Version 4, in force from 9 October 2026.
The short version
- The Architect is an AI build assistant for Minecraft: Java Edition. To design a build, it needs to see what you ask for and a bit of your Minecraft world. You are talking to an AI, not a person.
- You need an account: you sign in with your email address (we send you a sign-in link, no password). There is no free AI usage: you use The Architect with usage (a subscription or extra usage packs) or with your own API key.
- The Architect is for people aged 15 and over.
- To link the game to your account, the mod proves which Minecraft account you play with, and we store its ID and name.
- There is also a website, the Studio, where you chat and keep your builds. Your builds are private: nothing is shown publicly. If you share a build, anyone who has its code can open it (section 3.3).
- When you send a message, the mod sends your message, a screenshot of your game (you can turn this off) and game info, like your position and the blocks around you, to our server. Our server asks an AI model to write the reply.
- The AI models behind The Architect Small, Medium and Large are run by Anthropic, and sometimes by OpenAI (as a fallback). OpenAI also runs our automatic moderation check. Both are US companies.
- We keep your conversations and builds so you can continue later, and delete game conversations 30 days after you last used them.
- We don't sell your data, we don't show ads, and we don't use your data to train AI models.
- We use only strictly necessary cookies (sign-in and security), no tracking and no ads, so there is no cookie banner.
- Turn screenshots off with
/screenshots off. You can export your data, or delete your account, at any time in the Studio. - If you use your own API key, we never store it.
- When something breaks, our server and the Studio send a technical error report to Sentry, without your messages, world data, email, IP address or keys. The game only sends error reports if you turn them on in the mod's settings.
1. Who we are
The Architect is run by Mikkel Nøhr, a private individual, Hvidkløvervej 8, 6650 Brørup, Denmark ("we", "us"). There is no company behind it for now. We are the data controller for the data described here.
Contact for privacy questions: [email protected]. We have no data protection officer, because the law doesn't require one for us.
This policy covers The Architect hosted service: The Architect mod while it is connected to our server, your account, usage and payments, the Studio, and this website.
2. How The Architect works
- The Architect mod runs on your computer, next to Litematica.
- It sends data only to our server, never straight to an AI company.
- Our server builds the reply with an AI model and sends the reply and the ghost blueprint back to your game.
When data is sent
- When you join a world, the mod connects to our server. It sends the mod and Minecraft versions, your game language, your login token (if you are signed in), your The Architect settings, and which world you are in (the server address, or the name of your singleplayer save) and which dimension. We use this to open your saved conversation for that world, and we store a conversation entry for that world. No screenshots, blocks or positions are sent at this point.
- When you send a message, or use a command such as undo, export or rate, and while The Architect answers, the mod sends the data in section 3.
- If the mod can't reach our server, nothing is sent. Without sign-in, the mod does not connect at all.
- Using the Studio website, you send your messages and the files you upload (section 3.3) to our server, which asks an AI model in the same way.
- Turn screenshots off with
/screenshots off.
3. What we collect
3.1 What you send in the chat
| Data | Details |
|---|---|
| Your messages and The Architect's replies | Up to 8,000 characters per message. Also your answers to The Architect's questions, /rate good or /rate bad with an optional note, and rules you save with /remember. |
| Screenshots | On by default. The mod takes one when you send a message, one about 1 second after the ghost changes (sent with your next message), and The Architect can take one itself while it answers. Game view only: the hotbar, hand, Minecraft chat, debug screen and The Architect window are hidden. Up to 1024 pixels wide (up to 1568 when The Architect asks for more detail). A screenshot shows whatever is visible in your game, for example other players and their skins, signs and builds. Turn off with /screenshots off, or use /permissions screenshots ask to be asked before The Architect takes one itself. |
| Images you attach | Images you drag into the The Architect window, shrunk to at most 1024 pixels. Also the 📎 button (a picture of your current view), pasted images and image links, at most 3 images per message. When you paste a link to an image, the mod downloads it straight from that website (so that website sees your IP address) and then sends the image to us. Attached images are sent even when screenshots are off, because you chose to send them. |
| Schematic files | .litematic files you drag into the The Architect window. |
3.2 Game data
| Data | Details |
|---|---|
| Game state (with every message) | World (server address or save name), dimension, game mode, the ghost you see (build name, version, position, rotation), where you stood and which way you looked when you sent the message, and the block you pointed at (up to 128 blocks away). |
| Build progress (survival) | How much of the ghost you have built, and up to 32 examples of blocks you placed differently from the ghost. |
| Blocks around you | When The Architect needs to see the terrain, the mod reads the blocks in an area of at most 128 × 128 × 128 blocks: around you, or your Litematica selection. Only chunks your game has loaded. |
| Your position | Position, facing, biome, the block under you and the time of day in the game. |
| Other players nearby | See section 4. |
| Your schematic library | Only if you turn it on with /library on. The list of your schematics stays on your computer. While you chat, The Architect can search it (names, authors, descriptions, sizes, main blocks, a rough sketch) and open a schematic file. The chat shows a line when it opens one. |
3.3 Account, Studio, subscription and payments
- Account: your email address (and a normalised copy of it), an account ID, sign-up and sign-in times, whether you confirmed that you are 15 or over, and which version of these documents you accepted.
