Privacy Policy
Last updated: 2026-08-07 · v2.0
1. Who we are and how to reach us
BedrockConnect is operated by:
GKM Interactive UG (haftungsbeschränkt) Managing Director: Davin Gindorf Wasserstraße 5, 37186 Moringen, Germany Registered: Amtsgericht Göttingen, HRB 207239 VAT ID: DE364802252
We are the controller for the personal data described in this policy. The full company details are on our imprint page.
| What you want | Where to write |
|---|---|
| Privacy questions, data requests, complaints, legal notices | contact@gkminteractive.com |
| Help with the app, bugs, subscriptions | help@bedrockconnect.app |
Postal mail reaches us at the address above. We have not appointed a data protection officer; privacy requests are handled by our management and answered from contact@gkminteractive.com.
This policy covers the BedrockConnect mobile app on iOS and Android and the website at https://bedrockconnect.app. It does not cover the Minecraft servers you connect to. They are operated by third parties under their own rules — see section 8.
The rules for using the app are in our Terms of Service. If you want to report content or a listed server, use the routes on our notice and contact page.
2. At a glance
This section summarises the policy. The detail follows below.
- There are no accounts. No sign-up, no email address, no password, no real name, no phone number, no postal address, no photos, no biometrics, no precise location. We do not know who you are.
- We do see your Xbox identity when you join a listed server. When your console connects through the app, the app reads your gamertag and Xbox User ID (XUID) out of the Minecraft login handshake. If the server you join is one of the servers listed in the app, that pair plus a timestamp is sent to us and passed to that server's operator. This is the most intrusive processing in the app and it is set out in its own section — section 4.
- Servers you add yourself are different. For a server you type in yourself, no join record is ever written. Only an anonymous counter for the address is recorded.
- Much of the data never leaves your phone. Your imported texture packs, the servers you added, your onboarding choices, your age answer, the local crash identifier and your advertising choice all stay on the device.
- BedrockConnect is not a VPN. It does not have a VPN entitlement on iOS and does not use Android's VPN service. It runs a small server on your phone that your console connects to on your own network.
- In Nintendo Switch mode the app answers your console's DNS queries — all of them, not just the seven Mojang domains it needs. Nothing about that is stored or sent to us. See section 5.
- Ads pay for the free version. Google AdMob serves them, with AppLovin and Meta Audience Network as mediation partners. Premium subscribers see no ads.
- We do not sell your personal data to anyone.
- We do not process payments. Apple and Google bill all consumer subscriptions. We never see card details.
3. What we process
The following is organised by the source of the data.
3.1 What you enter in the app
| Data | Why | Where it goes |
|---|---|---|
| Servers you add yourself: name, address, port | So the app can show and start them | Stored on your device. The address alone is sent to us as an anonymous counter so we know which addresses are popular. Your name for the server and your port are never sent. |
| Texture packs you import | So they can be merged into a supported server's pack (Premium) | The pack file is uploaded to our object storage at Cloudflare and merged there. The pack's name, description, preview image and sub-pack list stay on your device. |
| Onboarding choices: console type, transport mode | To set the app up | Stored on your device only |
| Your answer to the age question | To configure advertising and age-appropriate behaviour | Stored on your device only, as a single yes/no value. See section 11. |
| Messages you send to our support assistant on Discord | To answer you | See section 12 |
3.2 What the app collects automatically
| Data | Why | Where it goes |
|---|---|---|
| Your IP address | Unavoidable — every internet connection exposes it | Seen by whoever the app is talking to at that moment: our backend, Cloudflare's edge, Google, RevenueCat, the ad networks, Discord, and the app store when checking for updates. We do not store IP addresses. There is no column for one anywhere in our database. |
| Coarse country and continent, derived from your IP by Cloudflare | To recommend a server host that is closer to you and therefore faster | Used for that request and discarded. Never stored, and it never changes the order of any server list — see /ranking. |
| Device model, operating system version, app version, language | Crash diagnostics and app measurement | Google (Crashlytics, Google Analytics for Firebase) |
| A crash-report identifier generated on your device | So multiple crash reports from the same install can be grouped | Google Crashlytics. It is a random value created on your phone, not a device identifier. It is not displayed, but you can copy it by pressing and holding the version number at the bottom of the settings screen. |
| Firebase installation ID | Created automatically by Google's SDKs | |
| Automatic app-measurement events (first open, session start, app update, app removal, purchase and ad events) | Google Analytics for Firebase collects these automatically | Google. We do not send Google any custom events, we do not set user properties, and we do not give Google an ID of our own for you. |
| Advertising identifier (IDFA on iOS, GAID on Android) | Advertising | Only with your consent, and only where you are an established adult. See sections 7 and 11. |
| Subscription status, store country, receipt data | To know whether you have Premium | RevenueCat, under an anonymous app user ID that RevenueCat generates. We never call RevenueCat's login function, so there is no identity attached to it. |
| Network connection type (Wi-Fi / mobile / none) | To warn you when the console will not be able to find your phone | Stays on the device |
| Your phone's local Wi-Fi IP address (e.g. 192.168.x.x) | Needed so the console can be pointed at your phone | Stays on the device. It is used in the app's own DNS answers and shown on screen. It is never sent anywhere. |
Two further network calls should be noted: the app asks the App Store or Play Store whether a newer version exists, and it asks Discord how many people are in our community server. Both expose your IP to Apple, Google or Discord. Neither sends anything about you.
Fonts are bundled inside the app. The app does not fetch fonts from a font CDN at runtime.
