Craftia Privacy Policy
Effective date and last updated: August 26, 2026
Craftia is operated by JMS Corporation (제이엠에스코오포레이션), a sole proprietorship in the Republic of Korea operated by Jung Minsuk (“Craftia,” “we,” “us,” or “our”). This Privacy Policy explains how Craftia collects, uses, discloses, retains, and protects information when you use the Craftia application, its backend services, and Craftia content-sharing pages (together, the “Service”).
For privacy questions or requests, contact mcpecraftia20260715@gmail.com.
1. Information we process
The information processed depends on the features you use.
Account and profile information
When you sign in with Google, Google Sign-In and Firebase Authentication process your Google account credentials and authentication tokens. Craftia receives or maintains information such as:
- Firebase user ID (UID), sign-in provider, account email address, display name, and profile photo URL;
- the Craftia display name, normalized display name, profile description, selected profile image, title, role, account creation/update timestamps, and account or moderation status; and
- Firebase ID tokens used to authenticate requests. We do not receive or store your Google password.
Your email address is not displayed publicly. A creator UID may be included in public content records or responses as an internal creator identifier, even though Craftia does not present it as ordinary profile text. The other profile information described in Section 3 may also be visible to users.
Age group and consent choices
Craftia may ask for a self-declared age to assign the user to a child, teen, or adult group for advertising and consent settings. The exact age, age group, and verification time are stored locally on the device. For users in Russia, the exact age is sent with each ad request to Yandex for age-based ad targeting; the exact age is not sent to Google Mobile Ads. Craftia's minimum service age is 13. The Brazil storefront currently displays a ClassInd 14 content rating; this rating informs a parent or guardian's suitability decision and does not automatically create a 14+ service gate. Eligible teens as well as adults may submit content after pre-publication review. Craftia sends child-directed or under-age-of-consent signals, rather than the exact age, to Google Mobile Ads and UMP. Google may also process the consent choices made through UMP.
On supported Android devices, Craftia requests from Google Play the status indicating whether age information is shared or verified and, when Google Play shares it, a broad age range (by default, 0–12, 13–15, 16–17, or 18+). Craftia does not collect or store the Age Signals installId or an exact birth date. The Play Age Signals response and values derived from it—including the age range, sharing or verification status, and source—are held only in the app's runtime memory. They are used only on that device to enforce the minimum service age, determine UGC eligibility, and apply purchase protections, and are not transmitted to or stored by the Craftia backend, Firebase, advertising services, or analytics services. The transaction and UGC records described below do not contain values derived from Play Age Signals.
Uploaded content and files
When you submit or upload content, we process the files and information you choose to provide, including:
- source files such as maps, skins, add-ons, texture-related files, archives, or other supported content;
- selected preview images, thumbnails, filenames, file types, sizes, storage paths, and upload metadata;
- depending on the submission or publication workflow, title, description, category, game version, locale, price or access settings, and other content metadata;
- your UID, uploader profile snapshot, submission status, review/moderation information, and timestamps.
Craftia accesses only the files or images that you choose through the system picker or an upload flow. Uploaded files are stored using Cloud Storage for Firebase. Approved content, its preview images, and the public metadata described in Section 3 may be made public.
Minecraft server listings
When you submit a Minecraft Bedrock server listing, Craftia processes the server name, description, address and port, the country and content language you select, one to four images, your UID and uploader profile snapshot, submission and review status, and timestamps. Craftia also processes a short-lived ownership challenge, the result of a DNS and Bedrock RakNet reachability check, and a one-way evidence hash showing that the required challenge was observed in the server MOTD. The raw challenge is not retained with the published listing, and this technical check shows control at the time of verification rather than legal ownership of the server or domain.
Before publication, the server name, description, address, content language, and images are held in private Firebase review storage and sent through the OpenAI API in batch jobs for automated safety, abuse, spam, Minecraft-relevance, and image-consistency review. Craftia does not include your UID, email address, or display name in this OpenAI review input. Listings that pass review have their images resized and copied to Backblaze B2 for public delivery through Cloudflare. The approved listing and periodically refreshed public reachability and player-count status are then stored in Firebase and made visible to other users.
Activity, community, and entitlement information
We process activity needed to provide Service features, including:
- comments, including their text, related content ID, author UID and public profile snapshot, timestamps, and moderation status;
- likes, saves, libraries, downloads, or other user-provided community activity;
- content purchases, diamond balance and transactions, VIP status and expiration, daily rewards, rewarded-ad sessions and reward outcomes;
- search terms sent to Firestore to retrieve matching public content. Craftia does not intentionally save these as a user-linked search-history record; and
- content identifiers, timestamps, counters, and feature state needed to sync eligible items across devices or maintain official public counters.
