Overview
Tunnelcast is a game server integration platform. We collect only the data necessary to provide our service and do not use your information for advertising, tracking, or profiling.
Tunnelcast's core purpose is to relay live game-server events (including chat messages and player connect and disconnect data) out of your game server to other destinations. This means that words you type and connection data your game reports can leave the place they were created. The section below explains exactly where that data goes.
Where Your Data Goes
When a game server is linked to Tunnelcast, the chat messages and player events it produces are relayed in real time to one or more of the following destinations:
- Discord channels the server owner has linked: your messages appear in those channels and are visible to their members.
- A public web portal. Tunnelcast's portal is public, and relayed chat and events for a publicly visible server may be displayed to anyone on the internet, without an account. If you would not want a message to be seen publicly, do not send it through a linked server.
- Connected game clients: software connected to the relay (for example, in-game integrations) receives relayed events.
- Peer servers in a network. If a server belongs to a Tunnelcast "network", chat is bridged to the other servers and channels in that network and may be visible to their members, on the portal, and in their connected game clients.
In short: a message sent in one linked space may be visible in Discord, on the public portal, in connected game clients, and across networked peer servers. Player connection data (such as connect and disconnect events and country flags) is relayed in the same way.
We flag this relay where it happens. To keep the relay transparent, Tunnelcast posts a short disclosure notice in the linked Discord channel. Where Tunnelcast is able to set the channel topic (the Manage Channels permission), it keeps the notice in the channel's topic (description) and restores it if a server owner changes or removes it while the channel stays linked; where it cannot, it instead posts the notice as a message in the channel and re-posts it periodically. If Tunnelcast cannot deliver the notice through either surface, it does not relay messages from that channel. Maintenance runs through a background process that runs periodically rather than instantly. Players connected through a linked game client also see an always-on, non-removable in-client notice that their chat is relayed via Tunnelcast. These notices are informational, so that the people whose messages are relayed are told where those messages can go.
Browser Storage
We use browser storage only for functional purposes needed to sign you in, keep the Portal usable, and return you to the right page after login. No consent banner is required because these are essential for the service you requested.
| What | Purpose | Duration |
|---|---|---|
| Authentication token | Keeps you signed in across tabs and page reloads | Until you sign out or the token expires |
| Login return URL | Returns you to the page you requested after sign-in | Until the login callback completes or browser session data is cleared |
| Theme preference | Remembers your light/dark mode choice | Until you change it or clear browser data |
We do not use advertising pixels, cross-site analytics trackers, or any client-side storage for advertising or profiling.
For aggregate visitor statistics we use Cloudflare Web Analytics, a privacy-friendly, cookieless analytics service that does not use fingerprinting or track individuals across sites.
Player Data: GUIDs and IP Addresses
When players connect to a linked game server, Tunnelcast processes two pieces of player data: the player's game GUID (a unique identifier the game assigns to a player) and the player's IP address. We treat both as personal data and handle them carefully.
Lawful basis. We process this data under our legitimate interest in operating the relay, showing server owners who is connected, enabling moderation actions, and displaying country flags and aggregate statistics. You have the right to object to processing based on legitimate interest (see Your Rights below).
IP addresses are not stored in raw form. When we need to remember the country associated with a connection, the IP address is first hashed using HMAC-SHA256 with a secret key, and only that one-way hash (never the original IP) is stored. We cannot recover the original IP address from the hash. Hashed IP lookup records are kept for a maximum of 30 days and then automatically deleted (a time-to-live, or TTL, on the record). A live player's IP is also held briefly in server memory while they are connected and is cleared on disconnect.
The country lookup itself is performed entirely on our own infrastructure using a self-hosted, offline IP-to-country database. The IP address is not sent to any third-party lookup provider. Only country-level information is retained in our aggregate analytics; no IP, raw or hashed, is kept there. The lookup is not used for advertising or profiling.
Game GUIDs are used to identify a player within a session for live state and moderation actions such as kick and ban. GUIDs and IP-derived data are treated as moderation data: they are not shown in the public live view and are only sent to Portal clients that are allowed to manage the relevant server, and to Tunnelcast administrators (see Operator Access).
