Malevolent Gaming MultiversePrivacy Policy

What we keep.
What we never do with it.

Everything this website and its game servers record about you, why it exists, how long it survives, and how to get it back or have it erased.

Last updated19 September 2026

Fan-run, non-commercialNo data sold, everSelf-hosted analyticsAges 13+
The short version

Four promises, in plain English

The full policy is below and it is the one that counts. This is what it adds up to.

We do not sell or rent your dataNot to advertisers, not to data brokers, not to anyone. There is no ad network on this site.
No Google Analytics, no ad trackersOur stats come from Matomo running on our own server, not from a third-party analytics company.
You can get it out, or have it erasedAsk through support, the contact form or Discord and we will export or delete what we hold.
Staff read logs for two reasons onlyModeration and keeping the servers up. Not curiosity, and never for anything commercial.
The minimum

Only what an account needs

A username, an email address and a password you choose. Everything else on top of that — characters, Renown, Shards, guilds — is the game data you create by playing.

Our own roof

The stats stay in-house

Visits are measured by Matomo on our own hardware at stats.malevolentmultiverse.com. Nothing about your visit is handed to an analytics or advertising company.

One account, nine worlds

The website is the master record

Your Malevolent Gaming account here is what the game servers check when you log in. Change your password once and it moves with you across every world.

What we collect

Everything we hold, and why

Six buckets. If something is not in this list, we are not keeping it.

14 sections

Your account

Username, email, a hashed password and the profile you build on top of them.

When you create a Malevolent Gaming account we store the username, the email address you gave us and your password — the password as a one-way hash, never as readable text. Staff cannot look up your password; we can only reset it.

Alongside it sits the profile you build on the site: display name, avatar, the guilds you belong to, your friends list, your Renown rank and your Shard balance.

Where a service needs it, a Discord identifier is linked to your account so that roles, sign-in and support line up between the website and the Discord server.

What you do in the games

Characters, progression, and the login history that makes account recovery and moderation possible.

The game servers keep the things a game has to keep: your characters, their inventory, skills and progression, and the login timestamps and IP history that let staff investigate a compromised account or a rule break.

Because the website is the identity master for every world, the account record here and the account record on a game server refer to the same person by design.

Signing in

Time, result and IP for every sign-in attempt, held for 180 days.

Every sign-in, registration, password reset and failed attempt is written to a sign-in log with the time, the result and the IP address the request came from. It is what tells the difference between you forgetting a password and someone else guessing at it.

Repeated failures from one address are rate-limited. Because the site sits behind Cloudflare, the address recorded is the one Cloudflare forwards as the real visitor, not Cloudflare's own.

The sign-in log is kept for 180 days and then deleted automatically.

Site analytics

Our own Matomo counts page views. Signed in, those views carry your username.

Page views are recorded by Matomo, self-hosted at stats.malevolentmultiverse.com. It records the page, the referrer, a coarse location derived from the IP address, and the browser and screen size. Clicking certain buttons and cards also records an event, so we can see which parts of a page people actually use.

The part worth knowing:

While you are signed in, your visits carry your username in Matomo, so staff can tell one member's session from another when something breaks. Signed out, a visit is not tied to a name. Administrator visits are not counted at all.

Matomo is ours. It runs on our own machine and reports to nobody else.

Comments, posts and uploads

Your comment, plus the IP and browser it came from. Uploads can carry hidden location data — strip it first.

When you leave a comment we keep what you typed together with your IP address and browser user agent, which is what lets staff deal with abuse and spam.

Where you can upload media, other people may be able to download it and read whatever is embedded in the file. Strip EXIF location data from photographs before you upload them — a phone camera writes GPS coordinates into the image unless you have turned that off.

Support, applications and the shop

What you sent us, and which account sent it. No payment details, ever.

A support ticket keeps what you wrote and which account raised it. A staff application keeps the answers you submitted and the Discord name you gave, and it is emailed to the team.

Shop orders record which items an account redeemed and what it cost in Shards. Shards are an in-house currency — no card number, bank detail or billing address is ever handled by this website.

Nothing here matches that. Try a word from the heading, or clear the search.

Cookies

The small print, itemized

Cookies

Two jobs only: keeping you signed in, and counting visits.

Cookies here do two jobs: keeping you signed in, and counting visits. There is no advertising cookie on this site because there is no advertising on this site.

CookieWhat it doesHow long it lasts
Sign-in sessionKeeps you signed in and remembers screen preferences.Two days — or two weeks if you tick Remember me
Sign-in testChecks that your browser accepts cookies at all. Holds no personal data.Until you close the browser
Comment detailsSaves the name, email and website you typed so you need not retype them.Up to one year, and only if you ask for it
EditingPoints at the post being edited. Staff and editors only.One day
MatomoTells a returning visit from a new one for our own statistics.Matomo's defaults: 13 months for the visitor cookie, 30 minutes for the session cookie

Blocking cookies entirely will stop you from staying signed in. Clearing them signs you out and resets the counter that tells Matomo you have been here before.

