On this page

Privacy policy

Last updated: 5 October 2026

This policy explains what personal data Cool Apps ("we") handles when you visit coolapps.fyi, buy a license for one of our plugins, run one of our plugins or write to us. Questions about it go to [email protected].

This website #

The website is a set of static pages. It has no accounts, no forms and no comments.

We use Google Analytics to count visits and see which pages are read; how it works depends on where you are (see Analytics). The website sets no other cookies of its own.

The site is hosted on Cloudflare Pages. To deliver the pages and protect the site from abuse, Cloudflare processes technical data about each request, such as your IP address and your browser's user agent, and it may set a strictly necessary security cookie when it has to tell people apart from automated traffic. See Cloudflare's privacy policy.

The buy buttons open Polar's checkout in a window on top of our page. That window is served by Polar: what you type into it goes to Polar, not to us, and Polar's privacy policy applies. To open it, pages with a buy button load Polar's checkout script from the jsDelivr network (cdn.jsdelivr.net), which, like any server you load something from, receives your IP address and browser details; see jsDelivr's privacy policy. If JavaScript is off, or the window cannot open, the buy buttons take you to Polar's checkout page instead.

Analytics #

We use Google Analytics 4, a Google service, to measure how the website is used: which pages are visited, how visitors arrive and roughly from which country. There is no cookie banner. Instead, Google Analytics runs like this:

  • In the European Economic Area, the United Kingdom and Switzerland, every kind of storage is denied (Google's Consent Mode): Google Analytics does not set or read cookies, and its advertising features are off. Your visit is still measured, without cookies: your browser sends Google measurements that carry no cookie identifier, which Google uses for aggregate statistics and may use to model them.
  • Everywhere else, analytics and advertising storage are allowed. Google Analytics sets first-party cookies (_ga and _ga_<container id>) that let it recognise a returning browser for up to two years.

When you click a buy button, Google Analytics also records that a checkout was started and, if you finish it, that a purchase was made, naming only the plugin: never your name, e-mail address or payment details.

Google Analytics 4 does not log or store IP addresses. Google explains how it uses information from sites that use its services. You can block Google Analytics with Google's opt-out browser add-on or any content blocker.

Purchases #

Payments are handled by Polar (polar.sh), our merchant of record. Polar collects what it needs to process your order, charge sales tax or VAT and issue your invoice, such as your e-mail address, your name, your billing address and your payment details. Card details are processed by Polar and its payment providers; we never see them.

Polar shares with us the order details we need to deliver and support your license, such as your e-mail address, your name, your billing country, what you bought and the state of your order or subscription. How Polar handles your data is described in Polar's privacy policy.

License checks #

When a Pro license key is activated on a server, shortly after the server starts and then about every 12 hours, Manuka Moderation contacts Polar's license API (api.polar.sh). Activation sends the key, our store's Polar organization id and an instance label made of the server's configured server-name and a short hash of a random identifier created when the plugin was installed. Later checks send the key, the organization id and the activation id Polar assigned. The label contains no IP address, but like any web request the check reaches Polar from your server's IP address. Polar keeps a record of each activation, which we can see. No chat, player or panel data is sent.

Our plugins on your server #

Manuka Moderation stores chat lines, cases, punishments and panel accounts in a database on your own server. We do not receive any of it. As the server owner you are responsible for that data: telling your players about it, choosing how long to keep it and following the law that applies to you.

The plugin sends data to other services only in these cases:

  • the license check described above (Pro);
  • update checks and downloads: it asks Modrinth, or GitHub as a fallback, for its latest release, unless you turn updates.check off;
  • player skins: unless panel.skin-downloads is false, the server downloads players' skin images from Mojang's skin server (textures.minecraft.net) for the panel's player page; browsers viewing the panel never contact Mojang;
  • e-mail notifications, through the SMTP server you configure;
  • the optional AI features, which use the AI provider you configure, under your own account. An explanation or a second opinion sends the flagged case and the lines around it, with e-mail addresses and phone numbers masked; the digest paragraph (Pro) sends the period's digest, including player names, each new case's first evidence line and the punishments, without that masking.

E-mail to us #

When you write to [email protected], we receive your e-mail address and whatever you send, and we use them to answer you. We keep the conversation while it is useful for supporting you, and delete it earlier if you ask.

Your rights #

Depending on where you live (for example in the European Economic Area, the United Kingdom or Switzerland), you may have the right to get a copy of your personal data, to have it corrected or deleted, to object to or restrict how it is used, and to receive it in a portable format. Write to [email protected]. You can also complain to your local data protection authority. For data that Polar holds as merchant of record, you can also contact Polar directly.

Changes #

When this policy changes, we update this page and the date at the top.