Privacy Policy
Last updated: 24/07/2026
1. Data controller
The controller of personal data collected on the craftlauncher.app site is:
Name: scoogend
Email: contact@craftlauncher.app
Data Protection Officer (DPO): Not appointed. For any question relating to data protection, contact contact@craftlauncher.app
2. Data collected
As part of using the Service, the following data is collected:
Identification data
- Email address
- Password (stored hashed, bcrypt cost 12)
- Username (optional)
Payment data
- Billing data processed by Stripe (CraftLauncher never stores banking data)
- Transaction history
Usage data
- Connection logs (IP address, date, user-agent)
- Launcher configuration settings
- Uploaded files (mods, visuals, configurations)
- Build progress data (status, technical logs)
Cookies
Cookies strictly necessary for the site to function (PHP session, CSRF token). No advertising or tracking cookies are used.
Consent data
- Acceptance of the Terms (cgu_accepted) and acceptance date (cgu_accepted_at)
- Consent to marketing communications (newsletter_optin)
End-player data (moderation and crash reports)
When a launcher's administrator (the "client") enables player moderation or crash reporting features, the Service processes, on behalf of and at the request of that client, certain data relating to their players:
- Game identifier (UUID) and player username;
- Connection IP address;
- Playtime and number of sessions;
- Where applicable, technical crash logs.
For this processing, the client acts as data controller towards their own players (anti-cheat, security, community management — client's legitimate interest), and CraftLauncher acts as data processor within the meaning of article 28 GDPR. This data is only accessible to the client concerned. It is up to the client to inform their players of this processing and to ensure its legal basis. This data is automatically deleted after 180 days of inactivity.
In-launcher community: messaging, rooms and voice calls
When a launcher's administrator enables the "Community" feature (Pro and Max plans), that launcher's players can see each other online, add each other as friends, exchange messages in rooms or privately, and make voice calls. This service is strictly siloed per launcher: one community has no visibility into another.
The following data is then processed:
- Game identity: Minecraft username and UUID, verified with Microsoft. No Microsoft ID or password is processed;
- Message content (public rooms, private rooms, direct messages): encrypted at rest (AES-256-GCM). The database never contains the plaintext at any time;
- Social graph: friends list, friend requests, blocks, room membership;
- Presence status: online / in-game / on a server (an "invisible" mode allows disabling it);
- IP address: used only for rate limiting (anti-abuse protection). It is never stored in plaintext: only a salted cryptographic fingerprint (SHA-256) is kept, and it is not reversible;
- Reports: when a player reports a message, a copy of that message is retained along with the reason for the report (see "Reporting content" below).
Confidentiality of correspondence. Private messages exchanged between players are not accessible to CraftLauncher, the launcher administrator, or moderators. Moderators appointed by the administrator can only delete messages in public rooms. The only exception is content explicitly reported by a player, which becomes visible to the administrator so they can moderate it.
Voice calls. Voice conversations are never recorded, stored, or transcribed. The audio stream is end-to-end encrypted (DTLS-SRTP) between participants. By default it passes through a technical relay (Cloudflare TURN) that only carries encrypted data and therefore cannot listen to it. This relay serves a protective purpose: it prevents a player's IP address from being revealed to the other call participants. A player may, if they wish, allow a direct (peer-to-peer) connection in the launcher settings; they are then clearly warned that their IP address becomes visible to other participants.
Player information and age. Before any access to the community, the player receives a notice in the launcher informing them of the processing, and must declare being at least 15 years old (or have parental consent). Until this notice is acknowledged, no social data concerning them is processed. If they decline, the data created at session opening is immediately erased.
For this processing as well, the launcher administrator is data controller for their community, and CraftLauncher acts as data processor (article 28 GDPR).
Minecraft and Microsoft authentication data
CraftLauncher does not collect, store or process any authentication data relating to Minecraft or Microsoft accounts. Minecraft authentication, where applicable, is handled directly by the launcher on the player's machine and never passes through CraftLauncher's servers. CraftLauncher is not affiliated with Microsoft or Mojang and has no access to Minecraft's authentication systems.
