Privacy Policy
Last updated: October 2026
VoxelBench ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and Minecraft plugin. The controller of your personal data is Geoffrey Lecoq, the publisher of VoxelBench, whose details appear in our Legal notice.
We collect information in several ways when you use our services:
Account Information
- Email address (for account creation and communication)
- Username and display name
- Profile picture (if provided or from OAuth)
- Information from the accounts you connect: Discord or Google if you sign in with them (email address, name, avatar); the accounts you choose to show on your profile, Discord, GitHub, X (Twitter) and YouTube (username, display name, avatar, profile link); and the access tokens these services issue to us. If you use auto-bench with your own Microsoft account, we also keep its email address, its Minecraft username and UUID, its Xbox user ID, and its sign-in tokens, which are stored encrypted.
Benchmark Data
- Hardware specifications (CPU model, core count, RAM amount, disk type)
- Server software information (version, type, Java version, OS, installed plugins and mods)
- Performance metrics (TPS, MSPT, test results)
- Anonymous server identifier (hashed); a fingerprint of the IP address the report was sent from, and the server's country (shown on public reports and leaderboards) and network operator, derived from that address
Technical Information
- IP address (for security and rate limiting, and, as a fingerprint combined with your browser type, to count each visitor once a day on profiles, reports and blog articles; if you are signed in, your account identifier is used instead and recorded with the view)
- Browser type and device information
- Session and preference cookies
Certification Data (Hosting Providers)
- Announced and detected server specifications (CPU, RAM, storage)
- The tested server's IP address and how we accessed it (the server is the one we buy for the test)
- Purchase documentation (order confirmation, invoice, panel screenshot, order reference) and the proof code placed in the customer account
- Video recording of the benchmark process (confidential: shared only with the hosting provider concerned and our team)
- Contestation requests and resolution details
We use the collected information for the following purposes:
- To provide and maintain our benchmarking service
- To display benchmark results on public leaderboards
- To enable comparison of server performance
- To ensure security and prevent abuse
- To improve our services and develop new features
- Marketing: with your explicit consent, sending the blog newsletter (new benchmarks, hosting comparisons, release notes). Consent is optional, never required to use the service, and can be withdrawn at any time from any email or from your account settings.
We may share your information in the following circumstances:
- Benchmark reports you make public appear on our leaderboards and public pages; reports you make unlisted can be opened by anyone who has their link. A report sent without a linked account can be opened by anyone who has its link until it is archived; it expires 30 minutes after it is sent. Your profile page shows your name, username, avatar and role and, unless you make it private, your bio, the date you joined, your statistics, the linked accounts you choose to display, and the servers and reports you have made public.
- A certification is published only once the hosting provider has approved it. It then shows the plan name, the score and rank of the certified report, the scores of the three runs, the tested server's IP address, the main dates and whether it was contested, and the certified benchmark report becomes public. Purchase documents, the video, the specification check and the test notes are not published: they are shown only to the hosting provider concerned and to our team.
- The site never shows certification videos publicly: a video is hosted on a video platform (such as YouTube or Vimeo), and its link is shown only to the hosting provider concerned and to our team.
- With the service providers listed below, who help us run the service (hosting, payments, storage, email delivery, content moderation)
- When required by law or to protect our rights
We do not sell your personal information to third parties.
Remote monitoring is optional and needs a paid plan. It only runs for a linked server when both switches are on: the one on your Monitoring page, and the plugin setting on your server (/bench monitor remote on). While it runs, the VoxelBench plugin sends us the following.
What the plugin sends
- Performance measurements, once a minute by default: TPS, tick time, CPU and memory use, garbage collection, and the number of players, entities and loaded chunks, with the names of your busiest worlds. On a Folia server, each measurement also lists the server's regions (64 by default), each with its world, the block coordinates of its center and its number of chunks. No player names.
- A heartbeat every 30 seconds with the plugin version and the time the server started, used to show whether the server is online.
- Server events: starts and stops, performance incidents, benchmark runs.
- Security events: when a player gains or loses operator status, the event contains that player's in-game name. Whitelist and configuration changes are reported without names.
- Moderation events, only if you turn on the LiteBans integration (off by default): the in-game names of the sanctioned player and of the moderator, and the reason only if you also turn on include-reason.
- The address your server connects from, kept only as a keyed one-way fingerprint, never the address itself, so that you can notice a token used from somewhere unexpected.
