MonoGame Foundation Privacy Policy
This Privacy Policy explains how MonoGame Foundation, Inc., a Texas nonprofit corporation (501(c)(3), EIN 93-3803929) ("the Foundation", "we", "us"), collects, uses, shares, and protects personal information when you use monogame.net, community.monogame.net, docs.monogame.net, and any other service we operate that links to this policy (the "Services").
The short version: we run a free, open-source community. We collect the minimum needed to operate a forum and websites — an account name, an email address, IP addresses, the content you post, and a few cookies. We do not sell personal data, we do not run targeted advertising, and we never see your payment card details.
On request, we can show, correct, export, or delete your data at any time. If we suffer a data breach affecting you, we will tell you.
1. Who Is Responsible (Data Controller)
The data controller for the Services is:
MonoGame Foundation, Inc. 12225 Greenville Ave. STE. 1040 Dallas TX 75243. U.S.A. Privacy contact: privacy@monogame.net
Our community forum runs on Discourse hosted locally by the MonoGame Foundation.
2. What We Collect
| Category | Details | When |
|---|---|---|
| Account data | Username, display name, email address (private), password (stored hashed), optional profile fields you choose to fill in (bio, avatar, website, location) | When you register on the forum |
| Content | Posts, topics, replies, private messages on the forum, uploaded images/files, reactions, flags | When you participate |
| Technical data | IP address of requests and of posts, browser/user-agent, server logs | Automatically, for all visitors |
| Cookies | Session and preference cookies (see Section 10) | Automatically |
| Email interaction | Whether forum notification emails are delivered/bounced; newsletter subscription status if you opt in | When you enable notifications or subscribe |
| Donation and store data | Name, email, and transaction confirmation passed back from payment processors or the storefront. We never receive or store full payment card numbers. | If you donate or purchase merchandise |
| Correspondence | Emails you send to our contact, privacy, security, or DMCA addresses | When you contact us |
We do not knowingly collect data from children under 13 (Section 11), and we do not collect sensitive categories of data (health, biometrics, precise geolocation, etc.). Anything you choose to reveal in public posts is, of course, public.
3. Why We Use It (Purposes and Legal Bases)
For visitors and members in the EU/UK, the GDPR/UK GDPR requires us to state a legal basis for each purpose:
| Purpose | Examples | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Services | Operating your account, displaying your posts, sending notification emails you request | Performance of a contract (the Terms of Service) |
| Security and abuse prevention | Rate limiting, spam filtering, investigating attacks, retaining IP logs | Legitimate interests (protecting the Services and users) |
| Communication | Answering your questions; service announcements | Legitimate interests / contract |
| Optional newsletters or announcements | Project news you explicitly subscribe to | Consent (withdraw any time via unsubscribe link) |
| Legal compliance | Responding to lawful requests; breach notification; record-keeping duties | Legal obligation |
| Improving the Services | Aggregate, non-identifying usage statistics | Legitimate interests |
We do not use your data for targeted advertising, we do not sell or rent personal data, and we do not use personal data for automated decision-making with legal effects.
4. Who We Share It With
We share personal data only with:
- Service providers (processors) who run infrastructure for us — currently Discourse/CDCK (forum hosting, if applicable), our web/documentation hosting providers, and our email delivery provider. Processors act under contract, only on our instructions, and must protect the data.
- Payment processors and the storefront (independent controllers) when you donate or buy merchandise — they handle your payment under their own privacy policies, which are linked in those flows.
- Authorities, when we believe in good faith that disclosure is required by law or necessary to protect the rights, property, or safety of the Foundation, our users, or the public.
- A successor organization, if the Foundation's operations are ever reorganized, under the same commitments in this policy.
Third-party platforms where the community also gathers (GitHub, Discord, Reddit, YouTube, X, Bluesky, Mastodon, Facebook, Patreon) are independent services with their own privacy policies; data you share there is governed by those policies, not this one.
5. International Transfers
The Foundation is based in the United States and the Services are hosted there. If you use the Services from the EU, UK, or elsewhere, your data is transferred to the US. For EU/UK data we rely on data processing agreements incorporating the Standard Contractual Clauses with our processors, alongside the safeguards described in this policy.
6. How Long We Keep It (Retention)
We keep personal data only as long as needed, then delete or anonymize it:
| Data | Retention |
|---|---|
| Server logs containing IP addresses | No more than 90 days |
| IP addresses associated with registered users and their posts | No more than 5 years |
| Account data | For the life of the account; anonymized or deleted on verified request or account closure (public posts may remain in anonymized form — see Section 7) |
| Private messages | For the life of the accounts involved |
| Donation/transaction confirmations | As required for nonprofit financial record-keeping (typically 7 years) |
| Privacy/DMCA/legal correspondence | 3 years after resolution |
Records that no longer need to be retained are destroyed in line with Texas Business & Commerce Code § 521.052(b) by erasure or other means that make the information unreadable.
