Who this is for
“We” is RealAC. This page describes what RealAC receives from the Minecraft servers that run it, what we do with it, and the limits of what we will do.
It is written for the server operator who holds the licence, because that is who we have a relationship with. If you play on a server that runs RealAC, the operator of that server is the person to ask first: they chose to run it, they set what it does, and under European and UK data protection law they are the controller for what their server sends us. We act for them when we deliver detection to them, and on our own account when we use what we receive to operate, secure and improve RealAC.
What we collect
RealAC receives information from the Minecraft servers that run it. Specifically:
- Who is playing
- Minecraft UUID and username.
- How they play
- Movement, rotation, timing, combat events, and block and container interaction, sampled while they play.
- Their connection
- Ping, client brand and version, session start and end times, and the IP address the session connected from.
- What happened
- Flags raised, punishments your staff or your rules applied, and reports your staff sent us about a bad flag.
- Which server
- Your licence, the server name you configured, and the installation it is running on.
We record that a chat message was sent and how long it was, because timing around a message is useful for detection. We never receive what the message said.
We do not receive your world, your builds, your players’ inventories, your economy, your plugin list, your server files, or anything from your console other than what the plugin itself produces.
We also keep what you send us directly: what you give us when you buy, and what you say to us in Discord when you ask for a trial or for support.
This page describes what we receive in categories rather than field by field. A field list of what an anticheat measures is most useful to the people it is built to catch.
Why we collect it
To detect cheating on the servers that send it, and to improve the models that do the detecting. That is the whole list. We do not sell it, we do not share it with advertisers, and we do not use it to build a profile of anyone for any purpose other than detecting cheating and ban evasion on the servers they play on.
Ban evasion is worth spelling out, because it is the part people do not expect. RealAC compares how an account plays against how accounts that were banned played, so that the same person on a new account can be recognised. That means we hold information which links accounts to one another.
The bulk collection that feeds ban evasion and model work is on for every licensed server unless it is switched off. Ask us and we will switch it off for yours. Detection itself still needs what the plugin sends, so switching it off does not stop the plugin sending us anything, and it changes nothing about what we already hold.
Under the GDPR and the UK GDPR, delivering detection to the operator who holds the licence rests on our contract with them. Keeping the service secure, preventing abuse of it, and improving how it detects, including training our models, rest on our legitimate interests in running an anticheat that works.
Training our models on it
RealAC gets better by learning from what it sees. Gameplay your server sends us is used to build and improve the models that decide whether a player is cheating, and what is learned from your server improves detection on every server that runs RealAC, including yours.
Models, statistics and everything else we derive from what we receive belong to us, and we go on holding and using them after a licence ends. Once a session has contributed to a model it cannot be taken back out again: a model is built from very large volumes of gameplay and cannot be un-built from one part of it. The terms set out the rights this rests on in full.
No other customer sees what your server sends. What travels between customers is the improvement, not the data.
Who can see it
Your staff see detections about players on your server, through the plugin.
We see the data your server sends, and use it for the purposes above.
Other customers never see your data. We do not pool ban-evasion matching across customers: a match is scoped to the server that issued the ban, so nothing about your players reaches another customer’s staff.
Inside our own team, access is limited to the people who need it to run RealAC and to improve detection.
We use Discord, because that is where we talk to you. What you send us there is held by Discord as well as by us. We use a payment provider to take payment: they receive what they need to take it, and we do not receive or store your card details. Our own service runs on infrastructure we rent.
We rent that infrastructure, and it is in the European Union. What your server sends us is processed and stored there, and we do not transfer it outside the European Economic Area.
How long we keep it
We do not delete on a schedule, and there is no fixed retention period. We keep what we receive for as long as we need it to run the service, to keep detection working and improving, to enforce our terms, and to deal with disputes and legal obligations.
Some of it cannot be taken back. A detection model is built from very large volumes of gameplay and cannot be un-built from any one part of it, and the same is true of an aggregate statistic. Where we remove records about a player, we remove the records; we do not rebuild or retrain anything already derived from them.
We do not publish a fixed period per category. What we keep, we keep while it is useful for detecting cheating and for standing behind the decisions made from it.
Your players’ rights
If you are in the EU or UK, your players have rights over their personal data and you are the one they will ask. Tell them RealAC is running; you can link this page. Then talk to us at discord.gg/v6qYqdAMYQ and we will help you answer.
We act on requests we are required to act on. What removal can mean is set out under How long we keep it: removing a player’s records does not unwind anything already derived from them.
We keep what we need to keep whatever else is asked of us: to enforce our terms, to defend a claim, to keep a banned player from walking back in on a new account, and to comply with the law.
European law normally expects a written data processing agreement between us for that arrangement. Ask us in Discord and we will put one in place.
Children
Minecraft is played by children, and a server running RealAC will have children on it. We do not ask anyone’s age and we are not told it. We receive the same information about every player on your server whatever their age, and we use it only for the purposes on this page.
We do not ask for anyone’s age, we are not told it, and we treat every player on your server the same way whatever it is. Telling your players what runs on your server, and getting whatever their age requires where you are, is yours to do as the controller.
Changes to this page
When this page changes, the change is posted here and dated. If a change materially affects what we do with what we already hold, we will say so in our Discord.
This website
This site does not use cookies and does not track you.
Contact
Discord is how to reach us: discord.gg/v6qYqdAMYQ.
Or by email: info@realac.ac.