How it is used and who sees it
We use this data only to show your dashboards, evaluate the alert rules you set and send the notifications you chose. It is not used for advertising and is never sold.
Only you, as the owner of the server, can read its monitoring data: on the dashboard, or through the API and connectors with your own tokens. None of it is shown on a public page unless you open the server's public status page, described below.
If you set up Discord or webhook notifications, the content of each alert, event titles included, is sent to the destination you configured.
If you open a public status page for a server (off by default), anyone with its link can see the server's name and icon, whether it is up, not responding, under maintenance or down, its daily availability over the last 30 days, and when it started, stopped or went into maintenance. It never shows measurements, player names, maintenance reasons or event details, and it asks search engines not to index it. Closing it takes it offline within a minute.
If you create an external probe URL, the uptime tool you give it to learns only whether the server is running: a 200 or 503 answer, the server's detailed state, and whether a maintenance is under way. The URL names no server; we keep only a one-way fingerprint of it, and you can revoke it at any time.
How long it is kept
Turning it off and deleting it
Turn monitoring off in game with /bench monitor remote off, or with the switch on your Monitoring page: nothing more is accepted from that moment. Data already stored is kept for the periods above. Deleting the server, or your account, deletes all of its monitoring data.
A performance profile is only sent when you ask for it on your server (/bench profile upload <id>, then confirm within 60 seconds). Nothing is ever sent automatically.
A profile names every plugin that appeared on the sampled stacks (private plugins included), their classes and methods, the names of the server's threads, the server and Java versions, the operating system and the number of processors. Its structured fields contain no player name, UUID, IP address, command, file path or JVM argument. On a Folia server, a profile also names the worlds of the busiest regions and gives their block coordinates (where the server's load was): they stay private to your account (page, raw JSON, API and MCP).
Thread names are sent as the Java runtime reports them. Some can contain an address or a host name (for example Minecraft's remote console thread, or a database driver): the plugin warns you before sending when it detects one.
An uploaded profile belongs to the account the server is linked to. Only you can see it; it is never shown on a public page. Sharing publicly is a separate command, described below.
We keep at most 5 profiles for 30 days on the free plan, 50 for 180 days on Pro, and 200 for 365 days on Hosting and Enterprise. Beyond that, the oldest are deleted.
Each profile also leaves a short summary: its trigger and capture window, sample counts, server and Java versions, warning codes, the owners (plugins included) and methods that weighed the most, and a breakdown by kind of work. We keep summaries for 365 days on every plan, even after the limits above have deleted the full profile, so that you can follow how your server evolves. Deleting a profile yourself deletes its summary; deleting the server or your account deletes them all.
You can delete a profile at any time from its page or from the server's Monitoring settings. Deleting your account or the server deletes its profiles.
Public sharing is a separate command (/bench profile share <id>, then confirm). It needs no account: the plugin first removes what could identify the server — addresses, host names, paths, player and world names (Folia regions are kept by number only, without coordinates), the machine and user names — and sends that cleaned copy. Anyone with the link can open it; nothing lists it, and it asks search engines not to index it.
The public page never shows which server or account shared the profile. The server identifier and the address the request came from are only used, as keyed fingerprints, to limit how many profiles can be shared per day, and those counters are deleted after two days.
A shared profile expires 7 days after it was shared and is then deleted within a day. The plugin can remove it earlier with /bench profile unshare, and anyone can report a shared profile for an administrator to remove.
A memory report is only sent when you ask for it on your server, with a command and then a confirmation. Nothing is ever sent automatically. There are two kinds: a heap summary, which says how much memory the classes of each plugin take, and a heap dump analysis, which says which plugin retains the memory and through which references.
Both reports contain names and numbers only: plugin, class, field and class-loader names, object counts and sizes, the server and Java versions, the operating system, the number of processors and the server's memory settings. They contain no value read from the server's memory: no text or string content, no player name, UUID, IP address, chat message, file content or configuration value.
A heap dump (the .hprof file the plugin can write on your server) is never sent: it holds everything the server has in memory, secrets included. If one reaches us anyway, it is refused before anything is written and never stored.
An uploaded report belongs to the account the server is linked to. Only you can see it; it is never shown on a public page. Sharing publicly is a separate command, described below.
We keep at most 5 reports for 30 days on the free plan, 50 for 180 days on Pro, 200 for 365 days on Hosting and 200 for 365 days on Enterprise, and never more than 50 per server. Beyond that, the oldest are deleted.
You can delete a report at any time from its page or from your list of reports. Deleting the server or your account deletes its reports.
