Return

Privacy Policy

Last updated: 11 September 2026

RFU Back-End ("the service", "we", "us") is the online service used by RiccioFishingUtils. This policy applies only to data processed by the RFU Back-End. It does not cover Minecraft, Mojang/Microsoft, Hypixel, Discord, GitHub, Patreon, or any other third-party service.

At a glance

  • We do not sell personal data, serve advertising, or use advertising trackers.
  • The service provides Party Finder, live dye tracking, announcements, configuration synchronization, and update information.
  • Party Finder and authenticated real-time features require the optional backend connection to be enabled. Version checks and the latest-announcement request can be made without that connection.

Data we process

When a client connects to the service, we process the following data as needed to run it:

DataWhy it is used
Minecraft username and UUIDTo authenticate you and identify your Party Finder listing or join request.
RFU and Minecraft versionTo provide compatibility checks and aggregate version statistics.
IP address, network port, session ID, timestamps, and backend actions To operate and secure the service, troubleshoot problems, apply rate limits, and investigate abuse.
Party Finder data Your username, party title and description, island, fishing type, requirements, selected sea creatures, and current/maximum party size. This information is shared with other connected RFU users so Party Finder can work.
SkyBlock profile ID and eligibility results When a Party Finder listing has requirements, we use the profile ID provided by the client to check fishing level, Enderman Slayer level, and whether the inventory contains an item with Looting V.
Dye names When a connected client submits them, the service stores the three current dye names to provide the community dye rotation.

The service does not receive a player's Microsoft/Minecraft access token. It receives a Minecraft username and a temporary server-verification value, then verifies the session through Mojang's service.

Version checks and latest-announcement requests are unauthenticated. They include normal connection metadata, including the IP address and a request header containing the Java and RFU versions, but do not include the Minecraft username or UUID.

Necessary third-party processing

To provide authentication and Party Finder eligibility checks, the service sends limited data to:

  • Mojang/Microsoft session and profile services: username and temporary server-verification value for session verification; Minecraft UUID or username when resolving player identity.
  • Hypixel API: Minecraft UUID and, if provided, SkyBlock profile ID. The service reads profile information needed for the check, including fishing experience, Enderman Slayer progress, and inventory data needed to determine Looting V.

Those providers process data under their own terms and privacy policies.

How long we keep data

  • Authentication records (Minecraft UUID, username, last-seen date, and RFU/Minecraft versions) are kept while needed to run the service, prevent abuse, and maintain compatibility statistics. You may ask us to delete them.
  • Active Party Finder listings are removed when you disconnect, delete the listing, or after inactivity. The service also removes disconnected inactive listings after up to six hours.
  • A reported Party Finder listing is kept until it is reviewed or no longer needed for moderation.
  • Connection and WebSocket logs are retained for up to 180 days.
  • Profile and eligibility data used for Party Finder checks are kept only in temporary server memory and normally expire within about one hour. UUID-resolution cache entries normally expire within about two hours.
  • Aggregate statistics, such as total users, active sessions, feature use, and version distributions, are kept without directly identifying individual players.

Why we process data

We process data to provide the online features you choose to use, keep the service secure and reliable, prevent abuse, moderate reported content, and understand compatibility and aggregate feature use. Where applicable, this is based on your consent when you enable the optional backend, performance of the feature you request, and our legitimate interest in operating and protecting the service.

Your choices and rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or a copy of your personal data. To make a request, contact RFU through the official Discord server or GitHub repository. Please do not post personal information in a public GitHub issue; use a private Discord message or ticket where available. We may ask for your Minecraft username or UUID only to locate your data and verify the request.

If you are in the European Economic Area or United Kingdom, you may also complain to your local data-protection authority. Because RFU is available internationally, data may be processed in the country where the service infrastructure or its providers operate. Data sent to Mojang/Microsoft or Hypixel is also processed under their own privacy policies.

Security

RFU uses HTTPS/WSS for its production backend connection and uses access tokens with an expiry to authenticate backend sessions. No method of internet transmission or storage is completely secure, but we limit data collection to what is needed for the features described above.

Changes to this policy

We may update this policy when the service or its data practices change. The updated version will be published here with a new "Last updated" date.