Privacy Policy
Last updated: 20 September 2026
modsdrop.com is a small file host for video game mods. It is run by one person in Hungary, not by a company. This page says what happens to your data when you visit. Everything below describes what the site actually does today, not what a template says it might do.
The short version
- There is no analytics at all on this site — no Google Analytics, no tracking pixels, no heatmaps, nothing.
- You never need an account to download. If you are not logged in, the site sets no cookies on your device. Cloudflare, which sits in front of the site, may set a security cookie of its own — see below.
- Your IP address appears in the web server’s log file. For rate limiting and for counting a download once, the site stores a salted hash of it instead of the address itself, for ten minutes or an hour.
- The download counter is a number stored against the file. It is not a list of who downloaded what.
- I do not sell, rent or swap your data with anyone.
- There are no adverts on this site yet. If adverts are switched on later, an advertising network’s own consent tool will do the asking, and this page will be updated before that happens.
Who is responsible for your data
The data controller is Máté Geszti (CrashMozi), a private individual (this is not a company), XVII. utca 4., 5400 Mezőtúr, Hungary. E-mail: [email protected].
The site is small enough that no data protection officer is required, and none has been appointed. Requests go straight to the person who runs the site, at the e-mail address above.
What is collected, why, and the legal basis
1. Web server logs. Requests that reach the server are written to a log line by the web server (nginx). Each line holds your IP address, the date and time, the page or file you asked for, the user agent string your browser sends, and how many bytes were sent back. Nothing else. Cloudflare answers some requests from its own cache, so those never reach this log — but Cloudflare keeps logs of its own, under its own policy. The server’s logs are rotated and deleted automatically. Legal basis: legitimate interests, Article 6(1)(f) GDPR — keeping the site running, finding faults, and spotting abuse such as scripted mass downloading.
2. Downloads, rate limits and the download counter. When you click Download, the site creates a signed link that works for six hours, and the server then streams the file to you. To stop abuse and to count each download once, the site stores short-lived markers in its own database (WordPress transients, on the same server). Those markers are keyed by a salted hash — technically md5 of a secret site salt plus your IPv4 address, or the first half (the /64) of an IPv6 address. The address itself is not stored in them. They expire by themselves: after ten minutes for link creation, and after one hour for the marker that counts a download once and for the marker that limits how often reports can be sent. The web server separately limits each IP address to 240 requests a minute to the WordPress part of the site, six attempts a minute on the login page, and four downloads running at the same time. The counter that results from all this is a number on the file page; no record is kept of which person downloaded which file. Legal basis: legitimate interests, Article 6(1)(f) — keeping the server standing up under load, and keeping the download numbers honest.
3. Reports, contact messages and copyright complaints. If you use the report button on a file page, the contact form or the copyright form, the site stores the reason you picked, the text you wrote (up to 4,000 characters), your e-mail address if you gave one, and the IP address the message came from. The e-mail address is optional on the report form on a file page, and required on the contact and copyright forms, because otherwise there is no way to answer you. If you send a report without an address, expect no reply — there is nothing to reply to. Messages are stored as private posts in the site’s WordPress installation on the same server, and are also sent on to the operator by e-mail. Please do not put sensitive personal details into the message box; only enough to understand the problem is needed. Legal basis: legitimate interests, Article 6(1)(f), for reading and answering your message; and, for notices about illegal content or copyright, a legal obligation, Article 6(1)(c), because the EU Digital Services Act (Regulation (EU) 2022/2065) requires a hosting service to act on such notices and, where it has an address to write to, to say what it decided.
4. The operator’s own login. WordPress sets cookies for the logged-in operator so that he stays signed in. Visitors never receive these cookies.
5. Files and virus scanning. In this first phase only the operator’s own files are hosted — public uploading is not open. Files carried over from crashmods.com may have a VirusTotal result stored alongside them (clean, too large to scan, or not scanned), and the file page always shows the true state. It is not true that every file has been scanned, and this site does not claim it is. This is information about files, not about you.
Cookies and analytics
The site itself sets no cookies for visitors who are not logged in, and there is no analytics or measurement software of any kind on it. No Google Analytics, no advertising pixel, no social media button that phones home, no fingerprinting.
One exception is outside my hands: Cloudflare sits in front of the site to keep it fast and to absorb attacks, and if it decides a request looks automated it may set a strictly necessary security cookie of its own to remember that the check was passed. That is a security function rather than tracking, and it is not something this site reads.
Because nothing on the site currently needs your permission, there is no cookie banner here. That would change on the day adverts are switched on — see the next section.
Adverts (not running yet)
There are no adverts on modsdrop.com at the moment. The plan is to apply later to an advertising network — Google AdSense or Mediavine. If that happens, the network’s code will run on the pages and, if you agree, will store and read cookies or similar identifiers on your device in order to measure and personalise advertising.
