This policy explains what information Deadworks collects, why, who sees it, and what you can do about it. We have tried to keep it short and in plain language.
1. Who we are
Deadworks builds an open-source server framework for Deadlock, runs the public server browser at deadworks.net, and offers rented Deadlock servers through Deadworks Hosting. This policy covers all of those, the Deadworks launcher, and our community spaces.
The quickest way to reach us about privacy is our Discord. For formal requests, email [email protected].
2. What we collect, and why
We collect the minimum needed to run each part of Deadworks. Here it is, surface by surface.
Visiting the website
Our web servers keep standard request logs: your IP address, the page requested, the time, and your browser's user agent. We use these to keep the site running, spot abuse, and debug problems. We do not run advertising trackers or third-party analytics scripts.
The public server browser
Servers running the Deadworks framework register themselves with api.deadworks.net and send periodic heartbeats. That gives us each server's IP address and port, its name, map, player count, and version. This is information about servers, not about you as a player. The browser does not require an account and does not track who views it or who joins which server.
The launcher
The Deadworks launcher talks to api.deadworks.net only to fetch the server list and to open a server you choose to join.
Hosting accounts
Signing in to Deadworks Hosting uses WorkOS AuthKit. WorkOS handles the sign-in itself, either by emailing you a one-time code or through a sign-in provider you choose. We receive and store your email address, your name, and a WorkOS user identifier. We set one session cookie so you stay signed in. We keep an audit log of actions taken in the portal, such as creating, starting, stopping, or deleting a server, with the time and the account that did it.
Signing in with Google
If you sign in with Google, Google sends us your name, email address, and profile picture. That is all we request and all we use. We do not read your Google contacts, files, calendar, or anything else, and we never sell or share this information with advertisers.
Billing
Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers. We store your Stripe customer identifier, the state of each subscription, and the payment events Stripe sends us so we know which servers are paid for. Invoices and receipts are issued by Stripe. Stripe Tax needs your billing address to work out the correct tax, and Stripe holds that address.
Rented servers
For each server you rent we store the name you give it, its settings, its region and size, and the IP address and port allocated to it. To run the server we share its configuration with our infrastructure providers, who operate the machines it runs on. Console output and log lines are fetched when you view them and are retained by our infrastructure providers for a limited time. Files you upload or edit through the file manager are stored on the server itself; uploads pass through a staging area on our systems and are cleared once transferred.
Discord and GitHub
Our community lives on Discord and our code on GitHub. When you use those, their privacy policies apply, not this one.
5. How long we keep it
- Account details
- For as long as your hosting account exists. Deleted within 30 days of an account deletion request.
- Rented server data
- Server configuration, files, and logs are removed after a rental ends, following a short grace period of up to 14 days in case you change your mind.
- Audit logs
- 12 months, so we can investigate disputes and abuse.
- Web server logs
- Up to 90 days.
- Server browser data
- A server disappears from the browser when it stops sending heartbeats. Historical heartbeat data is kept only in aggregate form.
- Billing records
- Stripe keeps payment records for as long as their policies and tax law require. We keep our own record of subscriptions and payment events for as long as needed for accounting.
6. Security
All traffic to deadworks.net and the hosting portal is encrypted with TLS. Sign-in is delegated to WorkOS, so we never see or store passwords. Card details never reach our systems. Access to the rented server's console and files is limited to the account that rented it, and every management action is checked on our servers, not just in your browser. Our infrastructure providers' credentials are held only on our backend systems.
No system is perfectly secure. If we become aware of a breach that affects your information, we will tell you as quickly as we reasonably can.
7. Your rights
Wherever you are, you can ask us to:
- Access the information we hold about you.
- Correct anything that is wrong. Your name and email can be changed through your sign-in provider.
- Delete your account and the data attached to it. Active rentals must be cancelled first.
- Export your data in a machine-readable format.
- Object to or restrict how we use your data, where the law gives you that right.
We honour the rights granted by the GDPR and similar privacy laws wherever they apply to you. To make a request, message us on Discord or email us at the address above. We will respond within 30 days and may ask you to confirm you control the account first.
8. Children
Deadworks is not directed at children. You must be at least 13 years old to use our services, or at least 16 where local law sets that as the age of consent for online services. If you believe a child has created a hosting account, contact us and we will remove it.
9. International transfers
Our website and database run in the European Union. Rented servers run in whichever region you choose at checkout, which may be outside the EU, and their configuration is processed there. Our service providers may process data in other countries under their own safeguards. By using Deadworks you understand that your information may be transferred to and processed in countries other than your own.
10. Changes to this policy
We will update this page when our practices change and update the date at the top. If a change materially affects how we use your information, we will let hosting customers know by email or through the portal before it takes effect.
11. Contact
Questions, requests, or concerns: reach us on Discord or by email at the address in the first section of this policy.