- Sign-in link: when you sign in, we email you a one-time link. You can also ask for it in the game: then we also keep, with the link, which Minecraft account asked for it (its ID). We store only a scrambled version (a "hash") of the link itself, and delete it within 24 hours after it expires. Website sessions are stored as hashes too, with a label, last-seen time and expiry. We never ask for a password.
- Sign-in countries: to warn you about unusual sign-ins, we keep the country codes (for example "DE") your account has signed in from, when each was first seen, and the time of the last alert we sent you, and we email you when a sign-in comes from a country that is new for your account. We keep no IP address or city for this. They are kept until you delete your account.
- Linking the game (device login): the mod shows a short code that you approve on our website. To check that the Minecraft account is yours, the mod and our server use Mojang's session servers, the same check a Minecraft server does when you join. We store your Minecraft account ID (UUID) and name, and a record of each linked device (a label, when it was linked and last used). The mod then keeps a login token on your computer; we store only a hash. You can see and revoke linked devices in your account. On every sign-in from the game, we also keep, while that sign-in is open, a shortened form of the network address the game connected from (only the first part of the IP address, never the full address). When you confirm in the browser, we compare it with the browser's network: on a different network we ask for the code shown in your game, so nobody can link their game to your email with a single click. It is deleted together with the device-login code.
- Studio: the projects you create (a title and the conversation), the builds and every version of them (the blueprint file, the build program, the material list),
.litematicfiles you upload (at most 2 MiB each), and a list of builds you "send to Minecraft". Studio data belongs to your account and is only visible to you. We do not offer public profiles or a public gallery. - Subscription and usage: your plan, its status and renewal dates, and a ledger of every change to your usage (which request, how many usage units, when, purchases and refunds). Plan (Settler, Builder or The Architect), billing interval (monthly or yearly), pack purchases, and your optional monthly spending limit with the month's purchase total in US dollars.
- Payments: processed by Stripe, our payment provider (section 7). We never see your full card number. We receive from Stripe your customer and payment references, the product bought, the amount, the date and the payment status, and the email address you gave at checkout.
- Moderation records: when our automatic check flags a message, we store a flag record: the time, whether it was your message or a reply, which categories were flagged, the scores, whether it counted as a strike, and a short excerpt (at most 200 characters) of the flagged text with emails, links, numbers and keys removed. We also store whether your chat is paused or under review. See section 9 for how long.
- Reports: when you report a reply, we store the report and the reply it concerns.
- Shared builds (only if you use
/share): we store the build (block types and their settings only; we rebuild it ourselves and drop signs, books, items and any other text), the title you give it (at most 40 characters), your Minecraft name (shown as "Shared by"), your account ID as its owner, when it was made, when it expires and how often it was opened. Only if you tick "Include location", also the dimension and coordinates where it stands and a one-way scrambled form (a "hash") of the server's address, which is never shown to anyone. Who can see it: anyone who has the share code, and nobody else (there is no list or search); they see the build, the title and your Minecraft name, and the location only if they are on the same server. The title is checked by our automatic moderation (OpenAI, section 7), like a chat message. You can revoke a share at any time with/shares; then it is deleted at once. Live shares (only if you choose "Live"): each new version you make of that build is stored as a new version of the share, checked the same way, and we keep the last 10 versions (older ones are deleted). The game of someone who opened it checks about once a minute for a newer version while that ghost is in their world; that check sends only the share code. - Reports of shared builds: when you report a shared build, we store your account ID, the share code, your reason and the time. When several players report the same share, it is hidden until a person has looked at it.
