Legal
Privacy Policy
Last updated August 3, 2026
This Privacy Policy explains how HyHut (“we”, “us”) collects, uses, and shares information when you use our websites, APIs, hub integrations, and hosted Hytale servers (the “Service”). By using the Service, you acknowledge this Policy. For rules about using the Service, see our Terms of Use.
1. Information we collect
- Account data — email address, username, password hash (we do not store plaintext passwords), email verification status, and session metadata.
- Hytale link data — Hytale UUID and username when you complete account linking from the game hub.
- Server metadata — server name, description, icon choice, plan, status, player counts, resource settings, and ownership labels shown in the public directory.
- Operational data — console output you view/send, file paths you manage, lifecycle events, and technical logs needed to run agents and the proxy.
- Billing data — Stripe customer/subscription identifiers and plan history. Card numbers are handled by Stripe; HyHut does not store full payment card details.
- Technical data — IP address (for rate limiting and abuse prevention), user agent, and approximate timestamps of requests.
2. How we use information
- Provide accounts, authentication, and session security
- Create, host, start/stop, and route your Hytale servers
- Show public server listings you choose to expose online
- Process payments, cancellations, and plan changes via Stripe
- Send transactional email (verification, security notices)
- Prevent abuse, enforce quotas, and protect infrastructure
- Improve reliability and diagnose outages
3. Cookies and sessions
We use an HttpOnly session cookie (hyhut_session) to keep you signed in on the website. It stores a signed session token, not your password. We do not use this cookie for third-party advertising. You can end a session by logging out, which invalidates the server-side session version associated with that token.
4. Public information
When your server is online, limited public fields may appear in the server directory and profile pages — typically name, hostname, description, icon, owner display name, and player counts. Do not put secrets in server descriptions.
5. Sharing
We share information only as needed to operate the Service:
- Stripe — payment processing and customer portal
- Email delivery — if SMTP is configured, for verification and account notices
- Infrastructure providers — hosting, storage, and networking required to run servers
- Legal / safety — when required by law or to protect users and the platform from abuse or security threats
We do not sell your personal information.
6. Retention
We retain account and server records while your account is active and for a reasonable period afterward for backups, billing disputes, fraud prevention, and legal obligations. You may request account closure through support channels; some records may remain where we must keep them.
7. Security
We use industry-standard measures such as password hashing, signed sessions, transport encryption where configured, input sanitization for public text, and access controls between website users, the hub plugin, and agents. No method of transmission or storage is 100% secure.
8. Your choices
- Update email/password in account settings
- Verify or change email when prompted
- Edit or clear public server descriptions
- Stop or delete servers you own (subject to product controls)
- Cancel paid plans from the dashboard / Stripe portal
- Log out to clear the browser session cookie
Depending on your location, you may have rights to access, correct, or delete personal data, or to object to certain processing. Contact us to make a request. We may need to verify your identity first.
9. Children
The Service is not directed to children under 13 (or the minimum age in your country). If you believe we collected information from a child, contact us and we will take appropriate steps.
10. International users
The Service may be operated from the United States or other locations. If you access it from elsewhere, you understand information may be processed in countries with different data-protection laws.
11. Changes
We may update this Policy by posting a new version with a revised “Last updated” date. Material changes may also be announced by email or site notice.
12. Contact
Privacy questions can be sent through HyHut support channels listed on the website (including Discord in the footer).
This Policy describes current HyHut practices and is not legal advice. Consult counsel for jurisdiction-specific compliance (GDPR, CCPA, etc.).
Questions? Create an account or reach us on Discord linked in the footer.