3.3 What our servers process when you join a listed server
The app shows three tabs: Partner, Featured and Custom. Partner and Featured are servers we list. Custom is servers you added yourself.
| Data | When | Kept |
|---|---|---|
XUID, gamertag, timestamp, platform (android or ios), and whether a custom texture pack was used |
Only when you join a server in the Partner or Featured tab | Used for 12 months — see section 9 |
| A counter per server address: how many times it was started, how many times it was added | For every address, including servers you added yourself | Indefinitely. The counter is a number that contains no identifier and cannot be traced back to you. |
| The server address you are connecting to | To look up or build the right texture pack | Not linked to you |
| Your uploaded texture pack file | Only if you are a Premium subscriber using custom packs | 30 days after last use, removed at the next monthly cleanup run — see section 9 |
| The merged pack built from it and a server's pack | Same | Held in a content-addressed cache with no record of who requested it; no automatic expiry yet — see section 9 |
| The anonymous RevenueCat app user ID | Sent with texture-pack requests so we can check you have Premium | Not stored in our database |
Nothing else about the session is processed. After the app hands your console over to the server, gameplay and chat go directly between your console and that server. We do not proxy them, see them or store them.
For partner-facing servers, the operator's own business data — a contact email address and Stripe billing identifiers — is processed under /partner-terms. That is business data about the operator, not about you.
3.4 What third-party SDKs collect
These components are compiled into the app and collect data in their own right. The full list of recipients, their locations and the transfer basis for each is at /subprocessors.
| SDK / service | Provider | What it touches |
|---|---|---|
| Google Mobile Ads (AdMob) | Advertising identifier, IP address, device and OS, coarse location, ad interactions | |
| AppLovin MAX mediation | AppLovin | Device identifiers, IP address, ad engagement — as an AdMob mediation partner |
| Meta Audience Network | Meta Platforms | Device identifiers, IP address, ad engagement — as an AdMob mediation partner |
| Google User Messaging Platform | Presents the consent form and stores your consent record on your device | |
| App Tracking Transparency | Apple | On iOS, your answer to Apple's tracking prompt |
| Google Analytics for Firebase | Automatic app-measurement events, installation ID, device data, coarse geography from IP | |
| Firebase Crashlytics | Crash and error reports, device data, the local crash identifier | |
| Firebase Cloud Messaging | Registers a messaging token with Google. We do not read, store or use that token, and we do not send push notifications from our own systems. | |
| Firebase Installations | The installation ID other Firebase SDKs depend on | |
| RevenueCat | RevenueCat | Anonymous app user ID, store receipts, subscription state, store country, device data |
| Cloudflare | Cloudflare | Edge protection and delivery for everything the app calls; object storage for texture packs; the AI model behind our support assistant |
| Cloud hosting | Hosts our backend and our database | |
| Sentry | Sentry | Error reports from our backend, not from your device |
| Discord | Discord | Only if you join our community server or talk to our support assistant |
| Stripe | Stripe | Partner server operators only. Stripe never processes a consumer subscription for us and never receives your data. |
Apple and Google process your subscription as the merchant of record. We receive the fact of a subscription, never a payment method.
4. Your XUID and your gamertag
This is the processing you should read most carefully.
What a XUID is. Every Xbox network account has an Xbox User ID — a permanent number Microsoft assigns to it. It is not your name, your email address or your Microsoft account login. It is a stable number that identifies the same account over time. Your gamertag is the public display name attached to it, which other players already see in-game.
How we obtain them. To send your console to a server the console's own menus cannot reach, the app has to speak Minecraft's protocol. Your console connects to the app; the app performs the Minecraft encryption handshake itself; the login packet the console sends contains your gamertag and your XUID; the app then sends a Transfer instruction that redirects the console to the server you chose. Reading those two fields is a by-product of that handshake. There is no way to complete the transfer without processing the login packet.
When we record them, and when we do not.
- Servers listed in the app (Partner and Featured tabs): the XUID, gamertag, join time, platform and a flag for whether a custom texture pack was used are sent to our backend and stored.
- Servers you added yourself (Custom tab): nothing is recorded. No XUID, no gamertag, no join record of any kind. Only the anonymous per-address counter described above.
If you do not want a join to be recorded at all, add the server yourself instead of selecting it from a list. That is a genuine and complete opt-out, and it is free of charge.
Who else receives them. The operator of the listed server you joined can see the join records for their own server — the XUID, gamertag, how often that player joined and when they last joined — and can export that list. They cannot see any other server's data. Operators are bound by /partner-terms, which sets out what they may and may not do with it. Once they hold it they are a controller in their own right and their own privacy policy applies.
Why we consider this lawful. You asked the app to connect you to a specific server. Delivering that connection, and telling that server's operator that a player arrived through BedrockConnect, is performance of the service you requested — Art. 6(1)(b) GDPR. Keeping that record for twelve months afterwards, so the operator can see arrivals across a season, is a separate question: that rests on our legitimate interest and the operator's in operating and understanding a listed server — Art. 6(1)(f) GDPR — and you can object to it under Art. 21(1) GDPR. We do not use join records for advertising, we do not enrich them, and we do not combine them with anything else.
Pseudonymous, but still personal data. We hold no name, no email address, no account and no contact route. We cannot turn a XUID into a real-world person, and neither, in the ordinary case, can a server operator. Microsoft can, however, and a XUID identifies the same person consistently across time. Under the GDPR that makes it personal data, and we treat it as personal data throughout this policy. Pseudonymisation is a safeguard, not an exemption.
A limitation. Because there is no account, we cannot show you your join records unless you can tell us the XUID or gamertag they were written under. Section 10 explains what to send us.
5. Nintendo Switch mode and DNS
The Nintendo Switch does not let you type a server address, and it does not offer the LAN discovery path the PlayStation uses. The only way to redirect it is to answer its DNS queries. When you select Nintendo Switch as your console, the app starts a DNS server on your phone and you point the console's network settings at your phone.
This has the following implications.
- While Switch mode is running, every DNS query your console makes goes to the app. This includes all domains, not only the seven Mojang featured-server domains the app needs to answer.
- For those seven domains, the app answers with your phone's local IP address so the console connects to the app instead of to Mojang's servers.
- Every other domain is resolved recursively — the app forwards the query to a public resolver operated by Google and passes the answer back. Your console reaches whatever it was trying to reach.
