Skip to content
Connection Guard
Download

Privacy, in plain language

This page explains what is sent where. The formal privacy policy for the dashboard will be published before the dashboard leaves preview.

This website

connectionguard.net sets no cookies, uses no analytics and loads nothing from third parties. Your theme choice (light or dark) is kept in your browser's local storage and never leaves it. Download counts are read from Modrinth, SpigotMC, Hangar and GitHub when the site is built, not from your browser.

The plugin (0.4.x, current release)

The plugin sends a player's IP address only to the detection services you enable in config.yml, such as ProxyCheck or IP-API. Their own privacy terms apply. Nothing is sent to connectionguard.net.

The optional dashboard (from 0.5)

From 0.5, the plugin can link to the free dashboard at app.connectionguard.net. Logins never wait on it, and it turns off with cloud.enabled: false, /cg cloud disable or the environment variable CONNECTIONGUARD_CLOUD=false. Off means no request to connectionguard.net at all.

Off

Sent: Nothing.

On, not linked (default from 0.5)

Sent: An anonymous install ID, platform and versions, the protection mode, totals per interval (checks, refusals, cache hits, response times, counts per country and reason) and detection service health.

Never sent: Player IPs, UUIDs, names, API keys, webhook URLs.

Linked, terms accepted

Sent: Additionally one entry per check: time, IP, verified UUID, verdict and reason, and what each service answered (country, network, provider, risk).

Never sent: API keys, player names, console commands.

  • Entries are kept for 30 days, hourly totals for 13 months. Unlinked installs that stop reporting are deleted after 30 days.
  • Data is stored in the EU, on Cloudflare.
  • API keys entered in the dashboard are stored encrypted until your server confirms them, then deleted from the dashboard.
  • You sign in with Discord. The dashboard reads only your Discord user ID, name and avatar.
  • The server operator decides about their players' data. The dashboard processes it only to show it to them.

The exact wire format is public in packages/protocol.

Questions

Ask on Discord or open an issue.