Non-VIP users’ personal liked and downloaded-content lists are stored only on their device. Only users with an active VIP subscription have those personal lists synced to the cloud.
For signed-in users, Craftia processes a minimal server-only interaction marker consisting of the UID, content ID, like and download states, and related timestamps to prevent duplicate updates to official like and download counters and to support account deletion. This marker is not shown or used as a personal like or download list.
When you download content while signed out, the app generates a random installation ID on your device. To count no more than one download per installation for each item of content, the server stores only a one-way hash of that installation ID, the content ID, and a timestamp. This identifier is not used to sign you in or to create or maintain your personal downloaded-content list.
Purchase and subscription information
Purchases are processed by Google Play. Craftia and its Firebase backend process information needed to verify purchases and grant entitlements, including product ID, base-plan ID, order ID, purchase status and time, region code, subscription state and expiration, acknowledgment status, and an obfuscated account identifier. A purchase token is transmitted securely to our backend and the Google Play Developer API for verification; Craftia stores a cryptographic hash of that token rather than the raw token. Through the Google Orders API, the backend may process and retain the actual amount paid, currency, and purchaser country code when available. It also maintains a ledger distinguishing paid and free diamonds, the remaining balance of each paid-diamond lot, refund or chargeback adjustments, and an audit record of any shortfall that could not be recovered because the available balance was insufficient. We do not receive or store full card, bank-account, or other payment-instrument details.
Reports and support
If you report content, we process the reported content ID and metadata, reason, optional details, locale, time, your UID, and your Google account email address and display name so that we can review the report and prevent abuse. If you report a server listing, we process your UID, the server ID, an immutable snapshot of the approved server name, description, address and image URLs, the selected reason, time, and server-owned anti-abuse counters; the server-report flow does not accept free-form report text. If you report a comment, we process the comment ID and text, related content ID and title, reason, optional details, locale, time, your UID, the author's UID and available public display name, and server-owned anti-abuse counters. If you report or block a user, we process your UID, the target user's UID and available display name, the related content or comment ID, report reason, locale, timestamps, and server-owned anti-abuse counters as applicable; a block record is used to hide that user's content and comments from you. If you contact us by email, we process your email address, message, attachments, and the information needed to answer or verify your request.
Advertising, diagnostics, device, and network information
The Service and its providers may process:
- IP address and general location inferred from the IP address; Craftia does not collect precise GPS location;
- device model, operating system and version, app version, language/locale, network state, app or installation identifiers, advertising identifiers where permitted, and request timestamps;
- app launches, taps, ad impressions, ad video views, and other interactions used to deliver ads, measure performance, and prevent fraud;
- crash stack traces, exception messages, crash time, process/app state, device specifications, Crashlytics Installation UUID, Firebase installation ID, and related diagnostic data in release builds; and
- server request, security, and operational logs that may contain IP address, request metadata, identifiers, and error information.
Crashlytics collection is disabled in Craftia debug builds and enabled in release builds.
Firebase Analytics
Craftia uses Firebase Analytics to understand how the Service is used and improve it. Firebase Analytics may automatically process an app-instance or installation identifier; app launches, sessions, screen views, and other app interactions; app, device, operating-system, and language information; general location inferred from the IP address; and purchase or subscription information. When permitted by consent choices, device or app settings, and law, it may also process an advertising identifier.
Where Google UMP presents choices, its Consent Mode signals apply to Analytics storage and advertising-related Analytics uses. You can reopen Craftia’s Privacy choices when shown. Craftia does not set your Firebase Authentication UID as an Analytics user ID and does not intentionally send your email address, display name, exact age, Google Play Age Signals responses or derived values, uploaded content, or other custom personally identifiable information to Firebase Analytics.
Craftia also uses the google_fonts package. When a requested font is not already bundled with or cached by the app, the package may retrieve it from Google Fonts. That request discloses the IP address, requested font URL, and HTTP/device headers needed to deliver the font.
AppsFlyer deep links
Craftia uses AppsFlyer to resolve links that open shared Craftia content, including deferred links that continue after installation. The SDK may process IP address, device and app information, AppsFlyer-generated identifiers, link clicks, installation information, launches, and sessions needed for those links.