- None of it is logged, stored, analysed or transmitted to us. The app does not keep a query history and does not send hostnames anywhere. The queries exist in memory for as long as it takes to answer them.
- The DNS server runs only while the server is running in Switch mode. It stops when you stop the server or change your console setting away from Switch.
We disclose this because it is a broad capability even though we do nothing with it, and so that you can decide with the facts before you. If you do not wish to permit it, do not use Switch mode.
The same disclosure applies to the Minecraft handshake described in section 4: the app terminates your console's session and performs the encryption handshake itself. The interception window is the login and handshake only. After the Transfer packet the app is no longer in the connection path.
6. Legal bases
Two separate layers apply and they have to be satisfied separately.
6.1 GDPR Art. 6 — processing your data
| Processing activity | Legal basis | GDPR article |
|---|---|---|
| Running the app, connecting your console, reading the XUID and gamertag from the login handshake | Performance of a contract | Art. 6(1)(b) |
| Recording a join to a listed server and making it available to that server's operator | Performance of a contract | Art. 6(1)(b) |
| Keeping that join record for twelve months so the operator can see arrivals across a season | Legitimate interests of ours and of the operator; you may object under Art. 21(1) | Art. 6(1)(f) |
| Subscription and entitlement management | Performance of a contract | Art. 6(1)(b) |
| Texture-pack upload, merging and delivery | Performance of a contract | Art. 6(1)(b) |
| Support requests, including the AI assistant | Performance of a contract, or our legitimate interest in answering you | Art. 6(1)(b) / Art. 6(1)(f) |
| Crash reports and stability diagnostics | Legitimate interest in keeping the app working | Art. 6(1)(f) |
| Security and abuse prevention | Legitimate interest in protecting the service | Art. 6(1)(f) |
| Automatic app measurement (Google Analytics for Firebase) | Consent | Art. 6(1)(a) |
| Personalised advertising | Consent | Art. 6(1)(a) |
| Non-personalised advertising | Consent | Art. 6(1)(a) |
| Accounting, tax records, answering lawful requests | Legal obligation | Art. 6(1)(c) |
Aggregate counters per server address contain no identifier and are not personal data, so Art. 6 does not apply to them.
6.2 § 25 TDDDG — access to your device
Storing information on your device, or reading information already stored on it, is governed by § 25 of the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG). This is a separate requirement from the GDPR one above and it applies to app storage and device identifiers, not only to browser cookies.
| Device access | Legal basis | Reference |
|---|---|---|
| Reading the advertising identifier (IDFA / GAID) and the storage written by the advertising SDKs | Consent | § 25 Abs. 1 TDDDG |
| Storage written by Google's measurement SDKs | Consent | § 25 Abs. 1 TDDDG |
| Your settings, your saved servers, your texture-pack database, the local crash identifier, and the record of the advertising choice you made | Strictly necessary to provide the service you asked for | § 25 Abs. 2 Nr. 2 TDDDG |
Why both tables matter. Non-personalised advertising is not exempt from § 25. Even without profiling, the advertising SDKs still read and write device storage for frequency capping and fraud prevention. That access needs consent regardless of what the GDPR basis for the later processing would be. This is why the advertising rows in both tables say "consent". As to sequence: the advertising SDK starts with the first screen after setup, so a limited part of that storage access happens before your answer is recorded. Personalised advertising is only enabled once you have consented.
7. Advertising and your consent
The free version of BedrockConnect is paid for by advertising. Premium subscribers see no advertisements.
Who serves the ads. Google AdMob is our advertising provider. AdMob mediates through two partners, which means either of them may be the network that actually fills an ad slot:
- AppLovin (MAX mediation)
- Meta Platforms (Meta Audience Network)
All three can receive your advertising identifier, IP address, device and operating system information, coarse location and how you interacted with the ad. Their own privacy policies apply to what they do next; /subprocessors links to each of them.
How you are asked. We use Google's User Messaging Platform to present the consent form. It is shown right after onboarding, on the first screen after setup. The Google Mobile Ads SDK starts when that screen opens, so it initialises before your answer is recorded; your answer is then applied to advertising personalisation, and no personalised advertising is served unless you consent. "Reject" is available and is as easy to choose as "Accept". Refusing does not restrict the app: you keep every feature the free version offers. Advertisements still appear after a refusal, and your refusal is stored by Google's consent SDK and applied by Google's advertising SDKs.
On iOS there is a second prompt. Apple's App Tracking Transparency asks separately whether apps may track you across other companies' apps and websites. If you say no there, the advertising identifier is not available to the SDKs regardless of what you answered in our consent form. Both answers have to be positive for personalised advertising.
Withdrawing or changing your consent. The consent form is asked once, when you first start the app. You can withdraw or change your decision at any time afterwards by emailing contact@gkminteractive.com. You can also act on the device yourself, without contacting us: on iOS under Settings → Privacy & Security → Tracking, on Android under Settings → Google → Ads, and on either platform by clearing the app's data, which resets the stored consent record so that the consent form appears again on the next start. Withdrawing is as easy as giving consent and takes effect from the moment you withdraw it.
If you are not an established adult, personalised advertising is not available to you at all and no advertising identifier is read from your device — see section 11.
What we do not do. We do not run rewarded advertising. We do not offer to unlock features in exchange for data. We do not build advertising profiles ourselves, and we do not give the ad networks your XUID, your gamertag or anything about which servers you play on.
8. Who receives data and where it goes
We do not publish the recipient table twice. The maintained list — every recipient, what it does, where it sits and the transfer safeguard that applies — is at /subprocessors. The categories are:
- Cloud and infrastructure providers — hosting, database, object storage, content delivery and edge protection.
- Analytics and diagnostics providers — crash reporting and automatic app measurement.
- Advertising providers — the advertising network and its mediation partners.
