ModSeed Privacy Policy
Last updated: 2026-09-18
This Privacy Policy explains what data ModSeed collects, why we collect it, and what you can do about it. It is written in plain English for builders of every age. ModSeed is operated by Adam Ward, sole proprietor, doing business as ModSeed and CIServerModding Studios, Wyoming, USA. Questions: [email protected].
1. Who we are
We are a small, independent project (CIServerModding Studios) building a visual Minecraft add-on maker. We do not sell personal data, we do not run advertising trackers, and we collect as little as possible.
2. What we collect
Account data: your username, an encrypted (hashed) password, and timestamps (when you joined, when you last used the service). We never ask for your real name, email address, or date of birth to create an account.
Project data: the node graphs, node settings and pixel-art textures that make up your projects, plus your notepad notes (3000 characters maximum), and a count of the exports you have downloaded this window so we can enforce plan limits.
Collaboration data: if you use live collaboration, we store who is invited to which project (usernames), and your browser exchanges live editing messages (node changes and who is online) with our realtime service while a shared workspace is open. We also store the date you confirmed you are 13 or older to use collaboration.
Billing data: if you ever pay us, our payment processor (Stripe) handles your card details — we never see or store them. We store only a customer reference and what you purchased.
AI assistant data (Ultra only): the endpoint URL, model name, and your API key — the key is encrypted at rest with AES-256-GCM and is never displayed to anyone after you save it. When the assistant runs, your project graph and chat messages are sent to the endpoint you configured, under your own provider account.
Technical data: standard server logs (IP addresses for rate limiting and security) kept for a short period.
3. Why we collect it
To operate the service: showing you your account, hosting and exporting your projects, remembering your notepad, running live collaboration between the people you invite, and enforcing the plan limits you signed up for.
To keep the service safe: rate limiting, blocking abuse, and (very rarely) investigating clear violations of the Terms of Service.
To get paid: processing subscriptions and one-time purchases through Stripe.
4. Children's privacy (COPPA)
We knowingly collect personal information from children under 13 only with verifiable parental consent, as COPPA requires. If you signed up from the United States, you confirmed during sign-up that you are 13 or older, or that a parent or guardian consented.
A parent or guardian may email [email protected] at any time to review or delete a child's account and everything in it.
Live collaboration is only available to builders who confirm they are 13 or older. Accounts belonging to children under 13 (with parental consent) can build and export on their own, but cannot join or open shared workspaces — the 13+ checkbox is required each for the feature to unlock.
5. The AI assistant and the idea lightbulb
The BYOK AI assistant (Ultra) runs against the endpoint you configure. Your assistant requests and your API key belong to your provider relationship; we only store the settings (encrypted key, endpoint, model) so the editor can call it for you.
The idea lightbulb (Ultra) sends a short prompt to our AI provider to generate a fresh mod idea. The only personal context used is that you are a ModSeed builder — ideas are not personalized from your projects.
6. Cookies
We set one essential cookie (modseed_session) that keeps you signed in, plus a short-lived owner cookie used only by the site owner. There are no advertising or third-party tracking cookies.
7. Third parties we rely on
A managed database provider stores the service data described above. Stripe processes payments if you subscribe. If you connect the BYOK AI assistant, your chosen AI provider processes the requests you send it. That is the whole list.
8. Data retention
We keep your account and project data while your account exists. Free projects inactive for 7 days may be cleaned up, and cancelled-subscription projects are removed after the 30-day grace window (one free project remains).
When you delete your account, your personal data and projects are deleted. Note that the license to your creations described in our Terms of Service is irrevocable and survives deletion — it lets us keep using creations you already made, but it is not a store of your personal data.
9. Security
Passwords are hashed with a modern key-derivation function (never stored in plain text), AI keys are encrypted at rest, and all traffic runs over HTTPS. No system is perfect, so we also limit what we hold: no real names, no email addresses on your profile, no card numbers.
10. Your rights
You may access and download the data you put in (export your projects within plan download limits), correct it (edit your notepad, AI settings, and project contents any time), and delete your account — and everything in it — yourself from the account settings once subscriptions are cancelled.
You may also ask us to stop using your data without deleting it (restriction), object to our use of it where we rely on legitimate interest, or ask for a copy of what we hold. Email [email protected] and we will respond.
11. Changes to this policy
We may update this Privacy Policy as the service changes. The "last updated" date at the top always reflects the current version, and material changes are announced in the app.
12. Additional disclosures for European and California users
ModSeed is available worldwide, and this section adds the details that European and California law ask for. The rest of this policy still applies to everyone.
12a. Legal bases we rely on (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we process your data only where we have a legal basis. For account and project data, the basis is performing the contract — the service you signed up for. For subscriptions, the basis is performing that contract (taking payment and delivering the paid plan). For security logs, rate limiting, and keeping the service safe from abuse, the basis is our legitimate interest in running a secure service. For the small amount of marketing we may do (showing your creations as examples), the basis is the license you granted in our Terms of Service.
If we ever need your consent for something new, we will ask for it clearly, and you can withdraw it at any time.
12b. International data transfers
Our servers are in the United States. If you are in the EEA or the UK, your data is protected when it crosses the border by Standard Contractual Clauses approved by the European Commission, or by the EU-U.S. Data Privacy Framework where applicable. Our service providers (for example our database and payment processors) are bound to the same protections.
Because we collect so little — a username, hashed password, your projects, and billing records held by Stripe — the amount of personal data that ever crosses the border is small.
12c. Your GDPR rights
In addition to the rights in Section 10, you have the right to lodge a complaint with your local Data Protection Authority if you believe we handled your data poorly — for example, the authority in your country of residence in the EEA, or the Information Commissioner's Office in the UK. You also have the right to data portability for the data you provided to us (your projects export in standard formats).
We do not make automated decisions about you, and we do not profile you.
12d. California (CCPA/CPRA) notice
If you are a California resident, California law gives you the right to know what personal information we collect. In CCPA categories: we collect Identifiers (your username and account ID), Commercial information (your purchases and subscription history), Internet activity (your projects and export counts), and Geolocation is NOT collected. We do not collect sensitive personal information.
We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the past twelve months. We use the information only to operate the service, take payment, and keep it safe.
California users may request deletion of their data, disclosure of what we hold, or correction of inaccurate data by emailing [email protected] — the same rights everyone has, honored without discrimination.