Version 1 · Published 9/23/2026
Terms of Service & Privacy Notice
Falcon BMS Server Browser, run by BenchmarkSims.
In short
- BenchmarkSims runs this server browser for Falcon BMS for free, with no ads and no tracking.
- To host, we store your email address, sign-in provider ID and callsign. None of these is ever shown publicly.
- When you advertise a session, its name, map, IP address, port, region and player counts are public, so players can find and join it. We also keep a history of your hosted sessions and anonymous usage statistics.
- You can see everything we store about you on the My data page, download it, and delete your account at any time.
1. About this service
The Falcon BMS Server Browser ("the service") is run by BenchmarkSims, the team behind Falcon BMS ("we", "us"). It lists Falcon BMS multiplayer sessions that their hosts choose to advertise, so players can find and join them. This portal is where hosts sign in, manage API keys and see their data.
The service is free. We don't sell anything through it, show ads, or use your data for marketing. By ticking the acceptance box in the portal you agree to these terms. If you decline them when you first sign in, the account created for you is cancelled and its sign-in details are deleted.
2. Eligibility and your account
- You must be at least 16 years old, or the age of digital consent where you live if that is higher.
- You sign in with a third-party account (BenchmarkSims single sign-on, Google, Microsoft, GitHub or Discord). We never see your password. Some providers require a verified email address and two-factor authentication.
- One account per person. You are responsible for what happens under your account and its API keys.
- Your callsign starts as the name your sign-in provider gives us, and you can change it in the portal. It must not impersonate someone else or be offensive.
3. API keys
- An API key lets one Falcon BMS server register and stay listed. Each key runs one session at a time.
- Keys expire 60 days after they are issued. You can revoke a key at any time, and we can revoke keys that are misused.
- Keep your keys secret. Anyone with a key can advertise sessions under your account. If you think a key has leaked, revoke it straight away.
- We store each key as a one-way hash, which is what we check it against, plus an encrypted copy so you can view and copy it again in the portal.
4. What becomes public when you advertise a session
Advertising a session is your choice. While it is listed, anyone can see the following, both in the server browser and through our public API:
- session name and current map
- the server's public IP address and port, which players need to connect
- region (worked out from the IP address)
- connected players, maximum players and uptime
- your account's trust tier
Your email address, sign-in details and callsign are never public. A session stops being listed within about a minute of its heartbeats stopping. Before a session is listed, we check that a Falcon BMS server really answers at the declared address by sending it one small network packet.
5. Acceptable use
You agree not to:
- use session names that are offensive, hateful, sexually explicit, illegal or misleading;
- pretend to be BenchmarkSims, an official server, or another host or community;
- report false session data, such as fake player counts or sessions that don't exist;
- get around key limits, rate limits, bans or other restrictions, for example by opening extra accounts;
- overload, probe, scrape excessively or otherwise attack the service, its infrastructure or other users' servers;
- use the service in any way that breaks the law or the terms under which you use Falcon BMS.
6. Moderation and trust tier
To keep the list useful and safe, we may flag or remove sessions, revoke API keys, limit or suspend accounts, and block IP addresses, networks or countries, with or without notice. Where it is reasonable to do so, we will tell you why.
Your trust tier is shown to players as a quality signal. It is calculated automatically from your hosting history over the last 30 days (total hosted time and peak players), leaving out flagged sessions. Staff can adjust it manually.
7. Data we collect
This is everything the service stores about you:
- Account: your email address and your account ID at the sign-in provider you used (both received from that provider), your callsign, the date you joined, which version of these terms you accepted and when, your trust tier, and how many servers you may host at once.
- API keys: when each key was issued, expires and was revoked, plus the stored key itself (hashed and encrypted, see section 3).
- Hosted sessions (only if you advertise one): session name, map, the server's public IP address and port, region, connected and maximum player counts, start and end times, and peak players. To classify regions and apply bans, we look up the IP address in a copy of the MaxMind GeoLite2 database that runs on our own servers. No data is sent to MaxMind.
- Usage statistics: counts of sessions and players by region and map over time. These are anonymous and not linked to your account.
- Technical data: IP addresses of requests to the service, used briefly for rate limiting and security, and operational server logs.
- Cookies and local storage: only what is strictly necessary. That is a sign-in session cookie, short-lived cookies used during sign-in, and your light/dark theme choice saved in your browser. There are no analytics, advertising or tracking cookies.
We don't collect passwords, payment details or any data from your game client.
