Legal
Privacy Policy
Last updated: 5 July 2026
This policy covers the LuaNet Android app, the LuaNet website, and the NovaX External link control plane.
Contact: [email protected]
Summary
- LuaNet stores server data in app-private storage on the device.
- LuaNet does not upload worlds, game chat, player names, installed mods, or console logs to NovaX.
- Account and External link features use Firebase-backed authentication and send limited tunnel metadata to NovaX.
- Google AdMob/UMP may process advertising and consent data.
- Public game packets pass through the NovaX relay in transit when External link is active, but are not retained.
Data processed on the phone
LuaNet stores server profiles, worlds, games, mods, backups, settings, logs, player metadata, and ContentDB downloads in app-private storage on the Android device. This local hosting data stays on the phone unless the user exports it or shares it through Android.
The app may access network state, Wi-Fi state, foreground service, wake lock, notification, and storage/document picker capabilities only to run local servers, keep them reachable, show server status, import/export content, and notify the user.
Data sent to NovaX
For External link, the app sends Firebase account identifiers, app-generated device or installation identifiers, tunnel hold/lease metadata, assigned ports, lease timestamps, hashed tunnel session credentials, and aggregate usage needed for limits and abuse prevention.
NovaX does not receive or store world files, chat, console logs, in-game player names, game content packages, or local server configuration.
Third-party services
LuaNet uses Firebase Authentication, Google AdMob and the Google User Messaging Platform, ContentDB, GitHub sign-in, Cloudflare, and NovaX infrastructure when the related feature is used. Google Play Billing applies only if paid features are re-enabled in a future release. Each provider may process data under its own terms and privacy notices.
Advertising and analytics
LuaNet may show AdMob ads, including rewarded ads, banner ads, and occasional session interstitial ads. Google UMP is used for consent where required.
LuaNet does not run behavioral analytics. Crash reporting is disabled unless the user explicitly opts in.
Retention
- Account and active tunnel records are kept while the account exists or while needed to provide the feature.
- Stopped tunnel ports are kept only for the short grace period needed to prevent accidental reassignment during reconnects.
- Security and anti-abuse logs are retained for up to 30 days.
- Provider-side records follow Google, Firebase, AdMob, Play, GitHub, ContentDB, and Cloudflare retention rules.
- Local worlds and app data remain on the phone until the user deletes profiles, clears app data, or uninstalls LuaNet.
Account and data deletion
Users can delete their LuaNet account from the app. Deletion revokes active tunnels, removes NovaX tunnel allocations, and deletes the Firebase Auth user. Security records may remain for up to 30 days where needed for abuse prevention or legal obligations.
Users can also request deletion from the web through the account deletion page.
Deleting the LuaNet account does not delete local worlds or backups on the phone. Those remain under the user's local control.
Children
LuaNet is intended for a Teen/13+ audience and is not directed to children. Users under the minimum age required by their jurisdiction should not create a LuaNet account or use External link without appropriate permission.
User rights
Depending on location, users may have rights to access, correct, delete, export, restrict, or object to processing of their personal data. Send requests to [email protected].
Security
LuaNet uses HTTPS/TLS for API traffic and keeps tunnel credentials temporary. The app never asks users to disable Luanti mod security. Public tunnels carry traffic only for the selected Luanti server port.
Changes
This policy may be updated as LuaNet changes. The latest version is published on this page and reflected in the Play Console Data safety declaration.