You can browse and download mods without an account. The view and download counters don't record who you are, though the server's request log keeps your IP address for about two weeks (see Everywhere on the site). Signing in with Discord adds the things you do on purpose: likes, follows, comments, reports and collections. What the site keeps from your Discord account is on What data we collect, and what it keeps from mod authors is on Author data.

Views and downloads

Every mod shows how many times it was viewed and downloaded. To count each person once a day, the site mixes your IP address and your browser's user agent with the date and a server secret. It stores the resulting code with the mod or version and the day. It also stores a second code made from your IP address alone, so one address can't add more than three people to a count in a day. That code is the same on every mod you view or download that day.

Your IP address itself is never written to the database, and without the server's secret nobody can turn a code back into an address or match codes from different days. The codes are deleted after two days. Only the counts stay: totals for the mod and for each version, and one number for each day.

A view counts once a day per mod, and a download once a day per version. Bots, link previews and pages your browser loads ahead of time don't count. A mod's own authors don't add views to it while they are signed in, but their downloads count like anyone else's.

To slow down anyone who sends too many requests, the server also keeps your IP address in memory until it restarts. That copy is never saved. The request log below is a separate record.

Everywhere on the site

These apply to every page, mods or not:

  • Every request goes through Cloudflare, which delivers the site. Cloudflare sees your IP address, your browser and each address you open.
  • Cloudflare Web Analytics receives the address of each page you open, the page you came from and how fast it loaded. It sets no cookie, and the site reads the results only as totals.
  • The server logs every request that reaches it: your IP address, your browser, the address you asked for, the page you came from, your language and the time. A full log file is kept for at most 14 days, so a request can stay in the log a little longer than two weeks. CrowdSec reads the logs to spot attacks, and the addresses it flags are shared with CrowdSec's community blocklist.
  • Profile pictures and banners load straight from Discord's servers, and video covers in the mods section from YouTube's, so Discord and Google see your IP address when those pictures load. A mod's video player loads from youtube-nocookie.com only after you press play.

When you sign in

Everything in this table stays until you remove it, except reports, which are kept for good.

What you doWhat is storedWho can see it
Like a mod or a collection That you liked it, and when Everyone sees the number of likes and, on a mod's Stats tab, how many came in each day. Only you see that the like is yours.
Follow a mod, a collection or an author That you follow it, and when Everyone sees the number of followers. The list of followers isn't shown anywhere.
Comment The text, when you posted it and when you last edited it Everyone who can open the mod. An edit replaces the old text.
Notify me about new comments Your choice for that mod. Posting a comment turns it on, unless you turned it off before. Only you.
Report The reason, your message, your account and what you reported. Reports are kept for good, as the moderation record. Moderators only. The mod's authors never learn who reported it or what you wrote.
Build a collection Its name, summary, description and visibility, the mods in it with your note on each, and when you added them Public: everyone. Unlisted: anyone with the link. Private: only you.

The Following page is built from your follows each time you open it. It leaves out mods that are no longer public and authors who went incognito, but those follows stay stored. Nobody else can see the page.

Deleted comments

When you delete your own comment, its text is removed. The site keeps the fact that you commented and when, and if the comment has replies, an empty "deleted" line holds its place above them. When a moderator deletes a comment, the moderators' log keeps up to 280 characters of it for good, so that the decision can be checked later. Deleting your own comment leaves nothing in that log.

Notifications

The bell keeps notes about mods and authors you follow, comments you watch, replies to you and reports you filed. Read notes are deleted after 90 days, and every note after a year.

Push notifications are off until you turn them on in the bell. Then the site stores the address your browser's push service gave it and the keys that encrypt each message. The push service (Google, Mozilla, Apple or Microsoft, depending on the browser) carries the messages but can't read them. Turning push off deletes the address, and so does the push service reporting it gone.

Incognito and bans

Turn on Incognito under Privacy on your profile, and your comments and collections show "Incognito" to other players. Moderators still see your name. While Incognito is on, nobody can start following you as an author. Incognito changes what other people see; it deletes nothing.

A ban stops likes, follows, comments, reports and changes to collections, and it stops you undoing them too: until the ban ends you can't unlike, unfollow, or edit or delete your comments. You can still browse, download, turn comment notifications on or off and turn push on or off.

In your browser

The mods section keeps a few settings in your browser. They are never sent to the site.

KeyWhat it remembers
lucidpedia:mods-view Grid or list view in the catalog.
lucidpedia:mods-seen-at When you last opened the catalog, to mark what's new since then.
lucidpedia:mods-follow-nudge The mods where you already saw the suggestion to follow after a download.
lucidpedia:mods-catalog The last catalog address you had open, so Browse brings you back to it. Cleared when you close the tab.

The site sets a sign-in cookie while you are signed in, and two more for the 10 minutes a sign-in can take. Cloudflare can add its own security cookie, cf_clearance, when it checks your browser.

Removing your data

You can unlike, unfollow, delete a comment or delete a collection yourself, except while you are banned. Once a mod is hidden or taken off the site, or a collection is made private or hidden, your like, follow and comments there stay, and you can't remove them yourself; ask the staff. You can turn push off at any time. A report can't be taken back.

There is no button that deletes a whole account. To ask for that, write to the staff on the Lucidpedia Discord server.