Privacy Policy - The Modding Community
Privacy Policy
This is our privacy policy. We aim to be as transparent as possible regarding what we do with any and all personal data we store from users.
This policy covers The Modding Community (TMC, "we", "us") and the services we operate, which include:
- Our main website at moddingcommunity.com, including accounts, the server browser, mods, assets, communities, collections, articles and the blog.
- Our landing and legal pages , which is the site you are reading right now.
- Our forum at forum.moddingcommunity.com.
It does not cover third-party services we link to, such as Discord, GitHub, other modding platforms like Nexus Mods and CurseForge, or the game servers listed in our server browser. Those services have their own privacy policies, and we encourage you to read them.
The Modding Community is an independent, community-run project . We are not affiliated with the game developers and publishers whose titles we support, nor with any other modding platform — see our terms of service for the full statement.
We track every visit to our website using Umami and Plausible. We also track events such as clicks on buttons and links, scroll events , and general activity (e.g. page views, browser view and sorting changes, and search usage). ALL of this data is anonymous and not personally stored.
We want to note that our analytics services do process your IP address to provide us with data on what country and city the IP address is geo-located to. This is not your direct address , but typically the nearest city or town depending on your ISP (Internet Service Provider). As stated above, this information is kept anonymous and we do not store your IP address.
Neither service uses cross-site tracking , advertising identifiers, or sells your data. We do not run advertising networks on any of our services.
Creating an account is entirely optional . You can browse our sites, use the server browser and read every public page without signing in. An account is only required to publish content and interact with the community.
Sign-In Methods
You may sign in with any of the following, available on the login page:
We never store a password . Email sign-in is passwordless: the code we send is short-lived, single-use, and discarded once it is checked or expires.
When you sign in through an external provider, we store the data that provider returns to us, which may include:
- Email (Steam does not provide one, and other providers may withhold it)
- Username and display name
- Avatar (image)
- The provider's account identifier and the access tokens needed to keep the connection working
You may link or unlink additional providers at any time from your account's Connections page.
Profile Information
Everything on your profile is optional and supplied by you. This includes your username , display name , biography , avatar and any social links you choose to add (website, Discord, Steam, GitHub, X, Facebook or Instagram).
You control who can see you:
- Public listing - whether you appear in the public users browser. This is off by default ; we never list a member without their consent.
- Profile visibility - whether your public profile page is visible to everyone.
- Activity visibility - whether other members can see your presence indicator, and whether it is derived from your activity or pinned manually to Idle or Away.
Security Data
To keep accounts safe we store:
- Sessions - a session token and its expiry, so you stay signed in.
- Two-factor authentication - if you enable it, your TOTP secret and the date it was armed. Recovery codes are stored only as SHA-256 hashes and are consumed on use, so we can never read them back.
- Verification tokens - short-lived sign-in and verification codes, along with a failed-attempt counter that burns a code after a handful of wrong guesses.
- Rate-limit counters - keyed to an IP address or email address, kept only for as long as the limit window lasts.
Sign-in and other sensitive forms are protected by Cloudflare Turnstile, a privacy-focused CAPTCHA alternative. Turnstile receives your IP address in order to score the request.
Account Settings
Your account settings are stored alongside your account and include your time zone , language , and your notification preferences (email and push channels, plus per-category opt-ins for system messages, comments, reviews, releases, mentions and moderation notices). You can also mute mention notifications for individual items you own, or for an entire content type.
Activity Timestamps
We record when you registered , when you last signed in , and when you were last seen . The last of these is refreshed by a lightweight heartbeat while you are actually using the site. It powers presence indicators and lets our staff identify dormant accounts; it is not shared with anyone if you have disabled activity visibility.
Anything you publish is stored with your account as the owner, and is public unless you mark it hidden. This includes mods, assets, game servers, communities, collections, articles, releases, media, comments, reviews, ratings, questions and answers, groups, and the tags and categories you assign to them.
Published content keeps an author attribution and creation and edit timestamps . Editing history is not exposed publicly, but the fact that an item was edited, and when, is.
Engagement
We store the following interaction data:
- Favorites and filters (hidden items) - stored against your account when signed in, or in the tmc_settings cookie when you are not. Neither list is publicly visible.
- Views - a single row per item per visitor, keyed to your account when signed in or the anonymous sid cookie when you are not. This is what produces view counts; it is a count, not a browsing history.
