Privacy Policy

Version 1 · Published 16/09/2026

Privacy Policy

OG-Network Holdings Pty Ltd, based in Adelaide, South Australia, operates OG Network's community site. This policy explains how the forums, knowledge base, account registration, appeals, and reports use personal information. The Minecraft server Privacy Policy describes additional data collected during gameplay. The community site is accessible to players globally.

Information we collect and why

When you register, we receive a single-use code, your online-mode Minecraft UUID, Minecraft name, and a snapshot of your current LuckPerms group names from an OG Network hub. We use that information to confirm which Minecraft account you control, create your site account, and assign web-app group permissions. The hub sends a fresh group snapshot when you relog; we do not continually poll your ranks. We store your chosen username, a password hash rather than your plain-text password, and an encrypted authenticator secret. Password recovery requires a short-lived link issued to your signed-in Minecraft account plus your authenticator code. Site sessions and security logs help us keep accounts and services secure. Our web host may also log connection IP addresses.

Forum posts, news replies, and public knowledge-base contributions may be visible to other visitors according to the section's permissions. We keep revision and moderation records so content can be managed and abuse investigated.

On forum pages, a player's skin avatar is loaded from Crafatar. The visitor's browser sends Crafatar the player's Minecraft UUID and ordinary request information, including the visitor's IP address. Our server also sends the player's UUID to Mojang's profile service to check their current Minecraft name.

Appeals and reports are private cases. For a ban or mute appeal, we use the punishment type and numerical LiteBans ID to retrieve a limited punishment snapshot through a hub plugin. When LiteBans provides a Minecraft UUID, the appeal is attached to it immediately. If that UUID later registers, the associated appeal and its player-visible messages appear in the account, even if someone else originally submitted it; the anonymous-submission marker remains. If LiteBans has only an IP address or name and no UUID, the appeal stays unlinked. Its original anonymous writer can use the private receipt link; a signed-in original writer can use their site account. It is never linked to a later Minecraft account. Staff-only notes and restricted punishment fields are not shown to players. Reports require a registered account and include the description supplied by the reporter. Authorised staff use these records to investigate and respond. A future chat-log integration would require a policy update before it is enabled.

How we use and disclose information

We use this information to operate the site, authenticate users, grant access, moderate content, handle cases, investigate abuse, maintain security, and respond to support or privacy requests. We do not sell player information. Authorised staff see only the information needed for their work. Service providers may process data for hosting, storage, or security on our behalf; their names, locations, and any overseas disclosures must be confirmed before this draft is published. Public posts can be viewed and copied by other visitors. The knowledge base's GitLab CE storage contains page content and revisions, not password hashes or case records.

Security and retention

We restrict access to account and case records, protect passwords with a one-way hash, use encrypted connections, and log sensitive administrative actions. We keep information only while it is needed for the purposes above, a valid investigation, or a legal obligation. Our retention schedule for the community site is:

InformationRetention
Registration codes and password-reset tokensRemoved on use; expired records removed within 24 hours.
Login sessionsRevoked on logout, password reset, or account deactivation; sessions expire after 30 days.
Security and integration audit logs90 days. Relevant case records may be placed on a separate retention hold for an active investigation.
Email, password hash, and Minecraft account linkKept while the account is active; credentials removed after verified account closure, with necessary case or security records handled separately.
Public forum content and knowledge-base revisionsKept while published or archived; eligible personal content is removed or de-identified after a valid request where feasible.
Closed appeals and reportsKept for 24 months after closure; then the closed case and its messages are deleted, unless the case remains active or a legal hold applies.
BackupsEncrypted backups rotate out after 30 days, so scheduled deletions also age out of backup copies.

Your choices and requests

You can ask to access or correct information about you. You can request account closure, removal of eligible personal information, or review of an appeal/report record. Some records may need to remain for an active case, moderation, security, or legal reason; we will explain the decision. For privacy questions, requests, or complaints, contact OG Network staff privately through the official Discord server. Use a private message or the available staff support route in that Discord server.

OG Network is a general-audience community that includes Minecraft players. Parents or guardians can contact us to ask about information concerning a minor. Private cases, IP addresses, authentication factors, and staff notes are kept out of the site's public pages. We may update this policy as features and data practices change; the site will show the current version and material changes.