Privacy Policy
Effective 9 August 2026. Badger Studios LLC (“Badger Studios”, “we”, “us”). Contact: support@badgerstudios.net.
- Who this covers
- What we collect
- What we deliberately do not collect
- The AI assistant add-on
- Hosted dashboard links
- Error reports
- Why we process it, and our legal bases
- Who else touches your data
- How long we keep it
- Your rights, and how to exercise them
- Security
- Children
- International transfers
- Changes to this policy
- Contact us
1. Who this covers
This policy covers the BadgerOS website at badgerstudios.net, the BadgerOS control plane (the service your installation talks to for registration, licensing and updates), and the optional AI assistant add-on. It applies to you if you install BadgerOS, create an account with us, or buy a paid plan.
It does not cover the BadgerOS panel software itself once installed, because that runs on hardware you control and sends us nothing beyond what is described in section 2. If other people use your panel, you — not we — are the party handling their information.
2. What we collect
Everything we hold about you is listed here. There is no other category.
| What | When | Why |
|---|---|---|
| An installation identifier — a random ID, a public key your installer generates, and a hashed secret | When BadgerOS registers, on install | So your installation can prove it is itself when it asks for its licence or an update. We hold only the public half of the key and a hash of the secret; neither can be used to reach your machine. |
| A machine label and a panel name — for example a hostname and “Another Life” | On install | So you can tell your installations apart in a list, and so we can warn you when a new install looks like a duplicate of one you already have. |
| Your email address | If you supply it at install, create an account, or buy a plan | To link installations to you, to sign you in, and to contact you about your account. It is optional at install time. |
| A password hash, if you create an account | At signup | To sign you in. Stored as a PBKDF2 hash with a per-account salt. We cannot read your password and cannot recover it for you. |
| Plan and add-on status, and a Stripe customer identifier | When you buy or cancel | To grant and withdraw paid features, and to bill you. |
| Timestamps — when an installation was created, activated, and last checked in | Every few hours while running (currently every six) | So your installation learns that you have bought or cancelled something without needing a reinstall, and so we can tell a live installation from an abandoned one. It also reports how many servers the panel manages, which is the only thing the public install counter on our home page adds up. |
| A hosted-link slug and Cloudflare tunnel identifiers | Only if you enable a hosted dashboard link | To create and route yourname.badgerstudios.net to your machine. See section 5. |
| AI usage counts — model name, token counts and computed cost per request | Only on the metered AI plan | To bill you for what you used and to enforce your spending cap. Token counts only — never the text. See section 4. |
A session cookie named badgeros_account |
When you sign in to badgerstudios.net | To keep you signed in. It is strictly necessary, HttpOnly, SameSite=Lax, and set Secure over HTTPS. |
| Error reports | Only when you choose to send one | To fix bugs. Encrypted and redacted. See section 6. |
Our web server keeps ordinary request logs, which include IP addresses, for a short period for security and abuse handling.
Cookies and tracking
We use exactly one cookie, the sign-in session cookie above. We run no analytics, no advertising pixels, no third-party trackers and no cross-site profiling, so there is nothing to consent to and no cookie banner. Your installation's own dashboard sets its own session cookie on your own machine; that one never reaches us.
3. What we deliberately do not collect
The following never leave the machine you installed BadgerOS on, and we have no mechanism to request them:
- World files, region data, and anything else in your server directory
- Player names, UUIDs, inventories, statistics, playtime or chat
- Console output and server logs
- server.properties, plugin configuration, and any secrets in them
- Backups, and the files inside them
- Your panel's own usernames and passwords
- Your Minecraft server's IP address or port
- Any bank or financial data you connect to the finance dashboard
We do not sell personal information, and we do not share it for cross-context behavioural advertising, under any definition of those terms in any state privacy law. We never have.
4. The AI assistant add-on
This section matters more than the rest, because it is the only part of BadgerOS where the contents of your server can leave your machine. Read it before you turn the add-on on.
What the assistant can see
To be useful, the assistant reads files, runs commands and reads console output inside the one server directory it is attached to. Whatever it reads becomes part of the conversation sent to a large language model. If a file in that directory contains a password, an API key or a player's personal information, and the assistant reads that file, that content goes to the model provider. The assistant is confined to that single directory by the operating system, but within it, assume anything readable may be sent.
Bring your own key
If you supply your own Anthropic or OpenRouter key, or use a locally installed CLI tool, your conversations go directly from your machine to that provider. They do not pass through us, and we see nothing — not the text, not the token counts, not the fact that you used it. Your relationship is with that provider and their terms and privacy policy apply.
Metered AI billed by us
If instead you buy metered AI usage from us, your requests are sent to our control plane, which forwards them to Anthropic and returns the reply. In this mode:
- Your prompts and the model's replies pass through our server in transit. They are held in memory only for the moment it takes to forward them. We do not write them to disk, log them, or retain them.
- What we do record is a usage row containing your installation ID, the model name, token counts, a timestamp and a computed cost. No message content, no file contents, no prompts, no replies.
