This Privacy Policy explains what personal data InWorld·Online (the “Platform”) collects, why we
collect it, how long we keep it, and the rights you have. It applies to the Platform’s public site
at www.inworld.online, the tenant dashboard at my.inworld.online, and the
in-world and payment integrations the Platform uses to deliver the service.
Why this looks long. Most services publish a couple of generic paragraphs and rely on the fact that nobody reads them. We’d rather be specific about what is collected, why, how long, who sees it, and what you can do about it — the Platform actually follows what is written here. If anything below is unclear or looks out of step with how the Platform behaves, send an in-world IM to InworldOnlineSupport; corrections are welcome.
0. Who this covers
The Platform treats four kinds of users. Most sections below apply to all of them; a few are role-scoped and tagged accordingly.
- Visitor — anyone who steps onto a land owner’s land in Second Life. Data recorded: avatar identity, visit timestamps and durations, any chat in the land’s groups, moderation records (bans / ejects) if applied to you.
- Tenant — a visitor who rents land from a land owner through the Platform. Same as visitor, plus L$ rent payment history.
- Land owner — operates land through the Platform. Same as visitor for data about them, plus L$ payment history. As a joint controller they also hold their visitors’ data within the scope of their own land — obligations covered by the Land Owner Terms.
- Manager — assigned by a land owner to help operate the land. Data about a manager is the same as any visitor; their access to other users’ data is bounded by what the land owner can see.
1. Who is the controller
The Platform is the data controller for the personal data described below.
Land owners as joint controllers. When you visit virtual land managed through the Platform, the operator of that land (the “land owner”) also acts as a joint controller for data about your visit on their land, under Article 26 GDPR. The land owner can see only data about visits to their land, not across the Platform. The land owner’s obligations are set out in the Land Owner Terms and the Data Processing Addendum.
Contact for any privacy question: send an in-world IM to the Second Life resident InworldOnlineSupport.
2. What we collect and why
2.1 Account data
- Email address (optional) — for account recovery and notifications, only if you choose to provide one. The Platform does not require an email address.
- Hashed password — for authentication. Stored as a bcrypt/argon2 hash, never in plaintext.
- Two-factor authentication secret — for TOTP verification. Encrypted at rest.
- Second Life avatar identity (UUID, name, display name) — the primary identity you use across the Platform.
- Account status flags — verified, active, role assignments.
Lawful basis: performance of a contract (Art. 6(1)(b) GDPR).
2.2 Activity data
- Visits to land a visitor has entered (date, area, region, duration, last position).
- First-visit timestamp per area or region — retained for community-tenure display.
- Chat messages exchanged in-world via Platform-managed groups or rentals.
- Support requests, guestbook entries, and land-owner notes (“remarks”) about you.
- Moderation records: bans, ejects, guest lists.
- Estate and group access caches, kept in sync with Linden Lab’s authoritative data so the land owner’s dashboard can display and act on them: estate allow lists, estate banned lists, allowed groups, and members of groups the land owner uses for access control. These are caches of data the land owner already holds in-world.
Lawful basis: legitimate interest (Art. 6(1)(f)) — running the Platform, preventing abuse, and recognising community tenure. Recital 49 GDPR explicitly recognises ensuring network and information security as a legitimate interest.
2.3 Payment data (tenants and land owners)
- L$ (Linden Dollar) transactions: who paid, who was paid, amount, when, and the reference subscription or land.
- Subscription and renewal history.
Lawful basis: performance of a contract and legal obligation (Art. 6(1)(b) and (c) GDPR) — L$ transactions are retained to satisfy accounting record-keeping obligations.
2.4 Discord identity (land owners only)
This category applies only if you are a land owner and have connected the Discord integration to your land. The Platform then stores your Discord user ID, the guild IDs you have linked, and the webhook credentials we use to deliver messages to channels you nominated. Discord webhook tokens are encrypted at rest.
Visitors do not have a Discord identity stored on the Platform — the Platform never asks for or stores a visitor’s Discord account. What can happen is that in-world chat or visitor identifiers from a land where the integration is enabled get relayed to the land owner’s Discord channel; once on Discord that copy is under the land owner’s control on Discord’s infrastructure (see §6 below and the Land Owner Terms §5 and §6).
Lawful basis: performance of a contract (you opted in to the Discord integration).
2.5 Technical data
- IP address of the dashboard user only (never of an avatar in-world — Second Life does not expose those, and the Platform does not attempt to correlate them) — logged for at most 5 days, for abuse detection and incident investigation.
- Session cookie (IWOSESSID) — strictly necessary; expires when the session ends.
- CSRF token — strictly necessary.
- Cookie-consent record — remembers your cookie choices for one year.
Lawful basis: legitimate interest (Art. 6(1)(f)) for security; strictly-necessary cookies require no consent under ePrivacy.
3. How long we keep it
| Category | Retention | Basis |
|---|---|---|
| Account credentials | While the account is active; scrubbed on deletion | Contract |
| Avatar identity | While the account is active; soft-deleted on erasure | Contract / LI |
| First-visit timestamps | Indefinite while account exists | Legitimate interest |
| Ban / eject records | Indefinite (Recital 49 — ban-evasion prevention) | Legitimate interest |
| Visit records (raw) | 24 months, then deleted. Anonymous per-area daily counts are kept indefinitely for land-owner analytics. | Legitimate interest |
| Chat messages | 6 months | Legitimate interest |
| L$ payments and subscriptions | ~10 years (accounting obligation) | Legal obligation |
| Dashboard IP request logs | 5 days | Legitimate interest (security) |
| Super-admin access audit log | 24 months | Legitimate interest (accountability) |
| Manager assignment audit log | Indefinite | Legitimate interest (accountability) |
| Support tickets | 24 months after closure | Legitimate interest |
4. Who can see your data
- You. You can see and export your own data through your account settings.
