Skip to content

Privacy Policy

Last updated: 20 September 2026

modsdrop.com is a small file host for video game mods. It is run by one person in Hungary, not by a company. This page says what happens to your data when you visit. Everything below describes what the site actually does today, not what a template says it might do.

The short version

Who is responsible for your data

The data controller is Máté Geszti (CrashMozi), a private individual (this is not a company), XVII. utca 4., 5400 Mezőtúr, Hungary. E-mail: [email protected].

The site is small enough that no data protection officer is required, and none has been appointed. Requests go straight to the person who runs the site, at the e-mail address above.

What is collected, why, and the legal basis

1. Web server logs. Requests that reach the server are written to a log line by the web server (nginx). Each line holds your IP address, the date and time, the page or file you asked for, the user agent string your browser sends, and how many bytes were sent back. Nothing else. Cloudflare answers some requests from its own cache, so those never reach this log — but Cloudflare keeps logs of its own, under its own policy. The server’s logs are rotated and deleted automatically. Legal basis: legitimate interests, Article 6(1)(f) GDPR — keeping the site running, finding faults, and spotting abuse such as scripted mass downloading.

2. Downloads, rate limits and the download counter. When you click Download, the site creates a signed link that works for six hours, and the server then streams the file to you. To stop abuse and to count each download once, the site stores short-lived markers in its own database (WordPress transients, on the same server). Those markers are keyed by a salted hash — technically md5 of a secret site salt plus your IPv4 address, or the first half (the /64) of an IPv6 address. The address itself is not stored in them. They expire by themselves: after ten minutes for link creation, and after one hour for the marker that counts a download once and for the marker that limits how often reports can be sent. The web server separately limits each IP address to 240 requests a minute to the WordPress part of the site, six attempts a minute on the login page, and four downloads running at the same time. The counter that results from all this is a number on the file page; no record is kept of which person downloaded which file. Legal basis: legitimate interests, Article 6(1)(f) — keeping the server standing up under load, and keeping the download numbers honest.

3. Reports, contact messages and copyright complaints. If you use the report button on a file page, the contact form or the copyright form, the site stores the reason you picked, the text you wrote (up to 4,000 characters), your e-mail address if you gave one, and the IP address the message came from. The e-mail address is optional on the report form on a file page, and required on the contact and copyright forms, because otherwise there is no way to answer you. If you send a report without an address, expect no reply — there is nothing to reply to. Messages are stored as private posts in the site’s WordPress installation on the same server, and are also sent on to the operator by e-mail. Please do not put sensitive personal details into the message box; only enough to understand the problem is needed. Legal basis: legitimate interests, Article 6(1)(f), for reading and answering your message; and, for notices about illegal content or copyright, a legal obligation, Article 6(1)(c), because the EU Digital Services Act (Regulation (EU) 2022/2065) requires a hosting service to act on such notices and, where it has an address to write to, to say what it decided.

4. The operator’s own login. WordPress sets cookies for the logged-in operator so that he stays signed in. Visitors never receive these cookies.

5. Files and virus scanning. In this first phase only the operator’s own files are hosted — public uploading is not open. Files carried over from crashmods.com may have a VirusTotal result stored alongside them (clean, too large to scan, or not scanned), and the file page always shows the true state. It is not true that every file has been scanned, and this site does not claim it is. This is information about files, not about you.

Cookies and analytics

The site itself sets no cookies for visitors who are not logged in, and there is no analytics or measurement software of any kind on it. No Google Analytics, no advertising pixel, no social media button that phones home, no fingerprinting.

One exception is outside my hands: Cloudflare sits in front of the site to keep it fast and to absorb attacks, and if it decides a request looks automated it may set a strictly necessary security cookie of its own to remember that the check was passed. That is a security function rather than tracking, and it is not something this site reads.

Because nothing on the site currently needs your permission, there is no cookie banner here. That would change on the day adverts are switched on — see the next section.

Adverts (not running yet)

There are no adverts on modsdrop.com at the moment. The plan is to apply later to an advertising network — Google AdSense or Mediavine. If that happens, the network’s code will run on the pages and, if you agree, will store and read cookies or similar identifiers on your device in order to measure and personalise advertising.

The asking would be done by the advertising network’s own consent tool (Google’s EU consent message, or Mediavine’s Journey consent tool), because that tool is what records your answer and passes it on to the advertisers. I will not add a second, home-made banner of my own: on my other site two banners appearing at once caused real problems, and one is enough.

I cannot describe that tool’s screens here, or promise where its “change your choices” link will sit, because it is not installed and I have not seen it on this site. Before adverts go live, this page will be updated with the network’s name, a link to its own privacy notice, and how to reopen its dialog or withdraw consent. Until then there is nothing to consent to, and no consent control to offer. Legal basis, on that day: your consent, Article 6(1)(a) GDPR together with the EU cookie rules — collected and stored by the advertising network, not by me.

Who else sees your data

Hetzner, Cloudflare and Brevo act as processors under their standard data processing terms; they may use the data only to provide their service to this site. An advertising network would act as its own controller for advertising data, under its own privacy policy. Nobody buys data here, because none is sold.

Transfers outside the EU

The servers, the files and the site database are in Germany. Brevo processes within the EU. Cloudflare, however, is a US company running a worldwide network, so a request of yours may be handled by one of its data centres outside the EU or EEA. Those transfers rest on the European Commission’s standard contractual clauses and, where the provider is certified, on the EU–US Data Privacy Framework. The same would apply to Google if Google AdSense became the advertising partner. You can ask at [email protected] for details of the safeguards in place.

How long things are kept

Your rights

Under the GDPR you may ask me to:

Nothing here makes an automated decision about you that produces legal effects or similarly significant effects, and there is no profiling. The rate limits described above are automatic, but they only slow down or refuse a request; they do not build a picture of you.

To use any of these rights, e-mail [email protected]. I answer within one month, which is the deadline the GDPR sets. One honest warning about access and deletion requests: the log lines and rate-limit markers hold nothing that identifies you by name, so unless you can tell me the IP address and roughly when you visited, your records genuinely cannot be found — and I will not ask you for extra identity documents just to create a link that does not exist (Article 11 GDPR).

Complaining to the authority

If you think your data has been handled badly, please write to me first — it is usually faster. You also have the right to complain to the Hungarian supervisory authority:

If you live in another EU or EEA country, you may complain to your own national data protection authority instead. You can also take the matter to a court.

Security

The site is served over HTTPS, download links are signed and expire after six hours, the login page is rate-limited, and access to the server is restricted to the operator. No system is perfect, but the moving parts are kept few on purpose.

Children

This site is not aimed at young children and does not knowingly collect data from them. You do not need an account to download anything, so there is nothing for a child to sign up to. If you believe a child’s personal data has arrived here through a message, tell me at [email protected] and it will be deleted.

Changes to this policy

The site is new and still being built, so this page will change — most obviously when adverts are switched on, and when public uploading opens. The date at the top shows when it last changed. There is no mailing list and no announcement banner, so checking that date is the only way to tell.