IP geolocation data is provided by DB-IP (IP-to-Country Lite database), used under the Creative Commons Attribution 4.0 License.
Data We Collect
When you create an account, register a game server, use live activity, contact us, or link a Discord server, we process the data needed to provide those features:
- Your account details, such as username and email address
- Game server configuration you provide, including server name, token, IP address, visibility, and relay settings
- Discord server IDs, channel IDs, and publication settings you configure
- Live server state, such as map, game type, match status, player names, teams, join times, and country codes
- Connection diagnostics for your game server's relay link, such as connect, disconnect, and reconnect times, downtime, the reason a connection dropped (as reported by your server), the integration (client) version, and the server's connecting IP address, used to monitor relay health
- Player moderation identifiers (game GUID and IP address), used for live moderation actions such as kick and ban and for country flags. IP addresses are hashed and never stored in raw form; see Player Data: GUIDs and IP Addresses
- Contact form details, such as name, email address, subject, message, IP address, and user agent
- Closed-beta sign-up details, such as email address, Discord username, the game you run, IP address, and user agent
Player IP addresses and game GUIDs are treated as moderation data. They are not shown in the public live view and are only sent to Portal clients that are allowed to manage the relevant server, and to Tunnelcast administrators (see Operator Access).
Chat messages are relayed in real time to the destinations described in Where Your Data Goes above: Discord, the public web portal, connected game clients, and peer servers in a network. Tunnelcast does not provide permanent chat history as a product feature, but message content may appear in operational logs while diagnosing issues, filtering abuse, or operating the relay.
Tunnelcast administrators can view live chat on any server, including servers set to staff-only, when this is needed to diagnose problems, support a server owner, investigate abuse, or keep the service running. We don't keep a chat history, and we don't share chat with anyone except as described in this policy.
Aggregate analytics may store counts such as chat-message totals, player connections, map plays, player country counts, and unique-player counts. Unique players are counted using pseudonymised (hashed) identifiers; the raw player names are not stored.
We do not sell, share, or transfer your personal data to third parties for their own purposes.
Operator Access
Tunnelcast is run by a small team. To operate and secure the service, Tunnelcast administrators have technical access to the data described in this policy, for every server, including servers set to staff-only. This includes:
- Live chat, match state, and player rosters, including player names, IP addresses, and game GUIDs
- Server settings and connection diagnostics, including game server IP addresses
- Account details, such as email addresses, and account activity
- Contact form and closed-beta sign-up submissions, including the IP address and browser details sent with them
- Audit logs, including sign-in records and their IP addresses
The Portal also lets administrators take the same actions as a server's own staff, such as kicking or banning a player or changing a server's settings. We don't use this to moderate or manage a server on its owner's behalf. We only use it when the server owner asks us to, or to stop abuse or a security problem.
We use this access only when it is needed to run and secure the service, to help a server owner who asks for support, to investigate abuse or a security problem, or to meet a legal obligation. We don't share this data with anyone except as described in this policy. Changes administrators make to user accounts and networks are recorded in our audit log.
Service Providers
We use a small number of service providers to run Tunnelcast. They receive only the data they need to provide their service to us:
- Our hosting provider runs the virtual server that hosts the Tunnelcast backend and database, so all data described in this policy is stored there
- Microsoft Azure hosts the Portal website and receives your IP address when you visit it
- Cloudflare provides our DNS and the cookieless web analytics described under Browser Storage
- Google Fonts serves the fonts the Portal uses, so your browser sends your IP address to Google when it loads them
- Resend delivers our emails (sign-up, password reset, invitations, and notifications) using Amazon Web Services, and receives your email address and the email's content
- Discord receives the chat and player activity relayed to linked Discord channels, as described in Where Your Data Goes. Discord handles that data under its own privacy policy
Some of these providers are based in the United States or may process data there. Where that happens, the transfer relies on the safeguards the provider offers under the GDPR, such as the EU-US Data Privacy Framework or standard contractual clauses.