Nothing here matches that. Try a word from the heading, or clear the search.

Who sees it

Where your data actually goes

Who we share it with

Cloudflare, our firewall, our own game servers, and email. Nobody else.

We do not sell, rent or trade your personal data. It is not passed to advertisers, data brokers or analytics companies, because we do not use any.

The few places data does travel:

  • Cloudflare sits in front of the website.
    • Every request reaches Cloudflare before it reaches us, so Cloudflare sees the connection and its IP address, and filters obvious attacks.
  • Wordfence is the firewall running inside the site.
    • It logs requests it blocks, including the address they came from, so staff can see an attack in progress.
  • Our own game servers receive your account status.
    • They have to: that is how logging into a world works.
  • Email leaves our systems to reach you.
    • If you ask for a password reset, the message includes the IP address the request came from so you can tell whether it was you.

That is the whole list. Nobody is paid for access to it and nothing is shared for marketing.

Embedded content from other sites

An embedded video is a visit to that other site. Their rules apply, not ours.

Some pages embed things from elsewhere — a video, an image, an article. Embedded content behaves exactly as if you had visited that other site directly.

Those sites can collect data about you, set their own cookies and track how you interact with what they embedded, especially if you have an account with them and are signed in. We have no control over what they do, and this policy does not cover them.

Nothing here matches that. Try a word from the heading, or clear the search.

How long

Nothing kept forever by accident

How long we keep things

The sign-in log expires after 180 days. Most of the rest lives as long as your account does.

Different things live for different lengths of time. The one hard rule is the sign-in log, which expires on its own.

WhatWhich dataHow long
Sign-in logTime, result and IP of every attempt180 days, then deleted automatically
Your accountUsername, email, profile, Renown, ShardsWhile the account exists
Characters and progressionHeld by each game serverWhile the account exists, or until a world is retired
CommentsThe comment and its metadataKept so replies still make sense, until you ask for removal
Support tickets and applicationsWhat you sent, and from which accountKept as a record of the decision
AnalyticsPage views and events in our MatomoKept as long-term statistics

Members can view and edit their own profile at any time from My Account, except for the username, which is fixed once it is taken. Administrators can see and edit that information too, because moderating a community requires it.

Nothing here matches that. Try a word from the heading, or clear the search.

Your rights

It is your data

You do not need a legal reason to ask. Ask, and we will do it.

What you can ask us for

A copy, a correction, an erasure — and your own creations stay yours.

  • A copy. Ask for an export of the personal data we hold about you and we will put it together.
  • A correction. Most of it you can fix yourself from My Account; ask us for the rest.
  • Deletion. Ask for your personal data to be erased. Some records have to survive a deletion — a ban, for instance — or the ban would mean nothing.
  • Your own work. The posts, screenshots and fan art you make stay yours. Putting them on the site does not hand them over to us.

How to ask:

Open a support ticket, use the contact form, or speak to staff in Discord. Ask from the account in question, or be ready to prove the account is yours — otherwise the request itself becomes the security problem.

Age

13 and over, or older where local law says so.

You must be at least 13 years old, or older where your country requires it, to hold an account here. We do not knowingly keep data about anyone younger. If you believe a child has an account, tell staff and we will remove it.

Nothing here matches that. Try a word from the heading, or clear the search.

Security

Keeping it where it belongs

How it is protected

Hashed passwords, a firewall in front, 2FA on staff accounts, and honesty if it ever fails.

  • Passwords are stored as one-way hashes. Nobody here, staff included, can read yours.
  • The site runs behind Cloudflare and an in-site firewall, and administrator accounts are protected by two-factor authentication.
  • Repeated failed sign-ins are throttled rather than allowed to run on forever.
  • Staff access to logs and member records is limited to the people who need it to moderate or to keep the servers running.

No system is perfect, and this one is run by volunteers rather than a company with a security department. Use a password you do not use anywhere else. If something does go wrong, we will say so rather than quietly hope you do not notice.

Nothing here matches that. Try a word from the heading, or clear the search.

Changes and contact

Who to talk to

Malevolent Gaming is a fan-run, non-commercial community that started as an EverQuest guild in 1999. There is no company behind it — there are people, and you can reach them.

Changes to this policy

The date at the top is the version that counts. Big changes get announced.

This policy changes when the site does. The date at the top of the page is the date it last changed, and the version on this page is always the one that applies.

If a change materially affects what we collect or who sees it, we will say so in the news feed and in Discord rather than leave you to spot the edit.

Nothing here matches that. Try a word from the heading, or clear the search.

Scroll to top