respawn.sh
FeaturesGamesHow it worksPricingTrustBlog
ContactGet Started
respawn.sh

Enterprise-grade backups for game servers. Rollback seconds, not days.

Product

  • Features
  • Games
  • How it works
  • Pricing

Company

  • Blog
  • Contact
  • Trust center

Resources

  • Minecraft
  • Hytale
  • FiveM
  • Compare plans

Legal

  • Trust center
  • Terms
  • Privacy
  • Acceptable use
  • SLA
  • DMCA
  • Security
  • Status

© 2026 Renvo Productions LLC d/b/a respawn.sh. All rights reserved.

All legal documents

Trust center

Privacy Policy

Back to trust center

Effective date

Aug 26, 2026

Last updated

Aug 12, 2026

Version

1.0.0

Entity

Renvo Productions LLC d/b/a respawn.sh

On this page

  • 1. Identity of the Data Controller
  • 2. Scope
  • 3. Definitions
  • 4. Legal Frameworks We Comply With
  • 5. Information We Collect
  • 5.1 Account and Identity Data
  • 5.2 Game Server and Backup Data
  • 5.3 Billing and Payment Data
  • 5.4 Security and Anti-Abuse Data
  • 5.5 Communications Data
  • 5.6 Marketing Website Data
  • 5.7 Data We Do Not Collect
  • 6. How and Why We Use Your Information
  • 7. Backup Content - Our Role, Access, and Limitations
  • 7.1 Our Role
  • 7.2 Encryption
  • 7.3 Our Technical Access
  • 7.4 Your Responsibility for Third-Party Data
  • 7.5 Limitation of Liability
  • 8. Cookies and Tracking Technologies
  • 8.1 Categories
  • 8.2 Consent
  • 8.3 IP and Behavioral Monitoring
  • 9. How We Share Your Information
  • 9.1 Subprocessors
  • 9.2 Legal Disclosure
  • 9.3 Business Transfers
  • 9.4 Aggregated or De-identified Data
  • 10. International Data Transfers
  • 10.1 EEA Transfers (GDPR)
  • 10.2 UK Transfers (UK GDPR)
  • 10.3 Swiss Transfers (nFADP / revDSG)
  • 10.4 Canadian Transfers (PIPEDA and Quebec Law 25)
  • 10.5 Storage Location
  • 10.6 Requesting Transfer Safeguards
  • 11. Access to Backup Content
  • 12. Security
  • 12.1 Technical Measures
  • 12.2 Organizational Measures
  • 12.3 Our Security Framework Alignment
  • 12.4 Limitations and Disclaimer
  • 12.5 Breach Notification
  • 13. Data Retention
  • 14. Account Deletion
  • 15. Your Privacy Rights
  • 15.1 Universal Rights
  • 15.2 EEA Users - GDPR Rights
  • 15.3 UK Users - UK GDPR Rights
  • 15.4 Virginia Residents - VCDPA Rights
  • 15.5 California Residents - CCPA/CPRA Rights
  • 15.6 Canadian Residents - PIPEDA Rights
  • 15.7 What a Data Export Includes
  • 15.8 Exercising Your Rights
  • 16. Children's Privacy
  • 17. Contact, Complaints, and Data Subject Requests
  • 18. Changes to This Policy
  • 19. Limitation of Liability

This Privacy Policy ("Policy") is a binding legal document governing the collection, use, storage, sharing, and protection of personal information by Renvo Productions LLC d/b/a respawn.sh. It forms part of the legal framework that includes our Terms of Service, Acceptable Use Policy, Service Level Agreement, and Copyright and DMCA Policy (collectively, "the Agreement"). By using the Service, you confirm you have read and accepted this Policy. The limitations of liability and disclaimers in the Terms of Service apply in full to all matters covered by this Policy.


1. Identity of the Data Controller

Renvo Productions LLC, a Virginia limited liability company operating under the registered fictitious name respawn.sh pursuant to Virginia Code § 59.1-69 et seq., is the Data Controller for personal information collected through the Service.

Contact information for all privacy-related matters, data subject requests, and legal notices is published on the Main Website at https://respawn.sh. We do not publish a physical address in this Policy; contact us through the Main Website.

Where we process personal data on behalf of users (for example, encrypted backup content stored at user direction), we act as a limited Data Processor for that specific data only, as described in Section 6.


2. Scope

This Policy applies to all personal information we collect from:

  • visitors to the respawn.sh marketing website and landing pages;
  • registered account holders and users of the respawn.sh platform and dashboard;
  • individuals who install or operate the respawn.sh Minecraft server plugin ("Plugin"); and
  • individuals who contact us through any form, email, or communication channel.

This Policy does not apply to third-party websites, services, or platforms that we link to or integrate with. Those are governed by their respective privacy policies.

This Policy must be read alongside all other documents comprising the Agreement. In particular, the security framework described in Section 12 is supplemented by our Security and Trust Whitepaper, published on the Main Website.


3. Definitions

"Account Data" means personal information provided during account registration and profile management, including name, email address, username, and profile image.

"Audit Log" means a durable, persistent internal record of security-relevant actions, including logins, authentication attempts, administrative actions, and account changes, associated with IP address, user agent, and timestamps.

"Backup Content" means the actual file contents of Minecraft server backups uploaded to and stored on our infrastructure through the Plugin.

"Backup Metadata" means information about Backup Content that does not include the file contents themselves, including file paths, file sizes, content hashes, backup timestamps, and restore activity records.

"Biometric Data" means data not processed by us. We do not collect biometric data of any kind.

"Cloudflare" means Cloudflare, Inc., which provides infrastructure and security services for the Service.

"Consent Record" means a timestamped record that a user agreed to a specific version of a legal document, including document identifier, version string, timestamp, IP address, and user agent. Consent Records are retained in anonymized form after account deletion.

"Data Controller" has the meaning given in GDPR Article 4(7): an entity that determines the purposes and means of processing personal data.

"Data Processor" has the meaning given in GDPR Article 4(8): an entity that processes personal data on behalf of a Data Controller.

"Data Subject" means an identified or identifiable natural person to whom personal data relates.

"Device Fingerprint" means a hashed, non-reversible identifier derived from browser and device characteristics, used solely to detect new or unrecognized device logins. We store only the hash, never the raw fingerprint data.

"Dodo Payments" means Dodo Payments Inc., our primary payment processor.

"EEA" means the European Economic Area.

"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).

"Have I Been Pwned" or "HIBP" means the third-party breach-password detection service used to check whether passwords appear in known public data breaches, accessed in a privacy-preserving manner.

"Main Website" means respawn.sh and any successor domains.

"PayPal" means PayPal Holdings, Inc., an alternative payment processor.

"Personal Data" or "Personal Information" means any information relating to an identified or identifiable natural person.

"Plugin" means the respawn.sh server-side software agent installed on a user's Minecraft server.

"Prelude" means Prelude (or its successor), our SMS delivery and verification provider.

"Resend" means Resend, Inc., our transactional email delivery provider.

"Service" has the meaning given in the Terms of Service.

"Session Data" means IP address, user agent string, session token, and session expiry recorded at each login.

"Special Category Data" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health data, or data concerning sex life or sexual orientation. We do not intentionally collect Special Category Data and our systems are not designed to process it.

"Subprocessor" means a third-party Data Processor engaged by us to process personal data on our behalf.

"TOTP" means Time-Based One-Time Password, a form of authenticator-app-based two-factor authentication.

"UK GDPR" means the GDPR as retained in UK law by the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.

"VCDPA" means the Virginia Consumer Data Protection Act, Va. Code § 59.1-575 et seq.


4. Legal Frameworks We Comply With

This Policy is designed to meet the requirements of the following applicable legal and regulatory frameworks. Where a framework is listed, we comply with it to the extent it applies to our processing activities and user base. Listing a framework is not a claim of independent certification unless certification is expressly stated.

Data Protection and Privacy Laws:

  • GDPR (Regulation (EU) 2016/679) - for users in the EEA. Our lawful transfer mechanism for EU-to-US data transfers is Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Article 46(2)(c). We do not currently self-certify under the EU-US Data Privacy Framework (DPF); we rely on SCCs as our transfer mechanism. We will update this Policy if and when we pursue DPF certification.
  • UK GDPR and Data Protection Act 2018 - for users in the United Kingdom. We rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs as our transfer mechanism for UK-to-US transfers.
  • Swiss Federal Act on Data Protection (nFADP / revDSG) - for users in Switzerland. We rely on SCCs as our transfer mechanism for Switzerland-to-US transfers. We do not currently self-certify under the Swiss-US Data Privacy Framework; we will update this Policy if we pursue Swiss-US DPF certification.
  • VCDPA (Va. Code § 59.1-575 et seq.) - for Virginia residents.
  • CCPA/CPRA (Cal. Civ. Code § 1798.100 et seq.) - for California residents.
  • PIPEDA (Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5) - for Canadian residents. PIPEDA applies to our commercial collection and use of personal information of Canadian residents regardless of our US location. Our PIPEDA compliance is implemented through the consent, purpose limitation, access, accuracy, safeguard, and accountability principles described throughout this Policy. We are subject to the mandatory breach notification requirements under PIPEDA (see Section 12.5).
  • Quebec Law 25 (Act Respecting the Protection of Personal Information in the Private Sector) - for Quebec residents. Quebec's Law 25 imposes GDPR-analogous requirements for organizations serving Quebec residents including adequacy assessments for cross-border transfers. Our SCC-based transfer mechanism satisfies the cross-border transfer requirements of Law 25.
  • COPPA (15 U.S.C. § 6501 et seq.) - we do not knowingly collect personal information from children under 13 and block their registration.
  • TCPA and FCC regulations - for any SMS-based communications we send.
  • CAN-SPAM Act - for marketing email communications.

Security Frameworks (informing our security practices but not current certifications):

  • NIST SP 800-53 and NIST CSF - our security controls are structured around NIST frameworks.
  • ISO/IEC 27001 - our security practices follow ISO 27001 principles. We are not yet independently certified.
  • NIS2 Directive (Directive (EU) 2022/2555) - NIS2 does not directly apply to us as we fall below the size thresholds (50 employees / €10M revenue) and are not established in the EU. However, we are aware that EU-based users who are themselves NIS2-covered entities may have supply chain security obligations that affect their use of our Service, and our security practices are informed by NIS2 risk management principles as a matter of good practice.
  • SOC 2 Type II - not yet certified; planned as the Service scales.
  • PCI-DSS - payment card data is handled exclusively by our payment processors; we do not store, process, or transmit raw card data.

Note on the EU-US Data Privacy Framework (DPF): The EU-US DPF, UK Extension to the EU-US DPF, and Swiss-US DPF are voluntary self-certification programs administered by the U.S. Department of Commerce. Certification provides an alternative adequacy-based transfer mechanism to SCCs. We do not currently hold DPF certification. We rely on SCCs for all EU, UK, and Swiss transfers. We will notify users via this Policy if we pursue and obtain DPF certification, at which point the DPF Principles and their associated recourse mechanisms would apply to covered data transfers.


5. Information We Collect

5.1 Account and Identity Data

We collect the following when you create and use an account:

  • Name - provided at registration, used for account identification and communications.
  • Email address - primary account identifier, used for authentication, transactional communications, and security notifications.
  • Username - chosen display identifier, visible within the platform.
  • Profile image - optionally uploaded; stored on our infrastructure.
  • Email verification status - whether the email address has been verified.
  • Phone number - collected if SMS-based two-factor authentication is enabled; used solely for OTP delivery via our SMS provider Prelude. See Section 5.5 for Prelude data flows.
  • Date of birth - collected to enforce age gating. Users under 13 are blocked outright. Users aged 13-17 trigger a guardian-consent flow. Date of birth is deleted upon account deletion and is not used for any other purpose.
  • Password - stored exclusively as a salted cryptographic hash. The plaintext password is never stored or transmitted to our servers in any recoverable form.
  • Two-factor authentication state - TOTP secret (stored encrypted at rest) and/or SMS OTP enrollment status. A user may have either, both, or neither.
  • Device fingerprint history - stored as hashed, non-reversible identifiers only. Raw fingerprint data is never stored. Used solely to detect and alert on logins from unrecognized devices.
  • Session Data - IP address, user agent, session token, and expiry, recorded on every authenticated session.
  • OAuth-linked accounts - if you sign in using Google or Discord, we receive and store your provider name, provider account ID, and encrypted OAuth tokens. We do not receive your OAuth provider password. Only Google and Discord OAuth providers are currently active.
  • Consent Records - a timestamped record of your agreement to each version of each legal document, including document type, version, timestamp, IP address, and user agent. Retained in anonymized form after account deletion.
  • Consent flags - boolean records of: guardian consent (for minors), SMS verification consent, marketing email opt-in, and Terms/AUP acceptance, each stored with its own timestamp.

5.2 Game Server and Backup Data

When you install and operate the Plugin on your Minecraft server:

  • Server information - a customer-chosen display name, server type (Minecraft, Hytale, FiveM), server status, and an optional free-form metadata field (up to 32 key/value pairs) that you may populate with arbitrary information. We do not require a server address, but this metadata field could contain one if you choose to enter it.
  • Device/hardware identifier - a hash of the machine running the Plugin, used for anti-abuse enforcement and plan limit checks. This is a non-reversible hash; we do not store hardware serial numbers, IP addresses, or raw hardware identifiers.
  • Backup Metadata - file paths, file sizes, and content hashes for each backed-up file. For Minecraft servers, this may include filenames referencing player UUID data or server whitelists, which may contain player-identifying information from your own server. You are the Data Controller for your players' data; we process it solely as your Data Processor.
  • Backup Content - the actual contents of your backup archives. Backup Content is uploaded to and stored on our own cloud storage infrastructure. This is not a bring-your-own-storage model. Backup Content is encrypted at rest using AES-256. We hold the encryption key material and can technically decrypt Backup Content. See Section 6 for the limited circumstances in which we access Backup Content.
  • Restore activity - records of who requested a restore and when, plus expiring signed download links.
  • Usage and billing metering - bytes transferred per server and per backup job, used for plan quota enforcement and billing calculations.

5.3 Billing and Payment Data

We do not receive, store, or process raw payment card numbers, CVV codes, or full card data at any point. All payment processing occurs through our payment processors' hosted flows.

We store: your email address and name as provided to the processor, the processor's customer and subscription identifiers, plan and product identifiers, subscription status, and renewal date.

Our active payment processors are Dodo Payments and PayPal. Their respective privacy policies govern how they handle payment data on their end.

5.4 Security and Anti-Abuse Data

  • Signup abuse prevention - IP address and device signals are recorded per signup attempt and used to detect and prevent abusive account creation patterns. This data is retained solely by us and is not shared externally.
  • Audit Log - a durable, persistent record of: logins, signups, multi-factor authentication attempts, password reset events, admin actions, and organization changes, each associated with IP address, user agent, timestamp, and action type. This is not a transient server log; it is a permanent security record.
  • Failed login and lockout tracking - repeated failed logins can trigger a soft-lock on an account or organization. Tracked with timestamps and reason codes.
  • Breached password detection - on each login, we check whether your password appears in known public data breaches using a third-party breach detection service. This check is performed in a privacy-preserving manner; your plaintext password and its full cryptographic hash never leave our servers. If a match is found, we email you to change your password. We do not store the breach check result.
  • Bot and abuse prevention - Cloudflare's security technologies may be presented on authentication and signup flows. Cloudflare receives challenge tokens and visitor IP addresses as part of this flow. We do not control what Cloudflare processes beyond the scope of our Data Processing Agreement with them.

5.5 Communications Data

We send the following transactional communications:

  • Signup on an already-registered email: an anti-fraud notice (no account action taken).
  • Two-factor and OTP codes: one-time code, username, and a security notice.
  • Magic-link sign-in: a one-time sign-in link.
  • New device login alert: IP address, user agent, device/browser information, and a password-reset link.
  • Breached password alert: a prompt to change your password.
  • Organization invitation: invite link and organization name (sent to invitees who may not yet be users).
  • Data export ready: a download link.
  • Account deletion started or cancelled: deletion deadline and a cancellation link.
  • Legal terms update: advance notice of upcoming changes.

Transactional email is delivered via Resend. We control the content of each email. Resend's platform-level settings may include click or open tracking; we do not use or rely on such data, and we endeavor to keep tracking disabled.

SMS is delivered via Prelude. When you initiate an SMS-based authentication action, we transmit your phone number to Prelude for OTP delivery. Prelude is the sender of record for all SMS messages sent through our Service. Prelude processes your phone number as our data processor under a Data Processing Agreement. For EEA and UK users, the legal basis is contractual necessity (GDPR Article 6(1)(b)). You may request details of applicable transfer mechanisms by contacting us through the Main Website.

5.6 Marketing Website Data

The respawn.sh marketing website operates its own self-hosted, first-party analytics. We do not use Google Analytics, Meta Pixel, or any third-party tracking pixel or behavioral advertising technology.

We collect on every page load: page path, session identifier, a persistent but anonymous visitor identifier (not linked to any account), IP address, country, full user agent string, browser and operating system, referring URL, and whether the visit is new or returning.

When you submit a form on the marketing website, we collect: the fields you complete (name, email, message, and any other fields on the specific form), plus automatically captured context including IP address, country, browser and device type, session identifier, referring page, timezone, language, screen size, and form completion time. If the form includes a legal agreement checkbox, we record what was agreed to and when as part of the submission record.

Form submission data is retained for the operational lifetime of the form. When a form is deleted, all submissions associated with it are permanently deleted. By submitting a form, you consent to this retention and use.

Marketing site page-view and session data is retained as long as reasonably necessary for our legitimate first-party analytics interests, subject to periodic review. We do not set a fixed expiry on aggregate, anonymized session-level data, but personally-identifiable fields (IP address) in page-view records are subject to the same rights as any other personal data we hold.

5.7 Data We Do Not Collect

We do not collect: Special Category Data, biometric data, location data beyond country-level derived from IP address, financial account numbers or payment card data, data from children under 13 (who are blocked from registering), or any data from third-party data brokers or advertising networks.


6. How and Why We Use Your Information

We process personal information for the following purposes, each with a documented legal basis:

Providing and operating the Service - delivering backup, restore, authentication, billing, and dashboard features. Legal basis: contractual necessity (GDPR Article 6(1)(b)).

Account registration and authentication - creating and managing your account, verifying your identity, and managing sessions and two-factor authentication. Legal basis: contractual necessity (GDPR Article 6(1)(b)).

Payment processing and subscription management - processing payments, managing subscriptions, and handling billing events. Legal basis: contractual necessity (GDPR Article 6(1)(b)).

Transactional communications - sending security alerts, OTP codes, backup notifications, billing receipts, and other communications necessary to deliver the Service. Legal basis: contractual necessity (GDPR Article 6(1)(b)).

Security monitoring and fraud detection - operating the Audit Log, device fingerprinting, breached-password detection, abuse rate-limiting, and Cloudflare security technologies to protect the integrity of the Service and other users. Legal basis: legitimate interests (GDPR Article 6(1)(f), Recital 47 - fraud prevention and network security).

Multi-account detection and Terms enforcement - monitoring IP addresses, device identifiers, and behavioral signals to detect multiple accounts operated by the same person in violation of Terms of Service Section 6. Legal basis: legitimate interests (GDPR Article 6(1)(f)).

Backup Content access for enforcement purposes - accessing and reviewing Backup Content in the limited circumstances described in Section 11. Legal basis: legitimate interests and legal obligation (GDPR Article 6(1)(c) and (f)).

Age verification - using date of birth to enforce the minimum age requirement and, for users aged 13-17, to trigger guardian consent. Legal basis: legal obligation (COPPA; GDPR Article 8) and legitimate interests.

Marketing email communications - sending product updates and news where you have opted in. Legal basis: consent (GDPR Article 6(1)(a)). You may withdraw consent at any time.

Behavioral cookies and non-essential tracking - where you have consented through our cookie consent mechanism. Legal basis: consent (GDPR Article 6(1)(a)).

First-party analytics - understanding how the marketing website is used, improving the Service, and monitoring performance. Legal basis: legitimate interests (GDPR Article 6(1)(f)).

Legal compliance - complying with applicable laws, court orders, subpoenas, and regulatory obligations. Legal basis: legal obligation (GDPR Article 6(1)(c)).

Backup Metadata processing - processing metadata about your backups to operate backup scheduling, quota enforcement, restore operations, and billing metering. Legal basis: contractual necessity (GDPR Article 6(1)(b)).

We do not use personal information for automated decision-making that produces legal or similarly significant effects on individuals, targeted advertising, data brokerage, or any purpose not listed above.


7. Backup Content - Our Role, Access, and Limitations

7.1 Our Role

For Backup Content specifically, we act as a Data Processor processing data you upload at your direction. You remain the Data Controller for your backup archives and for any personal data of third parties (such as your Minecraft server players) contained within them.

7.2 Encryption

Backup Content is encrypted at rest using AES-256. Encryption is applied before storage and keys are held by us. This encryption protects against unauthorized access at the storage infrastructure layer, including in the event of a breach at our cloud storage provider level.

7.3 Our Technical Access

We hold the encryption key material and retain the technical ability to decrypt Backup Content. This is not a zero-knowledge or customer-key-only architecture. We do not routinely access or review Backup Content. Access is limited to the specific circumstances in Section 11.

7.4 Your Responsibility for Third-Party Data

You are solely responsible for ensuring that the personal data of third parties (including your Minecraft server players) contained in your backup archives is handled in accordance with all applicable privacy laws, including GDPR where applicable. We process that data only at your direction and are not responsible for your compliance obligations as a Data Controller for your players' personal data.

7.5 Limitation of Liability

To the maximum extent permitted by applicable law, we disclaim all liability for the contents of Backup Content, including any personal data of third parties contained therein. The full limitation of liability provisions in the Terms of Service apply to all matters relating to Backup Content. See Terms of Service Section 14.


8. Cookies and Tracking Technologies

8.1 Categories

We use the following technologies:

Strictly necessary session cookies - required for authentication and core platform functionality. These are exempt from consent requirements under the ePrivacy Directive and cannot be disabled without impairing the Service.

Preference cookies - remember your settings and configuration choices within the platform.

First-party analytics technologies - self-hosted, first-party tracking on the marketing website only, as described in Section 5.6. Not linked to individual accounts.

Behavioral cookies and tracking technologies - where you have given prior opt-in consent through our cookie consent mechanism. Used for platform improvement, abuse detection, and enforcement of the one-account-per-user rule in Terms of Service Section 6.

Cloudflare security technologies - Cloudflare may set cookies or use browser signals as part of its infrastructure and security services. Cloudflare's processing is governed by their privacy policy and our Data Processing Agreement with them. This is a security measure, not a tracking or advertising tool.

Intercom - our support and messaging provider sets cookies and uses browser storage to enable the support widget, remember conversation state, and deliver in-app messages. Intercom's cookie processing is subject to your consent where required. You may disable the Intercom widget by opting out of non-essential cookies through the cookie preference centre. Intercom's processing is governed by their privacy policy and our Data Processing Agreement.

8.2 Consent

All cookies other than strictly necessary cookies require your prior, freely given, specific, and informed consent, collected through our cookie consent mechanism on first visit. You may withdraw or modify consent at any time through the cookie preference centre accessible on the Main Website.

We do not use third-party advertising cookies, retargeting pixels, Meta Pixel, Google Analytics, or any behavioral advertising technology.

8.3 IP and Behavioral Monitoring

IP address monitoring, device fingerprinting, and Audit Log activity are distinct from cookie-based tracking and operate on the legal basis of legitimate interests for security and fraud prevention. These are not controlled by your cookie consent settings.


9. How We Share Your Information

We do not sell, rent, trade, or share personal information with third parties for their own commercial or advertising purposes. We share personal information only in the following circumstances:

9.1 Subprocessors

We engage the following Subprocessors to assist in operating the Service. Each Subprocessor is bound by contractual data protection obligations, including a Data Processing Agreement where required by GDPR Article 28:

Cloudflare, Inc. - infrastructure and security services. All traffic to the Service passes through Cloudflare's network, meaning Cloudflare processes visitor IP addresses and request metadata as part of providing these services.

ElysiaCloud (Valex Cloud LLC) - application hosting infrastructure for the backend, API, and dashboard.

Neon (Neon Inc.) - managed database service. Processes all personal data stored in our primary database including account data, billing records, consent records, and audit logs. Data is encrypted at rest and in transit within Neon's infrastructure.

Resend, Inc. - transactional email delivery. Receives recipient email address and email content (which may include IP addresses and security-related information as described in Section 5.5).

Prelude - SMS delivery and verification. Receives phone number and requested code length only. Generates, delivers, and validates OTP codes. Does not receive or store the code after delivery. Prelude is the sender of record for all SMS messages.

Dodo Payments - primary payment processor for subscription billing. Receives email address, name, plan identifier, and subscription identifier for billing purposes. Card data goes directly to Dodo's hosted payment flow; we do not receive raw card numbers.

PayPal - payment processor for recurring subscription billing. Receives email address, name, plan identifier, and subscription identifier. PayPal processes recurring charges directly under their own billing infrastructure. Subject to PayPal's own privacy policy and terms of service.

Breach detection service - a third-party breach-password detection service used to check on login whether your password appears in known public data breaches. This check is performed in a privacy-preserving manner; only a partial cryptographic derivative of your password is transmitted, never the plaintext or full hash.

Google - OAuth provider for "Sign in with Google." Receives a sign-in request from our platform; Google returns a basic profile (email, name, provider account ID). Governed by Google's privacy policy.

Discord - OAuth provider for "Sign in with Discord." Same structure as Google above. Governed by Discord's privacy policy.

Planned future subprocessors: We intend to deploy Intercom, Inc. for customer support chat and in-app messaging. When deployed, Intercom will process account identifiers (user ID, email, username) and support conversation content. This Policy will be updated before Intercom is activated and data begins flowing to their systems.

We do not use PostHog, Google Analytics, Meta, or any advertising, retargeting, or third-party behavioral analytics service. All marketing site analytics are self-hosted and first-party.

We do not currently publish a complete, versioned sub-processor list in this Policy because provider relationships evolve. A current list is available upon written request. Enterprise users requiring a formal DPA with sub-processor disclosure should contact us using the details on the Main Website.

9.2 Legal Disclosure

We may disclose personal information where required by applicable law, valid court order, subpoena, or governmental or regulatory request, or where we have a good faith belief that disclosure is necessary to: (a) comply with a legal obligation; (b) protect our rights or property; (c) prevent or investigate fraud or abuse; or (d) protect the safety of users or the public.

Where legally permitted, we will notify you before disclosing your personal information in response to legal process.

9.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of all or substantially all assets, personal information may be transferred to the acquiring entity. We will provide notice before such transfer and require the successor to honor this Policy or notify you of changes.

9.4 Aggregated or De-identified Data

We may share aggregated or fully anonymized data that cannot reasonably be used to identify any individual, for purposes such as product analytics, research, or marketing. This is not personal data and is not subject to the restrictions in this Section.


10. International Data Transfers

The Service is operated from the United States. Personal information collected from users in the EEA, UK, Switzerland, Canada, and other jurisdictions is transferred to and processed in the United States, which may not offer the same level of data protection as your home jurisdiction. We protect such transfers through the mechanisms below.

10.1 EEA Transfers (GDPR)

For transfers of personal data from the EEA to the United States, we rely on Standard Contractual Clauses (SCCs) in the form approved by the European Commission under Commission Implementing Decision (EU) 2021/914, incorporating Module 2 (Controller to Processor) or Module 3 (Processor to Processor) as applicable. SCCs are incorporated into our Data Processing Agreements with Subprocessors who process EEA personal data.

We do not currently hold EU-US Data Privacy Framework (DPF) certification. We do not rely on the DPF as a transfer mechanism. If we obtain DPF certification in the future, we will update this Policy and disclose the certification on the Main Website.

10.2 UK Transfers (UK GDPR)

For transfers of personal data from the United Kingdom to the United States, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs, as applicable and as recognized by the UK Information Commissioner's Office. The UK has issued an adequacy decision in respect of UK transfers to US organizations certified under the UK Extension to the EU-US DPF; however, as we are not currently DPF-certified, we rely on the IDTA/UK Addendum for UK transfers.

10.3 Swiss Transfers (nFADP / revDSG)

For transfers of personal data from Switzerland to the United States, we rely on Standard Contractual Clauses as our transfer mechanism. Switzerland's Federal Council recognized the adequacy of transfers to US organizations self-certified under the Swiss-US DPF effective September 15, 2024; however, as we are not currently Swiss-US DPF certified, we rely on SCCs. We will update this Policy if we pursue Swiss-US DPF certification.

10.4 Canadian Transfers (PIPEDA and Quebec Law 25)

PIPEDA does not prohibit the transfer of personal information outside Canada but requires that organizations ensure comparable protection through contractual or other means. We satisfy this requirement through our Data Processing Agreements with Subprocessors and through the security measures described in Section 12. For Quebec residents, we rely on SCCs as the contractual measure satisfying Quebec Law 25's cross-border transfer requirements, consistent with the adequacy status of the EU SCC framework recognized by Quebec's Commission d'accès à l'information.

10.5 Storage Location

Our cloud storage provider, which stores encrypted Backup Content, operates globally. Encrypted Backup Content may be stored on infrastructure outside your home jurisdiction. AES-256 encryption applied before storage provides a supplementary technical safeguard, meaning content is not accessible to parties at the storage layer without the key material held by us.

10.6 Requesting Transfer Safeguards

You may request a copy of the applicable Standard Contractual Clauses or other transfer safeguards governing your data by contacting us through the Main Website. Enterprise or B2B users requiring a signed Data Processing Agreement incorporating transfer mechanisms may contact us to arrange this.


11. Access to Backup Content

We do not routinely access, review, or analyze Backup Content. We make reasonable technical and organizational efforts to detect prohibited content through available signals (file type, metadata, hash matching), but we cannot fully inspect all Backup Content and are under no obligation to do so.

We may access and decrypt Backup Content only in the following specific, limited circumstances:

  • upon receipt of a credible report of illegal content or a violation of the Acceptable Use Policy from a third party or law enforcement;
  • where required by a valid legal order, court order, subpoena, or governmental authority;
  • where we have reasonable grounds to suspect a material breach of the Terms of Service or Acceptable Use Policy based on observable signals;
  • where necessary to investigate a security incident affecting the integrity or availability of the Service or other users' data; or
  • where strictly necessary for a technical operation that cannot be performed without decryption, such as a format migration of stored data, with notice to you where practicable.

All access to Backup Content is logged internally with the identity of the accessor, timestamp, scope, and stated purpose. We do not access Backup Content for commercial purposes, advertising, training of AI or machine learning systems, or any purpose not listed above.

We are not liable for any failure to detect prohibited content in Backup Content. The limitation of liability provisions in Terms of Service Section 14 apply fully to all Backup Content access and non-access decisions.


12. Security

12.1 Technical Measures

We implement the following technical security controls:

  • Encryption of Backup Content at rest using AES-256, with keys held by us
  • Encryption of all data in transit using industry-standard TLS
  • Cryptographic hashing of passwords; plaintext passwords are never stored or transmitted
  • Encrypted storage of two-factor authentication secrets and OAuth tokens
  • Non-reversible hashing of device identifiers
  • Access controls and authentication requirements for internal systems, including multi-factor authentication and PIN-based access for administrative functions
  • Two-factor authentication available for all user accounts
  • Rate limiting on authentication and signup flows
  • Breached-password detection on every login using a privacy-preserving third-party service
  • Audit logging of security-relevant account actions
  • Automated account locking after repeated failed authentication attempts

12.2 Organizational Measures

  • Access to production systems and personal data is restricted to a small number of authorized personnel
  • Access controls limit each team member to data and systems necessary for their function
  • Data Processing Agreements are in place with all Subprocessors
  • Internal access to Backup Content is logged as described in Section 11
  • Personnel with production access are subject to confidentiality obligations
  • Security reviews are conducted periodically

12.3 Our Security Framework Alignment

Our security program is informed by NIST SP 800-53 (security and privacy controls), NIST CSF (cybersecurity framework), and ISO/IEC 27001 principles. We are not yet independently certified against any of these frameworks. Certain Subprocessors hold independent security certifications relevant to their respective processing activities.

12.4 Limitations and Disclaimer

No security system is perfect or impenetrable. We cannot guarantee the absolute security of your information against all threats, including sophisticated cyberattacks, zero-day vulnerabilities, or unauthorized acts of personnel. You are responsible for maintaining the confidentiality of your account credentials and API keys. We are not liable for security incidents caused by your own acts or omissions, third-party attacks on infrastructure outside our reasonable control, or events constituting force majeure. To the maximum extent permitted by applicable law, the full limitation of liability provisions in the Terms of Service Sections 16 and 17 apply to all security-related claims, including claims arising from data breaches, unauthorized access, or failure of any security measure regardless of cause.

12.5 Breach Notification

In the event of a personal data breach, we will comply with all applicable notification obligations:

EEA users (GDPR): We will notify the relevant lead supervisory authority within 72 hours of becoming aware of a breach that is likely to result in a risk to the rights and freedoms of natural persons, as required by GDPR Article 33. We will notify affected EEA individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34.

UK users (UK GDPR): We will notify the Information Commissioner's Office within 72 hours and affected UK individuals as required by UK GDPR Articles 33 and 34.

Swiss users (nFADP): We will notify the Federal Data Protection and Information Commissioner (FDPIC) and affected Swiss individuals as required by the Swiss Federal Act on Data Protection.

Canadian users (PIPEDA): Under PIPEDA's mandatory breach reporting requirements (PIPEDA Breach of Security Safeguards Regulations, SOR/2018-64), we will: (a) notify the Privacy Commissioner of Canada as soon as feasible after we determine that a breach of security safeguards involving personal information has occurred and it is reasonable to believe the breach creates a real risk of significant harm to an individual; (b) simultaneously notify affected Canadian individuals of the breach; and (c) maintain a record of every breach of security safeguards for 24 months following the date we became aware of the breach and make that record available to the Privacy Commissioner upon request. Quebec Law 25 imposes equivalent obligations for Quebec residents.

US users (state breach laws): We will notify affected US users in accordance with applicable state breach notification laws, including Virginia Code § 18.2-186.6 (Virginia), the California Consumer Privacy Act (California), and all other applicable state statutes, within legally required timeframes. The Virginia breach notification obligation applies regardless of any contractual liability limitation.

General: Breach notification does not constitute an admission of liability. The limitations of liability in the Terms of Service apply to all claims arising from or related to a security incident or data breach to the maximum extent permitted by applicable law.


13. Data Retention

We retain personal information for as long as necessary to fulfill the purpose for which it was collected, to provide the Service, to comply with legal obligations, or to enforce our rights.

Account Data and profile information - retained for the duration of your account. On account deletion, email and username are anonymized, and name, date of birth, phone number, password, 2FA secrets, and account notes are permanently erased within 7 days of the deletion request being processed.

Consent Records - retained in anonymized form indefinitely after account deletion. The anonymized record preserves proof that someone agreed to a specific document version on a specific date, without retaining who.

Session Data - retained for the duration of the session, then deleted on session expiry or logout.

Security and Audit Log - retained for 90 days following account deletion, then permanently deleted. The Audit Log is retained in full during the account lifecycle for security monitoring and fraud prevention.

Backup Content - retained for the duration of your active Subscription Plan. Following plan expiry or account deletion, Backup Content is deleted as part of the organization wind-down process that precedes personal account deletion. We may, at our sole discretion, retain Backup Content for a short additional grace period of up to 7 days after plan expiry before permanent deletion. This is a courtesy and not a contractual obligation. See Terms of Service Section 10.2.

Backup Metadata - retained for the same duration as Backup Content, then deleted.

Billing records - retained for 7 years from the date of the transaction, for tax, accounting, and financial compliance purposes. This retention continues regardless of account deletion and is required by applicable law.

Usage and metering data - retained for 12 months on a rolling basis, then deleted.

Device fingerprint history - retained for the lifetime of the account, then deleted with the account.

Breached-password detection data - we do not store breach check results.

Marketing site page-view and session data - retained as long as reasonably necessary for legitimate first-party analytics purposes. Personally-identifiable fields (such as IP address) in these records are subject to your rights in Section 15.

Marketing site form submissions - retained for the operational lifetime of the form. When a form is deleted, all associated submissions are permanently deleted. By submitting a form, you acknowledge this retention period.

Deletion-request record - a minimal record that a specific email address requested and completed account deletion, and the date this occurred, is retained indefinitely. This record contains no other personal data and exists solely to prevent accidental re-creation or confusion of a deleted account's history.

Legal hold - notwithstanding the above, we may retain any personal data beyond the periods listed where necessary for legal proceedings, regulatory inquiry, governmental request, or enforcement of our rights. Such retention is described in Terms of Service Section 10.3. We are not required to disclose to you that a legal hold is in place.


14. Account Deletion

Account deletion is a 7-day, reversible process:

  1. You request deletion through your account dashboard (re-authentication required). You must first transfer ownership of or wind down any organizations and subscriptions you control.
  2. Your account is marked for deletion with a 7-day countdown. Nothing is erased at this stage. You receive a confirmation email.
  3. Signing in at any point during the 7-day window cancels the deletion and fully restores the account.
  4. After 7 days with no sign-in, an automated process permanently executes the deletion as described in Section 13.

Following deletion, the following data is removed or anonymized: email (anonymized), username (anonymized), name, date of birth, phone number, password hash, 2FA secrets, active sessions, pending tokens (verification, password reset, invitations), OAuth account links, organization memberships, and notifications.

The following data is retained after deletion: anonymized Consent Records, anonymized Audit Log entries (personally-identifying fields stripped), the permanent deletion-request record (email and date only), and billing records (for 7 years), and security/Audit Log data for 90 days as described in Section 13.


15. Your Privacy Rights

15.1 Universal Rights

The following rights apply to all users regardless of jurisdiction:

  • Access - request a copy of the personal information we hold about you.
  • Correction - request correction of inaccurate or incomplete personal information.
  • Deletion - request deletion of your personal information, subject to legal retention requirements and the deletion process in Section 14.
  • Portability - receive personal information you have provided to us in a structured, commonly used, machine-readable format.
  • Opt-out of marketing - unsubscribe from marketing emails at any time via the unsubscribe link in any marketing message or by contacting us.

15.2 EEA Users - GDPR Rights

In addition to Section 15.1:

  • Object - object to processing carried out on the basis of legitimate interests under GDPR Article 21. We will cease such processing unless we have compelling legitimate grounds that override your interests.
  • Restrict - request restriction of processing in circumstances defined in GDPR Article 18.
  • Withdraw consent - withdraw consent at any time where processing is consent-based, without affecting the lawfulness of prior processing (GDPR Article 7(3)).
  • Lodge a complaint - lodge a complaint with your national Data Protection Authority. A list of EU DPAs is at https://edpb.europa.eu.

We respond to GDPR data subject requests within 30 days. For complex requests, we may extend by up to 60 additional days with notice.

15.3 UK Users - UK GDPR Rights

UK users have the same rights as EEA users under Section 15.2, enforced under the UK GDPR and Data Protection Act 2018. Complaints may be lodged with the Information Commissioner's Office (ICO) at https://ico.org.uk.

Note on UK GDPR Article 27 representative: Because we offer services to UK residents without a UK establishment, we may be required to appoint a UK representative. If and when such a representative is appointed, their details will be published on the Main Website.

15.4 Virginia Residents - VCDPA Rights

Virginia residents have the right to: access, correct, delete, and obtain a portable copy of personal data; opt out of the sale of personal data (we do not sell personal data); opt out of targeted advertising (we do not engage in targeted advertising); and appeal our decision on a privacy rights request. To submit an appeal, contact us as described in Section 17.

15.5 California Residents - CCPA/CPRA Rights

California residents have the right to: know what personal information we collect, use, disclose, or share; delete personal information; correct inaccurate personal information; opt out of the sale or sharing of personal information (we do not sell or share personal information as defined under CCPA/CPRA); limit the use of sensitive personal information to necessary purposes; and be free from discrimination for exercising these rights.

To submit a California privacy rights request, contact us with the subject line "California Privacy Request."

Shine the Light (Cal. Civ. Code § 1798.83): We do not share personal information with third parties for their direct marketing purposes.

15.6 Canadian Residents - PIPEDA Rights

Canadian residents have the right under PIPEDA to: be informed of the existence, use, and disclosure of their personal information and to be given access to that information; challenge the accuracy and completeness of the information and have it amended as appropriate; know that their personal information is being collected in accordance with PIPEDA's ten fair information principles (accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance); withdraw consent to the collection, use, or disclosure of personal information at any time, subject to legal or contractual restrictions and reasonable notice; and make a complaint to the Office of the Privacy Commissioner of Canada (OPC) at https://priv.gc.ca if they believe their personal information has been handled in contravention of PIPEDA.

For Quebec residents, equivalent rights exist under Quebec Law 25 and complaints may be directed to the Commission d'accès à l'information du Québec (CAI) at https://www.cai.gouv.qc.ca.

15.7 What a Data Export Includes

When you request a copy of your data, we provide:

  • Account profile data (name, email, username)
  • Consent Records (document, version, timestamp, IP, user agent)
  • Billing history (masked payment method, invoice dates, amounts, plan names)
  • Session and login history (IP addresses, user agents, timestamps - rolling 12 months)
  • Backup job metadata (snapshot names, timestamps, sizes, status)
  • Support communications
  • Phone number consent records (if SMS 2FA was enabled)
  • A privacy summary document describing the legal basis and retention period for each data category, the recipients of your data, and your remaining rights

Backup Content itself is available for download through the dashboard restore function, which satisfies the data portability obligation under GDPR Article 20 without requiring inclusion of raw backup archives in the data export.

15.8 Exercising Your Rights

Submit requests using the contact details on the Main Website. We may verify your identity before processing requests. We will not discriminate against you for exercising your privacy rights. Response timeframes: 30 days under GDPR; 45 days under VCDPA and CCPA; as soon as reasonably practicable under PIPEDA (generally within 30 days). We may extend these periods by the maximum permitted by applicable law where requests are complex or numerous, with notice to you.


16. Children's Privacy

The Service is not directed to children under 13. We block account creation by anyone who self-reports as under 13 and do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact us immediately and we will delete such information without delay.

For users aged 13 to 17, we operate a guardian consent flow at registration. Users who do not complete the guardian consent flow cannot proceed.

For EEA users, age of digital consent varies by member state (13 to 16). Where a user's jurisdiction requires a higher minimum age, the guardian consent flow applies to users below that threshold.


17. Contact, Complaints, and Data Subject Requests

All privacy-related questions, requests, complaints, and legal notices must be submitted using the contact details published on the Main Website at https://respawn.sh.

For EEA users: if you believe we have not adequately addressed your concern, you may lodge a complaint with your national DPA. A list of EU DPAs is at https://edpb.europa.eu.

For UK users: contact the Information Commissioner's Office (ICO) at https://ico.org.uk or by telephone at 0303 123 1113.


18. Changes to This Policy

We may update this Policy at any time by posting a revised version on the Main Website and updating the document version metadata. For material changes to how we process your personal data, we will use reasonable efforts to notify you at least 14 days before the changes take effect, by email or by posting a notice on the Service. For changes that introduce new categories of personal data processing not previously disclosed, we will notify you before beginning that new processing. For changes to the legal basis on which we process your personal data under GDPR, we will notify you before the change takes effect and, where required by law, seek fresh consent. For all other changes, the updated Policy takes effect upon posting. Your continued use of the Service after the 14-day notice period has elapsed constitutes your acceptance of the updated Policy, to the extent permitted by applicable law.


19. Limitation of Liability

All limitations, exclusions, and disclaimers of liability set out in the Terms of Service (in particular Section 14) apply in full to all matters covered by this Policy, to the maximum extent permitted by applicable law. Nothing in this Policy creates any liability beyond what is set out in the Terms of Service. We are not liable for: the acts or omissions of Subprocessors beyond what is recoverable under our Data Processing Agreements with them; the contents of Backup Content or any personal data of third parties contained therein; security incidents caused by factors outside our reasonable control; or any failure to detect prohibited content in Backup Content. Our aggregate liability for privacy-related claims is subject to the cap in Terms of Service Section 14.2.


This Privacy Policy is governed by the laws of the Commonwealth of Virginia. Renvo Productions LLC d/b/a respawn.sh is a Virginia limited liability company. All other documents forming part of the Agreement are available at /legal. Contact information is published on the Main Website.

On this page

  • 1. Identity of the Data Controller
  • 2. Scope
  • 3. Definitions
  • 4. Legal Frameworks We Comply With
  • 5. Information We Collect
  • 5.1 Account and Identity Data
  • 5.2 Game Server and Backup Data
  • 5.3 Billing and Payment Data
  • 5.4 Security and Anti-Abuse Data
  • 5.5 Communications Data
  • 5.6 Marketing Website Data
  • 5.7 Data We Do Not Collect
  • 6. How and Why We Use Your Information
  • 7. Backup Content - Our Role, Access, and Limitations
  • 7.1 Our Role
  • 7.2 Encryption
  • 7.3 Our Technical Access
  • 7.4 Your Responsibility for Third-Party Data
  • 7.5 Limitation of Liability
  • 8. Cookies and Tracking Technologies
  • 8.1 Categories
  • 8.2 Consent
  • 8.3 IP and Behavioral Monitoring
  • 9. How We Share Your Information
  • 9.1 Subprocessors
  • 9.2 Legal Disclosure
  • 9.3 Business Transfers
  • 9.4 Aggregated or De-identified Data
  • 10. International Data Transfers
  • 10.1 EEA Transfers (GDPR)
  • 10.2 UK Transfers (UK GDPR)
  • 10.3 Swiss Transfers (nFADP / revDSG)
  • 10.4 Canadian Transfers (PIPEDA and Quebec Law 25)
  • 10.5 Storage Location
  • 10.6 Requesting Transfer Safeguards
  • 11. Access to Backup Content
  • 12. Security
  • 12.1 Technical Measures
  • 12.2 Organizational Measures
  • 12.3 Our Security Framework Alignment
  • 12.4 Limitations and Disclaimer
  • 12.5 Breach Notification
  • 13. Data Retention
  • 14. Account Deletion
  • 15. Your Privacy Rights
  • 15.1 Universal Rights
  • 15.2 EEA Users - GDPR Rights
  • 15.3 UK Users - UK GDPR Rights
  • 15.4 Virginia Residents - VCDPA Rights
  • 15.5 California Residents - CCPA/CPRA Rights
  • 15.6 Canadian Residents - PIPEDA Rights
  • 15.7 What a Data Export Includes
  • 15.8 Exercising Your Rights
  • 16. Children's Privacy
  • 17. Contact, Complaints, and Data Subject Requests
  • 18. Changes to This Policy
  • 19. Limitation of Liability
Back to trust center