LEGAL

Privacy Policy

What ResourcePack AI records about you, why, who else ever sees it, and what you can ask us to do about it. The short version: we store what the product needs to work, we run no analytics and no advertising, and we do not train AI models on your prompts or your creations.

LAST UPDATED 14 August 2026

1Who we are, and how to reach us

ResourcePack AI (we, us) runs resourcepack.ai and everything on it: the marketing site, the documentation, the Studio app at studio.resourcepack.ai, the sync service that connects a pack to a Minecraft server, our Discord bot, the plugins we publish, and our public test server. We operate from the United Kingdom, and for UK GDPR purposes we are the controller of the personal data described here.

Write to support@resourcepack.ai for anything about this policy — put Privacy in the subject line and it gets handled as a data-protection request rather than as support.

2Age, and children

You must be at least 13 to use ResourcePack AI. If you are in the United Kingdom or the EEA and under 16, a parent or guardian has to agree to our Terms of Service and consent to this policy on your behalf before you sign up.

We do not knowingly collect anything from children under 13, and we do not build profiles of anyone or target advertising at anyone, at any age. If you believe a child under 13 has an account, email support@resourcepack.ai and we will delete the account and its contents.

3What we collect

Your account

Your name, email address and avatar image URL. If you set a password we store a hash of it, never the password itself. If you sign in with GitHub, Google, Discord, Microsoft or X, we receive the basic profile that provider returns and store your account id with them plus the access and refresh tokens that keep the connection working. We use those tokens only to identify you at sign-in — we do not read your repositories, mailbox, calendar, contacts or posts.

Sessions and security records

Each signed-in session records its IP address, browser user-agent string and expiry. Our infrastructure provider, which serves every request for us, keeps its own short-lived edge and security logs. We use both to keep accounts secure, to enforce rate limits, and to spot duplicate accounts made to claim the free monthly credits more than once — which our Terms of Service does not allow. We are looking for the same person signing up repeatedly, not building a picture of where you are.

Your packs and everything in them

The resource packs you create and their contents: textures, block models, animations, sounds, skins, font icons, pack art, names and descriptions, version history and thumbnails. Also the prompts you write, the reference images you upload, and the edits you ask for.

Minecraft details, if you connect them

If you link a Minecraft account we store its username and UUID, and whether that link was verified on our test server. If you pair a pack with a server you run, we handle the short-lived pairing code and a record of which server the pack was pushed to.

Usage, credits and payments

A record of each generation you run — what kind it was, which model served it, how long it took and what it cost — and the ledger of AI Credits granted, spent, refunded and expired. For paid plans we store your Stripe customer and subscription identifiers, your plan, and the state of your purchases. We never see or store your card details. Those go straight to Stripe, which is the payment processor.

Provider keys you choose to bring

On plans that allow it you can supply your own AI provider API key. We encrypt it at rest with AES-GCM and use it only to make the calls you ask for. You can delete it from your account at any time, which removes it from our database.

Notification settings

Which of the three channels — email, a Discord DM, a line of Minecraft chat — you have switched on for finished generations. All three are off unless you turn them on. The Discord DM uses the Discord user id we already hold from your sign-in; there is no separate Discord setting to store.

Players on servers you distribute to

If you switch on Distribution and bind your Minecraft server to a pack, that server tells us, for each player who joins it, their Minecraft username and UUID, which Minecraft version they connected on, whether they are on Java or Bedrock, and whether their client accepted the pack. We hold it so the Distribution page can show you who is using your pack. We also count downloads, with the client version and country of the request, without holding an address against them.

This is your data about your players, held on your instructions. You decide what is collected by choosing to distribute, we only process it to produce your dashboard, and it is deleted when you unbind that server or delete the pack. We do not use it to build a profile of any player, sell it, or share it with anyone else. If a player wants their row removed, unbinding the server removes every one of them; ask us and we will remove a single player.

Announcement emails

We keep a list of email addresses for occasional announcements about the product — a new feature, a change worth knowing about. Against an address on it we store when it was added, where it came from, whether it has been unsubscribed, and a random token that identifies the address to the unsubscribe link, so that using that link never requires signing in.

Every announcement carries an Unsubscribe link in its footer, and one click is the whole process. When you use it we record that you unsubscribed rather than deleting the address outright — that record is what stops you being added back the next time the list is built. Unsubscribing does not affect the emails the service itself has to send you: a password reset, a receipt, an invitation to a pack, or a generation finishing.

The waitlist

If you joined the pre-launch waitlist we store your email address, the IP address and browser user-agent the signup came from, and the time. The IP address is there to stop the same person or script filling the list, nothing else.

Talking to us

Emails you send us and messages you send us on Discord, along with whatever you choose to put in them.

4What we deliberately do not do

Some of this policy is shorter than it might be, because these things simply do not happen:

  • No analytics or tracking. There is no Google Analytics, no Plausible, no PostHog, no session recorder and no advertising pixel anywhere on our sites. We do not build a profile of what you look at.
  • No advertising, ever. We have no ad network, no advertising cookies and no interest categories.
  • We do not sell, rent or trade your personal data, and we do not share it with data brokers.
  • No selling of your creations. We do not licence, publish or resell the packs and assets you make.

5We do not train AI models on your content

Your prompts, your uploaded reference images, and the textures, models, sounds and skins the service generates for you are not used to train, fine-tune or evaluate our models. They are not added to any training set, they are not reviewed to build one, and they are not licensed to anyone else for that purpose. Your pack is yours; it is stored so we can show it back to you and so you can ship it.