- Subscription infrastructure — the entitlement service that tells the app whether you have Premium. The app stores themselves bill you and are controllers in their own right.
- Support tooling — the community platform our support runs on and the AI provider behind the support assistant.
- Operators of listed servers — they receive join records for their own server only, as described in section 4. They are independent controllers.
- Professional advisers and authorities — where we are legally obliged, or need to establish or defend a legal claim.
Where data physically sits. Our backend and our primary database are hosted in the United States. Our edge and delivery provider operates a global network, so requests are handled at whichever location is nearest to you. Several of our providers are established in the United States or process data there.
Transfers outside the EEA. For each recipient outside the EEA we rely on one of:
- the European Commission's standard contractual clauses, supplemented where necessary by additional technical and organisational measures; or
- the EU–U.S. Data Privacy Framework, where that specific recipient is certified under it and the transfer falls within its certification; or
- an adequacy decision for the country concerned.
/subprocessors states which basis applies to which recipient. We do not claim any certification, audit outcome or seal for ourselves.
You can ask us for a copy of the relevant safeguards at contact@gkminteractive.com.
9. How long we keep data
| Data | Retention |
|---|---|
| Join records for listed servers — XUID, gamertag, timestamp, platform, texture-pack flag | We use them for 12 months from the join. After 12 months a record is no longer shown to the operator of the server you joined, no longer included in any export, and no longer used for any purpose. Records older than that are not removed automatically. Erasure requests are assessed under section 10. |
Aggregate counters per server address (total_starts, total_adds, join totals) |
Indefinitely. They contain no personal data. |
| Uploaded texture-pack files | Deleted once they have gone 30 days without being used. The cleanup job runs monthly, so a file is removed at the first monthly run after its 30 days are up. You can also delete a pack from within the app at any time, which removes it immediately. |
| Merged packs we build from your pack and a server's pack | Held in a content-addressed cache, keyed by a hash of the packs they were built from, with no record of who requested them. They have no automatic expiry. Because they are keyed only by a content hash, they cannot be traced back to the person who requested them. |
| Partner contact email address and Stripe customer, payment and invoice identifiers | For as long as the partnership lasts, then for the statutory retention periods German commercial and tax law require |
| Support conversations and the Discord username attached to them | 30 minutes per session. If a conversation is escalated to a human, 30 days. |
| Crash reports | Held by Google Crashlytics under Google's own retention rules. We keep no separate copy. |
| Backend error reports at Sentry | Held by Sentry for the retention period that applies to our Sentry plan; we set no longer period and keep no separate copy. We do not send Sentry client IP addresses, cookies or credentials, and only a sample of requests is traced for performance measurement. |
| Server and edge request logs at our hosting and edge providers | Held under those providers' standard log-retention settings. We do not use them to profile you and we do not copy them into our database. |
| Everything stored on your device — saved servers, imported packs, settings, age answer, crash identifier, advertising choice | Until you delete it in the app, clear the app's data, or uninstall the app. Uninstalling removes all of it. |
The 12-month period exists because partner operators need to compare a season against the same season a year earlier and to recognise returning players. Beyond 12 months a join record serves no further purpose, so we stop using it: the partner portal looks back at most 12 months, and nothing older is shown or exported. We do not yet delete those older records automatically, and we state that rather than assert a deletion we do not perform — erasure requests are assessed under section 10, and in the meantime the records are used for nothing. The aggregate counters survive because a running total of how often an address was started tells us nothing about any individual.
10. Your rights and how to use them
Depending on where you live you have some or all of the following. In the EEA, the UK and Switzerland you have all of them.
- Access — a copy of the data we hold about you and information about how it is processed (Art. 15 GDPR).
- Rectification — correction of inaccurate data (Art. 16).
- Erasure — deletion (Art. 17).
- Restriction — we keep the data but stop using it while something is being resolved (Art. 18).
- Portability — a machine-readable copy of data you gave us that we process on consent or contract (Art. 20).
- Objection — to processing based on our legitimate interests, including on grounds relating to your particular situation (Art. 21).
- Withdraw consent — at any time, for anything based on consent, without affecting what was lawful before you withdrew (Art. 7(3)).
- Complain to a supervisory authority (Art. 77).
How to ask. Email contact@gkminteractive.com with "Data request" in the subject. There is no form to fill in and no account to log into. Your advertising choices are asked once, when you first start the app; to change them afterwards you can write to us at that address, or act on the device yourself as described in section 7.
Identifying you when there are no accounts. We hold no name, email address or account for you. Join records are stored under your Xbox User ID (XUID), so that is the only thing we can look you up by. A gamertag on its own is not enough: Microsoft does not guarantee that the visible part of a gamertag is unique, and gamertags can be released and taken over by someone else, so the gamertag on an old record is not necessarily the gamertag anyone holds today.
For that reason we do not act on a request made on the basis of a gamertag alone. Anyone can see another player's gamertag, and anyone who was on the same server can see when they joined it, so those facts do not show that a request comes from you. Before we disclose or erase anything, we ask you to show that you control the Xbox account. You choose which way:
- Change your gamertag to a short one-time code we give you, tell us when it is done, and change it back once we confirm. We check the change against your XUID, not against anything you send us. Microsoft charges for gamertag changes after your first one.
- Join a server we name, within a time window we give you. A new join record appears under your XUID and we match it. This is free.
If neither is possible — the account is banned, the console has been sold — tell us and we will agree another route with you.
Please do not send us a copy of an identity document, a photograph of yourself, or a screenshot of your Xbox account settings. We hold no name, email address or date of birth, so there is nothing for such a document to be checked against, and it would tell us more about you than we have any reason to know. If one reaches us unsolicited, we delete it and confirm that we have.
We do not confirm or deny whether we hold records for a gamertag until this step is complete — that is what the step is for. This is the additional information Art. 12(6) GDPR allows us to ask for, and it collects no personal data we do not already hold. While we are waiting for you to complete it, the one-month period does not run. If we genuinely cannot connect a request to any data, we will inform you of that; under Art. 11(2) GDPR we are not obliged to acquire extra information purely to identify you. This does not apply to an advertising opt-out, which we act on without asking you to identify yourself at all.