The asking would be done by the advertising network’s own consent tool (Google’s EU consent message, or Mediavine’s Journey consent tool), because that tool is what records your answer and passes it on to the advertisers. I will not add a second, home-made banner of my own: on my other site two banners appearing at once caused real problems, and one is enough.
I cannot describe that tool’s screens here, or promise where its “change your choices” link will sit, because it is not installed and I have not seen it on this site. Before adverts go live, this page will be updated with the network’s name, a link to its own privacy notice, and how to reopen its dialog or withdraw consent. Until then there is nothing to consent to, and no consent control to offer. Legal basis, on that day: your consent, Article 6(1)(a) GDPR together with the EU cookie rules — collected and stored by the advertising network, not by me.
Who else sees your data
- Hetzner Online GmbH (Germany) — the servers and file storage. Everything this site stores physically sits on their machines in Germany.
- Cloudflare — sits in front of the site as a content delivery network and security proxy, so it handles your IP address, your request and the traffic itself, and keeps its own logs under its own policy.
- Brevo, formerly Sendinblue (France) — sends reports and contact messages on to the operator by e-mail, so it processes the text of your message and your e-mail address if you gave one. After delivery the message sits in the operator’s own mailbox, with whatever provider hosts it.
- An advertising network, later — only once adverts are switched on, and only if you agree in its consent tool.
- Authorities or courts, where a valid legal order requires it.
Hetzner, Cloudflare and Brevo act as processors under their standard data processing terms; they may use the data only to provide their service to this site. An advertising network would act as its own controller for advertising data, under its own privacy policy. Nobody buys data here, because none is sold.
Transfers outside the EU
The servers, the files and the site database are in Germany. Brevo processes within the EU. Cloudflare, however, is a US company running a worldwide network, so a request of yours may be handled by one of its data centres outside the EU or EEA. Those transfers rest on the European Commission’s standard contractual clauses and, where the provider is certified, on the EU–US Data Privacy Framework. The same would apply to Google if Google AdSense became the advertising partner. You can ask at [email protected] for details of the safeguards in place.
How long things are kept
- Web server logs: rotated automatically and deleted after 14 days.
- Rate-limit and download markers: ten minutes or one hour, after which they expire by themselves. A signed download link stops working after six hours.
- Reports, contact messages and copyright notices: for as long as it takes to deal with the matter, then kept as a record for 24 months — longer if there is an ongoing dispute or a legal claim to defend.
- E-mail sent through Brevo: Brevo keeps a short sending log under its own retention rules; the message itself stays in the operator’s mailbox for as long as the matter is live.
Your rights
Under the GDPR you may ask me to:
- give you a copy of the personal data held about you (access);
- correct anything that is wrong (rectification);
- delete it (erasure);
- restrict what is done with it while something is being sorted out;
- stop processing that rests on legitimate interests — you may object at any time, and it then stops unless there are compelling grounds that override your interests;
- hand it over in a portable format (in practice this rarely applies here, because your data is not processed on the basis of consent or a contract with you);
- withdraw consent for advertising cookies once adverts exist — that would be done in the advertising network’s own tool, and withdrawing does not affect what happened before.
Nothing here makes an automated decision about you that produces legal effects or similarly significant effects, and there is no profiling. The rate limits described above are automatic, but they only slow down or refuse a request; they do not build a picture of you.
To use any of these rights, e-mail [email protected]. I answer within one month, which is the deadline the GDPR sets. One honest warning about access and deletion requests: the log lines and rate-limit markers hold nothing that identifies you by name, so unless you can tell me the IP address and roughly when you visited, your records genuinely cannot be found — and I will not ask you for extra identity documents just to create a link that does not exist (Article 11 GDPR).
Complaining to the authority
If you think your data has been handled badly, please write to me first — it is usually faster. You also have the right to complain to the Hungarian supervisory authority:
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) — the Hungarian National Authority for Data Protection and Freedom of Information
- Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary (post: 1363 Budapest, Pf. 9)
- Website: https://naih.hu
If you live in another EU or EEA country, you may complain to your own national data protection authority instead. You can also take the matter to a court.
Security
The site is served over HTTPS, download links are signed and expire after six hours, the login page is rate-limited, and access to the server is restricted to the operator. No system is perfect, but the moving parts are kept few on purpose.
Children
This site is not aimed at young children and does not knowingly collect data from them. You do not need an account to download anything, so there is nothing for a child to sign up to. If you believe a child’s personal data has arrived here through a message, tell me at [email protected] and it will be deleted.
Changes to this policy
The site is new and still being built, so this page will change — most obviously when adverts are switched on, and when public uploading opens. The date at the top shows when it last changed. There is no mailing list and no announcement banner, so checking that date is the only way to tell.