Privacy policy
Who is responsible
The controller of your data is Gonzalo Verdugo, an individual based in Spain who runs Modyard as a free personal project. For anything about your data, write to verdugogarridogonzalo@gmail.com.
What Modyard keeps
You can browse the catalogue, read the guides and install mods without an account. Modyard keeps personal data only when you sign in and use it.
| Data | What it is | Why |
|---|---|---|
| Google account | Your name, email address, profile picture and Google account id, as Google sends them when you sign in | To create your account and know it is you |
| Sessions | A session cookie in your browser, and the session in the database with its expiry, IP address and browser | To keep you signed in, and to spot misuse |
| Publishers | The publishers you create or join, their name and slug, who belongs to each and with which role, and your invitations | To let you publish and work with others |
| API keys | Each key's name, prefix and dates. The key itself is stored only as a hash | To let your agents and scripts publish for you |
| Agent connections | The OAuth clients you authorise for MCP, your consent and the tokens issued to them | To let an agent such as claude.ai act for you |
| Mods | Every zip you publish, its files, README, versions and analysis, and the publisher it belongs to | To serve it to anyone: mods are public |
| Reports | The reason and details of each report you file, the mod it is about and your account | To moderate, and to keep a history of what was decided |
| Downloads | A count of downloads per mod version | To show how much a mod is used. It is an aggregate count: nobody is tracked per person |
Mods you publish are public. Anyone can read and install them, including the publisher name they go under, and they may already be installed on other machines. Deleting a mod or your account removes it from Modyard, not from those copies.
What Modyard does not do
No analytics, no ads, no tracking cookies and no profiling. Modyard does not sell or share your data with anyone beyond the processors below.
Cookies
Modyard sets two cookies, and both are needed for the site to work:
- The session cookie, only when you sign in, to keep you signed in.
PARAGLIDE_LOCALE, only when you choose a language, to remember it.
Who processes your data
- Google Cloud hosts the site, on Cloud Run in the europe-west1 region (Belgium).
- Supabase hosts the Postgres database where accounts, publishers, mods and reports are kept.
- Google handles the sign-in with your Google account.
Each acts on Modyard's behalf under its own data processing terms. Where any of them transfers data outside the European Economic Area, it does so under the safeguards the GDPR requires, such as standard contractual clauses.
Legal basis
- Contract: your account, your publishers, your keys and agent connections, and serving the mods you publish, because they are what you ask Modyard for when you sign up.
- Legitimate interest: keeping the site secure, preventing abuse, handling reports and moderating, and counting downloads.
How long data stays
- Account, publisher, key and connection data stays until you delete your account or ask for it to be erased.
- Sessions expire on their own, and are deleted when you sign out.
- Reports are kept after a decision, as the moderation history, even if the reported mod is removed.
- Mods stay published until their publisher deletes them or Modyard removes them.
Your rights
Under the GDPR you can ask to access your data, correct it, erase it, object to its processing, restrict it, or receive it in a portable format. Write to verdugogarridogonzalo@gmail.com from the email address of your account, and you will get an answer within one month.
If you think your data is not handled well, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es).
Changes
This policy can change. The date at the top of this page says when it last changed. The terms of use cover everything else about using Modyard.