Privacy Policy
Last updated: March 23, 2026
MantaScope ("we", "us") operates mantascope.com, a game server browser and management platform. This policy explains what data we collect, why, and your rights.
1. Data Controller
MantaScope is the data controller. For privacy inquiries, contact us at [email protected] or via our contact form.
2. Data We Collect
2.1 Account Data (you provide)
| Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Email address | Account login, password resets, notifications | Contract | Account lifetime + 30 days |
| Username | Public display name | Contract | Account lifetime + 30 days |
| Password (hashed) | Authentication | Contract | Account lifetime |
| Steam ID (optional) | Link Steam account, server claiming | Contract | Until unlinked or account deleted |
| Bio, avatar, country | Profile personalization | Contract | Account lifetime |
2.2 Automatically Collected Data
| Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| IP address | Rate limiting, abuse prevention, GeoIP country detection | Legitimate interest | 90 days |
| Authentication cookie (httpOnly JWT) | Keeping you logged in | Strictly necessary | Session / 7 days |
| localStorage preferences | Theme, favorites, UI state | Strictly necessary | Until you clear browser data |
| Push notification endpoint | Sending server status notifications | Consent (browser prompt) | Until you unsubscribe |
2.3 Game Server Data (collected from public sources)
We query publicly accessible game servers using standard protocols (A2S, Quake3, etc.) to collect server names, IP addresses, maps, player counts, and player names. This data is publicly broadcast by game servers for the purpose of server discovery.
| Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Server IP, port, name, map, settings | Server browser listings | Legitimate interest | While server is active |
| Player names, scores, session times | Server browser, admin tools | Legitimate interest (Art. 6(1)(f)) | 1 year |
| Server population history | Charts and analytics | Legitimate interest | Raw: 7 days; aggregated: 90 days |
Player names are collected indirectly per GDPR Art. 14. We rely on the "disproportionate effort" exception (Art. 14(5)(b)) as we cannot individually notify every player whose name appears on a public game server. This privacy policy serves as our transparency measure.
2.4 Server Admin Data
| Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| RCON passwords (AES-256-GCM encrypted) | Server management | Contract | Until server claim removed |
| Ban records (SteamID, reason) | Server moderation | Legitimate interest | 1 year or until removed by admin |
| Player IP addresses (from RCON) | Admin-only, never public | Legitimate interest | 1 year |
2.5 User-Generated Content
Reviews, ratings, and guides you create are publicly visible. You retain ownership and can delete them at any time through your account settings.
3. How We Use Your Data
- Providing and operating the game server browser
- Authenticating your account and maintaining sessions
- Sending notifications you opted into
- Preventing abuse and enforcing rate limits
- Server administration tools (RCON, bans, player tracking)
- Displaying server statistics and population history
4. Data Sharing
We do not sell your data. We share data only in these cases:
- Cloudflare - CDN and DDoS protection. Cloudflare processes requests (including IP addresses) under the EU-US Data Privacy Framework. See Cloudflare Privacy Policy.
- Public display - usernames, reviews, guides, and game server data are publicly visible by design.
- Legal obligation - if required by law or valid legal process.
5. Data Transfers
Our infrastructure is hosted in the European Union. Cloudflare (US) processes traffic under the EU-US Data Privacy Framework. No other cross-border transfers occur.
6. Cookies & Storage
We use only strictly necessary cookies and browser storage:
| Name | Type | Purpose | Duration |
|---|---|---|---|
refresh_token | httpOnly cookie | Authentication | 7 days |
mantascope_user | localStorage | Session metadata | Session |
mantascope_theme | localStorage | Dark/light mode preference | Persistent |
mantascope_favorites | localStorage | Favorite servers (guest) | Persistent |
No third-party cookies, analytics, or tracking scripts are used. No cookie consent banner is required as all storage is strictly necessary for service operation.
7. Your Rights
Under GDPR, you have the right to:
- Access (Art. 15) - request a copy of your data
- Rectification (Art. 16) - correct inaccurate data
- Erasure (Art. 17) - delete your account and associated data
- Restriction (Art. 18) - pause processing during disputes
- Portability (Art. 20) - export your data in machine-readable format
- Objection (Art. 21) - object to legitimate interest processing
- Withdraw consent (Art. 7(3)) - for push notifications, via browser settings
- Lodge complaint - with a supervisory authority in your EU Member State
To exercise these rights, email [email protected] or use our contact form. You can delete your account at any time.
Player Data Opt-Out
If your player name appears on MantaScope from public game server data and you want it removed, contact us at [email protected]. We will remove your data free of charge.
8. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. A list of EU data protection authorities can be found on the EDPB website.
9. Children
MantaScope is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided data to us, contact us and we will delete it.
10. Changes
We may update this policy. Material changes will be announced on the site. Continued use after changes constitutes acceptance.