This is a small Minecraft community, not a corporation — here's a plain-language rundown of what we collect, why, and what we do with it.
Creating a KOS Network account and playing on the server involves storing the following:
Your email address, your Minecraft username and UUID, and — if you link Discord — your Discord ID, username, and avatar. If you sign up with a password instead of Discord, we store a hashed version of it, never the password itself.
We record the IP address associated with your Minecraft logins. This is specifically to detect alt accounts — if a punished player logs in on a second account from the same IP, we can tell. It's used to apply bans and mutes consistently across a player's accounts and to catch ban evasion. It is never shown publicly, and it isn't used for anything besides this.
Bans and mutes issued to your Minecraft account are logged and tied to your UUID, so staff can see prior offenses and apply the right strike tier if you break a rule again.
We keep a count of how many support tickets and staff applications you've opened, plus the content of those tickets/applications themselves, so staff can review them and spot abuse of the system.
Any site preferences you set in Account Settings (like hiding certain nav links) and an optional profile picture you choose to upload are stored against your account.
When you log in, we set a single signed session cookie (kos_account_session). It's HttpOnly and Secure, expires after 30 days, and exists purely to keep you logged in. We don't use it, or anything else, for third-party tracking or advertising.
Nothing here is collected for marketing or resale. Every field exists for one of these reasons:
Account creation and login — your email, Minecraft account, and/or Discord account verify who you are.
Verifying ownership — confirming a Minecraft username/UUID or Discord account actually belongs to you before linking it.
Enforcing bans and mutes consistently — including catching alt accounts used to dodge a punishment.
Letting staff review tickets and applications — someone has to read what you submit to act on it.
Basic site functionality — preferences, avatars, and staying logged in.
Your data sticks around for as long as your account exists. If you want it gone, use the Delete My Account button in Account Settings — this removes your account and the data tied to it. Punishment history tied to your Minecraft UUID may be retained separately for moderation integrity, since bans need to survive account deletion to stop ban evasion.
Staff can see your punishment history and the content of your tickets and applications — that's how moderation and support work. Alt-account correlation (the IP-based linking described above) is never shown publicly or to other players. It's used internally, by the system and by staff, only to apply consistent restrictions across linked accounts.
Used for OAuth login and syncing your server roles. If you link Discord, they handle the authentication — we only receive your ID, username, and avatar.
Used to verify that a Minecraft username and UUID are real and belong to you.
Used to send account verification and password reset emails. It's not used for marketing or newsletters — if we don't have it configured, those emails simply aren't sent.
For privacy questions or to request your data be deleted, email kos.network.email@gmail.com or open a request on the Tickets page.