Privacy policy.
Effective and last updated 19 August 2026 · Notice version 2026-08
This notice explains how xtyl.ing handles information through this website, the game servers it lists or operates, and the self-hosted CubeCoders AMP control panel. It is intended to give Philippine and United States residents a clear notice at collection.
1. Who is responsible
xtyl.ing, operated from Singapore, is the personal information controller or business responsible for the processing described here. The privacy and data-protection contact is privacy@xtyl.ing.
This policy covers xtyl.ing’s public portal, whitelist and password-reset workflows, associated game servers, and the locally operated AMP installation. It does not govern a third-party website you choose to visit.
2. Information collected and why
| Category and source | Examples | Purpose | Typical retention |
|---|---|---|---|
| Whitelist information you submit | In-game username, email address, introduction, selected server, consent version, application reference and decision | Review the request, communicate with you, provision access, prevent duplicate requests, and keep an administrative record | Email, introduction, and the portal’s connection-derived submission hash are removed 90 days after submission. The username, decision, timestamps, and workflow record remain while needed to administer access or resolve disputes and can be deleted by staff or on a valid request. |
| EasyAuth credentials you submit | A new server password or replacement password | Register or update the credential on the selected Minecraft server | Encrypted before storage; never displayed to staff. Application credentials expire within 90 days and are removed after successful dispatch, denial, or expiry. Reset credentials expire within one hour and are removed after dispatch or terminal failure. |
| Account and reset records | Username, email, account/server link, hashed reset token, send/open/use timestamps, delivery status, and Brevo message identifier | Maintain approved access, deliver single-use resets, limit abuse, and diagnose delivery | Reset links are usable for 15 minutes. Identity and delivery records remain while the access identity is active or until the related application is deleted. |
| Website and security data collected automatically | Request time and route, IP address and user-agent in hosting logs; pseudonymous keyed hashes derived from IP address for application, reset, and staff-login limits; necessary staff-session and one-minute message cookies | Deliver and secure the service, prevent abuse, investigate errors, and authenticate staff | Failed-login and password-reset attempt hashes are removed after 7 days. Application hashes are removed after 90 days. Staff-session cookies normally expire after 30 minutes; message cookies after one minute. Hosting logs follow the host’s configured rotation and are kept only as needed for security and operations. |
| Gameplay and server records | Player name or identifier, IP address in game or proxy logs, joins and leaves, authentication events, chat/commands where logged, whitelist or ban status, game state and administrative actions | Run, moderate, secure, troubleshoot, and back up the game servers; enforce access rules | Operational logs rotate under the server configuration. Account, moderation, whitelist, and game-state records remain for the life of the account or server, or until no longer needed or validly deleted. |
| AMP Advanced in-game analytics | Player name, join time, session duration, visit frequency, and—when the game exposes it—IP address and country inferred with a GeoIP database; server health and performance metrics | Understand activity and reliability, troubleshoot performance, protect the community, and plan capacity | Player-level AMP analytics are kept in the local instance database for up to 12 months. Aggregate or non-identifying operational statistics may be kept longer. |
AMP obtains player analytics by reading game-console or RCON join and leave messages. Availability varies by game. Analytics do not make access decisions by themselves, and whitelist requests are reviewed by a person.
3. Legal reasons for processing
Under the Philippine Data Privacy Act of 2012, we rely as applicable on your consent, processing needed to act on your access request or provide the service, compliance with law, and our legitimate interests in operating a secure private community. We apply the principles of transparency, legitimate purpose, and proportionality. You may withdraw consent, but this does not affect earlier lawful processing and may prevent us from maintaining the access that depends on the information.
We do not use personal data for advertising. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. We do not offer financial incentives for personal information.
4. Cookies and similar technology
The public portal does not use advertising or audience-measurement cookies. It uses signed, strictly necessary cookies for staff authentication and short-lived status messages. Application and reset forms use signed security tokens rather than tracking cookies. Because these technologies are necessary to provide or secure the requested function, there is no optional analytics-cookie toggle.
