Last updated: 24 June 2026
TuServerMU ("we", "us") provides a single sign-on (SSO) account for the MU Online ecosystem - a toplist, server tools, and the "Login con TuServerMU" identity service (OAuth2 / OpenID Connect). This policy explains what we collect, why, and the choices you have. Questions? Email [email protected].
1. What we collect
- Account data - display name, username, email address, a securely hashed password, and (if you enable it) your two-factor authentication secret and recovery codes.
- Security & technical data - IP address (received via Cloudflare), browser user-agent, and a login audit log (sign-ins, failures, 2FA changes, password resets) used to protect your account.
- Connected applications - when you use "Login con TuServerMU" on a third-party site, we record which apps you authorized and the scopes you granted, so you can review and revoke them.
- Cookies - a session cookie to keep you signed in, the Cloudflare Turnstile anti-bot cookie on our sign-in forms, and, if enabled, privacy-friendly Cloudflare Web Analytics. We do not use advertising or cross-site tracking cookies.
2. How we use it
- To create and operate your account and keep you signed in.
- To authenticate you to third-party apps you choose, sharing only the data covered by the scopes you approve on the consent screen (e.g. your username and email).
- To protect the service - rate limiting, the anti-bot check, breach prevention and the audit log.
- To send transactional email (email verification, password resets, security notices). We do not send marketing email without your consent.
3. The password promise
Your password is stored only as a modern salted hash and is never readable by us or by the sites you log into. When you use "Login con TuServerMU", those sites receive a short-lived token - never your password.
4. Who we share it with
We do not sell your data. We share it only with:
- Apps you explicitly authorize through OAuth/OIDC, limited to the scopes you grant.
- Cloudflare - CDN, DNS, the Turnstile anti-bot check and (optionally) Web Analytics.
- Resend - our transactional email provider, used to deliver verification and security emails.
- Authorities - only where required by law.
5. Retention
We keep your account data for as long as your account exists. Security audit logs are retained for a limited period for abuse prevention. When you delete your account, we remove your personal data except where we must keep limited records to comply with the law.
6. Security
Passwords are hashed (bcrypt/Argon2), connections are encrypted with TLS, optional TOTP two-factor is available to every account, and access tokens can be revoked centrally from your dashboard.
7. Your rights & choices
- View and edit your profile from your account.
- Review and revoke connected apps under Connections.
- Enable two-factor under Security.
- Request access to, correction of, or deletion of your data by emailing us.
8. Children
TuServerMU is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect their data.
9. Changes
We may update this policy; material changes will be reflected by the "last updated" date above and, where appropriate, by notice on the site.
10. Contact
TuServerMU - [email protected].