Data Retention
We keep data only as long as it is needed for the purpose it was collected:
- Live activity snapshots and server diagnostics, including point-in-time player names and connect, disconnect, and reconnect events, are automatically deleted after 30 days.
- Hashed IP lookup data (used for country flags) is automatically deleted after 30 days, as described in Player Data: GUIDs and IP Addresses above.
- Audit logs (internal records of significant actions, kept for security, abuse-prevention, and legal-obligation purposes) are retained for 12 months. When you exercise your right to erasure, the identifiers within these logs are scrubbed (for example, replaced with a non-identifying placeholder) rather than the log entries themselves being deleted.
- Contact form submissions are retained for 12 months to handle your request and for support and abuse-prevention purposes, after which they are automatically deleted.
- Aggregate, non-identifying statistics, such as match, chat, kill, map, country, and unique-player counts (the latter derived from pseudonymised, hashed identifiers rather than stored names), are retained to power long-term historical charts for server owners.
- Account details and game server configuration are kept while your account is active and removed when you delete them or close your account (see Deleting Your Account below).
Your Rights (GDPR)
Under the General Data Protection Regulation, you have the right to:
- Access: request a copy of the data we hold about you
- Rectification: ask us to correct inaccurate data
- Erasure: delete your account and associated data (see Deleting Your Account)
- Portability: receive your data in a portable format (see Download Your Data)
- Object: object to processing based on legitimate interest
- Restriction of processing: ask us to limit how we process your data in certain circumstances
- Lodge a complaint with a supervisory authority: you may complain to your local data-protection authority
You can exercise erasure and portability directly from your account settings (see the sections below). For any other request, contact us using the details at the end of this policy.
Deleting Your Account
You can delete your account yourself at any time from your account settings ("Delete account"). When you do:
- Your account is immediately soft-deleted and enters a 30-day recoverable grace period. During this window you can recover the account; after it ends, your data is permanently purged.
- Relay access is revoked immediately: relay tokens are invalidated at once, so connected clients can no longer relay data under your account, even during the grace period.
- Data deleted as part of this process includes your game servers (and their linked Discord server and channel IDs), relay endpoints, Discord server ownership records, networks and network memberships, collaborators and invitations, and notifications.
- A small amount of data is retained in scrubbed or pseudonymised form. In particular, audit log entries are kept for 12 months (for security and legal-obligation reasons) with their identifiers scrubbed to a non-identifying placeholder, and submitter details in contact submissions are deleted or scrubbed.
If your account owns a network with other members, ownership is transferred to the longest-tenured active member; a network is deleted only if you were its sole member.
Note: removing Tunnelcast from a Discord server stops future collection from that server, but it does not by itself erase data we already hold. Erasure is handled by the account deletion flow described above.
Download Your Data
You can export the data associated with your account at any time using the "Download my data" option in your account settings. The export is provided as a JSON file in a structured, machine-readable format, with secrets such as tokens redacted. This lets you exercise your right to data portability without contacting us.
The export covers your account and the data you provided to us; short-lived operational and diagnostic records (which are auto-deleted within roughly 30 days) and ephemeral live server state are not included.
Who Is Responsible for Your Data
For the processing it carries out to operate the platform, Tunnelcast acts as a data controller (and, where it shares purposes with a server owner, a joint controller). We remain responsible for our own obligations (data minimisation, retention limits, security, and honouring your data-subject rights) regardless of any agreement with a server owner.
Server owners who link a Discord channel or server are responsible for informing their own Discord members and in-game players that their server uses Tunnelcast and that messages and connection data are relayed. We provide tools and notices to help, but the direct relationship with those communities (and the duty to tell them) sits with the server owner.
Who Is Responsible for Your Data
Tunnelcast is operated by its founder and acts as the data controller for the processing described here. A registered legal entity and its business address will be named here before public launch.
To reach us about your data or to exercise any of your rights, email us at privacy@tunnelcast.app or use our contact page.
Contact
For privacy-related questions or data requests, reach out via our contact page or join our Discord server.
