Hexloom Labs

Guide · Paper servers

What a Paper server stores about a player, and how to answer a data request

A player asks “what do you have on me?” or “delete my data”. This is where that data lives on a Paper server, how to find it by hand, and what to decide before you delete anything.

This is a practical checklist, not legal advice. Whether a privacy law applies to your server depends on where you and the player are and how the server is run. Under the EU and UK GDPR a request is generally answered within one month; check the rules that apply to you.

Where the data is

Everything below is plain files in the server folder. The first group is what the server itself writes; the second is what you added with plugins and hosting.

WhereWhat it holds
<world>/playerdata/<uuid>.dat and .dat_oldInventory, ender chest, position, health, experience and other player state, as binary NBT. Look in every world folder, not only the main one.
<world>/stats/<uuid>.jsonStatistics: play time, blocks mined, deaths and so on.
<world>/advancements/<uuid>.jsonAdvancement progress with timestamps.
usercache.json, whitelist.jsonName and UUID pairs. Both are keyed by the player.
ops.json, banned-players.json, banned-ips.jsonOperator level, ban reason and date, and banned IP addresses.
logs/latest.log and logs/*.log.gzJoin and leave lines with the player’s name, UUID and IP address, plus chat and command lines, for as long as you keep old logs.
Other pluginsPermissions, economy, claims, block logging, anti-cheat, web maps. Each keeps its own files or database. Check each plugin’s documentation for where.
Backups and the hostEvery backup archive holds the player’s files from that day. Hosting panels and Discord bots may keep their own logs.

Answering an access request by hand

  1. Confirm who is asking. Ask the requester to prove they control the account, for example by joining and running a command you name, or by messaging from the linked Discord or email address. Do not send personal data to an unverified person.
  2. Settle the UUID. Names change; files are keyed by UUID. Look the name up in usercache.json, and ask for old names too.
  3. Let the files catch up. The server writes an online player’s file when they leave or when it saves. Ask them to log out first, or the copy you take may be out of date.
  4. Copy the per-player files from the table above, from every world folder.
  5. Search the logs for the name and the UUID. On Linux: zgrep -h -e "Steve" -e "<uuid>" logs/latest.log logs/*.log.gz. A short name also matches other players’ lines, so read what you find before sending it.
  6. Add what other plugins hold, using each plugin’s own export or query.
  7. Send it securely and write it down: the date you received the request, how you checked identity, what you sent and when. An export contains personal data, so do not leave the zip lying in a public folder.

Before you delete anything

  • Make sure the player is offline. If they are online, the server writes their files again when they leave and the “erased” data comes back.
  • Decide what you keep, and why. Many servers keep an active ban so a banned player cannot simply come back. Whether you may is your decision; write the reason down instead of keeping it by accident.
  • Logs and backups. Editing old logs by hand is error-prone and can destroy evidence you need for moderation. A cleaner approach is a retention rule (delete logs and backups older than a fixed number of days) and telling the player that older copies expire on that schedule.
  • Other plugins. Deleting the server’s files does not touch a permissions or economy database. Go through each plugin that stores player data.
  • Keep a receipt. A list of what was deleted, with the date, is what you show if the player asks whether it happened.