Paper plugin · free edition
Answer a player’s data request in one command
When a player asks “what does your server know about me?”, the answer is spread over world folders, server lists and months of logs. Hexloom Privacy collects it into one zip, with a checksum manifest you can hand over as it is.
- Paper 1.21 or newer
- Java 21
- 20 KB
- No network requests
SHA-256 0ee9912ae976c25bad8f4b0a71310f0c23cf781d6044d8659a8e5bc966dca4a0
> privacy export Steve Exporting data for Steve (069a79f4-44e9-4726-a5be-fca90e38aaf5)... Export ready: plugins/HexloomPrivacy/exports/ export-Steve-20261007-153000.zip (6 data files, 214 log lines, 1 note(s): read manifest.json).
Example session. File and line counts depend on your server.
What is in the zip
One export per player, named by player name or UUID. The export runs off the main thread, so a big log folder does not freeze the server.
| In the zip | What it holds |
|---|---|
data/<world>/playerdata | Inventory, position, health and other player data, per world folder, as the binary NBT files the server keeps. |
data/<world>/stats | Statistics. |
data/<world>/advancements | Advancements. |
server-lists/ | Only this player’s entries from ops.json, whitelist.json, banned-players.json and usercache.json, plus matching banned-ips.json entries for IP addresses seen in the logs. |
logs/matching-lines.txt | Lines from the current log and rotated .log.gz files that mention the player’s name or UUID. |
manifest.json | Every file with its size and SHA-256, who ran the export and when, and notes about anything missing or cut short. |
README.txt | A plain-language summary you can forward to the player. |
Free for exports, Pro for erasure
The free edition does exports and stays free. Pro adds the other half of a privacy request: deleting the data, and proving you did.
Free edition
/privacy export <player|uuid>- Data files, server-list entries and log lines in one zip
- Checksum manifest with notes on anything missing
- Saves an online player’s data first, writes through a temporary file
$0 no account, no licence key
Pro edition
/privacy erase <player|uuid>shows what would go; addconfirmto delete playerdata, stats, advancements and the player’s whitelist and cache entries- Refuses while the player is online, because the server would write their files again on leaving
- A receipt file per erasure with the SHA-256 of every deleted file
/privacy requestslists every export and erasure: date, player, who ran it- Export zips are deleted after 30 days by default, so exports do not pile up
$12 once, for one server · free updates, no time limit · refund within 14 days
Secure checkout by Stripe. The download opens right after payment and the same link works again later. Ops and bans are kept on purpose, and logs are counted, never edited.
Install and use
- Put
HexloomPrivacy-0.1.0.jarin your server’spluginsfolder. - Start the server. The plugin creates
plugins/HexloomPrivacy/config.yml. - Run
/privacy export <player|uuid>from the console, or in game as an operator. The zip appears inplugins/HexloomPrivacy/exports.
Use the exact name of a player who has joined before. For anyone else, use the dashed UUID.
Configuration
| Key | Default | Meaning |
|---|---|---|
export.directory | exports | Folder inside plugins/HexloomPrivacy where zips are written. |
export.include-logs | true | Search the server logs for lines that mention the player. |
export.max-log-megabytes | 50 | Stop reading logs after this many megabytes. The manifest says when the limit was reached. |
Permission
hexloom.privacy.export allows /privacy export. Operators have it by default.
What it does not do
- It only sees this server’s files and logs. Data other plugins keep in their own databases (economy, claims, permissions, web maps) or services outside the server (Discord bots, hosting panels) is not included.
- Log search matches the player’s name and UUID as text. A line that mentions neither is not found.
- The free edition erases nothing. Pro erases only the files and list entries named above; data in other plugins’ databases stays where it is.
- Export zips contain personal data. Store and send them as you would any personal data, and delete them when the request is closed.
- It is a tool, not legal advice.
Tested with Paper 1.21.11 on Java 21: automated tests plus a run on a real headless server. Other 1.21 builds are not verified yet.
Get notified about new releases
Hexloom Privacy is the first of a small set of Paper admin plugins. Leave an address if you want one email when the next one ships.
Questions
Does the plugin send data anywhere?
No. It reads and writes local files only and makes no network requests. This page’s download link is a plain file; the plugin has no update check and no analytics.
Does it work on Spigot or Bukkit?
It is built and tested for Paper 1.21 and forks of it. It is not tested on Spigot or Bukkit, so do not rely on it there.
Do I need to buy anything?
No. The free edition is complete for exports. There is no licence key and no limit on the number of exports.
How do I answer a player's data request by hand?
The guide to player data requests lists where a Paper server keeps a player's data, how to search the logs, and what to decide before deleting anything.
Something went wrong. Where do I report it?
Use the support page. Include your server version (/version) and the console message that shows the problem.