Privacy notice.
Updated 9 October 2026
This notice covers the Hollow SMP website, its application forms, and its support chat. The website is managed by Hollow SMP’s owner, Viper. To ask a privacy question, open support chat and request a human operator. Discord membership is not required.
Information you provide
Applications save your Minecraft username, selected role, timezone, availability, experience, application answers, and optional Discord username. Support chat does not require a Minecraft username. It saves your messages, timestamps, and a randomly assigned guest reference; usernames or other details you choose to include are saved with your messages. The earlier support form also saves the username and optional contact details you submit. Conversations also store staff replies, AI replies when enabled, support notices, earlier automated help messages, and whether you requested a human operator.
Only provide what staff need to help or review your application. Do not send passwords, payment details, your home address, identification documents, or other sensitive information.
Why we save it
We use this information to review applications, investigate reports or appeals, answer questions, follow up with you, and prevent duplicate or abusive submissions. Sending a form or chat message stores it for those purposes. You can browse public pages without applying, opening a chat, or providing a Discord username.
Who can read it
Application and support inboxes and operator replies are restricted to the server owner’s account. Visitors cannot browse other players’ submissions. You can read and respond to your conversation using its support cookie or private reply link.
Keep private reply links secret: anyone who has the full link can read and reply to that conversation. Do not post your link in public chat or on Discord. The owner can generate a private link for an older submission and share it with the applicant directly.
Cookies and browser storage
When you start a support chat, an essential support cookie connects your messages to the current conversation while you keep the page open. Each new page load or refresh clears that cookie and starts an empty chat. The cookie has a maximum expiry of 30 days if it has not already been cleared by a new page load. The cookie contains a random access token; a hashed version is stored with the conversation’s access records. Refreshing resets the visible chat; it does not remove messages or requests from the owner’s inbox. To receive a human reply, keep the current page open or save a separate private link shared by staff. Private application reply links are not reset on refresh.
A browser session preference remembers whether you dismissed the welcome greeting. Private application conversation tokens are kept in the fragment of your reply link, after the #, and are sent to the conversation endpoint to authorize access. The website does not add advertising or analytics trackers.
Hosting and other services
The website and its database use Sites hosting with Cloudflare infrastructure. These providers process requests and may keep operational and security logs under their own policies. Staff sign-in uses ChatGPT; ordinary visitors do not need a ChatGPT account. Data may be processed outside your country by hosting providers.
The live Minecraft status section requests information from mcstatus.io in your browser. This third-party request can expose normal connection information, such as your IP address, to that service. Following Discord or other external links opens a separate service governed by its own privacy practices.
AI support and human review
When AI support is enabled, your recent support messages and earlier assistant replies are sent to the OpenAI API to generate a reply that follows your conversation. AI replies are labelled as AI. The assistant may make mistakes and cannot access Minecraft accounts or change the server. It does not approve applications, decide bans or appeals, or perform deletion requests.
We send a limited recent chat history, without private access tokens or the application database, and request that generated responses are not stored as API response objects. OpenAI may still retain data for security or abuse monitoring under its API data policies. Do not share sensitive information.
Requesting a human operator stops AI replies for that conversation. Later messages stay with staff until the conversation is closed. If the AI connection is not configured or fails, your messages are saved for the owner instead; the chat does not pretend a canned message came from AI. Human replies appear when the owner is available.
Retention and deletion
Submissions and conversations are kept until the owner removes them. There is currently no automatic deletion schedule. Access-cookie expiry does not delete the saved conversation. The owner can delete a conversation and its associated submission from the private inbox; hosting logs or backups may follow provider retention rules.
To request access to your information, a correction, or deletion, use your existing private conversation or open support chat and ask for a human operator. Include your application or request reference if you have one. Staff may ask for enough information to verify that a record belongs to you before sharing, changing, or deleting it. You can also contact staff privately in game.
Changes to this notice
If the website’s data practices change, this page and its update date will be revised.