For other data the position is simpler:
- for crash diagnostics: the crash-report identifier from the app's settings screen. It is not displayed, but it is copyable: press and hold the version number at the bottom of that screen and it is copied to your clipboard.
- for an uploaded texture pack: no request to us is required. You can delete it in the app. Otherwise it is removed at the first monthly cleanup run after it has gone 30 days without being used.
Erasure of join records. Making the connection you asked for, and telling the operator that a player arrived through BedrockConnect, are performance of the service you requested (Art. 6(1)(b) GDPR). Keeping that record for twelve months afterwards, so the operator can see arrivals over a season, rests on our legitimate interest and the operator's (Art. 6(1)(f) GDPR). You can object to that retention under Art. 21(1) GDPR on grounds relating to your particular situation, and we will erase unless we can demonstrate compelling legitimate grounds that override your interests. Records outside the twelve months serve no purpose and we erase them on request without asking anything further. We erase by XUID, not by gamertag, so a request removes the records of the account you have shown you control and nothing else. Records of a child are erased on request in every case, with no period applied — see section 11.
How fast. Under the GDPR we answer within one month. We may extend that by two further months for complex requests, and if we do, we will tell you inside the first month and say why. For requests under United States state privacy laws we answer within 45 days, extendable once by a further 45 days with notice. Requests are free unless they are manifestly unfounded or excessive.
Complaints. You can complain to us first at contact@gkminteractive.com; we encourage this route and it is usually faster. You can also go straight to a supervisory authority. Ours is:
Die Landesbeauftragte für den Datenschutz Niedersachsen Prinzenstraße 5, 30159 Hannover, Germany https://www.lfd.niedersachsen.de
You may also complain to the authority where you live or work, or where you think the problem happened.
11. Children and young people
BedrockConnect sits next to Minecraft, and a large share of the people who use it are minors. We take that seriously and set out our approach explicitly below.
11.1 The age question
The first time you set the app up, it asks for your date of birth on a neutral picker, with an option to say directly that you are under 18. Nothing about the question suggests one answer over another and nothing tells you what you would lose by answering honestly.
We do not keep the date of birth. The app computes one thing from it — whether you are 18 or older — stores that single yes/no value on your device, and discards the date. The date is never transmitted anywhere.
11.2 What changes if you are not an established adult
If the app has not established that you are 18 or older, then:
- No personalised advertising is served.
- No advertising identifier is read from your device for advertising purposes.
- Google's child-directed treatment applies. We set Google's child-directed treatment flag and the under-age-of-consent flag on advertising requests once your age answer is known, and we restrict advertising content to the general audience rating. This is deliberately broader than the law requires: the child-directed treatment flag is set for everyone under 18, not only for those under 13.
- No sale and no sharing of personal information under United States state privacy laws.
We apply this by default. Where an app store gives us a verified age signal for your region, we use it and it takes precedence over the self-declared answer.
11.3 Written retention policy for children's personal information
This section is our written data retention policy for personal information collected from children, provided here in the notice itself as 16 CFR § 312.10 requires. It states, for each element, why we collect it, why we need to keep it, and the period after which we stop using it.
| Data element | Purpose of collection | Business need for retention | How long we use it |
|---|---|---|---|
| Xbox User ID (XUID) | To complete the Minecraft transfer to the server the user chose, and to record that a player arrived at a listed server | So the operator of that listed server can see arrivals over a season and compare a period with the same period a year earlier | 12 months after the join |
| Gamertag | Same as above; it is the only human-readable label in a join record | Same as above | 12 months after the join |
Join timestamp, platform (android/ios), texture-pack flag |
To make the join record meaningful | Same as above | 12 months after the join |
| Uploaded texture-pack file | To merge the user's pack into a supported server's pack | Only while the pack is in use | 30 days after last use, removed at the next monthly cleanup run — or immediately when deleted in the app |
| Support conversation content and Discord username | To answer the question that was asked | Only for as long as the conversation is live, or the escalation is open | 30 minutes after the session ends; 30 days if escalated to a human |
| Crash-report identifier and crash diagnostics | To fix crashes | Only while the crash is being investigated | Held by Google Crashlytics under Google's retention rules; we keep no separate copy |
After the period shown, the data is no longer displayed, exported or used for anything. Automatic removal of join records at the end of that period is not yet in place — section 9 says exactly what that means. We delete a child's join records on request; a parent or guardian can ask on the child's behalf, and we do not charge for it. | Advertising identifiers | Not collected from children | — | Not applicable | | Precise geolocation, biometrics, government identifiers, contact details, photographs | Not collected from anyone | — | Not applicable |
Aggregate counters per server address contain no identifier of any person, child or adult, and are therefore outside this policy.
11.4 Who receives children's personal information, and why
As required by 16 CFR § 312.4(d), these are the categories of third parties to which personal information collected from a child may be disclosed, and the purpose of each disclosure:
| Recipient category | What they receive | Purpose |
|---|---|---|
| Operators of listed servers | XUID, gamertag, join count, last join time — for their own server only | To run the server the child asked to join, and to see arrivals from BedrockConnect |
| Cloud hosting and storage providers | Everything we store, as processors on our instruction | To host our backend, database and file storage |
| Crash reporting and app measurement provider | Crash diagnostics, device data, automatic app-measurement events | To diagnose crashes and keep the app working |
| Support tooling providers | Support message content and the Discord username | To answer support questions |
| App stores and the entitlement provider | Subscription state | To deliver a subscription that was purchased |
| Advertising networks | Nothing. No personal information from a user we have not established is an adult is disclosed to any advertising network. | — |
We take reasonable steps to satisfy ourselves that recipients can keep the data confidential and secure, and we require contractual assurances to that effect.
