Hexloom Labs

Paper plugin · free edition

Answer a player’s data request in one command

When a player asks “what does your server know about me?”, the answer is spread over world folders, server lists and months of logs. Hexloom Privacy collects it into one zip, with a checksum manifest you can hand over as it is.

  • Paper 1.21 or newer
  • Java 21
  • 20 KB
  • No network requests

SHA-256 0ee9912ae976c25bad8f4b0a71310f0c23cf781d6044d8659a8e5bc966dca4a0

> privacy export Steve
Exporting data for Steve (069a79f4-44e9-4726-a5be-fca90e38aaf5)...
Export ready: plugins/HexloomPrivacy/exports/
export-Steve-20261007-153000.zip
(6 data files, 214 log lines, 1 note(s):
read manifest.json).

Example session. File and line counts depend on your server.

What is in the zip

One export per player, named by player name or UUID. The export runs off the main thread, so a big log folder does not freeze the server.

In the zipWhat it holds
data/<world>/playerdataInventory, position, health and other player data, per world folder, as the binary NBT files the server keeps.
data/<world>/statsStatistics.
data/<world>/advancementsAdvancements.
server-lists/Only this player’s entries from ops.json, whitelist.json, banned-players.json and usercache.json, plus matching banned-ips.json entries for IP addresses seen in the logs.
logs/matching-lines.txtLines from the current log and rotated .log.gz files that mention the player’s name or UUID.
manifest.jsonEvery file with its size and SHA-256, who ran the export and when, and notes about anything missing or cut short.
README.txtA plain-language summary you can forward to the player.

Free for exports, Pro for erasure

The free edition does exports and stays free. Pro adds the other half of a privacy request: deleting the data, and proving you did.

Available now

Free edition

  • /privacy export <player|uuid>
  • Data files, server-list entries and log lines in one zip
  • Checksum manifest with notes on anything missing
  • Saves an online player’s data first, writes through a temporary file

$0 no account, no licence key

Available now

Pro edition

  • /privacy erase <player|uuid> shows what would go; add confirm to delete playerdata, stats, advancements and the player’s whitelist and cache entries
  • Refuses while the player is online, because the server would write their files again on leaving
  • A receipt file per erasure with the SHA-256 of every deleted file
  • /privacy requests lists every export and erasure: date, player, who ran it
  • Export zips are deleted after 30 days by default, so exports do not pile up

$12 once, for one server · free updates, no time limit · refund within 14 days

Buy Pro for $12

Secure checkout by Stripe. The download opens right after payment and the same link works again later. Ops and bans are kept on purpose, and logs are counted, never edited.

Install and use

  1. Put HexloomPrivacy-0.1.0.jar in your server’s plugins folder.
  2. Start the server. The plugin creates plugins/HexloomPrivacy/config.yml.
  3. Run /privacy export <player|uuid> from the console, or in game as an operator. The zip appears in plugins/HexloomPrivacy/exports.

Use the exact name of a player who has joined before. For anyone else, use the dashed UUID.

Configuration

KeyDefaultMeaning
export.directoryexportsFolder inside plugins/HexloomPrivacy where zips are written.
export.include-logstrueSearch the server logs for lines that mention the player.
export.max-log-megabytes50Stop reading logs after this many megabytes. The manifest says when the limit was reached.

Permission

hexloom.privacy.export allows /privacy export. Operators have it by default.

What it does not do

  • It only sees this server’s files and logs. Data other plugins keep in their own databases (economy, claims, permissions, web maps) or services outside the server (Discord bots, hosting panels) is not included.
  • Log search matches the player’s name and UUID as text. A line that mentions neither is not found.
  • The free edition erases nothing. Pro erases only the files and list entries named above; data in other plugins’ databases stays where it is.
  • Export zips contain personal data. Store and send them as you would any personal data, and delete them when the request is closed.
  • It is a tool, not legal advice.

Tested with Paper 1.21.11 on Java 21: automated tests plus a run on a real headless server. Other 1.21 builds are not verified yet.

Get notified about new releases

Hexloom Privacy is the first of a small set of Paper admin plugins. Leave an address if you want one email when the next one ships.

We send a confirmation link first, then at most one email a month: new Hexloom plugins and changes to Hexloom Privacy. Every email has an unsubscribe link.

Questions

Does the plugin send data anywhere?

No. It reads and writes local files only and makes no network requests. This page’s download link is a plain file; the plugin has no update check and no analytics.

Does it work on Spigot or Bukkit?

It is built and tested for Paper 1.21 and forks of it. It is not tested on Spigot or Bukkit, so do not rely on it there.

Do I need to buy anything?

No. The free edition is complete for exports. There is no licence key and no limit on the number of exports.

How do I answer a player's data request by hand?

The guide to player data requests lists where a Paper server keeps a player's data, how to search the logs, and what to decide before deleting anything.

Something went wrong. Where do I report it?

Use the support page. Include your server version (/version) and the console message that shows the problem.