Exylia

Exylia Analytics

Privacy Policy

Last updated October 5, 2026

How Exylia Analytics handles the data of the people who use the dashboard and of the players on the Minecraft servers that use it. We do not sell data, show ads or track you across other sites.

1. Who we are and what this policy covers

Exylia Analytics (the "Service") is an analytics platform for Minecraft servers and networks, made of the dashboard at analytics.exylia.net, the ingest at analytics-ingest.exylia.net and the ExyliaAnalytics server plugin (the "Agent"). It is operated by Cristobal Aranda, a natural person domiciled in Chile ("we", "us"). Contact: [email protected].

We handle personal data in two different roles:

  • As controller, for the people who sign in to the dashboard ("Users") and for visitors of our websites. Sections 2 to 12 describe that processing.
  • As processor, for the players of the servers that install the Agent. The owner of each server or network (the "Customer") decides to collect that data and is its controller; we process it only on the Customer's instructions under our Data Processing Agreement. Section 3 describes what the Agent collects, so that players and Customers can see it in full.

If you are a player and want to exercise your rights over data collected on a server, contact that server first: it decides what is collected and why. If you write to us instead, we will pass your request on to the server and help it answer.

2. Data about Users of the dashboard

We collect only what the Service needs to work:

  • Discord account: when you sign in with Discord we receive your Discord user ID, your display name and the address of your avatar. We request only the "identify" scope: we never receive your email address, your password, your servers or your messages. The Discord access token is used once and discarded.
  • Login sessions: a random session token, stored on our side only as a hash, with its creation and expiry dates. We do not store your IP address or browser with the session.
  • Workspace data: the workspaces you create or join, your role and permissions, the invitations you create or accept, and the content you add (annotations, campaigns, funnels, integration settings, generated reports).
  • Communications: the messages you send us by email and our replies.
  • Technical data: when you visit our sites, our network provider and our servers process your IP address, browser user agent and the requested URL to deliver the page, protect the Service against abuse and diagnose errors. If an error occurs, an error report with technical context (browser, URL, stack trace and, where applicable, IP address) may be sent to our error-monitoring provider.

We do not use the dashboard to profile you, we do not run advertising or third-party analytics on it, and we do not sell or rent personal data.

3. Player data processed for Customers

Which of the following is collected depends on the modules the Customer enables for each server. For every connection the Agent can record:

  • Identity in the game: Minecraft UUID, username, whether the player joined from Bedrock, and the rank or group they hold (for example from LuckPerms).
  • Sessions: when the player joined and left, why the session ended, the server address (hostname) they typed to connect, client version, client brand and game language.
  • Earlier play on the server: when a server is first linked, and on a returning player's first join after each server start, the dates the player first and last played there and their total playtime, read from the server's own player files and statistics, so players who played before the server was linked are not counted as new.
  • Location derived from the IP address: country and network operator (ASN), looked up locally in the DB-IP Lite database. The IP address itself is never stored in plain text. We always store a keyed hash of it (HMAC-SHA256 with a secret unique to each workspace), which lets the Customer spot alternate accounts without knowing the address. Only if the Customer turns on encrypted IP storage do we also keep the address encrypted with AES-256-GCM, for 90 days, visible only to Customer staff with explicit permission.
  • Activity: joins, leaves and AFK periods, and counts of chat messages, commands, deaths and kills. We count these events; we never store the content of chat messages or commands, nor the player's position in the world.
  • Server features, when enabled: votes (voting site), punishments (type, reason, duration and the UUID of the staff member who issued it), rank changes, values of PlaceholderAPI placeholders chosen by the Customer, economy transactions and balances, anticheat alerts, and custom events defined by the Customer.
  • Purchases, when the Customer connects its Tebex store: transaction ID, date, amount and currency, packages bought, country, player username and UUID, creator code and subscription status. Before storing a purchase we remove the buyer's name, email address, IP address and postal address, and mask gift-card numbers.

The raw events received from the Agent are deleted after 90 days. The statistics derived from them (sessions, player summaries, votes, punishments, purchases and similar) are kept while the Customer's workspace exists, unless the Customer erases a player or deletes the workspace sooner (see section 7).

Customers must not configure placeholders or custom events to send sensitive data (health, political opinions, religion, sexual orientation and the like), passwords or payment card data.

4. Why we use the data and on what legal basis

  • To provide the Service you signed up for: sign-in, workspaces, permissions and the analytics you ask for. Basis: performance of a contract (GDPR art. 6.1.b) and, in Chile, the contractual relationship and your consent given when you sign in (Law 19.628, arts. 4 and 20).
  • To keep the Service secure and working: preventing abuse, rate limiting, error diagnosis and backups. Basis: our legitimate interest in running a secure service (GDPR art. 6.1.f).
  • To answer your requests and communicate changes to these terms. Basis: performance of a contract and legitimate interest.
  • To comply with legal obligations and respond to lawful requests from authorities. Basis: legal obligation (GDPR art. 6.1.c).
  • Player data: we process it only to provide the Customer with its analytics. The Customer is responsible for having a legal basis (usually its legitimate interest in running, moderating and improving its server, or consent where required) and for informing its players.

We do not make decisions that produce legal or similarly significant effects on anyone solely by automated means. Indicators such as anticheat alerts are statistics for the Customer's staff, who decide on their own what to do.

5. Cookies and local storage

The dashboard uses only cookies that are strictly necessary for it to work or that remember choices you made. There are no advertising, tracking or third-party analytics cookies, which is why we do not show a cookie banner.

  • __Host-exa_session: keeps you signed in. 30 days, renewed while you use the dashboard. Strictly necessary.
  • __Host-exa_oauth: protects the Discord sign-in against forgery. 10 minutes. Strictly necessary.
  • NEXT_LOCALE: the language you chose. 1 year. Preference.
  • filters_*, details_*, exa_rail, exa_adv and exa_notice: remember filters, open panels, the sidebar state and dismissed announcements. 1 year. Preference.
  • The theme (light or dark) is kept in your browser's local storage and never leaves your device.

Some pages show images served by third parties: player heads from mc-heads.net and Discord avatars from cdn.discordapp.com. To load them your browser connects to those services, which receive your IP address and, in the case of mc-heads.net, the UUID of the player whose head is displayed.

6. Who receives the data

We run the Service on our own servers. We share personal data only with the providers needed to run it, each bound by its own data protection terms:

  • Cloudflare, Inc. (United States; global network): DNS, TLS and network protection. All traffic to our domains, including the batches the Agent sends, passes through Cloudflare.
  • Discord Inc. (United States): sign-in with Discord.
  • Functional Software, Inc. "Sentry" (United States): error reports from the dashboard and the ingest.
  • Tebex Limited (United Kingdom): only for Customers who connect their store; Tebex sends us their purchase events.
  • mc-heads.net: player head images, as described in section 5.
  • Artificial-intelligence providers, only if the optional AI analyst is enabled: they receive aggregated statistics of a workspace to write a report, never player names, UUIDs or IP addresses.

The geolocation database (DB-IP Lite) runs inside our servers: no IP address is sent to DB-IP. We may disclose data when required by law or by a court or competent authority, and to defend our legal rights. Customer staff see the player data of their own workspace according to the permissions the Customer grants them. Customers can also share the player data of their workspace with third-party tools of their choice (for example a Discord ticket bot) through API tokens they create and can revoke at any time; those tools receive only what each token's scopes allow, and never IP addresses.

7. How long we keep data

  • User account: until you delete it from the dashboard or ask us to. You cannot delete an account that still owns a workspace; delete the workspace or hand it to someone else first.
  • Login sessions: until they expire (30 days without use) or you sign out; the records are deleted 30 days later.
  • Invitations: deleted 30 days after they expire, are revoked or are accepted.
  • Raw player events: 90 days. Encrypted IP addresses, where enabled: 90 days.
  • Other player data: while the workspace exists. A Customer can erase a single player from its workspace settings; that player's data is deleted within 24 hours. When a workspace is deleted, all of its data is deleted within 24 hours.
  • Technical logs and error reports: up to 90 days.
  • Emails with us: as long as needed to handle the matter and for up to 2 years afterwards, unless the law requires longer.

Backup copies, where they exist, are rotated and overwritten within 30 days, so deleted data disappears from them within that period.

8. International transfers

Our servers are in Chile, and some providers in section 6 are in the United States or the United Kingdom. When data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (incorporated in our Data Processing Agreement for Customers) and on our providers' own safeguards, such as the EU-U.S. Data Privacy Framework or their Standard Contractual Clauses.

9. Security

We protect data with measures appropriate to the risk, including:

  • Encryption in transit (HTTPS/TLS) for all traffic to our domains.
  • IP addresses kept only as keyed hashes, or encrypted with AES-256-GCM when the Customer enables it; integration secrets and API keys encrypted the same way.
  • Session, invitation and server tokens stored only as hashes.
  • Databases not exposed to the internet, separate database users with the minimum permissions (the dashboard reads analytics with a read-only user) and query logging disabled.
  • Strict separation of each Customer's data by workspace, and role-based permissions within each workspace.

No system is completely secure. If a personal data breach occurs, we will notify affected Customers without undue delay, and the competent authority and affected people where the law requires it.

10. Your rights

Depending on where you live, you have the right to access your data, rectify it, erase it, restrict or object to its processing, receive it in a portable format and withdraw any consent you gave, without affecting earlier processing. In Chile, Law 19.628 grants the rights of access, rectification, cancellation and blocking, and from Law 21.719 taking effect also objection, portability and the right not to be subject to automated decisions.

To exercise them, write to [email protected] from a channel that lets us confirm your identity (for Users, we may ask you to confirm through your Discord account). You can also delete your account yourself from the dashboard. We will answer without undue delay and within the time the applicable law allows (under the GDPR, one month, extendable where necessary).

You can complain to a data protection authority: in the European Union, the authority of your country of residence or work; in Chile, the Personal Data Protection Agency created by Law 21.719 once it is operating, or the courts under Law 19.628. We would appreciate the chance to resolve your concern first.

11. Minors

The dashboard is intended for people who are at least 18 years old or of legal age where they live. We do not knowingly create accounts for minors.

Many Minecraft players are minors. The Agent does not ask for or record a player's age, and we never use player data for advertising or profiling. Customers whose servers are aimed at minors must assess their obligations, including parental consent where the law requires it, and can reduce collection by disabling modules.

12. Changes and contact

We will update this policy when the Service or the law changes, and show the date of the latest version at the top. If a change materially affects how we use personal data, we will announce it in the dashboard at least 30 days before it applies.

Questions or requests: [email protected].