← Back to Offchunk

Your data, explained

Privacy & cookies.

Browse the mods without creating an account. Sign in only to participate, or start a private support chat when you need help.

Updated 27 September 2026

Who is responsible?

Offchunk is operated by David Nicolas Pola (Nickynicolaus), Czechia, the controller of personal data used to run this website and its support service. For privacy questions or requests, email davidhasnexus@gmail.com.

Your community account

Google sign-in through Firebase verifies your identity. Google/Firebase processes your account identifier, email and profile information for authentication. Offchunk’s community database stores your account ID, chosen public nickname, contributions, timestamps, moderation reports and notification status. Your Google name and email are not displayed with your posts.

Your reviews, questions, replies and chosen nickname are public and may be indexed by search engines. Do not include private information in a post. You can edit or delete your own contributions. Deleting a thread also removes its replies.

We use this information in our legitimate interests to operate the voluntary mod community, answer questions, prevent abuse and moderate contributions (GDPR Article 6(1)(f)). You can read the public community without signing in. Authentication is required to contribute.

A private conversation with support

The support panel explains the chat before it connects. Selecting Start chat enables our self-hosted Chatwoot service at support.offchunk.com. It creates an anonymous contact even if you do not send a message. It uses conversation cookies and receives your IP address, browser information and page address while connected. Query parameters and fragments are removed in the browser before the address is passed to the widget. Do not put passwords, tokens or other private information in page addresses. IP geolocation is disabled; no campaigns, webhooks or agent bots are configured. It asks for an email address so we can continue helping if you leave the website. Messages and any details you choose to send are available to the support operator, not published in the community.

Gmail handles support email, including replies to existing chat conversations. Telegram receives only a conversation number and link, without your name, email, message text or attachments; link previews are disabled. Gmail receives email addresses, message content and attachments or links. An offline reply may include up to ten earlier chat messages. The mail integration checks selected headers of new messages to identify replies; unrelated personal mail is not imported into Chatwoot. A new email sent directly to our Gmail address stays in Gmail and does not automatically create a chat ticket.

We process support requests to answer questions and resolve problems in our legitimate interests (Article 6(1)(f)); where a request concerns a service agreement, Article 6(1)(b) may apply. Enabling chat storage is optional. You can email us instead. Closing the chat with its cross or Escape hides it but leaves its connection active. Use Disconnect chat to reload the page and stop the widget, or reload the page yourself. It will not connect again until you choose Start chat. Cookies and existing conversations are not deleted by disconnecting.

Cookies & browser storage

We have not added advertising trackers or Google Analytics to Offchunk. The hosting infrastructure also sets cookies before you use chat or sign-in; these are listed below, including one whose exact purpose remains unconfirmed. We do not load the chat widget until you choose Start chat. Google/Firebase authentication starts when you request sign-in, or when restoring a sign-in you previously requested on this browser.

Hosting and security — before chat

__Host-appgarden-visitor is set by the hosting platform and was measured with a 90-day lifetime. Its precise purpose and whether it qualifies for an exemption from consent have not been confirmed. We do not classify it as strictly necessary without that confirmation. It is not controlled by the chat choices on this page.

Cloudflare uses __cf_bm for bot protection (approximately 30 minutes) and cf_clearance to remember security checks (365 days in the audit; dependent on configuration). These infrastructure cookies are managed outside our application. Cloudflare cookie information.

Sign-in

Firebase uses browser storage, including IndexedDB or local storage, to maintain your authentication session. An Offchunk marker (offchunk-auth-requested) allows it to resume on your next visit. The marker is removed when you sign out; browser site-data controls can also clear it. Stored authentication can remain until sign-out or removal of site data.

Your Minecraft selection

offchunk-minecraft-v1 in session storage remembers the Minecraft version you choose in the download window across mod pages in this tab. It contains only that version number and lasts for the browser’s tab session. It is not used for tracking.

Unsent community drafts

offchunk-draft-… entries in session storage keep what you type in this tab. They are not published until you submit. They are removed when you post or discard the draft, or when the browser ends the tab session.

Support conversations

After you enable chat, cw_conversation recognises your conversation. It now uses the Secure attribute and a 30-day lifetime, renewed when the widget loads. Newly issued conversation tokens are valid for 30 days. Older tokens were not revoked by this change and may remain valid until their original expiry. Browser cookie expiry and token expiry are separate from server-side conversation retention. The server’s _chatwoot_session is a session cookie with Secure, HttpOnly and SameSite=Lax attributes. The widget also caches operator information for 24 hours and campaign information for one hour; these cache validity periods do not guarantee physical deletion from browser storage. Closing the chat does not erase these identifiers or server-side messages.

To remove stored chat identifiers, use your browser’s site-data controls for offchunk.com and support.offchunk.com. This may make an old conversation unavailable in that browser. To delete the conversation itself, contact us. Signing out or clearing site data does not delete your community contributions.

You choose whether to activate chat or sign-in. These controls do not accept or reject hosting cookies. The hosting visitor cookie still needs clarification from the provider; this notice alone does not replace any consent that may be required. Browser cookie lifetimes do not describe how long providers keep related server records.

Services that receive data

The site and community database run on OpenAI Sites infrastructure backed by Cloudflare. Google/Firebase provides authentication, Gmail delivers email, and our own server runs Chatwoot. Telegram receives support notifications. External download and profile links take you to services governed by their own privacy notices.

These providers may process information outside the European Economic Area. Their applicable processing terms and international-transfer arrangements govern that processing; hosting Chatwoot ourselves does not keep Gmail, Firebase or Telegram data exclusively on our server. Contact us for information about the arrangements applicable to your data.

How long information stays

Community profiles and contributions remain while the account and published discussions are maintained, unless you delete content or request removal. Deleting a post clears its title and body in the active community database, but related identifiers, timestamps and moderation records may remain where needed for integrity and abuse prevention.

A daily dry-run report identifies records that would qualify for deletion; it does not delete anything. Automatic retention-based deletion of support conversations, attachments and backups is not enabled. Gmail is excluded from automated deletion until support emails can be safely identified, and Telegram auto-deletion is off. Records remain until removed by the operator or following a valid erasure request. Log rotation and size limits are in place, but strict 14-day log retention is not active and these limits do not guarantee deletion after a fixed number of days. New support access logs contain time, request method, status, response size and duration; historical logs may contain more information and have restricted access. Deleting a conversation does not itself erase Gmail or backup copies. Ask us about a specific record or request erasure using the contact below.

Your choices and rights

You can request access, correction, erasure, restriction or, where applicable, portability of your data. You may object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. We do not use your data for automated decisions with legal or similarly significant effects.

Email davidhasnexus@gmail.com with your request and the account or conversation concerned. We may need to verify ownership before sharing or deleting information. Requests are normally answered within one month; any lawful extension will be explained. You can also lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ) or your local supervisory authority.