Privacy policy

Who is responsible

The controller of your data is Gonzalo Verdugo, an individual based in Spain who runs Modyard as a free personal project. For anything about your data, write to verdugogarridogonzalo@gmail.com.

What Modyard keeps

You can browse the catalogue, read the guides and install mods without an account. Modyard keeps personal data only when you sign in and use it.

DataWhat it isWhy
Google accountYour name, email address, profile picture and Google account id, as Google sends them when you sign inTo create your account and know it is you
SessionsA session cookie in your browser, and the session in the database with its expiry, IP address and browserTo keep you signed in, and to spot misuse
PublishersThe publishers you create or join, their name and slug, who belongs to each and with which role, and your invitationsTo let you publish and work with others
API keysEach key's name, prefix and dates. The key itself is stored only as a hashTo let your agents and scripts publish for you
Agent connectionsThe OAuth clients you authorise for MCP, your consent and the tokens issued to themTo let an agent such as claude.ai act for you
ModsEvery zip you publish, its files, README, versions and analysis, and the publisher it belongs toTo serve it to anyone: mods are public
ReportsThe reason and details of each report you file, the mod it is about and your accountTo moderate, and to keep a history of what was decided
DownloadsA count of downloads per mod versionTo show how much a mod is used. It is an aggregate count: nobody is tracked per person

Mods you publish are public. Anyone can read and install them, including the publisher name they go under, and they may already be installed on other machines. Deleting a mod or your account removes it from Modyard, not from those copies.

What Modyard does not do

No analytics, no ads, no tracking cookies and no profiling. Modyard does not sell or share your data with anyone beyond the processors below.

Cookies

Modyard sets two cookies, and both are needed for the site to work:

  • The session cookie, only when you sign in, to keep you signed in.
  • PARAGLIDE_LOCALE, only when you choose a language, to remember it.

Who processes your data

  • Google Cloud hosts the site, on Cloud Run in the europe-west1 region (Belgium).
  • Supabase hosts the Postgres database where accounts, publishers, mods and reports are kept.
  • Google handles the sign-in with your Google account.

Each acts on Modyard's behalf under its own data processing terms. Where any of them transfers data outside the European Economic Area, it does so under the safeguards the GDPR requires, such as standard contractual clauses.

  • Contract: your account, your publishers, your keys and agent connections, and serving the mods you publish, because they are what you ask Modyard for when you sign up.
  • Legitimate interest: keeping the site secure, preventing abuse, handling reports and moderating, and counting downloads.

How long data stays

  • Account, publisher, key and connection data stays until you delete your account or ask for it to be erased.
  • Sessions expire on their own, and are deleted when you sign out.
  • Reports are kept after a decision, as the moderation history, even if the reported mod is removed.
  • Mods stay published until their publisher deletes them or Modyard removes them.

Your rights

Under the GDPR you can ask to access your data, correct it, erase it, object to its processing, restrict it, or receive it in a portable format. Write to verdugogarridogonzalo@gmail.com from the email address of your account, and you will get an answer within one month.

If you think your data is not handled well, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es).

Changes

This policy can change. The date at the top of this page says when it last changed. The terms of use cover everything else about using Modyard.