7. Your Rights and Choices
Wherever you live, you can:
- Access and export your data — Discourse provides a self-service "Download My Data" export in your account preferences, and you may also ask us for a copy;
- Correct your profile information at any time in your account settings;
- Delete/anonymize — ask us to anonymize your account, which removes the link between you and your posts and erases your profile data. Because the forum is a public archive of technical discussion, the text of public posts may be retained in anonymized form (and under the content license you granted), but we will remove personal information contained within posts on a case-by-case basis where feasible;
- Object or restrict processing based on legitimate interests;
- Withdraw consent for anything based on consent (e.g., newsletters), without affecting prior processing;
- Not be discriminated against for exercising any of these rights.
To exercise a right, email privacy@monogame.net. We will verify the request comes from the account holder (normally by confirmation from the registered email address), respond within one month, and explain ourselves if we need a one-time extension or must refuse (e.g., a legal duty to retain). There is no fee for reasonable requests. If you are in the EU/UK you may also complain to your local supervisory authority; if you are in Texas, you may contact the Texas Attorney General's consumer protection division.
Although the Foundation, as a nonprofit, is exempt from the Texas Data Privacy and Security Act, we voluntarily extend the rights above to everyone.
8. How We Protect It (Security)
We implement reasonable administrative, technical, and physical safeguards appropriate to a community of our nature, consistent with Texas Business & Commerce Code § 521.052 and GDPR Article 32, including:
- encryption of data in transit (TLS) across all Services;
- passwords stored only in salted, hashed form;
- multi-factor authentication required on administrative accounts;
- least-privilege access — administrative access limited to a small, reviewed list of named individuals;
- security patching of forum software and infrastructure;
- backups, with access controls, to allow recovery from data loss;
- a designated security contact (privacy@monogame.net) for vulnerability reports.
No internet service can guarantee absolute security; what we can guarantee is honesty about incidents, as follows.
9. Data Breach Notification — Our Commitment
If we determine that a breach of system security has resulted in, or is reasonably believed to have resulted in, unauthorized acquisition of your personal data, we will:
- Assess promptly — our internal Data Incident Response Plan requires initial assessment and containment to begin immediately and a risk determination within 72 hours of discovery;
- Notify regulators where required — including the competent EU/UK supervisory authority within 72 hours where GDPR applies, and the Texas Attorney General within 30 days (via the AG's electronic form) if 250 or more Texas residents are affected;
- Notify you directly — without unreasonable delay and in any event within 60 days of determining the breach occurred, by email to your registered address (or substitute notice where permitted), describing what happened, what data was involved, what we have done, and what you can do;
- Notify consumer reporting agencies if more than 10,000 individuals must be notified at one time, as Texas law requires;
- Publish a transparency notice on the community site for incidents affecting the community at large, and update it as facts develop.
10. Cookies
The Services use a small number of cookies:
| Cookie type | Purpose | Consent |
|---|---|---|
| Strictly necessary | Session cookie keeping you logged in to the forum; security/CSRF tokens | Not required (essential to the service) |
| Preferences | Remembering interface settings such as theme (light/dark) | Not required / opt-out by clearing cookies |
| Analytics or advertising | None. We do not run third-party advertising or tracking cookies. | n/a |
If we ever introduce non-essential cookies, we will categorize them here and request consent from visitors in jurisdictions that require it before setting them. You can also control cookies through your browser settings; blocking essential cookies will prevent login.
11. Children
The Services are directed to people aged 13 and over. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact privacy@monogame.net and we will delete the account and associated personal data. We do not direct targeted advertising at anyone, including minors, and we apply data minimization to all users.
12. Notice of Sale or Transfer
Should the Foundation change ownership at any time, all registered accounts will be notified as early as possible for users to take action as they deem fit. However, this is a very unlikely scenario due to the nature of the MonoGame Foundation incorporation. The Foundation is not for sale or transfer at this time.
13. Scope and External Data
This policy covers information collected through the Services. It does not cover information collected offline (for example at conferences), on third-party platforms, or by the MonoGame framework itself — the framework is software you run; it does not transmit personal data to the Foundation. Any storage of data is on MonoGame Foundation owned hardware located at Foundation addresses, secured according to the legal requirements present at its location.
14. Changes to This Policy
When we change this policy we will post the new version here with an updated version number and effective date, and for material changes we will announce the change on the community forum with reasonable advance notice. Earlier versions will remain available on request.
15. Contact
Questions, concerns, complaints, or rights requests:
MonoGame Foundation, Inc. 12225 Greenville Ave. STE. 1040 Dallas TX 75243. U.S.A. General: contact@monogame.net · Legal: admin@monogame.net · Privacy/Security: privacy@monogame.net
This document is licensed CC BY-SA 4.0.