Craftia configures AppsFlyer to disable advertising-identifier collection and, on Android, App Set ID collection. We do not set a Craftia customer user ID, send custom in-app events or advertising revenue to AppsFlyer, or share AppsFlyer data with integrated advertising partners. These AppsFlyer restrictions do not disable identifiers that Google Mobile Ads may process for advertising as described above.
Country determination and regional advertising
At app startup and periodically thereafter, Craftia requests https://mcpecraftia.com/cdn-cgi/trace, a Cloudflare-managed endpoint, to determine the two-letter country code in the loc field. Cloudflare necessarily receives the request IP address and HTTP/device headers. Craftia reads only the country code needed for the regional age and advertising rules and does not store the returned IP address or use precise GPS location. The country code and last successful check time are cached locally on the device, normally refreshed within 24 hours, and removed when app data is cleared or the app is uninstalled. If a refresh temporarily fails, the app may use the last successfully cached country result.
If the country result is Russia (RU), Craftia requires the user to be at least 13 years old to enter and use the Service. Only after both RU and minimum-age eligibility are established does Craftia initialize or request ads from Yandex Mobile Ads. Users outside Russia remain subject to the generally applicable minimum age of 13, or a higher age required by local law, and Craftia continues to use Google Mobile Ads with the age and consent controls described in this Policy. The country result is a network-based estimate and may be inaccurate, including when a VPN, proxy, roaming connection, or carrier routing is used.
For Yandex rewarded ads, Craftia creates a short-lived backend reward session linked to the signed-in account and requested reward. After the Yandex SDK onRewarded reports its on-device reward callback, Craftia submits the claim to the backend, which records the outcome and applies duplicate and replay controls. This client callback is not independent or cryptographic server-to-server verification by Yandex that the ad was watched. Craftia does not send the session ID, UID, or balance to Yandex in this reward-session flow. The exact age is sent separately as part of the ad request as described in Section 4.
2. Why we process information
We use information to:
- authenticate users, maintain accounts and profiles, and provide requested Service features;
- store, review, publish, deliver, and share content;
- sync eligible items across devices, including active VIP users’ personal like and download lists, as well as saves, libraries, balances, purchases, rewards, and subscriptions;
- verify Google Play transactions, provide paid entitlements, prevent duplicate claims, and detect fraud or abuse;
- serve and measure ads, record consent choices, and verify rewarded-ad results;
- resolve direct and deferred content links;
- moderate content, investigate reports, enforce our terms, protect users, and comply with law;
- diagnose crashes, maintain security and reliability, answer support requests, and improve the Service.
Where applicable data-protection law requires a legal basis, we rely on:
- performance of a contract to provide the account and features you request;
- legitimate interests in security, fraud prevention, moderation, support, and Service improvement, balanced against your rights;
- consent for personalized advertising or other processing where consent is required; and
- legal obligations and the establishment, exercise, or defense of legal claims.
You may withdraw consent through the available privacy controls. Withdrawal does not affect processing already lawfully completed.
3. Information visible to other people
Depending on how you use Craftia, the following may be public:
- your Craftia display name, selected profile image, and title;
- a pseudonymous creator UID or similar internal creator identifier associated with published content;
- content you publish, including source/download files, previews, thumbnails, title, description, category, version, locale, price/access status, and uploader profile snapshot;
- approved server listings, including the server name, description, address and port, selected country and content language, images, uploader display information, and public reachability and player-count status;
- comments you post, including the comment text, related content, pseudonymous author UID, public display name and avatar, and timestamp;
- public counts such as likes or downloads; and
- information included in a content link that you choose to share.
Your email address, authentication tokens, raw or hashed purchase tokens, private balances, private libraries, and report details are not intentionally made public. Do not upload personal information that you do not want others to see.
4. Providers and recipients
We disclose information only as needed for the purposes described in this Policy:
- Google Sign-In, Google Play Services, and Firebase — authentication, Firestore database, Cloud Functions, Cloud Storage, Firebase Hosting, Analytics, and Crashlytics. These services process account identifiers, Service data, uploaded files, network information, usage and interaction data, app-instance or installation identifiers, and diagnostics as applicable. See the Google Privacy Policy and Firebase Privacy and Security information.
- Google Play Billing and Google Play Developer API — payment processing, purchase/subscription verification, entitlement delivery, and fraud prevention. See the Google Payments Privacy Notice and Google Privacy Policy.