- Downloads - recorded the same way, once per file per visitor, to produce download counts.
- Ratings and reviews - your like or dislike and any written review, both publicly attributed to you.
- Notifications - the notifications delivered to you, their read state, and the link they point at.
Aggregate statistics (view, download and favorite totals over time) are stored as periodic snapshots per item , not per user, and are retained for up to three years .
Uploads
Files you upload — images, archives, plugins and scripts — are stored with an object storage provider ( S3-compatible ). We record the file's owner , type , size , storage key , any title and description you supply, and its upload and edit timestamps . We do not read or index the contents of your archives beyond what is needed to serve and moderate them.
Please be aware that files you upload may contain personal data you did not intend to share — image EXIF metadata, paths containing your name, or configuration files containing credentials. We do not strip this for you. Review what you upload.
API Keys
If you create an API key , we store its name, a short public prefix , and a SHA-256 hash of the secret. The plaintext key is shown to you once at creation and is never recoverable afterwards. We also store the key's scope, permissions, expiry, revocation state, optional IP allowlist and rate limit.
Requests made with an API key are logged. Those logs contain the request method , path , response status , the item involved, and the IP address the request came from. This is a security and abuse-prevention measure, and the logs are visible to you for your own keys and to our staff.
Moderation Records
When you report content, we store the report, its contents, and who filed it. Reports are visible to our moderation staff, not to the reported party's audience.
When a penalty (a restriction or ban) is applied to an account or an item, we store its type, reason, expiry, the staff member who issued it, and any appeal conversation between the affected member and staff. Moderation records are retained even after the penalty expires so that repeat behaviour can be assessed fairly.
Our server browser is a core service in our organization. Users are able to explore and discover game servers across various games and applications.
Our primary server browser is located here (moddingcommunity.com/servers). There are also application-specific server browsers at moddingcommunity.com/<app url>/servers (these pages are also listed on our Games & Apps page here).
Settings Storage
We store and rely on site cookies for persistent settings across our browsers. The cookie name and key we use is tmc_settings , and settings are stored in JSON format. Preferences are kept per content type (apps, assets, mods, servers, server maps, communities, collections, groups, articles, categories and users), and cover:
- Layout - grid or table view, pagination style, and how many results to show per page.
- Sorting - the current sort column and direction.
- Filters - the apps, categories and tags you are filtering by, plus your favorited and filtered item IDs when you are not signed in .
- Content toggles - whether to show NSFW items and whether to show archived items.
- Appearance - whether background images are enabled.
The server browser stores a few additional options of its own, including showing only online servers, minimum and maximum user and slot counts, hiding full or empty servers, showing password-protected or insecure servers, showing only official servers, filtering by country, auto-refreshing the list, color-coding user counts, and whether to show ping.
Favorites & Filters
All users can favorite and filter (hide) servers in our server browser. The storage method depends on whether the user is signed in or not:
- Users who are not signed in use cookie storage as described above.
- Users who are signed in use our database (we map user IDs to server IDs in a database table).
Favorite and filtered server lists are not publicly visible to other users.
Show Ping Feature & Geo Location
If you enable the Show Ping setting, you will most likely need to give access to our website to access your location . This is just your geo location and we do not store any of this information.
Claiming a Server
If you claim a game server, we generate a short-lived claim token that you place on the live server (for example, in its name or description) so our query system can verify you control it. The token is valid for 15 minutes and is stored with your account and the server it targets.
