Where privacy controls live
Capture privacy is managed in Configuration Studio under Privacy. Sharing and team access are managed in the dashboard's sharing and role settings. You can set a workspace policy, inherit it through server categories and override an individual server explicitly.
ReplayCore acts as a data processor; you, the server operator, are the controller. These dashboard settings are where you exercise controller choices about what is captured and exposed.
Privacy-safe defaults
The managed defaults record that chat and command events occurred while redacting chat content and command arguments. Keep redaction enabled unless you have a lawful basis, have informed players and have deliberately published the changed policy.
Privacy-sensitive changes require the separate sensitive-change confirmation in Configuration Studio and identify any required recorder restart before publication.
Vanished staff
Vanished players (SuperVanish, PremiumVanish, EssentialsX vanish) are excluded from replays by default: they despawn in the replay when they vanish and reappear when they unvanish, exactly as players saw in game. Change Vanished players in Configuration Studio's Recording section if staff activity itself must be reviewable. See the Vanish plugins article for details.
Sharing and panel visibility
Public share links can be disabled for your whole account from the panel's sharing settings; with sharing disabled, every existing link stops resolving immediately. Replay visibility inside the panel is controlled by per-role permissions under Settings, so you decide which team roles can see which replay features.
For erasure and export rights (UK GDPR Articles 15, 17, and 20), see the Data subject access requests article.