Privacy Policy
Effective July 22, 2026
This Privacy Policy explains what [Legal Entity Name]("Basalt", "we", "us") collects when you use the Basalt website at basalt.host, purchase or activate a Basalt license, or run a self-hosted Basalt installation that talks to our license server. It does not cover data inside your own Basalt installation, which we never receive.
1. The short version
- Your game servers are yours. Worlds, server files, backups, console logs, user accounts, and everything else inside a self-hosted Basalt panel stay on your own hardware. We do not have access to them and do not collect them.
- Payments go through Polar. We use Polar as merchant of record for paid plans. Polar collects your billing details directly; we only receive limited order and subscription metadata.
- License checks are minimal. A Basalt installation periodically contacts our license server with your license key, an activation ID, an instance ID/name you choose, and (on the Pay as you go plan) aggregate counts of users, instances, and nodes, for entitlement and billing purposes only.
- Site analytics are cookieless. basalt.host uses privacy-preserving analytics with no tracking cookies.
2. Information we collect
2.1 Website (basalt.host)
When you browse the Site, we use Vercel Analytics to understand aggregate traffic (pages visited, referrers, approximate location from IP, device type). This is cookieless and does not build an individual profile of you across sites. Our hosting provider may also log standard web server data (IP address, user agent, request timestamps) for security and abuse prevention.
2.2 Purchases and billing
Checkout is hosted by Polar. Polar collects the information needed to process your payment: name, email, billing address, and payment method. We do not see or store your full card details. Through Polar's webhooks, we receive order and subscription events (for example, that an order was paid, or a customer's subscription state changed) so we can keep license entitlements in sync; this may include your email and a Polar-assigned customer ID.
2.3 License activation and validation
When you activate a license key from a Basalt installation, the installation sends the license server:
- The license key and a generated activation ID;
- An instance ID and optional instance name you choose (e.g. a hostname or label), used only to identify the activation in your Polar customer portal;
- On the Pay as you go plan, periodic aggregate counts of active users, instances, and nodes, used to meter usage-based billing and reported to Polar.
These requests do not include game server contents, player data, file contents, IP addresses of your game servers, or the identities of the individual users on your Basalt installation.
2.4 Self-hosted panel data
Everything you configure inside your own Basalt installation (owner and invited-user accounts, permissions, instance configuration, console output, files, and backups) is stored on infrastructure you control and is never transmitted to us. If your installation sends outbound email (for invites or password resets), that traffic goes through the email provider you configure, not through Basalt's infrastructure.
3. How we use information
We use the information described above to:
- Operate and secure the Site and license server;
- Issue, validate, and meter license keys and subscriptions;
- Respond to support requests and communicate about your account or purchase;
- Understand aggregate Site usage to improve documentation, pricing, and features;
- Detect, investigate, and prevent abuse or fraud.
We do not sell your personal information, and we do not use it for third-party advertising.
4. How we share information
We share information only with:
- Polar, to process payments and manage subscriptions and license keys, as your merchant of record;
- Infrastructure providers (such as our hosting and analytics providers) who process data on our behalf under their own confidentiality and data protection terms;
- Others, if required by law, to protect our rights, or with your consent.
5. Data retention
We retain license activation and usage metadata for as long as your license key is active and for a limited period afterward to handle support requests, disputes, and legal obligations. Billing records are retained by Polar under their own retention policy, including as required for tax and accounting purposes. Aggregate, de-identified analytics data may be retained indefinitely.
6. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal information we hold about you, or to object to or restrict certain processing. Because most billing data is held by Polar as merchant of record, requests about payment information are often best directed to Polar directly; for anything held by us, contact us at [privacy@basalt.host] and we will respond within a reasonable time.
7. International transfers
Our infrastructure and service providers may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for these transfers.
8. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
9. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, post a notice on the Site.
10. Contact
Questions about this Privacy Policy can be sent to [privacy@basalt.host] or via GitHub. See also our Terms of Service.