- Own API key: if you use your own key, we use it only for your requests and never store it (section 11).
3.4 Usage and technical data
- Usage log: for every AI call, we record your user ID, session ID, message ID, the AI model, the number of tokens (pieces of text) used, the estimated cost, the time, the result (ok, stopped or error), whether it ran on your usage or your own key, and the purpose (a reply, estimating the size of a request, or a one-line title for your history). It contains no message content. We need it to count usage correctly, set limits and spot abuse.
- Server logs: connection times, session ID, user ID, mod and Minecraft version, game language and error messages. Our logs are set up not to contain your messages or your own API key. IP addresses are seen by Cloudflare and our server software to deliver the service and apply rate limits; we don't keep web access logs of them.
- Error reports: when something breaks on our server or in the Studio, an error report goes to Sentry (section 7). It contains the type of error, where in our code it happened (file, function, line), the time, the app version, the environment (for example "production"), your browser or operating system type, and two labels: which app you used (game, Studio or API) and your plan name (for example "Builder"). It is set up so that it does not contain your messages, The Architect's replies, screenshots, images, uploads, world data, your email address, your IP address, your Minecraft name or ID, login tokens, cookies or API keys: our server and the Studio remove these before anything is sent, and we turned on Sentry's own data scrubbing and "don't store IP addresses" setting. Website addresses are cut down to the page path, without anything after
?or#. - Error reports from the game (opt-in, off by default): if you turn on "Send error reports" in the mod's settings, the mod sends our server the type of an error and where in the code it happened (class, method and line number) when a The Architect feature fails, plus your mod, Minecraft, Fabric Loader and Java version and your operating system type (Windows, macOS or Linux). Never message text, chat, world data, your Minecraft name, keys or login data. Our server forwards it to Sentry as above. Turn it off at any time in the same setting.
- Support: the emails you send us.
3.5 Improvement data (opt-in only)
If you opt in, we keep a correction log: how you react to builds, so we can make The Architect better. It records which build version you corrected, undo, redo, approve, export and clear, your ratings and notes, the text of your follow-up message, a comparison of the build before and after, and blocks you built differently in survival. We also keep copies of builds you rated good, exported or finished in survival (the build, a rendered picture and your request). Your /rate ratings and the feedback card are kept only with this opt-in too. It is off until you turn it on: "Help improve The Architect" on the Account page in the Studio, or in the mod's settings (/improvement on); both are the same switch for your account. Without your opt-in we don't collect it. You can withdraw your consent at any time in the same place or by email; we then delete what we kept.
3.6 What we don't collect
- Your Microsoft or Minecraft login or password.
- Minecraft chat, your inventory, or other players' chat, inventory or health.
- Files on your computer, except files you attach and, if you turn it on, your schematic library.
- Your Microsoft account details or Minecraft access token: during linking, the mod sends only a cryptographic proof to Mojang's session server and our server asks Mojang whether it is valid.
4. Other players near you
If other players are close to you, The Architect can get their Minecraft name and position: at most 8 players, within the range the server already shares with your game. It never gets their chat, inventory, skin data or health. Other players can also be seen in screenshots.
We use this so The Architect understands requests like "build next to Alex's house" and doesn't plan a build where people are standing. This data stays in the conversation it belongs to and is deleted with it. The legal basis is our legitimate interest (section 5).
Are you one of those players, and don't use The Architect? You can contact us (section 1) to ask about your data or object to it.
