Your data, explained.

Privacy

What BeatTheGoblins saves, why we use it and what other people can see. This overview covers the website and mod as they work today.

The data we keep

What we store

You can browse the website without an account. Creating an account, connecting a game profile or starting a run adds the records listed below.

Website account

Private
  • Account ID and email address, if supplied
  • Password hash for email-and-password accounts
  • Hytale sign-in provider association, if used
  • Account creation and update times, and account status

To create your account and let you sign in. Our self-hosted sign-in service stores password hashes and Hytale provider associations; your email and account ID are kept out of public player responses.

Connected game profiles

Partly public
  • Hytale player ID (UUID) and display name
  • The association with your website account
  • The time the game profile was first linked

To associate your Hytale player with the correct account and keep several connected game profiles separate. The player ID and name can appear publicly; the account association stays private.

Avatars & appearance

Partly public
  • Cosmetic selections sent by the connected mod
  • Player ID, asset version, appearance revisions, processing status, animation metadata and timestamps
  • Generated avatar images and textured 3D models
  • An uploaded face crop, its image fingerprint and update time

To display your Hytale appearance. The mod sends an appearance snapshot after connecting. Images, 3D models and avatar metadata are public; the source cosmetic snapshot stays private. A website image upload keeps a clean face crop and discards the original full-body preview.

Recorded speedruns

Partly public
  • Run ID and the associated Hytale player ID
  • Run category, mode and world identifier
  • Game version and difficulty, when supplied
  • Start, checkpoints, timestamped milestones and final result
  • Cumulative damage dealt and taken by game damage type, and damage events
  • Equipped item IDs, slots, quantities and timestamped changes
  • Loaded server plugin and asset-pack IDs and versions
  • Numbered snapshots, capture and receipt times, and assessment reasons
  • Versioned telemetry consent and its enable or revoke time

With your explicit consent, the mod sends snapshots every five seconds and when events occur during an active Goblin-world run. The server reconciles the stream, shows a public live preview and calculates an explainable plausibility score. Your world identifier and website account association stay private.

Game connection & linking

Private
  • Hashes of game connection tokens, link tickets and polling secrets
  • Link request IDs, associated player IDs and names, and registration or login state
  • Creation, expiry, completion and credential revocation times

To verify requests from the mod and complete an account link. The application database stores credential hashes. The mod keeps its usable connection token locally on your game server or computer.

Sign-in & security records

Private
  • Session IDs, session and logout tokens, and sign-in and expiry times
  • Login and registration flow state, security tokens and redirect URLs
  • Network address and browser information visible to the sign-in service

To maintain your browser session and protect sign-in requests. These records stay in our authentication service. Network and browser information can describe the website proxy rather than your own device.

Twitch connection & live activity

Partly public
  • Twitch user ID, channel login, display name and channel picture URL
  • Encrypted Twitch OAuth credentials and connection times
  • Your public live visibility setting
  • The connected Hytale player and recent Hytale or Goblin World activity

To verify your Twitch connection and show your live stream while a connected player is active, when public visibility is enabled.

Which cosmetic selections are saved?

Body shape, underwear, face, ears, mouth, haircut, facial hair, eyebrows, eyes, pants, outer pants, base and outer tops, shoes, head, face and ear accessories, skin features, gloves and cape. These are appearance choices used to build the avatar.

Who can see it

What is public

Visible to visitors

Hytale player IDs and names, avatar images, generated 3D avatars, recorded run activity, reached goals, final durations and eligible rankings. A consented run’s live preview also shows damage, equipped items and changes, plugin and asset-pack IDs and versions, received events and its plausibility assessment. Avatar metadata includes processing status, asset version, revision and update time. Avatar versions can remain accessible through their public links.

Kept private

Email addresses, website account IDs and associations, passwords and credential records, cosmetic source snapshots, sign-in records and world identifiers. The signed-in owner can see their own account and run details.

Historical starts show only that a start event was received. A completed run needs complete, plausible telemetry and supported rules to enter automatic rankings. The score checks consistency and delivery coverage; it is not a calibrated probability or proof that local gameplay was unmodified. Team runs need a website-created roster before they can be eligible.

When you connect Twitch, public live visibility is enabled. The stream listing can show your Twitch channel, stream title, preview, viewer count and active Hytale player with Hytale or Goblin World status. It never publishes private world identifiers or OAuth credentials. You can disable visibility or disconnect in your account.

