1What this notice covers
This explains how Volantis handles your personal information. We follow the Australian Privacy Principles, and we do not sell your data.
This notice applies to the Volantis website, the control panel and the hosting behind them. It covers personal information: anything that identifies you, or could reasonably identify you.
The entity responsible for that information is Volantis Servers (ABN 12 250 269 968), of Suite 1208/530 Little Collins Street, Melbourne VIC 3000, Australia. Section 17 has the ways to reach us.
We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). If you are covered by the GDPR or UK GDPR, we also honour the rights those laws give you, as set out in section 10.
We do not sell your personal information, and we do not share it with advertisers.
2What we collect
Your account details, how your server is performing, what you send us in support tickets, and the technical logs needed to keep the platform running.
2.1Account information
Your email address, a hashed version of your password, your display name and your plan. If you sign in with Google, we receive your email address, name and profile picture from Google, but never your Google password.
2.2Billing information
Your subscription, invoices, payment history and any credit on your account. Card payments are handled entirely by Stripe. We never see or store your full card number. We only receive the card brand, last four digits and expiry, so you can recognise your own payment method.
2.3Server and usage information
Which servers you run, their configuration and version, resource usage such as CPU, RAM, disk and player counts, and the events that happen to them: starts, stops, crashes, backups and restores. We use this to run the platform, show you the stats in your panel, and work out what went wrong when something breaks.
2.4Support conversations
The tickets and messages you send us, plus any screenshots, logs or files you attach. See section 6 for how our AI assistant fits into this.
2.5Technical information
Your IP address, browser and device type, and timestamped records of security-relevant actions such as logins, password changes and panel activity. We keep these to protect your account and the platform from abuse.
2.6Information about your players
Your Minecraft server naturally records things about the people who play on it: usernames, UUIDs, IP addresses and chat. That data is created by your server, it lives in your files, and you decide what happens to it. See section 4.
3Why we collect it
To run the service you asked for, keep it secure, bill you correctly, and meet our legal obligations. Nothing else.
- To provide the service. Creating and running your servers, showing you your panel, restoring backups and answering your tickets.
- To bill you. Taking payments, applying credit and discounts, issuing invoices and processing refunds.
- To keep things secure and stable. Detecting abuse, investigating incidents, preventing fraud and stopping attacks on our network. This is our legitimate interest in protecting the platform and our customers.
- To talk to you. Service notices, billing alerts, security warnings and replies to your tickets. These are part of the service, not marketing.
- To meet legal obligations. Keeping tax and financial records, and responding to lawful requests.
- With your consent. Anything optional, such as marketing emails if we ever offer them. You can withdraw consent at any time.
4Your worlds, files and players
Your world files are yours. We store and back them up so the service works, and we only look inside when you ask us to fix something. Images are automatically checked against a list of known illegal material, by fingerprint. Nobody reads your files.
For everything inside your server, including worlds, configuration, plugin data, logs and anything your players generate, you are in charge and we simply hold it for you. In privacy terms you are the controller, and we act on your instructions.
We access your files only when there is a real reason to: because you asked us to look at a problem, because we need to fix a fault or protect the platform, or because the law requires it. We do not browse your worlds, and we do not mine your data for any other purpose.
If you collect information about your players, such as chat logs or IP bans, you are responsible for handling it properly and for telling your players what you keep. If a player asks for their data to be deleted, that request is yours to action, not ours.
4.1Checking images against known illegal material
There is one narrow exception to the above, and it is worth being exact about, because it is not what "scanning your files" usually means.
Images stored on your server are checked against a list of known child sexual abuse material, maintained by Microsoft's PhotoDNA service and the child protection organisations that contribute to it. The same check applies to images you upload through the panel, such as a server icon or banner, and to images you send to our support team. No person and no AI looks at your files as part of this check. The check runs on the same machine your server already lives on. It works out a one-way fingerprint of the image, a short string of numbers that cannot be turned back into the picture, and only that fingerprint leaves the machine, together with the file's location on your server and which server it belongs to, so that a match can be acted on. The picture itself never leaves.
For an image that is not on the list, the comparison returns nothing at all: no description, no score, no detail. For one that is, it returns which child protection organisation's list it came from and how that organisation classified it. It never returns a copy, a description or a preview of your file.
For an image that is not on the list, we learn nothing about what it shows. We keep only the fingerprint and the fact that it was checked, so the same picture is never checked twice, and that record is not linked to you or your server.
It applies only to image files, meaning pictures. It does not read your configuration, your logs, your databases or your backups, and it never opens a world's map data, player data or statistics. Where an image sits inside your world folder or a plugin's folder, it is fingerprinted like any other image: some plugins let players upload pictures, and those are exactly the files this exists to check. Most images are never even fingerprinted: anything already checked anywhere on our platform is skipped, as is anything too small or too large for the check to work on.
We do this because the alternative is not knowing, and this is the one kind of content where we are not prepared to not know. If an image matches, a person reviews it immediately, we may suspend the server while we do, and we report it to the Australian Centre to Counter Child Exploitation. We do not delete the file, so that evidence is preserved for them.
6AI and automated decisions
An AI assistant helps answer tickets and diagnose crashes, and automated checks screen the public details of your server. The AI never reads your private files, and that boundary is deliberate. Almost everything the AI does is only a suggestion, and where a check does act on its own you can always ask a person to review it.
We use an AI assistant to give you fast first answers on support tickets, and to read crash logs and suggest fixes. To do that, the text of your ticket and the relevant parts of your server logs or configuration are sent to our AI provider, OpenRouter, for processing.
We also check the public details of your server against the acceptable use rules in our Terms. That means its name, message of the day, address and icon, and those details are sent to OpenRouter for the check. We do not send your world, your files, your console output or your players' chat.
- We send only what is needed to answer the question, diagnose the crash or run the check.
- We do not use your tickets, logs or server details to train public AI models.
- You can ask for a human at any point, and any ticket can be escalated to our staff.
- Please do not paste passwords, card numbers or other secrets into a ticket. If you do, tell us so we can remove them.
Where a decision is automated. Most of what the AI does is suggest. It drafts answers and proposes crash fixes, and a person decides whether to use them.
The check described above is the exception. It can reset one of your server's public details, or suspend a server, without a person looking at it first. Leaving serious content published while we wait for someone to be available is not an option. When that happens we tell you what was found and which rule it breached, your billing and support access stay open so you can reach us, and you can ask for a person to review it. The one exception is where telling you what was found would itself risk harm or prejudice an investigation, in which case we will say only that the server was suspended under our acceptable use rules.
Where a server is suspended by that check, we also stop your subscription so you are not charged again. That is done automatically for the same reason the suspension is: we should not keep taking payment for a server you cannot use. Nothing is torn down mid-period and no refund is decided automatically – refunds, and any decision to close an account for good, are always made by people.
The automated screening described here applies to the details we publish about your server, meaning its name, address, description and icon, and to images on your public server page. Pictures you send to our support team get the fingerprint check in section 4.1 only: no AI looks at them, because they are not published.
7Where your data lives
Your servers run on Australian hardware. A few of our providers are overseas, and we make sure your data stays protected when it goes there.
Your Minecraft servers, worlds and backups are hosted on hardware in Australia. That is the whole point of Volantis, and it is where your data stays.
Some of the providers in section 5 operate overseas, so limited personal information such as your email address, billing details or ticket text may be processed outside Australia, typically in the United States or the European Union. Before information goes overseas we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, including contractual protections with each provider, as required by APP 8.
8How we protect it
Encrypted connections, hashed passwords, separated servers, and staff access limited to what the job needs.
- In transit. Traffic to our website and panel is encrypted with HTTPS, and connections to our hosts run over encrypted tunnels.
- Passwords. Stored only as salted hashes. We cannot read them, and neither can our staff.
- Separation. Each customer's server runs in its own isolated container with its own storage.
- Access control. Staff access is limited to those who need it to do their job, and sensitive actions are logged.
- Two-factor authentication. Available on your account, and we strongly recommend turning it on.
No system is completely secure. Please use a strong, unique password, turn on two-factor authentication, and be careful about who you give panel or team access to.
9How long we keep it
While your account is open, plus a short tail afterwards. Billing records have to be kept for seven years by law.
- Account information: while your account is open, and for a short period afterwards in case you come back or a dispute arises.
- Server data: until you delete the server. Deleting a server removes its world, files and backups, and cannot be undone.
- Backups: for the retention period on your plan, then rotated out automatically.
- Support tickets: generally up to two years, so we have context if a problem comes back.
- Security and access logs: generally up to twelve months.
- Billing records: seven years, because Australian tax law requires it. This applies even after you close your account.
Trial servers follow the timeline in our Terms: suspended at 24 hours, and permanently deleted at 72 hours if you have not moved to a paid plan.
10Your privacy rights
You can see your data, correct it, download it or ask us to delete it. Open a ticket and we will action it within 30 days.
10.1What you can ask for
- Access. A copy of the personal information we hold about you.
- Correction. Fixing anything inaccurate or out of date. Most of it you can edit yourself in the panel.
- Deletion. Closing your account and deleting your data, subject to records we must keep by law.
- A copy to take elsewhere. Your worlds and files can be downloaded from the panel at any time.
- To object or restrict. Ask us to stop or limit a particular use, where the law gives you that right.
- To withdraw consent. Where we relied on your consent, you can take it back.
10.2How to ask
Open a ticket from the help centre while signed in to your account. We may need to verify who you are first, which protects you from someone else asking for your data. We respond within 30 days, and there is no charge for a reasonable request.
10.3When we may say no
Occasionally we cannot action a request in full, for example where it would reveal someone else's personal information, or where we are legally required to keep the records. If that happens we will tell you why, and what you can do about it.
11Cookies
Only the cookies needed to keep you logged in and the site working. No advertising, no cross-site tracking.
We use a small number of essential cookies:
- Session cookie. Keeps you logged in as you move around the panel. It expires when your session ends.
- Referral cookie. If you arrive through a referral link, this remembers who referred you so their credit is applied correctly.
- Early-access cookie. While the site is in private early access, this remembers that your browser is allowed in.
We do not use advertising cookies, cross-site trackers or third-party analytics profiles. Blocking essential cookies in your browser will stop you staying logged in.
12Children
You need to be 13 or older to have an account, and 13 to 17 year olds need a parent's permission.
Accounts are for people aged 13 and over. If you are between 13 and 17, you need permission from a parent or guardian, as set out in our Terms & Conditions.
We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has given us their information, contact us and we will delete it.
13If something goes wrong
If there is a data breach that could seriously harm you, we will tell you and the regulator, as the law requires.
If a data breach occurs and it is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner, as required by the Notifiable Data Breaches scheme. We will tell you what happened, what information was involved and what you should do about it, as quickly as we reasonably can.
If you spot a security problem, please report it through the help centre and give us a chance to fix it before telling anyone else.
14Business and school customers
If you need a formal data processing agreement, ask us and we will sort one out.
If you run servers for a business, school or club and you need a written data processing agreement, contact us and we will provide one. It covers the subject matter and duration of processing, the nature and purpose, the types of data involved, our sub-processors, the security measures we apply, and how we notify you of incidents.
Where the GDPR applies, we act as processor for the content on your servers and handle it under your instructions.
15Changes to this notice
We will update the date at the top for small changes, and tell you before anything significant.
We may update this notice as the service changes or the law requires. For minor changes we will update this page and the effective date at the top. If we make a change that significantly affects how we handle your personal information, we will tell you by email or in the panel before it takes effect.
16Complaints
Tell us first and we will investigate properly. If you are still unhappy, you can take it to the OAIC.
If you think we have mishandled your personal information, contact us first. We will acknowledge your complaint, look into it properly and come back to you with an outcome, normally within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001.
17Contact us
Real people, based in Australia. A support ticket is the fastest way to reach us.
For anything about your privacy, your data or this notice:
- Support tickets: volantis.com.au/help, the fastest way to reach us and the best place to start.
- Privacy requests: open a ticket and put "Privacy" in the subject so it is routed to the right person.
- By post: write to us at the address below.
Suite 1208/530 Little Collins Street
Melbourne VIC 3000
Australia