11.5 Parents
If you are a parent or guardian and you believe your child has used BedrockConnect and you want to see, or delete, what we hold, write to contact@gkminteractive.com. Tell us the gamertag the console was signed in with and, if you can, the servers and roughly when. Once we can locate the records and have taken reasonable steps to satisfy ourselves that you are the parent or guardian, we will tell you what we hold, delete it on request, and stop any further collection tied to that identifier.
We do not knowingly collect more personal information from a child than is reasonably necessary to let them use the app, and we never require a child to disclose more than that in order to take part.
11.6 Age of consent varies by country
Where a country sets a digital age of consent for consent-based processing, we apply that country's threshold. See Annex A for the EEA range and Annex C for the countries where the threshold is 18.
12. The AI support assistant
First-line support in our Discord community is answered by an AI assistant called Anya. It is a software system, not a person, and it will tell you so.
- What is sent. The content of the messages you send it, and your Discord username, are sent to Cloudflare, which runs the language model that produces the reply. Cloudflare processes the message on our instruction as our processor.
- What is stored. The conversation is held for 30 minutes so the assistant can follow the thread. If your question is escalated to a human, the conversation is kept for 30 days so the person picking it up has the context. After that it is deleted.
- Do not send confidential information. Do not put payment details, passwords or documents into a support chat. The assistant does not require them and we do not wish to receive them.
- You can ask for a person. Ask for a human in the chat, or write to help@bedrockconnect.app. No decision that affects your subscription is taken by the assistant.
- Its answers can be wrong. It is a language model answering questions about our app. If an answer is important, confirm it with us at help@bedrockconnect.app.
13. How we protect data
We describe our protection by what it achieves. We do not publish the details of our security configuration — it would assist an attacker and is not what Art. 13 GDPR requires — and we do not claim certifications, audits or standards we do not hold.
- Encryption in transit. Traffic between the app and our services is encrypted in transit, as is traffic between our services and our database.
- Authenticated interfaces. Our interfaces are not open. A request has to be authenticated, and it reaches only what the requester is entitled to reach — a partner can reach the data of their own server and nothing else.
- Protection at the network edge. Requests pass through a protective layer that filters malicious traffic, rejects malformed calls and limits request volume, so our interfaces cannot be enumerated or scraped at speed.
- Access on a need-to-know basis. Access to production systems and to personal data is limited to the people who need it for a specific task, and credentials are kept outside our source code.
- Data minimisation as a control. The most effective protection we have is the data we never collect. There is no account, no email address, no password to leak, no payment data, no IP address column and no precise location anywhere in our database.
No system is perfectly secure, and we do not claim otherwise. Where a personal data breach occurs, we notify the competent supervisory authority, and inform affected data subjects, to the extent Arts. 33 and 34 GDPR require.
14. Changes to this policy
We update this policy when the product changes, when the law changes, or when we find something in it that is not as clear as it should be.
- The current version and the date it took effect are shown at the top of this page.
- Material changes — a new category of data, a new purpose, a new category of recipient, or a shorter or longer retention period — are notified to you before they take effect where the law requires notice. We may give that notice in the app, on this page, or by another appropriate route.
- Minor changes — wording, structure, corrected links — take effect when published.
- We never apply a change retroactively to data already collected in a way that would be unlawful.
- Where a change depends on your consent, we ask again. Silence is not consent.
Earlier versions may be available on request at contact@gkminteractive.com.
Annex A — EEA, UK and Switzerland
This annex applies if you are in the European Economic Area, the United Kingdom or Switzerland. It adds to the main policy and, in the event of a conflict, prevails over it.
Controller. GKM Interactive UG (haftungsbeschränkt), Wasserstraße 5, 37186 Moringen, Germany. Contact: contact@gkminteractive.com.
Your rights are set out in section 10 and are the rights in Arts. 15 to 22 and Art. 77 GDPR. In addition:
- Automated decision-making. We do not make decisions about you by automated means that produce legal effects for you or similarly significantly affect you (Art. 22 GDPR). The order of the server lists is not personalised: it does not use your behaviour, your history, your device or your location. How it does work is set out at /ranking.
- Right to object. Where we rely on legitimate interests — crash diagnostics, security and abuse prevention — you can object under Art. 21 GDPR on grounds relating to your particular situation, and we will stop unless we can demonstrate compelling legitimate grounds that override your interests.
- Supervisory authority. Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, https://www.lfd.niedersachsen.de. You may also complain to the authority in your own country. In the United Kingdom this is the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner.
- UK and Switzerland. Where you are in the United Kingdom, references to the GDPR mean the UK GDPR and the Data Protection Act 2018. Where you are in Switzerland, references to the GDPR mean the revised Federal Act on Data Protection. Transfers out of the UK rely on the UK international data transfer agreement or the UK addendum to the EU standard contractual clauses; transfers out of Switzerland rely on the standard contractual clauses as recognised by the Swiss authority. The countries our recipients operate from are listed at /subprocessors.
Age of consent — Art. 8 GDPR. Where processing rests on consent, Art. 8 GDPR sets an age below which a parent or guardian has to give or authorise that consent. Member States set it anywhere between 13 and 16. In Germany it is 16. It is 13 in Belgium, Denmark, Estonia, Finland, Latvia, Malta, Portugal and Sweden; 14 in Austria, Bulgaria, Cyprus, Italy, Lithuania and Spain; 15 in Czechia, France and Greece; and 16 in Croatia, Germany, Hungary, Ireland, Luxembourg, the Netherlands, Poland, Romania and Slovakia. In the United Kingdom it is 13. If you are under the threshold that applies where you live, ask a parent or guardian before you consent to advertising in the app. Everything else in the app runs on contract or legitimate interest and does not depend on your consent.
Independently of Art. 8, the protections in section 11 apply to everyone the app has not established is 18 or older — that is stricter than Art. 8 requires, and it is deliberate.