- Google Mobile Ads (AdMob) and UMP — ads, consent management, measurement, and fraud prevention. Depending on consent, device settings, and applicable law, Google Mobile Ads automatically collects and shares IP address, general location derived from IP, product interactions, diagnostic data, and device/account identifiers for advertising, analytics, and fraud prevention. See Google’s AdMob privacy information and Google Privacy & Terms.
- Google Fonts — runtime delivery of fonts that are not bundled or cached. Google receives network request information such as IP address, the requested URL, and HTTP/device headers and states that Google Fonts data is not used for targeted advertising. See Google Fonts privacy and data collection information.
- AppsFlyer — direct and deferred deep-link operation, subject to the restrictions described above. See the AppsFlyer Services Privacy Policy and user-level data retention information.
- OpenAI — automated pre-publication review of server-listing names, descriptions, addresses, content languages, and one to four images through the OpenAI Moderation and Responses APIs using batch processing. Craftia does not include the uploader's UID, email address, or display name in this review input. See the OpenAI Privacy Policy and OpenAI API data-controls information.
- Backblaze B2 and Cloudflare — storage and delivery of public Craftia content, including approved server-listing images, through
cdn.mcpecraftia.com. When a file or image is requested, these providers may process the requested URL or object path, IP address, HTTP/device headers, cache and transfer information, and security logs. See the Backblaze Privacy Notice and Cloudflare Privacy Policy. - Email service providers, including Google/Gmail — delivery and retention of support, privacy, and deletion-request emails and attachments that you choose to send. See the Google Privacy Policy, or the policy of the email provider you use.
We may also disclose information when required by law, to respond to a lawful government request, to investigate fraud or security incidents, to protect rights or safety, or as part of a business transfer subject to appropriate safeguards.
We do not sell personal information for money. Advertising data may nevertheless be considered “sharing” or “targeted advertising” under some laws; use the privacy choices described in Section 7 where available.
Yandex Mobile Ads — advertising, ad delivery, measurement, and fraud prevention for users determined to be in Russia who are at least 13 years old. Depending on device permissions, settings, consent, and applicable law, the Yandex Mobile Ads SDK may transmit device or advertising identifiers and ad interaction information directly to Yandex. Craftia sends the exact self-declared age with every ad request through Yandex AdTargeting so Yandex can select ads based on age. The Cloudflare country result is not sent to Yandex. Craftia prevents Yandex SDK initialization and ad requests unless the regional and minimum-age conditions are satisfied. See the Yandex Privacy Policy and Yandex Mobile Ads data-safety information.
5. Retention and deletion
We keep account, profile, activity, entitlement, report, and upload data while your account is active and for as long as needed to provide the relevant feature, resolve disputes, maintain security, prevent fraud, or meet legal obligations.
Files from rejected submissions that were never published are deleted within 30 days unless longer retention is necessary for child safety, fraud prevention, legal compliance, or a dispute. Published content remains available after account deletion with the creator attribution anonymized, as described below.
For server listings, unfinished Firebase uploads are normally removed after 24 hours. Private review files and failed or rejected review records are normally removed within 30 days. OpenAI batch input, output, and error files are configured to expire after seven days and Craftia also requests deletion after results are applied. After approval, Firebase staging and review images are deleted and only the resized public copies remain on Backblaze B2 and Cloudflare.
If you delete your server listing, Craftia removes the public listing and status, releases the ordinary owner and address reservation, and queues the Firebase, Backblaze B2, and Cloudflare image copies for deletion or cache purge. An address removed by an administrator for safety or policy reasons may remain in a non-public block record to prevent re-upload. Server-report snapshots and reason codes may be retained as non-public moderation and safety evidence for as long as reasonably necessary.
You can permanently delete your Craftia account from Settings > Delete Account. The server deletes the Firebase Authentication account and user-linked profile, balances and entitlements, likes, saves, libraries, downloads, purchase and reward records, reports, and other private account records handled by the deletion process.
When an account is deleted, Craftia deletes the raw-UID interaction markers and removes the account’s canonical like records, decrementing the corresponding official like counters. Historical aggregate download totals remain after the UID linkage is removed because they are no longer linked to the deleted account.
Content already uploaded, including files and images, is not deleted with the account. Craftia removes account attribution from the primary public and submission database records handled by the deletion process, replaces the public uploader with a deleted-user label, and preserves the content for other users. Retained private or legacy records, storage paths, or object metadata may still contain the former UID, original filename, submission identifier, or other upload metadata for content integrity, moderation, and abuse investigation; these values are not intentionally displayed publicly. A deleted account can no longer manage that content. Contact us before deleting your account if you also want us to review deletion of uploaded content and its retained storage metadata.
