1. Introduction
This Privacy Policy explains how Boundless Missions collects, uses, stores and protects your personal information when you use the KSP add-on, the Discord bot, or this website (collectively, the “Service”). It is written in accordance with the KSP Forum Add-on Posting Rules (Rule 8) which require transparency about data collection in KSP add-ons.
By using the Service and providing your consent through the in-game consent window, you acknowledge that you have read and understood this Privacy Policy. This policy should be read alongside our Terms of Service.
2. Definitions
- Service: The Kerbal Space Program (KSP) add-on, the Discord bot, and this website collectively.
- Device identifier: A random identifier (GUID) the add-on generates once on first run and stores in its
PluginDatafolder. It contains no personal or hardware information: it is not derived from your MAC address, serial numbers or any other property of your computer. The add-on does not read any of those at all. - Device report: When someone tries to use your account from a device you have not approved, you receive a Discord prompt asking whether it was you. Pressing “report” opens a moderation ticket, and the reported device uploads its diagnostics (KSP.log) to that ticket.
- KSP.log: The standard diagnostic log file generated by Kerbal Space Program, used to identify software errors and verify game integrity during a report.
3. Data We Collect
We collect only the data necessary to provide the Service. The table below lists every category of personal data we process, why we need it, and when it is collected:
| Data | Purpose | When collected |
|---|---|---|
| Email address | Only when you create a Boundless Missions account on this website. It is your sign-in identity and how an account can be recovered. You can also use the add-on with a Discord account alone and never give us an email address at all. | On website sign-up (from Google, or from an email and password) |
| Boundless username and display name | The public handle other players see, and the name a friend request is addressed to. The username is reserved to you for as long as the account exists, so that two accounts cannot share one. | When you choose one |
| Profile picture you upload | Shown to other players in the same places a Discord avatar would be. Only if you upload one. | On upload |
| Two-factor enrolment | If you turn on two-factor authentication, the shared secret your authenticator app uses and the hashes of your recovery codes. Used only to check the codes you enter when signing in. | When you enable two-factor authentication |
| Discord server membership | Your Discord user ID, your Discord handle and the date you joined. Recorded so that a player record exists to hold your balance, progress and level, and so a moderator can look you up when you ask us about your account. No message content is ever read or stored. | When you join our community Discord server |
| Discord account link | Ties contracts, balance and missions to your identity | On linking |
| Discord profile information | Your Discord display name (the nickname you use in the community server, or your account name if you have none), your profile picture, your Boundless username if you have claimed one, and your level. Stored so they can be shown to other players inside the add-on (in the player selectors used to send a craft, offer a contract or issue a rescue) and next to the contracts, marketplace listings and auctions you take part in, so people can tell who they are dealing with | On linking, and refreshed whenever a list you appear in is drawn |
| Device identifier | A random GUID (no hardware data; see Section 2) that binds your install to your account, so an unapproved device cannot use it | On linking and with each request |
| IP address | Connection routing, rate-limiting and abuse prevention | Each server request |
| Gameplay data | Vessel telemetry, craft files, part lists and screenshots submitted to contracts or shared | When you submit |
| KSP.log | Debugging bug reports and investigating device reports | When you file a bug report (your own log, trimmed on your machine before upload), or from the reported device during a device report |
| Website & community activity | Marketplace listings and purchases, likes/dislikes, reports you file, auction bids, contracts you create or accept | When you use those features |
| Moderation records | The reason and duration of a service suspension, and the outcome of reports, so enforcement is accountable | When a moderation action is taken |
4. Consent and Legal Basis
Per KSP Add-on Posting Rule 8.1, we require clear, informed consent before collecting any information from your game. The add-on collects and transmits nothing until you explicitly opt in.
One collection sits outside that gate, and it is listed in the table above. If you join our community Discord server, the bot records your Discord user ID, your Discord handle and the date you joined, so that a player record exists to hold your balance and progress. That is the whole of it. No message content is read or stored, and nothing at all is collected from your game until you accept the consent window described below.
On first launch the add-on presents a consent window that asks you to:
- Read and agree to this Privacy Policy.
- Read and agree to the Terms of Service.
- Expressly consent to your account, device and gameplay data being collected and transmitted to the Boundless Missions servers.
All three acknowledgments must be checked before any data leaves your game. Your consent is recorded locally and can be revoked at any time (see Section 7).
5. How We Use Your Data
We use the data we collect to:
- Operate the Service: link your game to Discord, track contract progress, manage economy and missions.