In your browser and game

Cookies & your device

  • Sign-in cookies: a persistent session cookie keeps you signed in for up to 30 days. Security cookies protect login and registration requests. Blocking these cookies can prevent account features from working.
  • Game connection: the mod stores your player ID, connection token and expiry time locally so it can reconnect. An expired token file is removed when the mod next checks it. Your run-data choice is saved to your website account and checked by the mod before transmitting run data.
  • Browser storage: the website adds no analytics scripts or advertising trackers and does not save account data in local storage. Your browser may cache public images, avatar models and static files.
  • Abuse prevention: the application keeps IP-based request counters in server memory. They are separate from your game profile and are not written to the application database.

Technical service logs can contain request times, paths, status codes and connection information. Their retention depends on the hosting environment.

Expiry and removal

How long data stays

Account link
A game-to-browser link is valid for 10 minutes. Website login and registration flows are valid for 15 minutes.
Sign-in & mod credentials
Browser sessions and game connections last up to 30 days. A game connection can expire earlier with its associated browser session; renewing that profile’s connection revokes its previous mod credentials.
Profiles, runs, telemetry & avatars
These records currently have no automatic deletion deadline. Older generated avatar revisions are also retained. Opting out stops further run telemetry, removes public access to previously authorized run details and withdraws those runs from official rankings. Enabling again requires a new run; it does not republish earlier detailed telemetry. Retained records and basic historical run activity are not deleted.
Uploaded face crop
A new upload replaces the saved crop for that game profile. The original full-body image is not retained by the website upload.
Twitch connection & live activity
Disconnecting Twitch removes the stored connection, OAuth credentials and player activity. Disabling public visibility stops publication and removes the recent activity. Public player activity expires after 90 seconds without a fresh verified update.

Credential expiry stops further use of that credential. It does not automatically delete the account, its linked profiles, run records, authentication records or avatar files. Signing out of the website also does not remove those records or revoke a separate mod connection.

Connections outside the website

External services

Hytale sign-in

When available, choosing Continue with Hytale takes you to Hytale’s account service to sign in and authorize the connection. Hytale receives your browser and network information. Our authentication service receives a verified provider account identifier and the account details Hytale shares, which may not include an email address. You do not enter your Hytale password on BeatTheGoblins. Connecting a game profile still requires a separate game link and your confirmation.

Password safety check

Our sign-in service checks chosen passwords against Have I Been Pwned’s Pwned Passwords service. It sends the first five characters of a SHA-1 password hash from our server; the password itself and your email address are not sent to that service. How the password check works

YouTube video

The Home-page video connects to YouTube only after you select Play. It uses YouTube’s privacy-enhanced embed domain. YouTube then receives network and browser information, such as your IP address and the website origin, and may process playback data under Google’s privacy policy .

Twitch pictures & live player

Twitch channel pictures and stream previews load from Twitch’s image CDN. On HTTPS pages, displaying a live player also connects your browser directly to Twitch. On HTTP pages or smaller screens, the website shows a preview and a link to the channel instead. Connecting a channel takes you to Twitch for authorization.

Website fonts, avatar images and 3D models are served by BeatTheGoblins. Following an external link, such as CurseForge, takes you to that service and its own privacy practices.

The current scope

Collection limits

The mod sends account-connection requests and, for supported asset versions, an avatar appearance snapshot after connecting. Run capture and public live telemetry remain disabled until you explicitly accept the data notice on this website after your first sign-in. Your choice is saved to your account and applies to its connected Hytale profiles. You can change it in Account → Privacy. A new run is required after enabling it again.

During an authorized run in the canonical Goblin breach, the mod temporarily buffers events, sends numbered snapshots every five seconds and flushes events and the final snapshot before the run ends. It records applied health damage by game cause, equipped slots and item quantities, loaded server plugin and asset-pack IDs and versions, milestones and run timing. It does not send chat messages, world save files, world seeds, player positions, unequipped inventory contents or local file paths. The loaded-mod list describes the server’s loaded plugins and packs; it does not prove which of them changed a particular world.

If Twitch public live visibility is enabled, the connected mod reports recent Hytale activity and whether the player is in a Goblin World. This live activity does not enable speedrun telemetry.

Your Hytale identity proof is used transiently to verify the connection. The application does not retain that official game credential. Your website password is handled by the sign-in service and stored as a password hash.

Game updates can change the available event hooks. Unsupported categories, missing events, telemetry gaps, unapproved extra plugins or an unproved team roster can prevent automatic ranking. Authentication uses the locally saved BeatTheGoblins connection token bound to your verified player UUID; a username alone does not establish ownership. Local tokens and continuous sending cannot prove that the mod or game server was not modified.

Questions about your data?

Contact & requests

For questions about stored data, or to request access, correction or deletion, contact [email protected]. There is currently no self-service account or run deletion.

Include your account ID or associated email address, if supplied, and, where relevant, your Hytale player name or ID. Please keep passwords, game tokens and sign-in links out of your message.