The site loads fonts from Google Fonts. A visitor’s browser therefore sends Google the technical information needed to return those files, such as the IP address, browser information, requested font file, time, and referring page. Google acts under its own privacy terms.
5. Who receives information
- Authorized xtyl.ing staff can review applications, operational records, and AMP analytics. EasyAuth passwords are not visible to staff.
- Hostinger hosts the portal and database and may process stored data, backups, network details, and logs as a hosting provider.
- Brevo (Sendinblue) receives the recipient address, name where supplied, message content, tags, and delivery metadata to send application and password-reset email. Staff application alerts can include the submitted introduction.
- Google Fonts receives the browser request described above when it serves font files.
- CubeCoders AMP and EasyAuth run on server infrastructure controlled by xtyl.ing. AMP stores its in-game analytics in the local instance database. CubeCoders receives licensing information about the host, including a machine identifier and basic system details. If AMP’s optional product-metrics reporting is enabled, it may also send infrequent aggregate system and instance-configuration metrics to CubeCoders; it does not send the local player-session database merely because Advanced analytics is enabled.
We may also disclose information when reasonably necessary to comply with law, protect users or the service, investigate abuse, or complete a business transfer subject to appropriate safeguards. We do not permit service providers to use the information for their own advertising.
6. International processing
The service is operated from Singapore. Providers may process information in Singapore, the Philippines, the United States, the United Kingdom, the European Union, or other locations where they operate. A destination may provide different privacy protections from your home jurisdiction. We use contractual, access-control, and security safeguards appropriate to the transfer and remain accountable for processing performed on our behalf.
7. Your choices and rights
Email privacy@xtyl.ing with the subject “Privacy request” and identify the server and username involved. To protect users, we may verify the request using the application email, reference, or other proportionate information. We will respond within the time required by applicable law. A request may be limited where retention or disclosure is required for security, legal claims, fraud prevention, or another lawful exception.
Depending on where you live, you may ask to know or access the data and its sources, recipients, and purposes; obtain a portable copy; correct inaccurate data; object to or withdraw consent for processing; delete or block data; restrict certain uses; or appeal a denied request. Authorized agents may submit requests where local law permits and we can verify their authority.
Philippine residents
You have the rights provided by Republic Act No. 10173, including to be informed, object, access, rectify, erase or block, obtain portability where applicable, and seek damages. You may lodge a complaint with the National Privacy Commission.
United States residents
Residents of states with applicable comprehensive privacy laws may request access, correction, deletion, or portability and may appeal a refusal. California residents may also request the categories and specific pieces of personal information collected, sources, purposes, and categories of recipients. In the preceding 12 months, the categories collected and disclosed for business purposes are those in Sections 2 and 5. None were sold or shared for cross-context behavioral advertising. Because there is no sale, targeted advertising, or qualifying profiling, we do not provide a “Do Not Sell or Share” mechanism.
8. Children
The service is intended for a general audience and is not directed to children under 13. Do not submit an application or other personal information if you are under 13. Applicants aged 13 through 17 should obtain permission from a parent or guardian. We do not knowingly collect personal information from a child under 13. If we learn that this occurred, we will delete it. A parent or guardian may contact us to review, delete, or stop further collection of a child’s information.
9. Security and incidents
We use HTTPS, restricted staff access, signed and HTTP-only staff cookies, request forgery protection, rate limits, encryption for temporary EasyAuth credentials, hashed reset tokens, and server-side AMP access. No system is risk-free. If a breach creates a legally reportable risk, we will notify affected people and regulators as required by applicable Philippine and U.S. breach-notification laws.
10. Changes
We will update the date and version above when this notice changes. If a change materially affects information already supplied under consent, we will provide additional notice or seek new consent where required. The current version is always available at xtyl.ing/privacy.