- Show you to other players: display your Discord name, profile picture, Boundless username and level in the add-on’s in-game player selectors and beside the contracts, listings and auctions you take part in, so that players choosing who to send a craft or a mission to know who they are picking.
- Protect the community: detect cheating, abuse, and multi-accounting through device and IP identifiers.
- Investigate reports: review KSP.log data when moderation reports are filed or suspicion flags are raised.
- Review submissions automatically: screenshots, mission text and vessel telemetry you submit to a contract or mission may be assessed by an AI model (see Section 6) to classify the mission and review the submission. Review outcomes can be raised with the moderation team through a ticket if you believe one is wrong.
- Promote the Service: crafts you share (the file, the blueprint and thumbnail renders made from it, and the screenshots submitted with it) may be shown in material promoting Boundless Missions, credited to your display name, as described in Section 7 of the Terms of Service.
- Improve the Service: diagnose bugs and improve reliability using aggregated, anonymized data.
What other players can see. Boundless Missions is a community service, so part of your profile is visible to other players by design: your display name, your profile picture, your Boundless username and your level. If you linked from Discord, your account identifier is your Discord ID, and it is visible to other players wherever you appear — on a marketplace listing, in a player selector, on a friend request — because it is the identifier those features address you by. Your device identifier, your IP address and your KSP.log are never shown to another player, and neither is anything you have not published. The display name, picture and level are the same public profile Discord already displays in the community server; your Boundless username is ours, is the same in every server, and is shown only if you claimed one. All of it is shown only to other linked players. If you would rather not appear at all, turning off data sharing (Section 7) or deleting your data (Section 8) removes you from these lists. Separately, and for the opposite case, the add-on can hide other people’s profile pictures and usernames from your screen (useful when you are streaming or recording) under Settings → Privacy; while that is on, their pictures are never downloaded rather than merely not drawn.
We do not sell, rent, or share your personal data with third parties for their own use. Your data is never used to profile you, and never used to advertise anyone else’s product: the one promotional use we make is showing crafts you have shared, credited to you, in material about Boundless Missions itself (see above and Section 7 of the Terms of Service). The service providers that process data on our behalf are listed in Section 6.
6. Service Providers
Running the Service relies on a small number of providers that process data on our behalf, under their own published privacy terms:
- Google Firebase (Cloud Firestore and Cloud Storage, part of Google Cloud): all Service data described in Section 3 is stored here.
- Google Gemini API: screenshots, mission text, and craft/vessel telemetry you submit may be sent to Google's Gemini models for the automated review and classification described in Section 5. We do not use this data to train models or for advertising.
- Google reCAPTCHA Enterprise (via Firebase App Check): runs on this website to verify that signed-in requests come from the genuine web app, as an abuse-prevention measure.
- Discord: the bot and community features run on Discord, whose own privacy policy governs your Discord account.
7. Your Right to Opt Out
In accordance with KSP Add-on Posting Rule 8.2, the add-on provides a built-in way to stop all data collection at any time:
How to opt out: Open the mod toolbar → Settings → Data sharing → toggle off. The add-on will immediately stop sending any information to our servers.
Opting out means community features that require server communication (contracts, missions, economy) will become unavailable, but you can continue to use KSP normally.
8. Data Deletion and Your Rights
Per GDPR and KSP Add-on Posting Rule 8.3, you have the Right to Access, Right to Rectification, Right to Restrict Processing, and Right to Erasure regarding your personal data. To exercise these rights or request full deletion of your data at any time:
- Use the
/b deletemydatacommand in Discord, or - Contact us directly through the community Discord server, or
- Email legal@boundlessmissions.com — the route to use if you signed up on this website and have no Discord account, since the command above needs one.
Upon receiving a valid request we permanently delete, within a reasonable timeframe: your profile (XP, balance, levels, preferences); your account record, including your email address, display name, username and profile picture; your sign-in credential itself; your two-factor enrolment and recovery codes; your session and device bindings, and the device identifiers and IP addresses held with them; your friend list, and your entry in other players’ lists; your installed-parts catalog; your achievement progress and marketplace votes; your notification history and pending craft deliveries; and your corporation record. Your marketplace listings are delisted, so nothing further is sold.
Some records are kept, because they are also somebody else’s. Contracts and auctions you were party to, and support tickets you opened, remain so that the other person’s history stays intact and moderation stays accountable. Craft files another player has already bought stay available to that buyer — deleting your data stops further distribution, but it cannot recall a copy already delivered. Anonymized, aggregated statistics that cannot identify you may also be retained. Ask us if you need any of these looked at individually.