Transfers. See section 8. Our primary database is in the United States. Where a recipient is not covered by an adequacy decision, we rely on the standard contractual clauses.
Annex B — United States
This annex applies if you are a resident of a US state with a comprehensive privacy law, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Florida, Montana, Iowa, Delaware, New Hampshire, Nebraska, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island. It is written to the union of those laws, so some of it may go further than your own state requires. It adds to the main policy and prevails over it in the event of a conflict.
B.1 Categories we collect, why, and who receives them
| Statutory category | What that is here | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers | XUID, gamertag, advertising identifier, app installation and crash identifiers, anonymous subscription ID, IP address (in transit only) | You, your device, the Minecraft login handshake | Connecting your console; recording a join to a listed server; diagnostics; advertising; entitlement checks | Operators of listed servers; cloud, diagnostics and support providers; advertising networks (adults only) |
| Commercial information | Whether you have a subscription, store country | The app stores and the entitlement provider | Delivering Premium | Entitlement provider |
| Internet or other electronic network activity | Which listed server you joined and when; automatic app-measurement events; ad interactions | Your device | Service delivery, diagnostics, advertising | Diagnostics and advertising providers |
| Geolocation data | Coarse country and continent derived from your IP address at the edge. Never precise location. | Your connection | Recommending a nearer server host | Not disclosed; not stored |
| Audio, visual or similar information | Texture-pack files you upload | You | Merging your pack into a server pack | Storage provider |
| Sensitive personal information | We do not intentionally collect any. Where our records concern a user we know or should know is a minor, several states treat that as sensitive data and we treat it accordingly. | — | — | Never sold. Never used for advertising. |
| Inferences | We draw none. | — | — | — |
We do not collect social security or government identification numbers, financial account numbers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, health data, sexual orientation, genetic data or biometric data.
B.2 Sale and sharing — the accurate position
We do not sell personal information. We do not exchange personal information for money or other valuable consideration, to anyone, under the CCPA's definition in § 1798.140(ad) or the equivalent definitions in the other state laws.
We do treat advertising disclosures as "sharing". The CCPA defines "sharing" separately, in § 1798.140(ah), as disclosing personal information to a third party for cross-context behavioural advertising. When you consent to personalised advertising, your advertising identifier and related signals go to Google, AppLovin and Meta, and those companies can combine what they see in our app with what they see elsewhere. We treat this as "sharing", and you can opt out of it.
Partner listings are not a sale of your data. Operators of listed servers pay us to be listed, and they receive join records for their own server. The payment is for the listing, not for the data — the operator would receive the same join record whether or not they had bought a rank slot, because knowing who arrived at their server is part of running a listed server. We do not treat this as a sale. If you do not want it to happen at all, add the server yourself in the Custom tab, and no join record is written.
Minors. We do not sell or share the personal information of any user we have not established is 18 or older. That is stricter than CCPA § 1798.120(c), which sets the line at 16, and it matches Maryland, New York, Connecticut, Colorado, Texas and Oregon, which restrict targeted advertising to and the sale of data of minors more broadly.
B.3 Your rights
Subject to your state's law, you have the right to:
- know and access what we collect, use, disclose and share;
- delete personal information we hold about you;
- correct inaccurate personal information;
- obtain a portable copy of it;
- opt out of the sale of personal information — although we do not sell;
- opt out of sharing for cross-context behavioural advertising / targeted advertising;
- opt out of profiling in furtherance of decisions producing legal or similarly significant effects — we do no such profiling;
- limit the use and disclosure of sensitive personal information; and
- not be discriminated or retaliated against for exercising any of these. Nothing you can ask for here affects your price, your Premium features or your access to the app.
B.4 How to exercise them
There are two routes:
- On your device — on iOS, decline or revoke tracking for BedrockConnect under Settings → Privacy & Security → Tracking; on Android, use Settings → Google → Ads. On either platform, clearing the app's data resets the stored advertising choice and the consent form is asked again on the next start. This is the fastest way to opt out of sharing for advertising, and none of it requires you to identify yourself in any way.
- By email — contact@gkminteractive.com, subject "US privacy request", or by post to GKM Interactive UG (haftungsbeschränkt), Wasserstraße 5, 37186 Moringen, Germany.
We respond within 45 days, and we may extend once by a further 45 days if the request is complex — if we do, we will tell you within the first 45. There is no charge.
Identity. Because there are no accounts, see section 10 for what to send us so we can find your records. We do not require identity verification to accept an opt-out of sale or sharing — that is an opt-out, not an access request, and we act on it within the period your state's law allows.
Authorised agents may submit requests on your behalf with written, signed permission. We may contact you to confirm the agent is acting for you.
B.5 Appeals
If we refuse a request, we will tell you why in writing. You can appeal by replying to that message, or by emailing contact@gkminteractive.com with "Appeal" in the subject line, within a reasonable time.
We will review the appeal and give you a written answer explaining the reasons for our decision within 45 days — or within 60 days where your state allows longer and the appeal is complex.
If we deny your appeal, you may complain to your state Attorney General. Our written response to an appeal includes a method of contacting the Attorney General for your state to submit a complaint, as your state's law requires. California residents may also contact the California Privacy Protection Agency.
B.6 Global Privacy Control and universal opt-out signals
Where you use a browser or extension that sends a recognised opt-out preference signal such as Global Privacy Control, we treat that signal as a valid opt-out of sale and sharing for that browser. No verification of your identity is required and none will be asked for.
In practice, we do not run advertising, advertising analytics or any sale or sharing of personal information on bedrockconnect.app, so there is nothing there for the signal to switch off. There is currently no standardised universal opt-out signal that a native iOS or Android app can receive — Apple and Google do not expose one. For the app, the opt-out routes are your device's advertising settings — Apple's tracking prompt and Settings → Privacy & Security → Tracking on iOS, Settings → Google → Ads on Android — and resetting the stored advertising choice by clearing the app's data. All of them are honoured.