5. Why we use your data, and our legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Design builds and answer you | Chat, screenshots, images, schematics, game data, conversations, builds, base memory | Contract (art. 6(1)(b)) |
| Nearby players' names and positions | Section 4 | Legitimate interest (art. 6(1)(f)): so that requests like "build next to Alex's house" work |
| Account, sign-in, linking your Minecraft account, Studio, usage and limits | Account, Minecraft ID and name, devices, Studio data, usage log, usage ledger | Contract (art. 6(1)(b)) |
| Payments and bookkeeping | Purchase and usage records | Contract (art. 6(1)(b)) and legal obligation (art. 6(1)(c)), the Danish Bookkeeping Act |
| Security, abuse prevention (including bans of Minecraft accounts), rate limits, error fixing | Server logs, usage log, server and Studio error reports, Minecraft ID | Legitimate interest (art. 6(1)(f)): keeping the service working and secure. You can object (section 13) |
| Error reports from the game | Section 3.4 "Error reports from the game" | Consent (art. 6(1)(a)): off until you turn it on; turn it off at any time |
| Moderation and reports | Messages, attached images, replies, flag records, reports | Legitimate interest (art. 6(1)(f)), in particular protecting young users, and our duty to keep the service safe |
| Sharing a build (only if you share) | The shared build, its title, your Minecraft name, the location if you include it | Contract (art. 6(1)(b)): you ask us to share it with whoever has the code |
| Moderating shared builds | Share titles, reports of shared builds, the record of a removed share | Legitimate interest (art. 6(1)(f)): keeping shared content safe, in particular for young users, and handling notices about illegal content |
| Improving The Architect | Improvement data (3.5) | Consent (art. 6(1)(a)); you can withdraw it at any time |
| Support | Your emails | Contract or legitimate interest |
6. AI in The Architect
- The Architect's replies are written by an AI, not a person. They can be wrong. The game window, the Studio and our website tell you that you are talking to an AI.
- The Architect Small, Medium and Large are names for different AI models. They run on models from Anthropic. If Anthropic fails, our server may automatically use a model from OpenAI for that request instead. We may change the model behind a tier.
- Besides the reply itself, The Architect makes small extra AI calls. For example, it estimates how big a request is, and writes a one-line title for your conversation list.
- We don't use your data to train AI models. Under their business terms, Anthropic and OpenAI don't train their models on the data sent through their APIs.
- Moderation: your messages, the images you attach and The Architect's replies are checked by OpenAI's moderation service. It is an automated check. If it flags a message, the message is not sent to the AI model, and repeated flags pause your chat or send the account to a person for review (see the Terms, section 12). A pause is automatic and temporary. A ban is never automatic: a person decides it. If you think an automated block is wrong, email us and a person will look at it. The moderation also applies when you use your own API key.
- If a message suggests you might hurt yourself, you see a kind note with where to find help. This is never held against you and we don't store it.
- OpenAI gets only the text or image to check, never your account, email or key. If the moderation service is down, messages go through unchecked for that time (the AI models have their own safety rules).
- Apart from that short automatic pause, we make no decisions about you by automated means alone that have legal or similarly significant effects.
7. Who we share data with
We only share data with companies that help us run The Architect, and only what they need. We don't sell data or share it for advertising. Each of them is a data processor under its own data processing terms, except where noted.
| Who | What for | Where |
|---|---|---|
| Anthropic | Runs the AI models: gets your messages, screenshots, images, game data and schematic summaries while The Architect answers. By default Anthropic deletes this data within 30 days, but may keep it for up to 2 years if it is flagged for breaking Anthropic's usage policy (Anthropic's policy, checked 29 September 2026). | USA |
| OpenAI | Fallback model when Anthropic fails (gets the same data as Anthropic for that request), and the automatic moderation check (gets your message text, attached images and The Architect's replies). | USA |
| Stripe | Payment provider: processes payments, receipts, refunds and fraud checks for our sales. Stripe is a controller for the payment data it collects for its own legal duties (e.g. fraud and anti-money-laundering checks), under its own privacy policy. | EU / USA |
| Hetzner and Ubicloud | Our servers and our database (Hetzner Online GmbH, Germany; Ubicloud for managed Postgres). | EU |
| Cloudflare | Our website, domain, network protection and the bot check (Turnstile) on sign-in. Sees IP addresses. | USA / worldwide |
| Google (Gmail SMTP) | Sends the sign-in link, receipts-related and support emails (gets your email address and the email text). | USA / worldwide |
| Sentry (Functional Software, Inc.) | Error reports from our server, the Studio and (only if you turn it on) the game: what is listed in section 3.4. Used in a Sentry organisation of its own, in Sentry's EU data region. | EU; the company is a US company |
| Backup storage | Our database backups. They are encrypted on our server before they are uploaded, so the storage provider can't read them. | EU |
| Mojang / Microsoft (Minecraft session servers) | Used when you link the game: the check that proves you own the Minecraft account. They see our server's request and your Minecraft name. | USA / worldwide |
| Authorities | Only when the law requires it | n/a |
With your own API key, Anthropic or OpenAI processes your requests under your own agreement with that company and its privacy policy, as your service provider. Our moderation check (OpenAI) still applies.