- The land owner of a land you have visited. Only data scoped to their land (your visits there, in-world chat in their groups, ban/eject records they applied, support requests they received). They cannot see your activity on other land owners’ lands.
- Managers assigned by a land owner, with the same scope as that land owner.
- Platform staff (super-admin) only for support purposes. Every super-admin access to personal data is logged in an audit trail.
We do not sell personal data. We do not use personal data for marketing without separate consent.
5. Third-party services
The Platform integrates with a small number of third-party services to operate. See the Sub-processors page for the current list.
Linden Lab (Second Life) and Discord are not sub-processors of the Platform in the GDPR Art. 28 sense: the Platform does not have a data-processing contract with them, does not direct their processing, and cannot bind them to obligations no less protective than its own. They are independent services you have your own relationship with — you signed up to Second Life with Linden Lab, and (if you connected one) to Discord with Discord Inc. The Platform exchanges data with them only as needed to deliver the in-world or Discord features you use, on the basis of those services’ own terms and privacy policies. To exercise rights against the data those services hold about you, please contact them directly.
6. Your rights
Under the GDPR, you have the right to:
- Access the data we hold about you (Art. 15) — send an in-world IM to
InworldOnlineSupport with the command
!contact <your request>. The bot opens a support ticket and we will confirm what data exists about your avatar and provide a written summary. Where you also have a dashboard account, the structured export below covers most of this automatically. - Rectify inaccurate data (Art. 16) — edit fields directly in your account.
- Pause your account — disables access; all data is preserved and reactivation is instant.
- Erasure (Art. 17) — schedule permanent deletion. Your account is paused immediately and the irrevocable scrub runs 7 days later, so you can cancel by logging back in during the window. After the scrub: identity fields are removed; L$ payment records are retained under accounting law with the link to your avatar removed; ban / eject records are retained indefinitely to prevent ban evasion (Recital 49).
- Restrict processing (Art. 18).
- Data portability (Art. 20) — download a structured archive of your data from your account. Limit: one self-service export per 24 hours (Art. 12(5)).
- Object to processing based on legitimate interest (Art. 21).
- Lodge a complaint with your supervisory authority.
You can exercise export, rectification, pause, and erasure rights directly from your
account page on the dashboard. Access (Art. 15) and any rights that cannot be self-served go
through !contact IM to InworldOnlineSupport — see the access
bullet above.
The self-service export excludes in-world chat (bilateral conversations involve other parties),
land-owner moderation notes about you, and ban / eject records. For these categories the right of
access is honoured by support: send an in-world IM to InworldOnlineSupport with
!contact <your request> and we will confirm whether such data exists and, where
appropriate, provide a written summary. Verbatim copies are not produced.
Erasure on the Platform does not reach third-party services. When you erase your
data with us, we remove what we hold on our own systems. We have no ability to delete data held by
third parties such as Linden Lab (Second Life) or Discord —
your Second Life avatar account, your Discord account, and anything those services have logged
about you live entirely on their infrastructure and under their privacy controls. To exercise
your rights against those services, please contact them directly: Linden Lab via
secondlife.com, Discord via discord.com.
The Discord integration is operated by the land owner, not by the Platform.
Whether your visit data flows out to a Discord channel depends entirely on the land owner’s
configuration of their own land. For data that has already been forwarded to a Discord channel,
the land owner is the controller on the Discord side — only they can delete the messages
and only they can act on a deletion request directed at that copy. Erasing the corresponding
records on the Platform does not, and cannot, delete the copies that now live in Discord. To
exercise this right, contact the land owner whose parcel you visited; if they do not respond or
you cannot identify them, contact us via !contact IM to
InworldOnlineSupport and we will help route the request.
The Land Owner Terms require land owners to
post an in-world notice telling visitors that data is being processed and, where the Discord
integration is enabled, to disclose that fact — so that you can identify them as the
controller for that flow. Where the notice is missing, a land owner has failed an obligation
they accepted when they enabled the integration; please report it to support via
!contact so we can follow up with the land owner.
Visitors: erasure without a dashboard account
If you have never created a dashboard account — for example, you only ever set foot on a
land owner’s parcel as a visitor, but you never subscribed to our Platform —
you can still exercise your right to erasure directly
with the Platform. Send an in-world IM with the message !forget to
InworldOnlineSupport. The bot will reply with a one-time link to a page where
you can review what the Platform holds about your avatar and confirm the deletion. The right
remains available indefinitely: if new visit data accumulates after a previous erasure, send
!forget again to remove it.
Limited exception (GDPR Art. 17(3)). In specific situations recognised by Art. 17(3) GDPR
— for example, where data is needed to defend legal claims, comply with a legal obligation, or
address an active incident such as a harassment investigation — the Platform may temporarily
withhold an erasure request. The hold is set by a super-administrator with a documented reason and is
released as soon as the situation no longer applies. While a hold is in place, the in-world
!forget command will refuse the request with a generic legal-hold message; the specific
reason is kept as internal context and is not disclosed in the refusal.
7. Security
Sensitive secrets are encrypted at rest using authenticated symmetric encryption. Passwords are stored as one-way hashes. Access to admin tools is restricted by role and logged. Backups contain encrypted ciphertext for sensitive fields, not plaintext.
8. International transfers
Some sub-processors are based outside your jurisdiction. Where applicable, transfers rely on the European Commission’s Standard Contractual Clauses or the equivalent adequacy mechanism.
9. Changes to this policy
When we change this policy, we update the version date at the top and prompt you to review the new version on your next sign-in. Continued use after the prompt constitutes acknowledgement.
Version 2026-05-28.