Mermaids.dev

Privacy Policy

What mermaids.dev collects, why, who processes it, and how to get it corrected or deleted.

On this page

The short version: we sell mods, not data. There are no advertising trackers on this site, no analytics scripts following you, and your card number never touches our servers. We keep the minimum needed to know who bought what, and this page lists all of it.

Last updated: August 12, 2026.

What we collect, and why

Browsing the wiki and the store collects nothing and needs no account. An account only exists once you sign in, and everything we hold traces back to signing in, optionally linking Discord, and buying.

Signing in is with your Hytale account, not Discord — Hytale never gives us your email or your real name, only what’s in the table below.

DataWhere it comes fromWhy we keep it
Hytale account ID (an anonymous per-app identifier, not your Hytale username)Hytale, at sign-inIt is your account — how you sign in and how purchases attach to you
Your chosen Hytale game profile (UUID and username)Hytale, at sign-inDelivering name-bound content in game — see below. Hytale lets you pick a different profile each time you sign in, so this is refreshed on every sign-in, not fixed forever
Whether Hytale reports your account as managed by a parent or guardianHytale, at sign-inShowing a permission notice before checkout if it does — see Age
Discord ID and access tokensDiscord, only if you choose to link your Discord accountGranting purchase roles and joining you to our Discord server, and nothing else — Discord is optional and never how you sign in
Session IP address and browser user-agentYour browser, while signed inSession security — recognizing your sign-in and expiring stale ones
Orders and entitlementsYour purchasesWhat you bought, what you hold, what you may download. Amounts and Stripe reference IDs, never card details
Hytale player UUID bound to a name-bound purchaseYour own Hytale sign-in, captured automatically the moment such a purchase completesDelivering that content in game. For each name-bound product, the UUIDs of its buyers are published in a public delivery list that game servers read — a UUID and nothing else: no name, no email, no purchase details
Email addressYou, optionally, at checkoutNeither Hytale nor a linked Discord account reliably gives us one, so this is the only way a Stripe receipt reaches you. Asked once — skip it and you still get everything you bought, just no email about it. Not verified; it’s whatever you typed
Card detailsNever collectedPayment happens on Stripe’s pages; card numbers go to Stripe, not us

That table is exhaustive for this website. The mods are a separate matter, and they do send something home — what the mod reports, below, covers it.

Who processes it

We run on infrastructure other companies operate, each seeing the slice needed for its job:

ProviderRoleWhat reaches them
HytaleSign-inThe sign-in handshake — your account picks which scopes we’re allowed to ask for
StripePaymentsYour card and billing details, purchase amounts, and your email if you gave one at checkout
DiscordOptional linking and perksThe linking handshake, if you choose to link; role changes on our server
VercelHostingStandard web request logs
PrismaDatabaseThe account and purchase records above
CloudflareFile deliveryThe download requests for mod files

One thing worth stating outright: when a purchase completes, a notification is posted to a channel in our Discord server so we can say thank you and keep count. It names the buyer by their linked Discord account if they have one, or by their Hytale profile name otherwise — never email, never payment details. If that ever bothers you, tell us and we will leave your purchases out of it.

We do not sell data, rent data, or share it with anyone beyond that table, unless the law compels it.

What the mod reports

Everything above is about this website. The mod is a separate thing, running on someone else’s machine, and it does send one thing home: every released build of Cultivation carries HStats (hstats.dev) and Modifold Analytics (modifold.com), the two shared metrics services Hytale mods use to count installs — the same idea as bStats elsewhere. Our other mods carry HStats, and some carry Modifold as well.

Both report on the server, never on the people playing on it. Between them they send exactly this, and nothing else:

SentHow oftenWhat it is for
A random ID, generated on that serverEvery reportTelling one server apart from another without knowing anything about either. It is written to a text file in the server folder, belongs to that machine, and can be deleted at any time
Number of players onlineEvery 2–5 minutesThe live count on the home page
The mod’s versionOnce, at startupWhich releases are still running, so a fix can be aimed at the builds that need it
Operating system name and version, Java version, CPU core countEvery 2–5 minutesKnowing which platforms to keep the mod working on before a report arrives saying it doesn’t

Never sent: player names, player UUIDs, chat, coordinates, world or save data, config contents, IP addresses of players, or anything typed in game. Nothing that leaves your server identifies a person. HStats and Modifold do see the connecting server’s own IP address, as any web request does, and HStats tallies it to a country — three servers in the US, and so on.

What comes back out is aggregate and public: the counts on the home page are read straight from the HStats feed for Cultivation, which anyone can open.

Switching it off

Both reporters ship switched on and both can be switched off, per server, without touching the mod. In your server’s folder — the one the server starts in — open these two files:

hstats-server-uuid.txt
modifold-analytics-server-uuid.txt

Each has an enabled=true line. Change it to enabled=false, restart, and that reporter goes quiet for good; the console says Metrics are disabled on this server. on the next start. Nothing else about the mod changes.

That switch belongs to the server, so it covers every mod on it that uses the same service, not just ours. Deleting the files instead does not disable anything — they are simply written again, with a fresh ID.

Cookies and storage

One functional cookie: your sign-in session. Your theme choice (Yin or Yang) lives in your own browser’s storage and never leaves it. There is no tracking to consent to, which is why there is no cookie banner.

Keeping it, deleting it

Account data is kept while the account exists. Ask us to delete your account and we will remove it — your profile, any email you gave us at checkout, sessions, entitlements, linked Discord account and the Hytale game profile your purchases were bound to. Order records are the exception: those are financial records we retain as bookkeeping requires, detached from the deleted account.

Deleting your account forfeits access that subscriptions or purchases granted, so cancel first and keep what you need.

Your rights

Ask and we will show you what we hold about you, correct it, delete it as above, or hand it over in a portable form. These are your rights under GDPR and similar laws, but we don’t check passports — anyone can ask.

Age

You need a Hytale account to sign in; how old you need to be to hold one is Hytale’s own rule, not ours. This site is not directed at children.

Buying has a further rule of its own: anyone under 18 needs a parent or guardian’s permission first, which the terms explain. If Hytale reports your account as managed by a parent or guardian, checkout shows a notice asking you to get their permission before continuing — this isn’t a real approval workflow on Hytale’s side, just an acknowledgment we ask you to make.

Where it lives

Our providers operate in the United States and other countries; your data is processed wherever they run. Each handles international transfers under its own linked policy.

Changes and contact

Changes to this policy appear here, with the date at the top updated. For anything in it — questions, corrections, deletion — the Siren’s Cove Discord server is the fastest route.