When a generation needs a third-party model we send that provider only what the request needs, and we use their API on terms under which the content is not used to train their models where that choice is offered.

We do look at aggregate numbers — how long a kind of generation takes, how often one fails, what it costs — to keep the service working and priced sanely. That is counting, not reading, and it never leaves our own systems.

If this ever changed, it would change here first, we would tell account holders before it took effect, and it would be something you opt into rather than something you have to notice and switch off.

6Why we use it, and our legal bases

  • To perform our contract with you — creating your account, storing and serving your packs, running the generations you ask for, syncing a pack to a server, metering and billing.
  • Our legitimate interests — keeping accounts and credits secure, preventing abuse and fraud, enforcing rate limits and our one-account-per-person rule, diagnosing faults, and understanding in aggregate which parts of the product work.
  • Your consent — the notification channels, the waitlist, and our announcement emails. You can withdraw consent at any time, from your account settings, from the unsubscribe link at the bottom of any announcement, or by asking us.
  • Legal obligation — keeping records of payments for tax and accounting.

7Who else handles it

We use a small number of service providers to run the product. Each gets only what its job needs, and none of them are allowed to use it for their own purposes.

  • Our infrastructure provider — hosting, our database, object storage for pack contents, our CDN, email delivery, and edge security. Effectively everything is stored on their infrastructure.
  • Stripe — payments and subscriptions. Your billing and card details are given to Stripe directly and are governed by their privacy policy; we receive back only identifiers, the plan, and whether a payment succeeded.
  • Our AI providers — image, model, and sound generation each run on a third-party model service, which receives the prompt and any reference image needed to produce that one output. Some of them are hosted in the United States.
  • Mojang, via a skin signing service— a Minecraft client will only load a skin from Mojang’s own host, so applying a generated skin in-game means uploading that image to be signed. This happens only when you apply a skin.
  • Discord — if you turn on Discord notifications, our bot sends your Discord user id and the text of the notification to Discord in order to DM you.
  • The sign-in provider you choose — GitHub, Google, Discord, Microsoft or X, each of which learns that you signed in to us.

We may also disclose information if the law requires it, to establish or defend legal claims, or to protect people from harm. If the business were ever sold or reorganised, information would transfer with it and we would tell you first.

8Things you share with other people

Some parts of the product hand your content to somebody else because that is the point of the feature. It is worth being clear about which:

  • Pack members. If you invite someone to a pack, they can see and edit everything in it, and can see who did what. Membership is per pack — inviting someone to one pack gives them nothing in any other.
  • Pushing to a Minecraft server. When you push a pack to a server you have linked, a signed, time-limited download link for that pack goes to that server. Whoever runs it can therefore obtain a copy of the pack.
  • Distributing a pack.A pack you publish for distribution is downloadable by anyone who has its link, which is by design — it is being served to your players. The link is not guessable from your pack’s name, and nothing is served until you publish and switch distribution on.
  • Our test server. If you play there, it sees your Minecraft username and UUID and asks us which plan rank or supporter badge you hold, so it can show it. It is not told your email address, your packs, or anything else about your account.

9Cookies

We set strictly necessary cookies only: the ones that keep you signed in and protect the sign-in form, plus the security cookies our infrastructure provider sets. There are no analytics, advertising or cross-site tracking cookies, which is why you have never seen a consent banner here — there is nothing to consent to.

Blocking the necessary cookies will stop you being able to sign in.

10Where your data goes

We are in the United Kingdom, and some of our providers — including our payment processor and several AI providers — are in the United States or serve requests from wherever their network is closest. Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision, as applicable.

11How long we keep it

  • Your account and your packs — for as long as your account exists. When you delete an asset or a pack, we remove it from storage; copies may persist briefly in caches and backups before they age out.
  • Sessions — until they expire, then they are cleared.
  • Generation and credit records — kept while your account exists, because they are the account of what your credits were spent on.
  • Payment records — kept for as long as UK tax and accounting law requires, currently six years, even after an account is closed. This is the one category deleting your account does not clear.
  • Waitlist entries — until launch, or until you ask us to remove yours.
  • The announcement list — an address stays on it until it is unsubscribed. After that we keep the address and the fact that it opted out, for as long as the list exists, because forgetting it is the one thing that would let a later addition put you back on.

12Your rights

Under UK and EU data protection law you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or send it to another service in a portable form. You can withdraw consent at any time without affecting what came before. Email support@resourcepack.ai; we will respond within one month.

Deleting your account

There is not yet a self-serve delete button in the product — we are building it. Until there is, email support@resourcepack.ai from the address on the account and we will delete the account, its packs and its assets, keeping only the payment records described above. We would rather say that plainly than imply a button exists.

Complaints

If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk), or to the supervisory authority in your country if you are in the EEA.

13How we protect it

Traffic is encrypted in transit. Pack contents live in private storage that is reachable only through short-lived signed links. Passwords are hashed. Any provider key you bring is encrypted at rest. Credentials for the services we depend on are held as platform secrets, split across the smallest number of systems that need them. Card details never reach us at all.

No service is perfectly secure. If a breach happens that puts your rights at risk, we will tell the ICO within 72 hours where required, and tell you without undue delay.

14Changes to this policy

The product is under active development and this page will change with it. We will update the date at the top whenever it does. If a change materially affects how we handle your data — the no-training commitment above especially — we will tell account holders by email or in the product before it takes effect, rather than relying on you to re-read this page.