3. Purposes and legal bases
Each processing activity relies on a legal basis compliant with the GDPR:
| Purpose | Legal basis |
|---|---|
| User account management and authentication | Contract performance (art. 6.1.b GDPR) |
| Providing the Service (launcher creation, hosting, updates) | Contract performance (art. 6.1.b GDPR) |
| Billing and payment management | Contract performance (art. 6.1.b GDPR) |
| Sending transactional emails (confirmation, password reset) | Contract performance (art. 6.1.b GDPR) |
| Security logs and abuse prevention | Legitimate interest (art. 6.1.f GDPR) |
| In-launcher community (messaging, rooms, voice calls) — processing carried out on behalf of the launcher administrator | Performance of the contract between the administrator and their players, and the administrator's legitimate interest in running and moderating their community (art. 6.1.b and 6.1.f GDPR) |
| Retention of reported content (moderation, evidence) | Legitimate interest and duty of care regarding unlawful content (art. 6.1.f GDPR, art. 17.3.e for retention) |
| Sending newsletters and commercial communications | Consent (art. 6.1.a GDPR) |
| Compliance with legal obligations (billing, accounting) | Legal obligation (art. 6.1.c GDPR) |
4. Retention period
Personal data is kept for the period strictly necessary for the purposes for which it is collected:
- Account data: duration of the subscription + 30 days after account deletion
- Billing data: 10 years (legal accounting obligation)
- Connection logs: 12 months
- Uploaded files: duration of the subscription + 30 days after termination
- End-player data (moderation, crash): automatically deleted after 180 days of inactivity
- Community messages (rooms, private messages): kept as long as the launcher exists, as they constitute the conversation history expected of the service. They are deleted immediately when the player exercises their right to erasure, or when the launcher is deleted
- Reported content: kept as long as the launcher exists, even if the author deletes the original message or requests erasure of their data (art. 17.3.e — defense of legal claims)
- Voice calls: no retention — conversations are neither recorded nor stored
- IP address fingerprints (anti-abuse): a few minutes (duration of the rate-limiting window)
- Session cookies: deleted when the browser closes
5. Reporting unlawful content
In accordance with the European Digital Services Act (DSA), any player can report content they consider unlawful or against the rules, directly from the launcher: a report button is available on every message. The report is forwarded to the launcher administrator, the only one authorized to moderate their community (message deletion, player sanction).
A copy of the reported content is kept with the report, so it survives even if its author deletes it. This retention is necessary for the establishment and defense of legal claims (art. 17.3.e GDPR): without it, an author could erase evidence of their own abuse.
If content appears clearly unlawful to you and the launcher administrator does not act, you can contact us directly at contact@craftlauncher.app. As a host, we will promptly remove any clearly unlawful content as soon as we become aware of it, and may suspend the community feature of the launcher concerned.
6. Data recipients
Personal data is shared only with the following processors, strictly within the scope of their tasks:
Stripe (payments)
Payment data processing. Banking data is never stored by CraftLauncher.
Policy: stripe.com/privacy
Cloudflare R2 (storage)
Hosting of launcher and mod files. Data stored in the EU.
Policy: cloudflare.com/privacypolicy
Cloudflare Workers, D1 and Durable Objects (in-launcher community)
Hosting of messaging, the social graph and presence. Database and instances constrained to European Union jurisdiction. Message content is stored encrypted there (AES-256-GCM), with the key held only by CraftLauncher.
Policy: cloudflare.com/privacypolicy
Cloudflare Realtime / TURN (voice call relay)
Technical relay for the audio stream. The stream is end-to-end encrypted between participants: the relay only carries encrypted data and cannot decrypt it. No recording.
