Privacy

Last updated 23 September 2026

01What we collect

Account data: the email address you sign up with, the display name you choose, and — if you use Google or Discord — the profile name, email and avatar those services hand us. We never receive your Google or Discord password.

Bot data: the server addresses you add, the Minecraft usernames you attach to them, and the connection state of each bot.

Usage data: how much online time you have earned, which sponsor links you completed, daily bonuses you claimed, invites you sent, and the resulting balance entries.

Technical data: your IP address and standard server logs, kept so we can spot abuse and debug failures.

02Why we collect it

To run the service: connecting bots, metering the time they consume and showing you an accurate balance.

To stop abuse: sponsor links pay us per verified completion, so we need to detect duplicate or forged completions.

To reach you: password resets, alerts when a bot drops, and answers to messages you send us.

03Minecraft account credentials

For Microsoft accounts we use the official device-code login flow. You approve the login on Microsoft's own page and we receive an access token — we never see or store your Microsoft password.

Tokens are encrypted before they are written to the database and are only decrypted in memory when a bot connects. Removing a bot account deletes its token.

Offline-mode (Java) bots need no credentials at all: only the username you choose.

04Sponsor links and other services

Online time is funded by sponsor link providers. When you open a sponsor link you leave RunAFK and land on that provider's site, where their own privacy policy and cookies apply.

We send the provider a one-time random token so we can match your completion. We do not send them your email address or your name.

Our database lives on Supabase (PostgreSQL). The site and the bot workers run on our own servers.

05Cookies

A session cookie keeps you signed in. Without it there is no way to stay logged in.

A language cookie remembers whether you picked English or Turkish.

We do not run advertising or cross-site tracking cookies of our own.

06How long we keep it

Account, server and bot data stay until you delete them or delete your account.

Balance entries stay while the account exists, because they are the ledger behind your time.

Server logs are rotated regularly and are not kept long-term.

07Your rights

You can see and change your profile data in Settings at any time.

You can ask for a copy of everything we hold about you, or ask us to delete it. Deleting your account removes your servers, bots, tokens and balance.

Write to the address in the contact section and we will act on it.

08Children

RunAFK is not aimed at children under 13. If you believe a child has created an account, contact us and we will remove it.

09Changes

If this policy changes in a way that affects you, we will say so on this page and update the date above.

10Contact

Questions about this policy, or about data we hold: use the contact page or email us directly.