The same account-deletion rule applies to a published server listing: its public listing and approved images remain available with anonymized uploader attribution, while private drafts, ownership challenges, upload limits, and private review files linked to the account are removed. The former account can no longer manage the listing. Reporter and target-uploader UIDs are removed from server reports when the related account is deleted, but the non-public server snapshot and reason code may remain as moderation and safety evidence.
Deleting Craftia does not cancel an active Google Play subscription. Cancel it separately in Google Play > Payments & subscriptions > Subscriptions. Google Play may retain transaction records under its own legal and retention requirements.
To prevent a later Google Play event for an active subscription, refund, or chargeback from being attached to a new or unrelated account after deletion, Craftia may retain only a one-way account hash and transaction, security, and audit metadata that no longer contains the former UID or age group for up to 400 days after the last relevant Google Play event. These records are automatically scheduled for deletion and are not used to restore the account or content or for advertising.
Firebase states that Crashlytics keeps crash reports and associated installation identifiers for 90 days before beginning removal from live and backup systems. Firebase Analytics data is retained according to the retention settings configured for the Firebase/Google Analytics property and applicable Google policies. AppsFlyer and Google Mobile Ads retain provider-processed data according to their policies and applicable settings. Security logs, backups, and deletion records may remain for limited periods on normal deletion cycles or where law requires retention.
Uninstalling the app stops future app-originated collection but does not delete information already stored on our servers or by providers. Use the in-app deletion control or contact us for a data request.
Account deletion does not automatically erase files already downloaded to the device or all locally cached likes, saves, downloads, libraries, and age-group settings. Remove downloads in the app where available and clear the app’s storage or uninstall the app to remove remaining local data.
6. Security and international processing
We use reasonable administrative and technical safeguards, including authenticated access, Firebase security controls, access restrictions, hashing of purchase tokens, and HTTPS/TLS for data in transit. Firebase states that the Firebase services used by Craftia encrypt applicable customer data at rest. No system can guarantee absolute security.
Craftia and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, transfers are made using provider contractual protections or other lawful transfer mechanisms.
7. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of your information; object to certain processing; withdraw consent; and complain to a data-protection authority.
You can:
- update profile information in the app;
- delete the account from Settings > Delete Account;
- open Craftia’s Privacy choices when shown to review available Google UMP advertising and Analytics-storage choices;
- reset or delete the Android advertising ID through device settings and manage Google ad personalization through Google controls;
- manage or cancel subscriptions in Google Play; and
- request access, correction, deletion, or assistance by emailing mcpecraftia20260715@gmail.com.
We may ask for information reasonably necessary to verify that you control the relevant account. For applicable AppsFlyer deletion requests, we will submit the request to AppsFlyer.
8. Children and teens
Craftia uses an age screen to apply age-appropriate advertising settings. For a child or an unknown age group, Craftia requests child-directed treatment and limits the maximum ad content rating; for a teen, it sends an under-age-of-consent signal. The exact age is not sent to AdMob by Craftia.
Users under 13 may not use Craftia. The Brazil storefront currently displays ClassInd 14 as content-suitability information for parents and guardians, not as an automatic 14+ access ban. All users under 18 in Brazil receive the minor protections described in this Policy. Eligible users aged 13 to 17 may submit UGC after pre-publication review. If local law requires parental or guardian authorization for account, community, advertising, purchase, or UGC features, that authorization must be provided. Comments are public UGC and display the author's public profile; users can report comments or users and block or unblock users. Craftia does not offer direct messages or chat. A parent or guardian may contact us to review or delete a minor’s information, and we will take reasonable steps to verify the request.
9. Changes to this Policy
We may update this Policy when the Service, providers, or legal requirements change. We will change the effective date and provide additional notice in the app when a change is material. Continued use after an update is subject to the updated Policy, but we will obtain consent when the law requires it.
10. Contact
Operator and data controller: JMS Corporation (제이엠에스코오포레이션), sole proprietor Jung Minsuk
Business registration: 728-38-01468
Address: 21, Jungbu-daero 746beon-gil, Giheung-gu, Yongin-si, Gyeonggi-do 17077, Republic of Korea
Telephone: +82 10-8301-8775
Email: mcpecraftia20260715@gmail.com
Child safety and CSAM: minsukj4@gmail.com
Effective date: 2026-08-26