NeroLink · Privacy

NeroLink Privacy Policy

Last updated: 9 October 2026 · Applies to the NeroLink app and the NeroLink relay

NeroLink is a companion app for Minecraft servers that run the Neroland mod ecosystem and the NeroLink bridge mod. It is built to know as little about you as possible. This policy explains, in plain language, what is processed, where it goes, how long it is kept and how to get it deleted. It is written to meet both the Protection of Personal Information Act (POPIA, South Africa) and the General Data Protection Regulation (GDPR, EU).

Who is responsible

  • Neroland (South Africa) develops the app and operates the default NeroLink relay (nerorelay.neroserver.xyz). Contact and Information Officer: info@neroland.co.za.
  • The operator of each Minecraft server you pair with runs the NeroLink bridge on their own server and is responsible for the game data held there. Neroland does not operate your game server and cannot see its data, except as described under "The relay" below.

What stays on your phone

DataWhyProtection
Access token for each paired serverTo prove to the server that this phone is pairedAndroid Keystore / iOS Keychain; never logged
List of paired servers (name, address or relay Server ID, your Minecraft name and ID as that server knows it, the server certificate fingerprint for direct mode)So you can switch between serversPlatform secure storage
Cached copies of what your screens last showed (energy, quests, mods, …)So screens load quicklyEncrypted database (SQLCipher, 256-bit key held in the Keystore/Keychain)
Your choices for crash reports and usage statistics, and which servers you turned notifications on forTo respect those choicesPlatform secure storage

This data is excluded from cloud backups and device-to-device transfers. Removing a server (Settings → Unpair & wipe) deletes its token and cache; uninstalling the app deletes everything.

What the app sends, and to whom

  1. The Minecraft server you pair with. When you pair you send the device name you type and the pairing code (in direct mode, only a cryptographic proof of the code). Afterwards the app sends authenticated requests and receives only your own player's data; the API has no way to browse other players.

    • Direct mode connects to the server on your network over TLS, locked ("pinned") to that server's certificate, which you confirm at pairing by comparing a security code.
    • Relay mode connects through a NeroLink relay (see below).
  2. Modrinth (api.modrinth.com), only when you open the Ecosystem screen, to check for mod updates. Modrinth receives your IP address and the names of the Neroland mods on the server, and nothing about you or your world. Modrinth's own privacy policy applies: https://modrinth.com/legal/privacy.

  3. Google Firebase (Google LLC), which processes data for us as our service provider (processor) in our Firebase project "nerolandmc", for the four things below. Each Firebase service also uses a random installation ID that identifies the app install, not you.

    • App configuration (Remote Config) — every launch, the app may fetch a few on/off switches we use to pause a feature quickly if it misbehaves. Google receives your IP address, the installation ID, app version and device language. Always on; it sends nothing about you or your game.
    • Push notifications (Cloud Messaging) — only if you turn notifications on (relay mode only; direct mode has no push). After you pair with a server through the relay, the app asks once whether you want notifications from that server ("Get notified from ?"). If you say yes, Android asks for permission to show notifications, all of that server's notification types are turned on, and only then does the app create a push token, which is registered with the NeroLink relay for that server. Not now changes nothing. You can turn individual types on or off at any time in Settings → Notifications. Notifications say which part of the game changed (for example "energy"), never what you own or where you are. Turning the last notification type off, unpairing, or erasing your data removes the registration and deletes the token.
    • Crash reports (Crashlytics) — off until you turn on Send crash reports in Settings → Privacy. When the app crashes it then sends the error, the code location, app version, device model and operating system version, and free memory/disk. Server addresses, player IDs, tokens and e-mail addresses are removed from error messages before they leave the phone. Reports are kept for 90 days.
    • Usage statistics (Google Analytics for Firebase) — only for players aged 18 and over; you can switch it off at any time in Settings → Privacy → Share usage statistics. The first time you open the app, a one-time notice explains usage statistics, and nothing is collected until you have seen and answered it. In the EU/EEA, the UK and Switzerland — or if the app cannot tell your region — usage statistics are off unless you allow them: the notice offers No thanks and Allow, I'm 18 or older. Everywhere else they are on by default: the notice offers Turn off and OK, I'm 18 or older. The app works out your region on the phone from its language and region setting; the region is not sent anywhere or stored. NeroLink does not ask for or store your age: if you are under 18, please tap Turn off or No thanks, and turning the switch on later in Settings asks you to confirm that you are 18 or older. When on, the app records which screens are opened, by screen type only (for example /more/mods/:id, never which mod, item, server, player or game data), the app version, device model and operating system version, the device language, an analytics app-instance ID (a random ID for this install of the app), and an approximate country that Google derives from your IP address (NeroLink does not keep your IP address). No user ID or custom user properties are set, and nothing is linked to your Minecraft account. The app does not read the advertising ID (that permission is removed), advertising signals (ad storage, ad user data, ad personalisation) are always denied, Google signals and Analytics data sharing are off, and the statistics are never used for ads. They are kept for 2 months. Turning the switch off stops collection, deletes statistics not yet sent and resets the app-instance ID.