8. Why we use it
- To provide the service (necessary to perform our agreement with you): signing you in, issuing keys, and listing and verifying your sessions.
- To keep it safe and fair (our legitimate interest): preventing abuse, enforcing these terms, moderation, and working out trust tiers.
- To run and improve it (our legitimate interest): anonymous usage statistics, capacity planning, troubleshooting and backups.
We don't use your data for advertising, profiling for marketing, or automated decisions with legal effect.
9. How long we keep it
| Data | How long we keep it |
|---|---|
| Account details (email, provider ID, callsign) | While your account exists. They are erased as soon as you delete your account. |
| API keys | Keys expire 60 days after they are issued. Revoked keys, including every key revoked when you delete your account, are permanently deleted 7 days after revocation. Expired keys stay in your key history while your account exists. |
| Live session listing | Until about a minute after your server's last heartbeat. |
| Hosted session history | Kept for moderation and abuse prevention, with no fixed deletion date. When you delete your account, this history is permanently unlinked from you within about 7 days, as soon as your revoked keys are deleted. What remains is the session name, map, region, IP address, times and player peak, with nothing that ties it to your account. |
| Usage statistics | Anonymous. Full detail is kept for 30 days, then reduced to hourly figures kept for 180 days, then deleted. |
| Backups | The database is backed up daily and the 14 most recent backups are kept, so deleted data can remain in a backup for up to about 14 days. |
| Technical data and logs | Only as long as needed for rate limiting, security and troubleshooting. |
10. Who we share it with
We don't sell or rent your personal data, or share it for advertising. We only share data:
- publicly, when you advertise a session (section 4);
- with the sign-in provider you choose (BenchmarkSims single sign-on, Google, Microsoft, GitHub or Discord), which handles sign-in under its own privacy policy;
- with providers that host or protect the service, such as a network security and delivery provider like Cloudflare. They process data only to provide that service to us;
- with BenchmarkSims staff who run and moderate the service.
Some of these providers may process data outside your country. Where the law requires it, such transfers use appropriate safeguards.
11. Your rights and choices
Depending on where you live (for example under the EU/UK GDPR or the California CCPA), you have these rights. Most of them are built into the portal:
- Access and portability: the My data page shows everything linked to your account and lets you download it as a JSON file.
- Correction: change your callsign in the portal. Your email address comes from your sign-in provider, so update it there and sign in again.
- Deletion: "Delete my account" in the portal immediately revokes your API keys and erases your email, callsign and sign-in identifiers. Section 9 explains what remains afterwards and for how long.
- Objection and restriction: you can object to or ask us to limit processing based on our legitimate interests. Stopping advertising sessions, or deleting your account, stops new data being collected.
- Complaint: you can complain to your local data protection authority.
We don't sell or "share" personal information as the CCPA defines it, and we won't treat you differently for using your rights. Moderation records, such as flags and bans, may be withheld where the law allows, for example when showing them would undermine abuse prevention. For anything the portal can't do, contact us (section 16).
12. Security
We protect your data with encrypted connections, hashed and encrypted API keys, restricted staff access, and regular backups and integrity checks. No system is perfectly secure. If a breach affects your personal data, we will let you know.
13. Free service, no warranty
The service is provided free of charge, "as is" and "as available", with no guarantee of availability, accuracy or fitness for a particular purpose. It may change, be interrupted, or be discontinued at any time.
We don't run the listed servers and aren't responsible for them, how their hosts run them, or what happens in them. Session details come from their hosts, and you connect to third-party servers at your own risk. As far as the law allows, BenchmarkSims is not liable for indirect or consequential loss, or for loss of data, arising from use of the service. Nothing in these terms limits liability that cannot be limited by law, or your statutory rights as a consumer.
14. Ending your use of the service
You can stop using the service at any time by revoking your keys or deleting your account. We may suspend or close accounts that break these terms, and we may shut the service down. If we do, we will try to give reasonable notice in the portal.
15. Changes to these terms
We may update these terms. Each version is numbered and dated, and the portal shows which one you accepted. When a change needs your agreement, the portal shows a notice until you review and accept the new version. Your servers stay listed in the meantime, but you can't generate new API keys until you accept. Minor edits that don't change your rights, such as fixing typos, don't need a new acceptance. If you decline a change, your account is deleted, just as if you had used "Delete my account" (see sections 9 and 11).
16. Contact
For questions about these terms or your data, or to use a right the portal doesn't cover, contact BenchmarkSims through the Falcon BMS forum. We may need to confirm that the account is yours before acting on a request.
