize accounts, and enforce roles or permissions.
- Display public profiles, project pages, downloads, changelogs, roadmaps, galleries, community posts, comments, replies, likes, follows, and notifications.
- Accept and review community submissions, creator projects, uploaded files, release updates, recruitment applications, contact messages, reports, and moderation actions.
- Store, serve, resize, compress, convert, or optimize uploaded media and files so the site can display and deliver them reliably.
- Measure traffic, downloads, active sessions, content activity, popular projects, and general platform usage.
- Detect spam, abuse, unsafe links, suspicious activity, unauthorized access, upload problems, and technical errors.
- Provide staff tools for moderation, publication review, project review, user management, recruitment review, activity auditing, and platform administration.
We use essential cookies, Laravel sessions, CSRF protection, and limited browser storage to keep you signed in, secure requests, remember preferences, support account panels, and make community features work. Persistent sign-in is disabled by default. Advertising and embedded fundraising widgets are disabled unless the site has enabled an appropriate consent-management flow; when enabled, those providers may use cookies or similar technologies under their disclosed policies and your consent choices.
Many parts of cookiecraftmods are public. Your username, avatar, optional profile details, project pages, community posts, comments, replies, likes, follows, project updates, release information, gallery media, roadmap entries, and other published content may be visible to other users and visitors. If you choose to add optional profile fields, those fields may appear on public-facing pages.
We keep moderation and operational records to protect users and operate the platform. This may include reports, deleted or hidden content references, review notes, role or permission changes, mute and ban reasons, activity logs, authentication events, route visits, download events, errors, and control-panel actions. New traffic, download, and activity records use keyed one-way identifiers instead of direct IP addresses. Short-lived server session records may still contain an IP address and user agent for session security.
The site uses or links to third-party services including Discord authentication and avatars, CurseForge, Modrinth, Ko-fi, Patreon, YouTube, GitHub, social profile links, Google AdSense, and external project links added by creators or staff. When you use or open those services, they may receive information according to their own policies. We do not control their privacy practices.
We do not sell your personal data. We may share or disclose information when reasonably necessary to operate hosting, storage, authentication, advertising, analytics, security, moderation, legal compliance, abuse response, or platform administration. Public content is shared by displaying it on the website. Internal content such as mail, contact messages, recruitment answers, reports, and moderation notes may be visible to staff or intended participants who need access to handle the relevant feature.
Automated retention controls remove detailed traffic and download events after 400 days, activity logs after 180 days, and rejected recruitment applications after 365 days. Account records, active private messages, accepted applications, projects, and public content remain while needed to provide the service or meet legitimate moderation, security, or legal requirements. Backups may retain deleted records for a limited disaster-recovery period before rotation.
You can browse many public pages without signing in. If you sign in or use account, profile, project, community, mail, contact, recruitment, follow, like, reporting, or publishing features, some data is required for those features to work.
- You can edit many profile fields and visibility preferences in your account/profile tools.
- You can choose whether to publish optional profile details such as links and bio, and whether to show online-status visibility where supported.
- You can unfollow projects or creators and mark notifications as read.
- You can download a machine-readable copy of your account data from the account settings panel.
- You can ask for access, correction, restriction, objection, portability, or deletion of account or content data, subject to applicable moderation, security, and legal limits.
- Where processing relies on consent, you may withdraw that consent. You may also contact the relevant data-protection authority if you believe your rights have not been respected.
We may update this Privacy Policy as the platform changes. When we do, we will update the Last updated date on this page. Continued use of the site after a policy update means the updated version applies from its effective date.
The data controller is CookieCraftMods. If you have questions or want to exercise a data right, contact us through the official CookieCraftMods community channels.