8. Transfers outside the EU
Some of these companies are based in the USA. We only transfer data with a legal safeguard: the European Commission's Standard Contractual Clauses in the provider's data processing terms, and/or the provider's certification under the EU-US Data Privacy Framework. Email us (section 1) if you want details or a copy.
9. How long we keep data
| Data | How long |
|---|---|
| Game conversations and builds (including nearby players' names in them) | Deleted 30 days after you last used the conversation. At most 100 conversations per player. |
| Screenshots and attached images | Not stored by us. After the reply they are replaced by a placeholder in your saved conversation. |
Attached .litematic files and schematics The Architect opens from your library |
Kept in memory for the session only. |
| Known areas (block snapshots from area reads, used so The Architect doesn't read the same area twice) | 30 days after the last update. |
| Sign-in links and device-login codes (with the shortened network address of an email sign-in from the game) | Deleted within 24 hours after they expire (device codes and the network address after 1 hour). |
| Website sessions and login tokens | Until they expire or you sign out or revoke them. Linked devices that are unused for 90 days are removed; a removed or revoked device's record is deleted 30 days later. |
| Studio projects and builds | Until you delete them or delete your account. We don't delete them automatically. |
| Studio "send to Minecraft" entries | 30 days. |
| Checkout records | 90 days. |
Base memory (/remember rules) |
Until you delete them with /forget or delete your account. |
| Usage log | 24 months, then deleted. |
| Account | Until you delete it. 30 days after you delete it, your account, Studio data, linked Minecraft ID and devices are deleted. Billing and usage records stay, with your email address removed. |
| Purchase and usage records | 5 years (Danish Bookkeeping Act). |
| Moderation flag records | The text excerpt is cleared after 30 days, and the record is deleted after 90 days. Pause and review status of an idle account is deleted after 90 days. |
| Reports | Until we have handled the report, then 90 days. Deleted earlier if you delete your account. |
| Shared builds | 30 days after the share was last opened or updated (each opening or new live version renews it), then deleted. A live share keeps its last 10 versions. Deleted at once when you revoke it. When you delete your account, your shares stop working at once and are deleted with your account data. A share we took down is kept, hidden, until those 30 days run out, as a record of the decision. |
| Reports of shared builds | 90 days, then deleted (earlier once the share is gone and the report was handled). |
| Improvement data | 12 months, or until you withdraw your consent (then deleted within an hour). |
| Server logs | 30 days. |
| Error reports (at Sentry) | At most 90 days, then deleted by Sentry. |
| Database backups | 30 days, then deleted. A deleted account can therefore remain in a backup for up to 30 days. |
| Support emails | 24 months after your last message. |
| Your own API key | Never stored. |
| At Anthropic and OpenAI | Anthropic: up to 30 days, or up to 2 years if flagged (Anthropic's policy). OpenAI: as set in its API data terms; we ask it not to store requests where that is possible. |
10. How we protect your data
- An encrypted connection (TLS,
wss://andhttps://) between the mod or browser and our server. The mod refuses unencrypted connections to anything except your own computer. - Login tokens and sign-in links are stored only as a hash, and you can revoke linked devices.
- Data files on our server can be read only by the server's own user account. Only Mikkel Nøhr has access to the data.
- Your own API key is removed from logs, chat text and stored data.
- Database backups are encrypted, and we get alerts when something goes wrong.
- If a data breach happens, we tell the Danish Data Protection Agency (Datatilsynet) within 72 hours, and you too when the law requires it.
11. Using your own API key
- Only for players aged 18 or over, because the AI companies' accounts require it. You still need an account with The Architect. This works in the game only.
- You paste the key into the mod's settings (it is never typed into the chat). The mod keeps it on your computer in a separate file that only your computer user can read, and shows only its last 4 characters.
