Data we collect
We collect different types of information depending on how you use the Service:
Users without an account
- Standard browsing data (IP address, browser type, pages visited)
- Minecraft player names you look up in the search bar
Registered users
- The username you choose when registering
- Email address
- Password (stored as a bcrypt hash, never in plain text)
- Profile picture, if you choose to upload one
- Registration date and last activity
Login with Google or Discord
- Name and email address provided by the OAuth provider
- Public profile picture from the provider (Google or Discord)
- Unique provider identifier used to link the account
How we use your data
We use the information we collect only to:
- Provide and maintain the Service
- Authenticate your session and keep it secure
- Send you transactional emails (password reset, security changes)
- Detect and prevent fraudulent or abusive use
- Improve the experience and performance of the Service
We do not sell, rent or share your personal data with third parties for advertising purposes. We do not profile users or run automated marketing.
Third-party services
The Service interacts with the following external services:
- Mojang API — to resolve premium Minecraft player UUIDs from their nickname
- Visage / Crafatar — to render player skins and avatars
- mc-api.io — to obtain public server information
- Google OAuth — if you choose to sign in with your Google account
- Discord OAuth — if you choose to sign in with your Discord account
- Amazon S3 — to store the profile pictures you upload
Each external service has its own privacy policy. We recommend reviewing them before linking your account.
Storage and security
Your data is stored on secure servers with the following measures:
- PostgreSQL database with restricted access and encryption at rest
- Passwords hashed with bcrypt (cost factor 12)
- Security tokens hashed with SHA-256 before being stored
- Profile pictures on Amazon S3 with permission-controlled access
- Communications protected with TLS/HTTPS
- Rate limiting on every sensitive endpoint
Despite our security measures, no system is 100% foolproof. If you find a vulnerability, please report it responsibly to our contact email.
Your rights
As a registered user, you have the right to:
- Access the personal data we hold about you
- Correct or update your name, email or profile picture
- Delete your account and all associated data
- Unlink OAuth providers (Google, Discord) from your account
- Request a copy of your data in an exportable format
To exercise any of these rights, you can do so from your profile settings or by contacting us directly by email.
Data retention
We keep your data while your account is active. When you delete your account:
- Your personal data (name, email, picture) is deleted immediately
- Active session tokens are revoked
- Linked OAuth accounts are unlinked
- Anonymous usage data may be kept for statistical purposes
Browsing data from users without an account is retained for a maximum of 30 days in server logs for security and diagnostics.
Minors
PracticeStats is not directed at children under 13. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe your child has created an account, contact us to have it deleted.
Changes to this policy
We may update this Privacy Policy at any time. We will publish the new version on this page with the update date. If the changes are significant, we will notify you by email.
Continued use of the Service after the changes are published implies your acceptance of the new policy.
Contact
For any question related to the privacy of your data: