Your data.
Your choices.
Privacy notice · Updated 2 October 2026
1. Information we process
- Account and consent: public GitHub username, numeric account ID, accepted Terms version and acceptance time. GitHub supplies identity during sign-in. We discard its access token after checking identity and do not request private-repository or repository-write access.
- Directory activity: submitted and edited descriptions, categories, stages, GitHub links, optional server addresses, community picks, creation/update times, and moderation decisions and notes.
- Authentication: session and CSRF token hashes, session expiry, and short-lived OAuth state/verification information. Cookies hold the corresponding browser values.
- Communications: the contact details, account identifiers, report evidence, and correspondence you choose to send for support, appeals, rights complaints, security reports, or privacy requests. Email is handled outside the website's D1 directory database.
- Delivery and security: Cloudflare processes network and request information, such as IP addresses, headers, and logs, to host and secure the service. GitHub processes sign-in requests. These providers have their own policies.
Do not send passwords, access tokens, game files, unlawful material, or unnecessary sensitive information. ModPorts has no game-upload feature and does not receive game traffic.
2. Why we use it
We use this information to authenticate accounts, record agreement, display approved listings, administer picks and moderation, respond to reports and requests, protect the service, investigate disputes, and comply with applicable legal obligations. We do not add advertising trackers, sell personal information, or use private reports as public promotional material. We do not claim that consent to the Terms is blanket consent to unrelated data processing.
Where data-protection law requires a lawful basis, the relevant purpose may involve providing the requested service, legitimate service/security interests, compliance with law, or consent where required. The precise obligations, lawful bases, and international-transfer safeguards depend on applicable law and need operator-specific legal review; this notice is not a certification of compliance.
3. Public and private information
Only moderator-published listings appear in the public catalog. Their metadata, repository URL, optional server address, and creator username are public and can be copied or indexed by others. Public pick activity identifies the project, not the person making a pick. Unpublished submissions are available to their creator and authorized moderators. Account consent records, sessions, and reports are not part of the public catalog.
A public server address can reveal your hosting location or home IP. Never submit a private endpoint or an address you are not authorized to publish. Withdrawal removes a listing from the public catalog, not from independent copies, search-engine caches, or the linked GitHub repository.
4. Cookies and providers
Essential cookies keep you signed in and protect requests: rp_session expires after 30 days, rp_csrf after 30 days, and rp_oauth_state after 10 minutes. Signing out ends the current session. These are not advertising cookies. Blocking them can prevent account features from working; public browsing does not require a ModPorts account.
Cloudflare hosts the site, API, and D1 database and routes support email. GitHub handles identity authentication and public repository metadata checks. Email delivery and replies involve the operator's mailbox provider and may involve your provider. See Cloudflare's privacy policy and GitHub's privacy statement. Data may be processed internationally; we do not promise local-only storage or a transfer mechanism that has not been verified.
5. Sharing and legal requests
Providers process relevant information to deliver the service. Authorized moderators and the operator can access information needed for their duties. We may share relevant report details with an affected creator so they can respond, or limited records with advisers or authorities when necessary and legally permitted. We do not promise absolute anonymity for reports, automatic identity disclosure on demand, or disclosure of entire accounts to a complainant. Send only necessary information and tell us if particular contact details should not be passed to the creator.
6. Retention and removal
Account and project records are retained while needed to operate the account and directory. Withdrawal hides a listing immediately but does not erase stored metadata or moderation history. Expired sessions and incomplete OAuth attempts are periodically purged. Reports, consent evidence, moderation history, and relevant backups may be retained as reasonably needed for security, disputes, compliance, and legal obligations.
We do not currently publish fixed retention periods for every type of record or claim immediate erasure from provider backups. For a deletion request we will explain any relevant retention exception and verify ownership before acting. Deletion is a manual verified request, not an automatic dashboard button.
7. Your choices and rights
Use your dashboard to correct a listing or withdraw it. For access, correction, deletion, or other applicable rights such as objection, restriction, or portability, email rights@rustports.com with your GitHub username and the requested action. We may ask for proportionate evidence of account control; never send passwords or authentication codes. The available rights, exceptions, and response deadlines depend on applicable law, which we must follow. You can complain to a competent data-protection authority where that right applies.
Requests remain available after you stop using the site and do not require acceptance of revised terms. No security measure guarantees perfect protection; report suspected unauthorized disclosure through our private security process.
8. Children and sensitive information
Account holders must meet the age and legal-consent requirements applicable to them. We do not provide age verification or permit age-restricted listings. If you believe a child has provided information without required authorization, contact us for review and appropriate action. Do not submit medical information, identity documents, children's information, or other sensitive data unless specifically necessary and requested through an appropriate private process.
9. Third-party connections
Opening GitHub, obtaining software elsewhere, or joining a creator-operated server is your choice. Those services can receive your network information and use their own cookies and privacy practices. ModPorts does not host games, connect to listed servers, or relay game traffic, and cannot control information collected by those services.
10. Changes and contact
We update this notice when the service's data practices change and show the date above. The operator's formal identity, required contact address, jurisdiction-specific duties, retention schedule, and provider-transfer arrangements remain legal-review items. Contact rights@rustports.com. Read the reporting process, hosting boundaries, and Terms of Service.