Privacy Policy
This notice explains the processing of personal data by XIVFriends under Articles 13 and 14 GDPR. The data actually processed depends on the features you use, your visibility settings and your consent choices.
1. Controller
Maurice Bothe, Tischbeinstr. 14, 34121 Kassel, Germany
Email: admin@xivfriends.net
2. Categories of data
- Account data: email, username, display name, password hash, roles, verification, recovery and two-factor data, sanctions and acceptance of the Terms
- Profile and FFXIV data: character name, server, data centre, Lodestone ID and public character information, profile text and media, languages, time zone, birthday settings, jobs, playstyles, interests, goals, search/contact preferences and optional social handles
- Content and interactions: feed, Daily Prompt, blog, forum, community, creator, gallery, housing and event posts, media, tags, comments, reactions, polls, shouts, guestbook entries, reports and moderation records
- Communications and relationships: friends, communities and roles, mentoring, pen pals, icebreaker matches, direct/group messages, reactions and shared media
- Game and reward data: points and Tomestone transactions, levels, badges, shop items, bingo activity and group loot
- Technical and usage data: IP address, time, requested URL, browser/device, login and session events, refresh-token sessions, presence, push token, security, rate-limit, audit and error data and—after consent—analytics data.
3. Purposes and legal bases
- Art. 6(1)(b) GDPR: registration, authentication, profiles, communications and delivery of the community features you select
- Art. 6(1)(a): optional audience measurement and consent-required external content; consent can be withdrawn at any time for the future
- Art. 6(1)(c): legal disclosure, evidence, retention and security obligations
- Art. 6(1)(f): protection against attacks and abuse, moderation, report handling, fraud prevention, stability, debugging, legal claims and needs-based improvement. Our legitimate interests are the secure and reliable operation of a social community platform.
4. Public visibility and search
Public profiles and content may be available without login, appear in Discover/search and be indexed by external search engines. This may include usernames and character names, avatars, servers, profile details, posts, images, blogs, comments, events, communities, creator content and reactions.
Use the available visibility and contact settings. Search-engine or third-party caches may remain temporarily after deletion outside our control.
5. Accounts, Discord and Lodestone
Passwords are stored only as cryptographic hashes. For Discord login, linking, server verification or presence, we may receive a Discord ID, username, tag, avatar, OAuth tokens and verification status as required. Discord processes data independently.
For character verification and profiles, we retrieve the public data you request from the SQUARE ENIX Lodestone and, where technically used, FFXIV data sources. It may be refreshed periodically.
6. Content, communications and moderation
We process your content and metadata so it can be stored, formatted, delivered, searched, commented on and displayed to the audience you select. Messages are stored for delivery and synchronisation; participants can report content.
Authorised administrators and moderators access necessary account, content, message, report and log data only when needed for security, troubleshooting, moderation or legal compliance. Moderation decisions with significant effects are not made solely by automated means.
7. Logs and security
Servers, reverse proxies and security services process IP address, time, target URL, status, browser/device information and technical identifiers. Login sessions may include IP and user agent. Audit, messaging, view counts, rate limits, abuse prevention and debugging can create further event data.
The legal basis is Art. 6(1)(f) GDPR; our interest is security, accountability and availability. Access is restricted and logs are retained only as long as required for these purposes or legal claims.
8. Cookies and local storage
Necessary technologies store login/session tokens, role information (normally up to 30 days), language (normally up to one year), security and session state. Login and core features cannot work without them.
Functional storage includes theme, filters, volume, favourites, last-seen Discover items and comfort preferences. Consent choices are normally stored locally for up to one year. Session data generally ends with the session; other preferences remain until deletion, reset or a specified technical expiry.
Analytics and consent-required external content load only after your selection. You can change it through "Cookie settings" in the footer at any time. Section 25 TDDDG also applies to access to your device.
9. Recipients and processors
- hosting, database, storage, content delivery, DDoS protection and technical operations providers; production delivery may in particular use Cloudflare and EU hosting infrastructure
- the configured email/SMTP service for verification, security, notifications and contact requests
- Discord for optional login, linking, server verification, presence and the server widget loaded after consent
- Google services: Google Analytics after analytics consent, privacy-enhanced YouTube after content consent, and Firebase Cloud Messaging when app push is enabled
- SQUARE ENIX Lodestone and related FFXIV data sources for public character/game data; the external Lodestone tooltip script loads only after content consent
- GIPHY when searching for or displaying selected GIFs
- Ko-fi, Patreon, social networks and external community/event sites when you open their links
- authorities, courts, legal advisers or rights holders where required by law or for legal claims.
10. International transfers
Discord, Google/YouTube/Firebase, GIPHY and other external services you choose may process data outside the EEA, particularly in the United States. Depending on the provider, transfers rely on an Art. 45 GDPR adequacy decision—including the EU-US Data Privacy Framework for certified organisations—Art. 46 Standard Contractual Clauses or your deliberate request for external content. Different government access rules may remain despite safeguards.
11. Analytics, external media and push
If Google Analytics is configured by an administrator, it loads only after analytics consent. Pseudonymous usage, device and event data may be processed and identifiers stored in the browser. After withdrawal, we disable future measurement and remove accessible analytics cookies where technically possible.
YouTube embeds, the Lodestone tooltip script and Discord widget load only after content consent. Opening an item once or following an external link transfers data to the provider on your initiative. App push is optional and uses a device token and your notification choices.
12. Retention
- account data generally for the life of the account; verification, reset and session tokens until expiry, use or revocation
- profile and user content until you delete it, delete the account or a justified moderation measure
- shared conversations, communities or threads may remain for context and, where appropriate, be separated from or anonymised from a deleted account
- reports, moderation, security and audit data as long as needed for abuse prevention, evidence, legal duties or claims, then deletion or anonymisation
- backups are overwritten in regular cycles; deleted data is not used operationally meanwhile except for required recovery or security
- records subject to legal retention until the relevant period ends; public search caches follow the provider’s schedule.
13. Required data and consequences
A conventional account requires in particular email, username and password; supported login methods instead require relevant third-party data. Without them we cannot provide an account. Lodestone verification and further profile details are required only for features that depend on them.
14. Recommendations and automated decisions
Search, Discover, filters, rankings, matches and recommendations may rank profile, content and interaction attributes by rules. This only supports sorting and discovery and has no legal or similarly significant effect. There is no solely automated decision within Art. 22 GDPR.
15. Your rights
Email admin@xivfriends.net to exercise a right. We may request reasonable information to verify identity.
- access (Art. 15), rectification (Art. 16), erasure (Art. 17) and restriction (Art. 18 GDPR)
- data portability (Art. 20), where applicable
- objection to processing under Art. 6(1)(e) or (f) (Art. 21)
- withdrawal of consent at any time for the future (Art. 7(3))
- complaint to a supervisory authority (Art. 77), in particular the Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, datenschutz.hessen.de.
16. Security and breaches
We use risk-appropriate measures including encrypted transport, password hashing, role-based access, session/rate-limit protection and security-event logging. No internet service is absolutely secure. Report suspicious activity to admin@xivfriends.net. Breach notifications are made under Articles 33 and 34 GDPR where required.
17. Changes
We update this notice for legal, technical or functional changes and provide appropriate notice of material changes. The current version is always available here.
Last updated: 10 August 2026 · Version 2.0
