Privacy

What TunnelVision sends, where it goes, how long it stays

To do its job, the plugin installed on your server sends part of your CoreProtect history to the hosted TunnelVision API, which analyses it and returns a list of sessions to check. This page describes precisely what leaves, what never does, where it is kept, for how long, and who can access it.

In short

The block break/place history (CoreProtect) of your server only — never chat, inventories or player IP addresses. Stored in an isolated space specific to your server, never shared between servers, automatically purged past 90 days. Nothing automatic follows from it: a human moderator always decides.

i

This is an English translation provided for convenience. TunnelVision is operated from France and the French version is the reference text; the GDPR rights described below apply identically.

1Who is responsible for this data

TunnelVision (contact: contact@tunnelvision.fr) is the data controller for the access request form and the site statistics.

For the data sent by the plugin (CoreProtect history, see below): the owner of your Minecraft server remains the data controller towards their players — they install the plugin and decide on that collection, as part of moderating their own server. TunnelVision acts as a technical processor for hosting and analysing that data, within the limits described on this page.

2What the plugin sends

The plugin reads the CoreProtect log your server already keeps (the co_block table) and transmits an incremental copy of it to the API, in batches, over an encrypted connection (HTTPS) authenticated with a token specific to your server.

FieldContent
PlayerUsername and Minecraft identifier (UUID) — needed to know which session belongs to whom.
PositionX/Y/Z coordinates and world of the block concerned.
BlockBlock type (ore, stone, etc.) and action (broken or placed).
TimestampDate and time of the action.

Nothing else: exactly the subset of CoreProtect columns needed to rebuild mining paths — no CoreProtect BLOB (block metadata, raw data) is ever transmitted.

Sent

  • History of blocks broken and placed
  • Username + UUID of the player concerned
  • Coordinates, world, timestamp

Never sent

  • Chat, private messages, commands
  • Inventory, items, game statistics
  • Player IP addresses
  • Any activity other than mining blocks

3Access request form

The access request form collects your username, an email address, your server's name and size, and an optional message. An automatic acknowledgement is sent when you submit, then an email reply once your request is handled. Legal basis: steps taken at your request before providing access (GDPR article 6.1.b). Used only to process your request and give you access if it is accepted — never shared, never sold. Kept until you ask for its deletion (contact@tunnelvision.fr); the submitting IP address is never recorded (only a hash of it is used to limit abusive submissions, see the service source code).

4Where it is hosted

The API runs on the central infrastructure operated by TunnelVision. Each client server has its own isolated space (dedicated database and volume): no data is ever mixed or readable across two different servers, including through the API itself — each access token only opens its own server's space.

5How long it is kept

90 rolling days by default: older history is purged automatically, with nothing to do on your side. A report you choose to share through a link (the optional "online hosting" feature) expires and is deleted after the duration you picked, or immediately if you revoke it.

6Who can access it

Your server's moderators, through the in-game menu (/tunnelvision menu, permission tunnelvision.admin) — that is the only intended use of this data.

The TunnelVision team, which operates the infrastructure, has technical access to the machines and volumes (as any host does), used only for maintenance and support — never to read, exploit or share the content of your data. Even the platform's internal audit log (which traces administrative actions, for debugging) explicitly excludes player usernames and UUIDs from what it records.

i

The marketing site you are reading separately measures aggregate audience figures (country/region/hour of visit), with no cookie and no identifier — see the technical detail in the project source code. Legal basis: legitimate interest (site audience measurement, GDPR article 6.1.f), with the minimisation safeguards described above. These statistics have no connection to the Minecraft server data described above.

7Your rights

On the data TunnelVision processes directly (the access request form), you have the rights of access, rectification, erasure, restriction and objection provided by the GDPR — exercised at contact@tunnelvision.fr. You may also lodge a complaint with the French data protection authority, the CNIL (cnil.fr), or with your own national authority.

On your Minecraft server's data (the CoreProtect history sent by the plugin), those rights are exercised first with your server's owner (see "Who is responsible" above) — they set up the collection and can ask TunnelVision, as their processor, for deletion or export.

The site statistics (previous section) are aggregated at collection time: once reduced to a country/region/hour counter, they no longer relate to an identifiable person, so those rights do not apply to them individually.

8What never happens

A question?

This page will evolve with the project (particularly when a paid offer arrives) — the principles above will not change silently. For any question about this data, or to request its deletion: contact@tunnelvision.fr.