Privacy Policy
Effective 25 September 2026
Who operates BedrockRelay
BedrockRelay is operated by BedrockRelay, part of the myGen network. For privacy questions or requests, contact privacy@bedrockrelay.com.
Information we handle
Dashboard sign-in
When you sign in with Discord, we ask only for the identify and guilds permissions. We receive your Discord user ID, display name, avatar and the Discord servers you belong to, including the permissions needed to identify servers you can manage. We do not receive your email address. We store an encrypted Discord access token and refresh token in a server-side session so the dashboard can recheck your permissions. The browser receives a secure session cookie and a short-lived OAuth state cookie.
Relayed messages and events
To deliver the features an administrator enables, we process Minecraft player names, chat, join, leave, death and other addon event content; Discord message text, display names, channel and server identifiers, avatar URLs and attachment links; and command requests. The bot reads messages only in channels an administrator has connected, and sends them only to that Minecraft server. Optional shared chat can also copy human Discord messages to other connected channels when it is switched on at both ends.
Commands and plugins
When someone uses /relay run or a plugin command in Discord, we pass the command, the options they gave and their Discord display name to the Minecraft server, and return its answer. Plugin answers are shown only to the person who asked, except for commands made to be shared, such as leaderboards, which are shown in the channel. If the person has linked their account, we also pass their linked Minecraft name. Plugins run on the Minecraft server, not on our systems. Some plugins post to Discord by themselves, such as a playtime milestone, but only in channels the Minecraft server's owner chooses. Some reveal information about players, such as their location or inventory. The dashboard shows what each plugin reveals beside its switch, and the Minecraft server's owner chooses which Discord roles may use it.
Linked accounts
A Discord member can use /relay link to link their Discord account to their Minecraft name on one Minecraft server. To prove it's them, we send a one-time code to that player in the game, which we keep in memory for ten minutes. Once linked, we store their Discord user ID, their display name at the time and their Minecraft name for that Minecraft server. The server's owner can see and remove links in the dashboard, and the member can undo theirs at any time with /relay link.
Server status and statistics
We keep the list of player names currently online on each Minecraft server so /relay online and the dashboard can show it. We also remember the names of players who have played on it, and when they were last seen, to suggest names when someone types a plugin command. For each Minecraft server we also count, per day, messages in each direction, joins, deaths and the peak number of players. These are counts, not the messages themselves. When a Minecraft server stops checking in for a minute, and again when it returns, we post a notice in channels that have the Status event switched on.
Reachability checks
To show whether players can join, we record the IP address the pack connects from, the game ports in server.properties when an SFTP visit reads them, and any join address the owner enters. About once a minute we send Minecraft's standard status ping to that address and store the result. We never ping addresses on private networks.
What the gateway stores
Minecraft server registrations (name, Minecraft and pack versions, last check-in); channel routes, their names, event filters and Discord webhook credentials; command and plugin rules, including Discord role IDs; installed plugins and the commands the pack reports; hashed installation tokens; the status and reachability data above; and audit records. Audit records note which Discord user made a dashboard change, ran a command (with the command text) or used a plugin (with the options given), and when.
Installation and technical data
If you install, update or uninstall the pack or a plugin over SFTP, the host, port, username, password or private key and server path are used for that one connection. Passwords and private keys are never saved or logged. An audit entry records the host, username and selected world for troubleshooting. Gateway and web-server logs may contain IP addresses, request paths, timestamps and errors. We use essential cookies for sign-in and OAuth security, and do not run advertising or analytics cookies on this site.
Why we use it
For dashboard users, we process identity, permissions and configuration to provide the service they request and to manage their installations, including status, statistics and reachability checks. For players and Discord members whose messages are relayed, we rely on our legitimate interest in providing the chat bridge the administrator has configured, with channel controls and short-lived delivery queues. We also use limited technical and audit data for our legitimate interests in keeping the service secure, diagnosing faults and preventing abuse. Administrators should tell their community which channels are linked, and which plugins are switched on, before enabling the relay.
Where information goes
- Discord: Minecraft chat, selected events and status notices are posted to the chosen Discord channels. Discord's own privacy policy governs messages stored on Discord.
- Connected Minecraft server: Discord chat from connected channels, command requests and plugin requests are sent to that server. If shared chat is enabled, messages and attachment links can be copied to other connected Discord channels for the same Minecraft server.
- MinecraftRender: a Minecraft gamertag may be sent to its image service to obtain a player-head avatar.
- Service providers: our hosting provider runs the gateway, and Cloudflare carries traffic to this site. Fonts are served from this site, not Google Fonts.
Some of these providers may process data outside the UK. Their privacy notices describe their own processing. Contact us if you need details of safeguards for a transfer we control. We do not share data with data brokers or advertising networks.
How long we keep it
- Dashboard sessions stop granting access after seven days; signing out removes the current session immediately. Expired session records may remain in the database until they are manually removed.
- Delivered messages in the gateway queue are removed after roughly one minute; undelivered messages expire after ten minutes. BedrockRelay does not keep a relay-chat archive. Messages delivered to Discord or Minecraft are subject to those services' and server owners' own retention rules.
- The online player list is replaced on every update and cleared when the world restarts. Player-head images are reused from memory for up to one hour, then replaced on the next request or cleared on a gateway restart.
- Minecraft server records, channel settings, rules, tokens, reachability data, linked accounts, the names of players seen and daily statistics remain while the Minecraft server is registered. Link codes are forgotten after ten minutes, or sooner when used.
- When its owner removes a Minecraft server in the dashboard, it stops working at once. A snapshot is kept for seven days so the removal can be undone. After that, or sooner if the owner chooses Delete forever, the snapshot, its statistics and its Discord webhooks are permanently deleted.
- Removing the bot from a Discord server or uninstalling the pack does not delete gateway records. Remove the Minecraft server in the dashboard, or contact us.
- Audit entries remain until they are manually removed or you request deletion. Operational backups may take longer to cycle out.
Security
Discord sign-in tokens are stored encrypted. Installation tokens are stored only as hashes, so they cannot be read back, even by us. SFTP passwords and keys are never stored. Traffic to the site and the gateway is encrypted in transit. Every dashboard change rechecks that you still manage the Discord server concerned. If personal data is accessed without authorisation, we will tell the people affected and Discord, as the law and Discord's developer terms require.
Children
The dashboard and bot are for Discord users, who must meet Discord's minimum age. BedrockRelay is not directed at children. Minecraft players' names and chat are handled only as the server's administrator configures.
Your choices and rights
A Minecraft server's owner can change or switch off routes, direction, events, shared chat, command rules and plugins in the dashboard. They can also revoke every pack token, uninstall the pack and remove the Minecraft server there. Anyone who manages a Discord server can disconnect a Minecraft server from it, using the dashboard or /relay disconnect, or remove the bot. You can sign out of the dashboard at any time.
You may ask us to access, correct, delete or restrict your personal data, and you may object to processing based on legitimate interests. Rights depend on the circumstances and applicable law. Contact privacy@bedrockrelay.com with your request.
If you are in the UK, you can also complain to the Information Commissioner's Office. We do not make decisions about people solely by automated processing that have legal or similarly significant effects.
Changes
We will update this page when the service or its data handling materially changes, and show the new effective date here.