Privacy

Privacy policy

Gatebound is a menu that hands players to their own servers. It needs very little about you to do that, and this page lists all of it.

Last updated 8 September 2026

The short version

Gatebound stores the identity your Minecraft session already proved, the servers you chose to save, and - if you use the website - a hash of your browser sign-in token. There is no analytics, no advertising, no third-party script, and no email address or password anywhere in the system. Nothing is sold or shared.

Who is responsible

This policy covers the Gatebound service reachable at the address on this site, and the software running it. The operator of this deployment is the data controller for everything described below. Reach them at privacy@gatebound.net.

What is collected, and why

DataWhere it comes fromWhy
Platform identity - your Xbox XUID on Bedrock, or your Mojang UUID on JavaThe authenticated login your Minecraft client performs when it joins It is the key your saved-server list is stored under. Without it the menu cannot tell whose list to show.
Your in-game nameThe same loginShown in the menu and the control panel so you can tell which profile you are managing.
Saved servers - display name, hostname or IP, port, optional note, and the times each was created and last joinedTyped by you, in game or on this siteThey are the product. Nothing else is done with them.
A SHA-256 hash of your browser sign-in token, the profiles linked to it, and its expiryCreated when you redeem a six-digit link codeKeeps you signed in to the control panel for 90 days. The token itself exists only in your browser cookie - the server cannot reconstruct it from the hash.
Your IP addressYour connectionHeld in memory for at most 15 minutes to rate-limit failed link-code attempts, and written to the web server's ordinary access log.
Six-digit link codesGenerated when you ask for one in game One use, valid for ten minutes, then discarded.
Counts: how many times you joined, how many times you were transferred, which of your saved addresses you went to and when, and how long you spent in the menuYour own use of the serviceSo the site can say how many transfers it has done, and so a future page can show you your own figures. These are counters against the identity above - no new information about you is collected to produce them.

What is never collected

  • No email address, password, or Microsoft account sign-in on this website.
  • No payment details. Nothing here is sold.
  • No chat, no gameplay content, and no world data - after the handover your client is not talking to Gatebound at all.
  • No analytics, advertising, fingerprinting, or third-party embeds. This site makes no request to any other origin, which you can verify in your browser's network panel.

Legal basis

Where the UK or EU GDPR applies, processing rests on two bases. Storing your identity, your saved servers and your sign-in session is necessary to perform the service you asked for (Article 6(1)(b)). Keeping short-lived IP records to stop brute-force attempts on link codes is a legitimate interest in keeping other people's lists secure (Article 6(1)(f)).

Who else sees it

  • Nobody, by default. Saved lists are not published, shared or sold, and one player's identity never reveals another's list.
  • Microsoft and Mojang authenticate your Minecraft session before Gatebound sees anything. That exchange is between your client and them, under their own privacy terms.
  • The servers you transfer to. Once you pick a destination your client connects to it directly, and what that server logs is entirely up to its operator. Gatebound sends it nothing about you.
  • The Friends tab. If this deployment publishes itself as a joinable Xbox session, joining that way makes your gamertag visible to the accounts running the broadcast, in the same way joining any friend's session does.

How long it is kept

  • Saved servers and your profile record: until you delete them. They survive signing out and unlinking a browser.
  • Browser sessions: 90 days, or immediately when you use Sign out device.
  • Link codes: ten minutes, or the moment they are used.
  • Rate-limit records: 15 minutes, in memory only. A restart clears them.
  • Usage counters: kept while your player record exists, and removed with it. Per-day totals for the hub as a whole are kept for about two years and identify nobody.
  • Web server access logs: rotated on the host's ordinary schedule, typically a couple of weeks.

Your choices and rights

Most of what you would ask for, you can do yourself and immediately:

  • See everything stored about you - the control panel shows your whole list and every linked profile.
  • Correct or delete a saved server - in game or on the control panel. Deletion is immediate and permanent.
  • End a browser session - Sign out device revokes the token everywhere it was valid.
  • Delete everything - ask, and the whole player record is removed.

Where the GDPR applies you also have the rights of access, rectification, erasure, restriction, objection and portability, and the right to complain to your national supervisory authority. Requests go to privacy@gatebound.netand are answered within one month. You may be asked to prove control of the Minecraft account in question - by requesting a link code from inside it - because that account is the only identifier the service has.

Security

  • The website is served over HTTPS only, with HSTS.
  • Sign-in tokens are 48 random bytes and are stored only as a SHA-256 hash.
  • Every form is protected against cross-site request forgery, and the session cookie is HttpOnly, Secure, SameSite=Lax and __Host- prefixed.
  • The page's content security policy permits this origin and nothing else.
  • No system is perfect. If you find a flaw, report it to privacy@gatebound.net rather than to the players.

Children

Gatebound has no separate account system: everyone who uses it is already signed in to a Minecraft account governed by Microsoft's or Mojang's own terms and age rules. It is not directed at children under 13, and it deliberately collects nothing beyond the identity that account already provides.

Where the data lives

Saved lists and sessions are stored on the server running this deployment, as plain files on that host's disk. They are not replicated to a third-party cloud service or a managed database, and nothing is transferred to any processor for analytics.

Changes

If this policy changes materially, the date at the top of the page changes with it and the current version always sits at this address. Continuing to use the service after a change means the new version applies.