Public sharing is a separate command. It needs no account: the plugin first builds a cleaned copy, removing what could identify the server (addresses, host names, paths, player and world names, the time zone, support data and the machine's exact memory figures), and sends that copy; we refuse a shared report that does not carry the record of this cleaning. Plugin names stay visible. Anyone with the link can open it; nothing lists it, and it asks search engines not to index it.
The public page never shows which server or account shared the report. The server identifier and the address the request came from are only used, as keyed fingerprints, to limit how many reports can be shared per day, and those counters are deleted after two days.
A shared report expires 7 days after it was shared and is then deleted within a day. The plugin can remove it earlier, and anyone can report a shared report for an administrator to remove.
VoxelBench relies on the following sub-processors. Each one acts under a contractual data-processing agreement (DPA) and processes personal data only on our documented instructions:
hosting
Hetzner Online GmbH (Germany) — application hosting and database. DPA: https://www.hetzner.com/AV/DPA.pdf. Encrypted database backups, and a copy of uploaded files, are stored with Backblaze (backup storage). Once a week, an automated test restores the latest database backup on a temporary GitHub, Inc. (USA) server to check that it works.
stripe
Stripe Payments Europe Ltd (Ireland) — payment processing, billing, invoicing. DPA: https://stripe.com/legal/dpa
storage
Cloudflare, Inc. — storage of uploaded files (R2: avatars, logos, certification evidence) and the network through which the site is served (content delivery, protection against attacks, and the Turnstile anti-bot check on the sign-up, sign-in, password and contact forms). DPA: https://www.cloudflare.com/cloudflare-customer-dpa/
Email delivery providers (SMTP) — transactional and notification emails: account and security messages, billing, certification updates, monitoring alerts, moderation notices about your reports, notices when your score is overtaken on a leaderboard, the newsletter if you asked for it, and, if you turn on “Notify on new report” for a server, a notice for each benchmark report it sends (not for auto-bench runs or single tests) with the server's name, the mode, the score, the rank and a link. That notice goes to your account address, or to the notification address you entered once its holder has confirmed it through a link valid for 7 days, which carries only a fingerprint of the address; each notice lets you unsubscribe in one click. DPA available on request.
oauth
Sign-in: Discord and Google, if you choose to sign in with them. They confirm your identity and send us your email address, name and avatar. Linked accounts: Discord, GitHub, X (Twitter) and YouTube, to show an account on your profile and to help us detect duplicate accounts (anti-abuse); they send us its username, display name, avatar and profile link, and are never used to sign in. We send these services nothing but the authorization request.
ai
OpenAI (USA) — moderation of the text you submit (profile name, username and bio, server names, report descriptions, public status page addresses). We send only the text to check; OpenAI returns a classification and, under its API terms, does not use it to train its models. Images are checked on our own servers and are not sent to OpenAI. DPA: https://openai.com/policies/data-processing-addendum
We never sell your data, and we share with these sub-processors only the minimum needed for the feature you use. Notifications you choose to receive on Discord or on your own webhook (for example monitoring alerts, certification updates or the arrival of a new benchmark report) are sent to the destination you configured, which handles them under its own terms.
We retain your information for as long as necessary to provide our services; the main periods are listed below. They apply to the site itself: copies can remain in our backups beyond them, and the backup copy of uploaded files is not limited in time.
Depending on your location, you may have the following rights:
To exercise these rights, please contact us using the information below. You can also lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr).
We use cookies for the following purposes only, and no advertising or audience-measurement cookies:
- Essential cookies for the site to work and for security: sign-in and its protection against forged requests, the second step of two-factor sign-in, a pending passkey request (5 minutes), the device you choose to trust (30 days), and security cookies that Cloudflare may set to protect the site
- Session cookies to keep you signed in
- Preference cookies: your language (1 year) and, if you vote in a blog poll without an account, a random identifier that prevents voting twice (1 year). Your theme and display choices are kept in your browser's local storage, not in a cookie.
We implement appropriate technical and organizational measures to protect your personal information: encryption of data in transit (HTTPS), password hashing, optional two-factor authentication whose secrets we store encrypted, optional passkeys of which we keep only the public key (with the name you give it and when it was last used), encryption of the Microsoft account tokens you lend to auto-bench, encrypted database backups, and access controls. However, no method of transmission over the Internet is 100% secure.
Our services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
If you have questions about this Privacy Policy or our data practices, please contact us: