1. Who we are and scope
Beacon Atlas is operated by ThoughtsOnThings LLC, based in Brooklyn, New York, USA. We are the controller for the Atlas data described here. Contact us at admin@beacon-mc.io.
This statement covers Atlas only. A beacon's dashboard, allowlist, world files, backups, chat history, audit logs, and connection logs live on the operator's own server and are controlled by that operator, not by us.
2. Information we collect
Beacon registration
Atlas has no website accounts — no name, email, or password. When a beacon registers, we store its generated beacon ID, a hashed client secret, a display name, a slug, the redirect-URI allowlist used for sign-in, and timestamps. The raw secret is shown to the operator once and never stored; operators manage the registration over HTTPS with the beacon ID and secret.
Listings and heartbeats
A listing stores what an operator chooses to publish — server name, description, tags, region, Minecraft address, links, rules, events, and visibility settings — plus heartbeat data: online status, compatible version, loader, installed mods or plugins, player counts, and an optional Vantage-stream capability. Atlas may ping the advertised Minecraft address and keeps hourly aggregate availability statistics.
The member roster and recent activity are stored only when the operator opts into each. Roster and activity may include Minecraft usernames, account IDs, roles, online status, and recent gameplay activity. An opted-in Vantage world is streamed directly from the independently operated beacon; Atlas does not store or proxy its manifest, texture array, tiles, or thumbnails.
Minecraft sign-in broker
To confirm a player's Minecraft identity we process Microsoft sign-in artifacts, a Microsoft access token used once to look up the Minecraft profile, the Minecraft username, and the Minecraft account ID (UUID). We do not receive the player's Microsoft password or email address, do not request offline access, and do not store Microsoft, Xbox, or Minecraft tokens. Each sign-in attempt creates a short-lived record (request state, nonce, PKCE challenge) that expires within minutes.
Reports
If you report a listing, we store the reason you select, any detail you add, and a hashed form of your IP address used for rate-limiting and abuse prevention. We do not store your raw IP address with a report.
Communications and technical delivery
Atlas sends no transactional email. If you email admin@beacon-mc.io, we process the contact details and message content needed to respond. Our hosting and database providers process technical data such as IP addresses and request metadata to deliver, secure, and maintain the service.
3. Why we use information
- Provide the service — registrations, listings, heartbeats, public pages, documentation, and the sign-in broker.
- Secure the service — secret hashing, redirect URI checks, abuse prevention, and reliability monitoring.
- Respond to you — support replies and security notices when you contact us.
- Operate the public directory — search, discovery, live status, and aggregate statistics.
- Comply with law and enforce our [Terms](/terms).
For EEA and UK users, our legal bases are contract where needed to provide the service, legitimate interests where needed to operate and secure Atlas, consent where we ask for it, and legal obligation where the law requires processing.
4. Public listings and operator control
Listings are public by design and may be viewed, indexed by search engines, cached, copied, and shared by others. Operators decide what their beacons publish to Atlas and are responsible for any player information they choose to expose. For player data stored on a beacon itself, the operator is the independent controller.
7. How long we keep information
- Beacon registrations, listings, and listing content — until deleted by the operator or removed under our Terms, subject to limited backup retention and legal or security needs.
- Broker sign-in attempts — about 10 minutes; one-time codes about 2 minutes; signed identity statements expire after about 5 minutes and are not stored by us.
- Hourly heartbeat statistics — about 90 days.
- Backups — age out under our database provider's retention process.
- Support and legal communications — as long as reasonably needed to handle the request and keep business records.
8. Where information is processed
We are based in the United States and process Atlas information primarily there; our providers may process it in other countries. Where transfer safeguards are required, we rely on provider data-processing terms, Standard Contractual Clauses, Data Privacy Framework participation, or other lawful transfer mechanisms.
9. Your choices and rights
Operators can edit, pause, or delete a listing from their beacon's dashboard. To delete a beacon registration, or for access, correction, deletion, export, objection, restriction, or other privacy requests, email admin@beacon-mc.io.
Your rights depend on where you live. EEA and UK users may also complain to their local supervisory authority; US state privacy rights can be exercised by contacting us. Because we do not sell personal information or share it for targeted advertising, there is no sale or share opt-out to offer.
10. Security
We use safeguards proportionate to what Atlas handles: TLS for traffic, hashed client secrets, short-lived broker artifacts, exact redirect URI allowlists, and minimal cookies. No online service is perfectly secure; if a breach requires notice, we will provide it as the law requires.
11. Children
Beacon Atlas is not directed to children under 13, and children under 13 may not register a beacon or use the sign-in broker. If we learn we collected personal information from a child under 13 without the required consent, we will delete it. A player's use of an individual beacon is between them and that server's operator; if you are a parent or guardian with a concern about Atlas itself, contact us at admin@beacon-mc.io.
12. Changes and contact
We may update this statement as Atlas changes and will revise the effective date when we do. Questions, requests, or complaints can be sent to admin@beacon-mc.io.