Watermelon72
WriteGet started
YOUR INFORMATION

Privacy policy

How your information is used, what other readers can see, and the choices you have.

Effective September 10, 2026

This policy covers Watermelon72, an independent publishing community for DemocracyCraft players. It describes the features currently implemented on this site.

Information we collect and why

  • Sign-in details. Discord provides your account ID, username, and basic profile information using its identify permission. We store your Discord ID and username to recognize your account. We do not request access to your Discord messages or your password. OAuth access tokens are used during sign-in and are not saved in the application database.
  • Minecraft identity. We store your verified Minecraft UUID, username, and verification time. To confirm account ownership, we record a small in-game payment challenge, transaction reference, and refund status. These records also help prevent an account from being linked to multiple people.
  • Your content and preferences. We store your display name, bio, interests, posts, drafts, uploaded images, comments, follows, bookmarks, likes, and poll votes to provide the features you use.
  • In-game wallet activity. Balances, deposits, withdrawals, subscriptions, unlocks, and ledger records are stored to process and reconcile in-game currency. The site does not collect payment card details for these features.
  • Security and usage. We keep sessions, rate-limit records, moderation reports, privacy requests, and an audit log of account and publishing actions. The app uses a hash of the request’s network address for rate limiting and daily read counts. Hosting infrastructure may also process network addresses and request logs.

What other readers can see

Your display name, Minecraft handle, skin avatar, bio, join date, and verification badge can appear publicly. Published posts, replies, publication membership, and aggregate engagement counts are public. Your Discord ID and Discord username are not included in public profile responses. Your drafts, wallet details, bookmarks, and topic preferences are not included in those responses.

Site administrators have access to records needed to operate the service, resolve issues, and moderate content. Drafts are available to their author and site administrators. Poll totals are shown to readers; individual voter account IDs are not included in public poll responses.

How anonymous shorts work

When you choose “Post anonymously,” readers see “Anonymous” without your name, profile link, or Minecraft avatar. The short is excluded from your public profile and author-based following feed. We retain its connection to your account so you can edit it and administrators can investigate reports. This feature hides public attribution; it does not erase account ownership. Replies you leave still use your public profile, and information you include in the short itself may identify you.

You can change a short’s anonymity setting in the editor. If it was previously published under your name, screenshots, cached pages, or copies may still show that earlier identity.

Cookies and browser storage

The wm_session cookie keeps you signed in for up to 30 days. The short-lived wm_oauth cookie helps secure Discord sign-in and expires after 10 minutes. These cookies are HTTP-only. Your light, dark, or system appearance preference is stored in your browser under watermelon72-theme. Signing out ends the current session; clearing browser storage removes the theme preference.

Services involved

Discord handles sign-in, Minecraft identity services resolve player accounts, and DemocracyCraft’s treasury service handles verification payments and in-game transfers. Minecraft avatars load from Crafatar, which receives the avatar request and player UUID. Your browser may contact external image hosts when viewing images embedded by writers. Those providers handle requests under their own policies. The application does not include an advertising tracker or a data-selling integration.

Storage and retention

Account records, content, and wallet activity are stored in the site’s database; uploaded images are stored on the server. We currently retain these records until they are removed through an administrative process. Session access expires after 30 days. Unpublishing moves a post back to drafts rather than deleting it. Backups may retain earlier copies, and some transaction, moderation, or security records may need to be retained when handling a removal request.

Your choices and privacy requests

You can edit your name, bio, and interests on your profile, edit or unpublish your posts in Your stories, remove your responses, undo likes and follows, and remove saved posts from your library. To request a copy of your information, account deletion, a correction, or help with another privacy issue, use the form below. Requests go to site administrators for review; submitting one does not immediately delete your account. Include only the details needed to identify the issue.

Policy updates

We will update this page and its effective date when these practices change. Review it before sharing information you consider sensitive.