Privacy Policy
This Privacy Policy outlines how ECHO NeT collects, uses, and safeguards data when you authenticate via Discord or play on our Minecraft server.
1. Information We Collect
ECHO NeT operates under a strict privacy-first framework. We only collect essential data required to maintain server whitelist integrity, manage support tickets, and enforce anti-cheat protection:
- Discord OAuth2 Identification: When signing in with Discord, we receive your public Discord User ID, Username, Discriminator/Handle, and Avatar image URL via standard OAuth2 scope permissions. We NEVER access your email address, Discord password, friends list, or direct messages.
- Minecraft IGN & Network Activity: Your Minecraft In-Game Name (IGN), Mojang Account UUID, connection IP address (used strictly for ban evasion defense and pterodactyl console logging), and submitted Whitelist application details.
- Support & Feedback Desk Records: Content of bug reports, tickets, or appeals you submit to staff.
- Session Cookies: Encrypted, HTTP-only session cookies (`echo_user_token` & `echo_staff_token`) used solely to keep your session authenticated on our web portal across page reloads.
2. Purpose & Usage of Information
Your information is used strictly for technical operations and network moderation:
- Verifying identity and assigning the automatic Whitelist Member role on Discord.
- Enforcing server security, Pterodactyl console commands, and ban management.
- Dispatching in-site Mailbox notifications and Discord DM alerts regarding application approvals or support ticket responses.
We NEVER sell, rent, monetize, or trade your personal data with third-party advertisers or data brokers.
3. Data Storage & Security Measures
All persistent application records, whitelist tokens, and support tickets are stored in encrypted Google Firebase Realtime Databases. Access is restricted exclusively to authenticated ECHO NeT Owners and Community Managers via secure HTTPS API endpoints.
4. Data Retention & User Deletion Rights
You have the right to request full deletion of your whitelist application history, stored Discord tokens, or ticket logs. To initiate a data deletion request, submit a ticket on our Support Desk or contact Staff Management on Discord. Upon verification, all associated RTDB records will be permanently purged within 48 hours.
5. Third-Party Service Integrations
Our web portal integrates with third-party service providers essential to server operation: Discord (OAuth2 & Bot API), SparkedHost (Pterodactyl server panel), and GitHub (issue tracker sync). Each third-party service operates under its respective privacy policy.