Back to i.らぶ.moe
Privacy Policy
Established and effective: July 24, 2026

The operator of i.らぶ.moe (the “Operator”) handles user information processed through the Service as described below, in accordance with Japan’s Act on the Protection of Personal Information and other applicable laws.

1. Information we collect

The Operator collects the following information:

  1. Account information: Email address, user ID, and registration time.
  2. Device and authentication information: Device IDs; hashes of device tokens, sign-in links, sessions, and passphrase access tokens; creation and expiration times; and last-used times.
  3. Uploaded data: Screenshots, image titles, file sizes and dimensions, album names and descriptions, display order, tags, favorites, visibility, Minecraft server names and addresses, server-page profiles, verification and editor information, connected custom domains, short URLs, and expiration dates.
  4. Discord integration information: Encrypted webhook URLs, management display names, enabled or disabled status, delivery results, and delivery times.
  5. Minecraft profile information: Minecraft UUIDs and Minecraft IDs sent by the Mod with images, source devices, first- and last-seen times; UUIDs, Minecraft IDs, and verification times confirmed by the Velocity verification server; hashes and expiration times of verification codes; and per-image display settings.
  6. Verification server connection information: Connection times, source IP addresses, and other logs required for secure operation of Velocity and the VPS.
  7. Protection settings: Salts and hashes derived from passphrases. The passphrases themselves are not stored.
  8. Subscription information: Stripe Customer, Subscription, and Price IDs; subscription status; billing interval; price; scheduled cancellation time; and payment success or failure. Stripe handles card numbers and other payment credentials, which are not stored in the Operator’s database.
  9. Usage and security information: Upload and access times, automated image-check results and model versions, error and processing logs, IP addresses transformed into keyed hashes for rate limiting and anonymous-favorite deduplication, email addresses similarly transformed for rate limiting, and technical information accompanying browser and network communication.

2. Purposes of use

  1. To provide image storage, short-URL sharing, albums, visibility controls, and other Service features.
  2. To authenticate devices, send magic links, maintain sessions, and verify identity.
  3. To process Plus enrollment, payment, subscription status, cancellation, and support.
  4. To manage expiration, usage limits, migration, and other plan-specific features.
  5. To notify Discord channels configured by verified-server managers about public images.
  6. To detect and prevent unauthorized access, passphrase guessing, excessive device registration, prohibited content, and other violations of the Terms.
  7. To investigate failures, improve quality, understand usage, and send operational notices.
  8. To comply with legal obligations and address disputes or rights infringements.

3. Cookies and locally stored authentication information

  1. The Service uses an HttpOnly, Secure, SameSite=Lax session cookie to maintain sign-in for up to 30 days.
  2. A similarly protected cookie maintains permission to view passphrase-protected content for up to 24 hours.
  3. The Fabric Mod stores a token on your device to identify it and authenticate uploads.
  4. Immediately before the first upload, the Mod explains what will be sent. Only after you agree does it send the Minecraft UUID and Minecraft ID with an image. It does not send them before an upload.
  5. A SameSite=Lax preference cookie stores the language selected in the footer for up to one year.
  6. These technologies are necessary to provide and secure the Service. The Operator does not use advertising-tracking cookies.

4. Public and shared content

  1. Public Uploaded Data, server-page profiles, and verified connection addresses can be viewed by anyone, including through search results and user-connected custom domains.
  2. Uploaded Data shared with anyone who has the URL can be viewed by anyone who knows it.
  3. Passphrase-protected Uploaded Data can be viewed by people who know both the URL and the passphrase. You are responsible for managing disclosure of the passphrase.
  4. Private Uploaded Data can generally be viewed only by its signed-in owner.
  5. Information you share with another person may be stored or reshared by that recipient.
  6. If a server manager configures a Discord webhook, public images associated with that server may send their title, image, sharing URL, server details, and any publicly displayed Minecraft ID to the configured Discord channel.

5. Service providers

The Operator entrusts information to the following providers only as necessary to provide the Service. They may use infrastructure outside Japan.

  1. Cloudflare, Inc.: Workers, D1, R2, Queues, email delivery, Turnstile, content delivery, security, and logging infrastructure.
  2. Stripe, Inc. and its affiliates: Payments, recurring billing, Customer Portal, and fraud prevention.
  3. Amazon Web Services, Inc.: Automated prohibited-content checks. Before storage, a resized and converted temporary copy of an image is sent to Amazon Rekognition. The moderation result and model version are recorded.
  4. Discord Inc.: Channel notifications for public images when enabled by a verified-server manager.

Each provider’s privacy policy applies to its handling of information.

6. Disclosure to third parties

The Operator does not provide personal data to third parties except with your consent, as required by law, when necessary to protect life, body, or property, in connection with a business succession, or when processing is entrusted in a manner that is not legally treated as third-party disclosure.

7. Retention and deletion

  1. Image files are generally retained until the expiration shown at upload. As of this Policy’s effective date, the period is 60 days for Free and 365 days for Plus.
  2. When you delete an image or its retention period expires, the image is scheduled for deletion. Short processing delays, cached copies, or disaster-recovery remnants may temporarily remain.
  3. Magic links remain valid for 15 minutes, sign-in sessions for 30 days, and passphrase viewing permission for 24 hours.
  4. Account information, subscription and transaction records, security logs, and minimal metadata about deleted data are retained only as necessary for operation, legal compliance, dispute handling, and abuse prevention, then deleted or de-identified.

8. Security measures

The Operator uses measures appropriate to the information handled, including access controls, hashing of authentication tokens and passphrases, encrypted transport, separation of privileges, rate limits, log monitoring, and expiration-based deletion. However, internet security cannot be guaranteed completely.

9. Requests for disclosure, correction, or suspension

Subject to applicable law, you may request notice of purpose, disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of third-party provision of your retained personal data. The Operator will verify identity and respond in accordance with law. Use the contact information in the Commercial Transactions Disclosure linked from the footer.

10. Information about minors

Minors must use the Service with consent from a parent or other legal representative. The Operator may request confirmation of that consent when necessary.

11. Changes to this Policy

The Operator may change this Policy in response to changes in law or the Service. Material changes will be announced through the website or another appropriate method before taking effect.

12. Contact

For questions about this Policy, handling of personal information, or disclosure requests, use the Operator contact information in the Commercial Transactions Disclosure linked from the footer.