You can also log out every device at any time from the add-on, which immediately revokes every session token issued for your account. Both this control and data deletion remain available even while your account is under a service suspension: a moderation action never takes away your privacy rights.
9. Data Minimisation
In line with KSP Add-on Posting Rule 8.4, we only collect the minimum data necessary to provide the Service:
- Everyday device identification uses a random identifier that contains no hardware or personal information (see Section 2). We do not read your MAC address or any other hardware identifier, in this flow or any other.
- Your KSP.log is read only in two user-initiated flows: a bug report you file yourself (your own log only), or a device report (the reported device's log). It is never read in the background.
- A bug report's KSP.log is trimmed on your own machine before upload (the first 2 MB and last 7 MB), so a large modded log is never transmitted whole.
- IP addresses are logged only for connection integrity, rate limiting and abuse prevention.
10. Data Storage and Security
Your data is stored in Google Firebase (Cloud Firestore and Cloud Storage, running on Google Cloud infrastructure) in projects administered by the Boundless Missions team. We take reasonable measures to protect your information from unauthorised access, loss or misuse. However, no system is completely secure and we cannot guarantee absolute security.
Internal access is limited: full account data is accessible only to the project owner, and Discord-server moderators can see only the moderation surface of their own server (listings originating there, reports and tickets filed there). A moderation role in one server grants no visibility into any other.
We retain your data only for as long as it is needed to provide the Service or as required to fulfil the purposes described in this policy. When data is no longer needed, it is deleted or anonymized.
11. The Local Browser Interface
The add-on includes an optional interface that opens in your own web browser instead of drawing windows inside the game. It is off by default and can be enabled or disabled at any time from the mod toolbar under Settings → Interface.
When you enable it, the add-on runs a small web server inside your own computer, on the loopback address 127.0.0.1, and opens your default browser to it. This is worth being precise about:
- The server accepts connections only from your own machine. It is never reachable from the internet or from other devices on your network, and there is no setting that would make it so.
- It listens on a different, randomly chosen port each time you start the game, and stops when you close the game or switch back to the in-game sidebar.
- It collects nothing additional. The interface displays the same account and gameplay data described in Section 3, and requests still travel to our servers through the add-on itself, under the same consent and opt-out controls.
- Your session token stays inside the add-on and is never given to the browser page.
Cookies. The interface sets one cookie, named gk, scoped to 127.0.0.1. It exists only so the page can prove to your own running copy of KSP that it is the page the game just opened. It is marked HttpOnly and SameSite=Strict, holds a random value with no personal information in it, is not sent to us or to any website, and disappears when you close your browser. It is not used for analytics, advertising or tracking of any kind.
Stored locally. Some preferences the interface uses are saved on your computer in the add-on's PluginData folder rather than in the browser, for example the players you mark as favourites. These files never leave your machine, and deleting the add-on removes them.
12. Cookies on This Website
This website (as opposed to the local browser interface above) sets exactly two cookies, both strictly functional:
__session: your sign-in session, set when you link the website to your account. It isHttpOnly(unreadable by page scripts) and is what authenticates your requests.bm_signed_in: a companion flag holding no secret and no personal data; it only tells the page whether to draw the signed-in navigation.
We use no analytics, advertising or tracking cookies. Google reCAPTCHA Enterprise (see Section 6) runs on signed-in pages for abuse prevention and operates under Google's own privacy policy.
13. Children's Privacy
The Service is not directed at children under the age of 13. Some countries set a higher minimum age of digital consent, for example up to 16 in parts of the European Economic Area under the GDPR, and where that is the case, the higher age applies to you. We do not knowingly collect personal data from anyone below the age that applies in their country. If you believe a child has provided us with personal data, please contact us through the Discord server or at either email address in Section 16 and we will promptly delete it.
14. Open Source and Transparency
All source code for Boundless Missions is publicly available under the GNU General Public License v3.0 (GPL-3.0). You are free to inspect the code to verify exactly what data is collected and how it is transmitted. You can also modify and redistribute the code in accordance with that licence.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, for material changes, notify users through the Discord server, this website and/or an in-game prompt. For material changes the add-on additionally stops transmitting any data and re-presents the consent window: nothing further leaves your game until you have read and accepted the updated policy. Continued use of the Service after changes constitutes acceptance.
16. Contact
Questions about this Privacy Policy? Reach out to us via email at legal@boundlessmissions.com. For account help, bug reports and anything else, email support@boundlessmissions.com, ask in the Boundless Missions Discord server, or open an issue on our GitHub repositories.