- The mod sends the key to our server over an encrypted connection. Our server keeps it in memory only, for your connection, and uses it only to run your requests. It is never saved to disk or a database, and never logged. If you disconnect while The Architect is answering, the answer finishes on your key, and then the key is gone.
- The Architect removes anything that looks like a key from chat text before the AI sees it.
- Your AI provider bills you directly, and its own terms and privacy policy apply to what it processes on your key.
- We still keep the usage log (section 3.4) for your own-key requests: token counts only, no content.
- To remove the key, use
/provider clearin the game, and revoke it with your provider.
12. Children and teens
Many players are teenagers. Our rules:
- The Architect is for people aged 15 and over. We ask you to confirm this when you create an account. We don't check your age any further, so please tell us if you know that a child under 15 has an account.
- If something is based on consent (like improvement data or game error reports) and you are under the "digital age of consent" in your country (13 in Denmark, up to 16 elsewhere in the EU), a parent or guardian must agree, so please ask them first.
- Under 18: a parent or guardian must make any purchase.
- Own API key: 18 and over only.
- The Architect window and the Studio clearly say that you are talking to an AI. Messages and replies are moderated automatically.
- No ads, no selling of data, no marketing profiles, no public profiles, no public gallery of builds (a shared build can only be opened by people who have its code, and shows only your Minecraft name), and no chatting with strangers through The Architect.
- If we learn that a child under our minimum age has an account, we delete it.
- Parents and guardians can contact us to see or delete their child's data.
- Tip: don't write personal details in the chat, like your real name, address, school, phone number or passwords.
13. Your rights
You have the right to:
- see the data we have about you, and get a copy;
- have wrong data corrected;
- have your data deleted;
- limit how we use it, or object to it (especially when we rely on legitimate interest);
- get your data in a machine-readable format;
- withdraw your consent at any time, when we rely on it;
- ask that a person looks at an automatic moderation decision.
How: in the Studio, on the Account page, you can export everything we store about you and delete your account. For anything else, or if you prefer, email [email protected]. We answer within one month, and may first check that it's really you.
In the game:
/screenshots offstops screenshots./permissions screenshots askmakes The Architect ask before taking one./library offstops The Architect from using your schematics./improvement offwithdraws your improvement data consent (section 3.5) and deletes what we kept./forget <n>deletes a base memory rule./clear-builddeletes the current build./newstarts a fresh conversation. The old one stays in your history until it expires (section 9).
Complaints: you can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, www.datatilsynet.dk, or to the authority in your own country. We'd be glad if you contact us first.
14. Data that stays on your computer
The mod keeps some files in your Minecraft folder. We can't see them. They are only sent as described above.
config/architect.json: your settings, including whether game error reports are on (off by default). Your login token is kept in a separate file that only your computer user can read.config/architect-anthropic-keyandconfig/architect-openai-key: your own API keys, if you use them.architect/areas/: a cache of blocks the mod has read (at most 64 MB).architect/builds/andarchitect/snapshots/: ghost versions, and undo snapshots for creative placement.architect/library/index.json: the list of your schematics (only if you turned the library on).schematics/architect/: builds you exported.
You can delete these files at any time.
15. Our website and cookies
- Cookies: the website and the Studio use only strictly necessary cookies: a session cookie that keeps you signed in, and a security (CSRF) cookie that protects your actions in the Studio. They are needed to provide the service you ask for, so under the ePrivacy rules no consent and no cookie banner is needed. We use no analytics, no tracking, no advertising cookies and no social-media plug-ins.
- The legal pages and landing page set no cookies. The page font is hosted by us, so your browser does not contact Google or other font services.
- The website is delivered through Cloudflare, which processes your IP address to deliver the pages and protect against attacks. The sign-in page uses Cloudflare Turnstile, a bot check, instead of a captcha with tracking.
- If error reporting is switched on, the Studio loads Sentry's error-reporting script from our own server (not from Sentry). It sets no cookies, stores nothing in your browser, records no clicks, screen recordings or performance data, and sends only the error reports described in section 3.4, directly to Sentry. It runs on legitimate interest (fixing errors); you can object (section 13).
16. Changes to this policy
If we change this policy in a way that matters, we tell you in the game, in the Studio or by email at least 30 days before the change takes effect. The version and date at the top show the current version.