Privacy Policy
This policy explains how JLSource Community handles information when you use our game-development forum and related features.
Introduction
JLSource Community is a technical community for game development, game servers, tools, documentation and responsible knowledge sharing. This policy applies to the forum, member accounts, profiles, discussions, Marketplace features and protected resources operated under the JLSource Community name.
Information We Collect
Depending on the features you use, we may collect your username, display name, email address, profile information, avatar, banner, biography, signature and social links that you choose to provide. We also store topics, replies, messages, reactions, reports and files that you publish.
For account security and operation, the service may record IP addresses, request and authentication logs, timestamps, failed-login information and other technical security data. VIP and Marketplace records are stored when those features apply to your account. We do not ask you to place passwords, payment card data or API secrets in public posts.
How We Use Your Information
We use information to create and secure accounts, authenticate sessions, confirm email addresses, recover access, deliver requested notifications, operate discussions and profiles, moderate content, protect files, administer VIP and Marketplace features, prevent abuse and comply with legal obligations.
The applicable legal basis depends on the activity and jurisdiction. It may include performance of your request or account relationship, legitimate interests in security and community administration, compliance with legal obligations, and consent where consent is specifically required. We do not treat a general account registration as consent to unrelated marketing.
Account Registration and Security
New accounts use ASP.NET Core Identity. Email confirmation may be required before an account becomes active. Passwords are processed by the identity system and are not stored as readable passwords. Session cookies, antiforgery protection, access controls and account restriction states help protect the service. Password-reset links are time-limited and should never be shared.
Google Authentication
Google sign-in is an optional integration and is only available when it is configured for the service. If enabled and you choose it, Google provides the identity claims needed to sign you in, such as a verified email address and basic display identity. JLSource stores only the account information needed to create and maintain your member account; Google credentials are not stored by JLSource. Google processes data under its own terms and privacy policy.
Public Profiles and User Content
Forum posts, topics, public profile fields, avatars, banners and Marketplace resources may be visible to other visitors according to their visibility and moderation settings. Profiles can include private fields and privacy preferences. Private messages and private profile information are restricted to the intended participants and authorized administration.
Before publishing, check whether the content contains personal information, credentials, copyrighted material or private files. Moderators and administrators may edit, restrict, archive or remove content under the Community Rules and applicable law.
File Uploads and Malware Protection
Uploaded avatars, banners and resource files are validated for permitted type and size, stored in application-managed locations and served according to their access rules. Files that require security review remain restricted until a valid scan result is available. ClamAV scanning, hashes, audit records and quarantine controls may be used to detect suspicious or changed files.
No scanning process can guarantee that every file is harmless. Do not upload files containing secrets or information you are not authorized to share.
Data Storage and Security
The production service currently runs on an AWS EC2 host with PostgreSQL for application data and private application storage for managed files. Email delivery uses the configured Spacemail SMTP service. Access is limited by application permissions and host controls; backups and operational copies may exist for recovery and security.
Infrastructure location, providers and security controls can change. We will update this policy when a change materially affects how personal information is handled. We do not claim encryption, certifications or security guarantees beyond the controls actually deployed.
Data Retention
We retain account and community data while it is needed to operate the account, provide requested features, maintain discussion history, enforce moderation and meet legal or security obligations. Retention varies by record type. Security logs, moderation history, backups and public discussions may be retained after account closure when necessary for those purposes.
Your Privacy Rights
Subject to applicable law, you may request access to, correction of or information about your personal data, and may request deletion or restriction where appropriate. You may also object to certain processing or withdraw consent where consent is the legal basis. These rights may be limited by legal duties, security needs, the rights of other members or the integrity of public discussions.
For users in Brazil, requests will be assessed under the LGPD. Other local privacy laws may provide additional rights.
Account Deletion and Data Requests
To request access, export, correction or deletion, contact us using the address below and include the account username and a description of the request. We may need to verify account ownership before disclosing or changing information. We will not request your password by email.
Deleting an account does not automatically erase public posts, moderation records, audit trails, backups or information that must be retained for legal, security or dispute-resolution reasons. Where deletion is not possible, we will explain the applicable reason.
Third-Party Services
Services currently relevant to the forum include AWS infrastructure, PostgreSQL, Spacemail SMTP and ClamAV malware scanning. Google authentication is optional and only applies when enabled and selected by a member. Each provider processes information under its own terms; JLSource shares only what is needed for the requested operation.
Policy Updates
We may update this policy when the service, law or data practices change. The version and “last updated” date at the top of this page will change with each published revision. Material changes may also be announced through the forum or account email where appropriate.
Contact Us
For privacy, access, correction or deletion requests, email noreply@jlsource.forum with the subject “Privacy request”. This mailbox is the currently configured JLSource Community contact channel; do not include passwords, tokens or sensitive attachments.
This policy is an operational draft for legal review. Confirm the service inventory, retention periods, responsible legal contact and jurisdiction-specific notices before treating it as the final legal document.