Microsoft / Mojang (game identity verification)
Verification that the player actually owns the Minecraft account they claim, before any access to the community. CraftLauncher neither receives nor stores any Microsoft identifier.
Resend (emails)
Sending of transactional emails (confirmation, password reset).
Policy: resend.com/legal/privacy-policy
Clouding.io (infrastructure)
Build servers for compiling launchers.
GitHub (CI/CD)
Source code repositories for launchers and automated builds.
No data is transferred to third countries that do not provide an adequate level of protection, except under appropriate safeguards provided by our processors (standard contractual clauses).
7. User rights
In accordance with the GDPR and the French Data Protection Act, each user has the following rights:
- Right of access (art. 15): obtain confirmation that data concerning you is being processed and obtain a copy of it;
- Right to rectification (art. 16): correct inaccurate or incomplete data;
- Right to erasure (art. 17): obtain deletion of your data ("right to be forgotten");
- Right to restriction (art. 18): request temporary suspension of processing;
- Right to portability (art. 20): receive your data in a structured, commonly used, machine-readable format;
- Right to object (art. 21): object to processing on legitimate grounds, particularly for direct marketing purposes;
- Right to withdraw your consent at any time, without affecting the lawfulness of prior processing.
To exercise your rights, contact us at: contact@craftlauncher.app
You can also exercise your rights from your dashboard settings. If you are not satisfied with our response, you have the right to lodge a complaint with the CNIL: www.cnil.fr.
Players: direct erasure from the launcher
Players in a community do not have a CraftLauncher account and therefore have no steps to take with us: they exercise their right to erasure directly from the launcher (Community tab → settings → "Erase my data"). This immediately deletes: all messages they have sent (rooms and private messages), their friends list, their blocks, their room memberships, and their username.
Two elements remain, and article 17.3 of the GDPR expressly allows this: ongoing sanctions (a ban, without which it would suffice to request erasure to bypass it) and reported content from other players, kept as evidence. Messages received are not deleted: they belong to their authors.
8. Cookies
The site only uses cookies strictly necessary for the service to function:
- PHPSESSID: PHP session cookie, essential for authentication. Duration: browser session.
- csrf_token: CSRF protection token. Duration: browser session.
No advertising, audience measurement or tracking cookies are used. In accordance with article 5 of the ePrivacy directive and CNIL recommendations, these necessary cookies are exempt from consent.
9. Data security
CraftLauncher implements appropriate technical and organizational measures to protect personal data:
- Encryption of communications (HTTPS/TLS);
- Password hashing with bcrypt (cost 12);
- CSRF protection on all POST requests;
- Prepared SQL statements (PDO) to prevent injections;
- Data isolation per user (separate R2 bucket);
- Administrator access restricted by role with audit log;
- Banking access handled exclusively by Stripe (PCI-DSS certified).
10. Minors
CraftLauncher account holders (clients)
Creating a CraftLauncher account, which requires subscribing to a paid plan, is reserved for adults or persons with legal capacity to contract.
Community players
We are aware that some Minecraft players are minors. Before any access to the in-launcher community, each player must review an information notice and declare being at least 15 years old (the digital consent age in France, art. 7-1 of the French Data Protection Act) or have the consent of a holder of parental authority. This declaration is timestamped. Until it has been made, no social data is processed: the player does not appear to anyone, and cannot write or speak.
Protective measures apply by default to all players, minors and adults alike: no profiling, no advertising, no resale of data, systematic relaying of voice calls so that a player's IP address is never revealed to other participants, blocking and reporting tools, and moderation by the community administrator.
If a holder of parental authority finds that data concerning their child under 15 is being processed without their consent, they can write to us at contact@craftlauncher.app: this data will be deleted as soon as possible. The player can also erase it themselves at any time from the launcher.
11. Changes to this policy
This privacy policy may be modified at any time. Substantial changes will be communicated to users by email or dashboard notification. The date of the last update is shown at the top of this page. Continued use of the Service after modification constitutes acceptance of the revised policy.