Tracked Servers
We track and display servers in our server browser. We currently track servers in the following games (this list will expand over time):
- Counter-Strike 2 (Valve)
- Rust (FacePunch)
- Project Zomboid (The Indie Stone)
- Garry's Mod (FacePunch)
- Arma 3 (Bohemia Interactive)
- 7 Days to Die
- Left 4 Dead 2 (Valve)
- Team Fortress 2 (Valve)
- Unturned
- Counter-Strike: Source (Valve)
- Killing Floor (Tripwire Interactive)
- Killing Floor 2 (Tripwire Interactive)
- No More Room In Hell
- Left 4 Dead (Valve)
- Counter-Strike (Valve)
- Half-Life 2: DeathMatch (Valve)
- Sven: Co-op
- Insurgency
- Fistful of Frags
- Synergy
- Hell Let Loose
- Day of Defeat: Source (Valve)
- Red Orchestra 2
- Zombie Panic! Source
- Pirates, Vikings, & Knights II
- Half-Life DeathMatch: Source
We track , store , and display the following information from each server:
- Name
- IP address and hostname
- Port number (game and query)
- Online status
- User counts (current, max, and bots)
- Map name and game mode
- Game version, operating system, and whether the server is passworded, secure or dedicated
- Approximate geographic location (country, and latitude/longitude of the hosting region)
- Publicly exposed server variables and rules
Additionally, we also track , store , and display user information from servers. This includes:
- Name (usually Steam display name)
- Steam ID, when the server exposes it
- Score (current session and cumulative)
- Play time (current session and cumulative)
- Current index on server, online status, and session start and end times
This information is broadcast publicly by the game server itself over the game's standard query protocol. It is the same data any player sees in their in-game server browser. We do not join servers, read chat, or collect anything a server does not already publish.
We also automatically add servers to our server browser without permission from server owners. This is because these servers are already listed in public server browsers . We retrieve them from the Valve Master Server . Users can also manually add servers by IP and port.
If you are a server owner and would like your server removed , or an in-game player who would like your name and statistics removed , please reach out to us and we will take care of it.
Our forum is located at forum.moddingcommunity.com. We use Discourse as our forum software. Users can sign up using an email and password , or use alternative sign-in methods such as Discord or Steam. Email and password storage is handled securely by Discourse, and we keep the forum software up-to-date .
The forum keeps its own account system separate from the main website. Deleting one does not delete the other.
We rely on a small number of third parties to operate our services. Each receives only what it needs to do its job:
- Cloudflare - network protection, and Turnstile for CAPTCHA.
- S3-compatible object storage - hosting of uploaded files and images.
- SMTP email delivery - transactional email only (sign-in codes and the notifications you opted into). We do not run marketing mailing lists.
- Umami and Plausible - anonymous analytics.
- Discord, Google, GitHub and Steam - authentication, if you choose to use them.
- Discourse - our forum software.
We do not sell your personal data, and we do not share it with advertisers or data brokers. We will only disclose data to others where it is legally required of us, or where it is necessary to protect our services and our members from abuse.
We keep data for as long as it serves the purpose it was collected for:
- Account data - until you delete your account.
- Sign-in and verification codes - minutes. They are destroyed as soon as they are used or expire.
- Sessions - until they expire or you sign out.
- API request logs - retained for security auditing and abuse prevention.
- Item statistics - up to three years , then automatically deleted.
- Moderation records - retained after expiry so that repeat behaviour can be assessed fairly.
- Server and in-game player data - retained while we track the server, and on request for removal.
You are in control of your data. Specifically, you may:
- Access and correct your information at any time from your account pages.
- Delete your account yourself from the Security tab of your account. This is permanent and irreversible . It removes your profile, settings, sessions, connected providers, API keys, uploads, favorites, filters, notifications and the content you published.
- Control your visibility using the public listing, profile and activity toggles described above.
- Opt out of notifications per channel and per category, or mute mentions on individual items.
- Unlink providers you no longer want connected to your account.
- Clear cookies at any time through your browser. Doing so resets your preferences but does not affect your account.
If you need a copy of your data , want something corrected that you cannot change yourself, or want your data removed without deleting your whole account, contact us and we will help.
We take reasonable technical measures to protect your data. Passwords are never stored, recovery codes and API keys are stored only as hashes, sensitive cookies are httpOnly and marked secure in production, and authentication endpoints are rate limited and CAPTCHA protected. Two-factor authentication is available to every account and we strongly recommend enabling it.
That said, no online service can promise perfect security . If we ever become aware of a breach affecting your personal data, we will notify affected members promptly and describe what happened.
Our services are not directed at children under 13 , and we do not knowingly collect personal data from them. If you believe a child has created an account with us, please contact us and we will remove it.
We operate from, and store data on, servers that may be located in a different country than your own. By using our services you understand that your data may be processed outside your country of residence.
Questions about this policy, requests for your data, or requests to remove a server or an in-game name can be sent to [email protected], or raised through our Discord or our forum. We are a small team and we read everything.
This Privacy Policy may be updated from time to time. When we make a material change we will update the date at the top of this page. Continued use of our services means you accept the latest version.