    Turning a switch off stops collection immediately and deletes anything not yet sent. Firebase may process data outside South Africa and the EU (mainly the United States) under Google's Firebase Data Processing and Security Terms and the EU Standard Contractual Clauses. Google's policy: https://policies.google.com/privacy; Firebase privacy information: https://firebase.google.com/support/privacy.

The app contains no advertising and no advertising identifiers and creates no accounts. It sends crash reports only if you turn them on, and usage statistics only after you have seen the first-launch notice, only while Share usage statistics is on, and — in the EU/EEA, the UK and Switzerland — only if you have allowed them. It does not collect your location, contacts, photos or messages.

The relay

The relay lets your phone reach a server without port forwarding. Your traffic is encrypted between your phone and the relay, and between the relay and the server; the relay decrypts it in memory only to pass it along (it is not end-to-end encrypted) and does not store the content of your requests, your access token or your game data. The relay runs on Cloudflare's global network, so this processing may take place outside South Africa or the EU; Cloudflare acts as our service provider under its data processing terms.

The relay stores only:

  • each registered server's name and a hashed server key — deleted when the server operator removes it, or automatically after 90 days without the server connecting;
  • if you turn on notifications: your phone's push token, per player and device — deleted after 60 days without renewal, when you turn the last notification type off, when the device is unpaired, or on erasure. To deliver a notification the relay passes that token, a short title and text, and the notification type to Google Firebase Cloud Messaging.

To enforce rate limits the relay derives a short-lived key from your IP address using a salted hash that changes every day; the IP address itself is not stored or passed to game servers. Per-request access logs are switched off.

What the game server stores

The NeroLink bridge on the server stores, keyed to your Minecraft account: a hashed copy of your access token, the device name you entered, when you paired and last connected, and your notification preferences. Devices unused for 90 days (by default; the server operator can change this) are deleted automatically, and every pairing expires after at most one year. Game data shown in the app is read live from the server's mods; the bridge keeps no copy of it.

Your rights and how to use them

  • Access — Settings → Privacy → Export my data shows everything the bridge holds about you.
  • Deletion — Settings → Delete my NeroLink data erases everything NeroLink holds about you on that server (and your relay push registrations), then unpairs the phone. To erase your data from every Neroland mod on a server, run /neroland data eraseme in-game.
  • Withdraw / object — turn off Share usage statistics (to object to usage statistics, or to withdraw your consent to them in the EU/EEA, the UK and Switzerland) or Send crash reports (to withdraw consent) in Settings → Privacy, or turn notifications off in Settings → Notifications. Unpair at any time; you can also remove devices in-game with /nerolink devices and /nerolink revoke.
  • Questions or complaints — email info@neroland.co.za. You may also complain to the Information Regulator (South Africa, https://inforegulator.org.za) or to the data protection authority in your EU country.

We rely on your request (pairing and using the app, turning on notifications) as the basis for processing; on your consent for crash reports (withdraw it any time with the same switch); on our legitimate interests in improving the app for usage statistics (POPIA section 11(1)(f); GDPR Article 6(1)(f)), which you can object to at any time by turning off Share usage statistics — except in the EU/EEA, the UK and Switzerland (or where the app cannot tell your region), where usage statistics are collected only with your consent (GDPR and UK GDPR Article 6(1)(a)), which you can withdraw at any time with the same switch; and on our legitimate interest in keeping the service secure and working (rate limiting, abuse prevention, the Remote Config on/off switches).

Children

NeroLink is intended for players aged 13 and over. It is not directed at children under 13, and we do not knowingly collect personal information from them. The app has no chat, no social features, no purchases and no ads; crash reports are off unless switched on; usage statistics (never linked to the player, never used for ads) are only for players aged 18 and over; and it only ever shows a player their own game data.

  • Under 13: please do not use NeroLink. If we learn that we hold personal information about a child under 13 (for example a push registration on the relay), we delete it. A parent or guardian can ask us to do this at any time by emailing info@neroland.co.za; the Minecraft server's operator can also remove the child's devices with /nerolink revoke.
  • Under 18: usage statistics are not for you — please tap Turn off or No thanks on the first-launch notice and leave Share usage statistics off (NeroLink does not ask for or store your age; turning the switch on asks you to confirm that you are 18 or older). You need a parent's or guardian's permission before you pair NeroLink or turn on crash reports. POPIA treats everyone under 18 as a child, and we process a child's information only on the basis of the consent of a parent or guardian (a "competent person"); in the EU the same applies below the age of digital consent in your country (between 13 and 16). A parent or guardian can switch off usage statistics and crash reports in Settings → Privacy at any time.
  • Parents and guardians can use every right listed under "Your rights and how to use them" on their child's behalf, including export and deletion, and can withdraw consent at any time by unpairing the app or emailing us.

Changes

If this policy changes, the "last updated" date above changes and the app's store listing links to the new version. Questions: info@neroland.co.za.

← Website privacy · About NeroLink

Search across every Nero mod wiki.