- Anthropic processes the content as our subprocessor, under their terms.
- A monthly spending cap applies and is enforced before any request is sent.
If you would rather no third party — including us — ever be in the path of your server's contents, use your own key, or do not enable the add-on.
5. Hosted dashboard links
A hosted link gives your panel an address like yourname.badgerstudios.net. It is optional.
Traffic to that address is routed through Cloudflare to a tunnel running on your own machine. Cloudflare terminates TLS at its edge, which means Cloudflare — not us — is technically able to see that traffic, in the same way it can for any site behind it. We hold only the slug you chose and the tunnel and DNS record identifiers needed to keep the route working. The panel itself continues to listen only on 127.0.0.1 and is never exposed directly to the internet.
Signing in through badgerstudios.net uses a short-lived signed assertion that your panel verifies locally. Your panel password is never sent to us and never transits our servers.
6. Error reports
BadgerOS keeps an error log on your own machine. Nothing in it is sent anywhere unless you explicitly choose to send a report. When you do:
- Secrets are removed before the entry is ever written to disk, not on the way out — API keys, bearer tokens, anything under a key named like a password or secret, email addresses, and absolute filesystem paths are replaced with placeholders at the moment the error is recorded.
- The report is then encrypted to a key whose private half is kept offline. Even if our control plane were fully compromised, the attacker could not read reports already sent.
- A report contains the error code, the redacted message and context, and the BadgerOS version.
7. Why we process it, and our legal bases
Where the UK or EU GDPR applies to you, our legal bases are: performance of a contract for account data, installation identity, plan status and billing; legitimate interests for security logging, abuse prevention and duplicate-install detection; and consent for optional error reports, which you can decline without losing any functionality. Where consent is the basis, you may withdraw it at any time.
8. Who else touches your data
| Who | What they get | When |
|---|---|---|
| Stripe | Your email, payment details and subscription record. We never see or store your card number — it goes directly to Stripe. | Only if you buy a paid plan |
| Cloudflare | DNS and tunnel routing; traffic to your hosted link passes through their edge | Website access always; tunnel traffic only if you enable a hosted link |
| Anthropic | The content of AI conversations, as our subprocessor | Only on the metered AI add-on. Not applicable if you bring your own key |
We do not otherwise disclose personal information, except where we are legally compelled to, or where it is necessary to investigate abuse or protect someone's safety. If we are ever acquired, information may transfer as part of that transaction, and this policy would continue to apply until replaced by one you are told about.
9. How long we keep it
- Installation and account records: until you ask us to delete them, or two years after an installation last checked in, whichever comes first.
- Sign-in sessions: until they expire or you sign out.
- AI usage rows: seven years, because they underpin invoices and are needed for tax records.
- Billing records: as long as tax and accounting law requires, typically seven years.
- Web server logs: a short rolling window, then discarded.
- Error reports: deleted once the bug is resolved, and in any event within twelve months.
10. Your rights, and how to exercise them
Depending on where you live, you may have the right to access a copy of what we hold, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent. If the UK or EU GDPR applies to you, you also have the right to complain to your data protection authority. If a US state privacy law applies to you, you have the right not to be discriminated against for exercising these rights — and since we neither sell personal information nor use it for targeted advertising, there is nothing for you to opt out of on that front.
Email support@badgerstudios.net and we will respond within 30 days. We will ask you to confirm control of the email address on the account, which is the only verification we can meaningfully do. Deleting your account removes your account record, installation records and hosted-link routing; billing records that we are legally required to retain will remain until that obligation expires.
Because almost everything BadgerOS touches is already on your own hardware, the most complete deletion available to you is one we cannot perform and do not need to: uninstall the panel and delete its state directory.
11. Security
Credentials we store are hashed, never held in a form we could read back. Traffic to our control plane is over HTTPS. Installations authenticate with a per-installation secret we hold only as a hash. Software updates are cryptographically signed and verified before installation, so a compromised download cannot become a compromised panel. Error reports are encrypted to an offline key.
No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and any regulator we are required to notify, without undue delay. If you believe you have found a vulnerability, please write to support@badgerstudios.net; we will not pursue anyone who reports a genuine issue in good faith and does not access or destroy other people's data.
12. Children
BadgerOS is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has given us information, write to us and we will delete it. Note that BadgerOS never receives your players' information, so a young player on your server is not someone we hold data about — you are the one handling that.
13. International transfers
We operate from the United States, and our processors may process data in the United States and elsewhere. Where we transfer personal information out of the UK or EEA, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) as the transfer mechanism.
15. Contact us
Badger Studios LLC
attn: David Roberts
117 S Lexington Street, STE 100
Harrisonville, MO 64701, USA
Telephone: (816) 710-3032
Email: support@badgerstudios.net
14. Changes to this policy
If we change this policy materially — particularly if we ever begin collecting a category of information not listed in section 2 — we will update the effective date and email account holders before the change takes effect. Continuing to use BadgerOS after that means you accept the updated policy.
See also our Terms of Service.