B.7 Retention
Retention periods per category are in section 9. Where a period cannot be stated because the data sits with a provider under its own rules, we state that there rather than substitute a vague formula.
B.8 Children
COPPA-specific disclosures, including our written retention policy for children's personal information and the categories of recipients, are in section 11. State-law minors' protections are in B.2 above. We do not use personal information of a known minor for targeted advertising and we do not sell it.
B.9 Notice of financial incentive
We offer none. Premium is an ordinary paid subscription: you pay for features. It is not a reward for giving us data, no price depends on any privacy choice you make, and refusing advertising consent does not change what Premium costs or what it includes.
Annex C — Other regions
This annex states concisely what applies. It adds to the main policy and prevails over it for the region concerned.
Brazil. We process personal data of people in Brazil under the LGPD. You have the rights in Art. 18 LGPD, including confirmation that processing takes place, access, correction, anonymisation, blocking or deletion of unnecessary or excessive data, portability, information about who we share data with, information about the consequences of refusing consent, and withdrawal of consent. Contact contact@gkminteractive.com; you may also complain to the ANPD. Personal data of children and adolescents is processed in their best interests, we do not profile minors for advertising, and we do not require a child to give more data than the activity strictly needs. Brazilian law places additional obligations on services likely to be accessed by children; where those obligations require product capabilities we do not yet have, we say so rather than claim compliance we cannot demonstrate.
Canada. We process personal information of people in Canada under PIPEDA and, in Quebec, under Law 25. Purposes are identified in section 3; consent for advertising is obtained separately from everything else. You may access and correct your information, and challenge our compliance, by writing to contact@gkminteractive.com — that address reaches the person accountable for privacy at our company. You may complain to the Office of the Privacy Commissioner of Canada, or in Quebec to the Commission d'accès à l'information. We do not make decisions about you based exclusively on automated processing. The server lists are not personalised and we do not track or profile you across services.
Australia. We handle personal information of people in Australia in accordance with the Australian Privacy Principles. The kinds of information we collect and how we hold it are in section 3; how to access, correct and complain are in section 10. We are likely to disclose personal information to overseas recipients — principally in the United States, and to providers operating global networks whose locations are listed at /subprocessors. We do not use personal information in an automated program to make decisions that significantly affect your rights or interests. You may complain to the Office of the Australian Information Commissioner.
India. We process digital personal data of people in India under the DPDP Act. This policy, together with the itemised tables in section 3, describes each item of personal data we process and the purpose for it. You may withdraw consent as easily as you gave it, by writing to contact@gkminteractive.com, by using your device's advertising settings, or by clearing the app's data; you may request access, correction and erasure, and nominate another person to exercise your rights, by writing to contact@gkminteractive.com; and you may complain to us at that address before approaching the Data Protection Board of India. Under Indian law a "child" is anyone under 18. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children. This policy is provided in English; write to contact@gkminteractive.com if you need it in another language listed in the Eighth Schedule to the Constitution and we will make arrangements.
Japan. We handle personal information of people in Japan under the APPI. Our purposes of use are those set out in section 3. Our name, address and the name of our managing director are in section 1; requests for disclosure, correction or suspension of use, and complaints, go to contact@gkminteractive.com. Personal data is handled in the United States on our primary infrastructure, and at global locations operated by our edge and delivery provider — the recipients and their locations are listed at /subprocessors, and for each we apply the safeguards described in section 8. The security control measures we take are described in section 13.
South Korea. We process personal information of people in Korea under PIPA. The purposes, retention periods, recipients, cross-border transfers and destruction practices required by Art. 30 PIPA are in sections 3, 8 and 9; personal information is transferred to and stored in the United States and processed at global edge locations, for the purposes and for the periods stated there. Consent for advertising is obtained separately from any other consent, and declining it does not restrict your use of the app. For a user under 14, consent must be given by a legal guardian. Privacy contact: contact@gkminteractive.com. You may complain to the Personal Information Protection Commission or the Korea Internet & Security Agency.
Everywhere else. BedrockConnect is available worldwide, and many countries have their own data protection laws — including Turkey, Singapore, Malaysia, Thailand, Indonesia, Vietnam, South Africa, Nigeria, Kenya, Israel, Mexico, Argentina, Saudi Arabia and the United Arab Emirates. We apply the standard in this policy globally, because it is at least as protective as most of them, and we will honour any right your local law gives you that this policy does not already grant. Write to contact@gkminteractive.com and tell us where you are and what you want. Where a country requires us to appoint a local representative or complete a registration, we may note it on this page once it is done — we do not claim representatives, registrations or accreditations we do not have.
Appendix — Apple App Privacy label summary
This summarises what we declare on the App Store for the version of the app that is shipping. It is a summary of the sections above, not a substitute for them.
Data used to track you
Apple counts it as tracking when a third-party SDK combines data from our app with data from other developers' apps to target advertising. AdMob's mediation partners can do exactly that, so we declare it:
- Identifiers — advertising identifier (IDFA)
- Usage data — advertising interaction data
This applies only where you are an established adult and you have consented in both our consent form and Apple's tracking prompt. If either answer is no, no identifier is read and nothing in this group is collected.
Data linked to you
- Identifiers — Xbox User ID (XUID) and gamertag, for app functionality: connecting your console and recording a join to a listed server
- Purchases — subscription status, for subscription management
Data not linked to you
- Diagnostics — crash data and performance data, with a randomly generated local crash identifier
- Usage data — automatic app-measurement events collected by Google Analytics for Firebase
- Identifiers — app installation identifier and the anonymous subscription identifier
- User content — texture-pack files you upload, which are stored without any record of who uploaded them
Data not collected
Contact information, name, email address, phone number, physical address, precise location, contacts, photos or videos from your library, audio, browsing history, search history, health and fitness data, financial information, payment information, sensitive information, and any customer support content beyond what you voluntarily send us in a support conversation.