Legal
Privacy Policy
Last updated: 1 August 2026
This policy covers the LuaNet Android and desktop apps, the LuaNet website, and the NovaX connected-services control plane.
Contact: [email protected]
Summary
- LuaNet stores server data in app-private storage on the device.
- LuaNet does not upload worlds unless the user explicitly chooses NovaX Cloud Backup.
- Account features use Firebase-backed authentication. External link sends limited tunnel metadata; optional Sync and Cloud Backup store only the data needed for those features.
- Google AdMob/UMP may process advertising and consent data.
- Public game packets pass through the NovaX relay in transit when External link is active, but are not retained.
Data processed on the device
LuaNet stores server profiles, worlds, games, mods, backups, settings, logs, player metadata, and ContentDB downloads in local application storage on the Android or desktop device. This local hosting data stays on that device unless the user exports it or enables a feature described below.
The app may access network state, Wi-Fi state, foreground service, wake lock, notification, and storage/document picker capabilities only to run local servers, keep them reachable, show server status, import/export content, and notify the user.
Data sent to NovaX
For External link, the app sends Firebase account identifiers, app-generated device or installation identifiers, tunnel hold/lease metadata, assigned ports, lease timestamps, hashed tunnel session credentials, and aggregate usage needed for limits and abuse prevention.
If the user explicitly enables Sync, LuaNet also stores the device name and platform plus server profile identifiers, names, selected engine and game, configuration values, ports, public-address state, and runtime state. This data is used to show signed-in devices and deliver start, stop, and backup commands requested through Remote. Turning Sync off stops further synchronization.
NovaX does not receive world files, chat, console logs, in-game player names, player databases, or crash log contents through External link, Sync, or Remote.
If the user explicitly uploads a backup to NovaX Cloud Backup, LuaNet stores the encrypted archive, its server and device identifiers, file name, size, checksum, and creation time. The archive may contain the world, configuration, game, and mods selected by the user. Backup contents are encrypted before storage and remain available only to the signed-in account.
Third-party services
LuaNet uses Firebase Authentication, Google AdMob and the Google User Messaging Platform, ContentDB, GitHub sign-in, Cloudflare, and NovaX infrastructure when the related feature is used. Google Play Billing applies only if paid features are re-enabled in a future release. Each provider may process data under its own terms and privacy notices.
Advertising and analytics
LuaNet may show AdMob ads, including rewarded ads, banner ads, and occasional session interstitial ads. Google UMP is used for consent where required.
LuaNet does not run behavioral analytics. Crash reporting is disabled unless the user explicitly opts in.
Retention
- Account, synchronized device/profile records, remote commands, and active tunnel records are kept while the account exists or while needed to provide the selected feature.
- Stopped tunnel ports are kept only for the short grace period needed to prevent accidental reassignment during reconnects.
- Security and anti-abuse logs are retained for up to 30 days.
- Provider-side records follow Google, Firebase, AdMob, Play, GitHub, ContentDB, and Cloudflare retention rules.
- Local worlds and app data remain on the phone until the user deletes profiles, clears app data, or uninstalls LuaNet.
- Cloud backups remain until the user deletes them or deletes the LuaNet account. Incomplete uploads may be retained temporarily for recovery and cleanup.
Account and data deletion
Users can delete their LuaNet account from the app. Deletion revokes active tunnels, removes NovaX tunnel allocations, synchronized devices and profiles, remote commands, and deletes the Firebase Auth user. Security records may remain for up to 30 days where needed for abuse prevention or legal obligations.
Users can also request deletion from the web through the account deletion page.
Deleting the LuaNet account deletes its NovaX cloud backups. It does not delete local worlds or backups on the user's devices.
Children
LuaNet is intended for a Teen/13+ audience and is not directed to children. Users under the minimum age required by their jurisdiction should not create a LuaNet account or use External link without appropriate permission.
User rights
Depending on location, users may have rights to access, correct, delete, export, restrict, or object to processing of their personal data. Send requests to [email protected].
Security
LuaNet uses HTTPS/TLS for API traffic and keeps tunnel credentials temporary. The app never asks users to disable Luanti mod security. Public tunnels carry traffic only for the selected Luanti server port.
Changes
This policy may be updated as LuaNet changes. The latest version is published on this page and reflected in the Play Console Data safety declaration.