Privacy
What Pallas stores, why, for how long — and how to have it deleted.
Privacy Policy
Version 2026-09-15.
Governing law and language. German law applies to this policy. If you are a consumer, you also keep the protection of the mandatory rules of the country you live in — nothing here takes those away (Art. 6(2) Rome I Regulation (EC) No 593/2008).
Last updated: 2026-09-14 · Applies to: the Pallas launcher, the Pallas Fabric mod, the Pallas online services (api.pallasclient.com) and the website pallasclient.com.
1. Who is responsible (Art. 13(1)(a) GDPR)
Valentin Weinert Dr.-Rohmer-Weg 11 65719 Hofheim am Taunus Germany
VAT ID under § 27a UStG: DE451355427 Email for all privacy matters: support@pallasclient.com Security reports: security@pallasclient.com
Full provider details: see the Imprint.
Data protection officer (Art. 13(1)(b)): none, and none is required. § 38(1) BDSG only requires one from 20 people permanently occupied with processing; Pallas is run by one person. Art. 37(1)(b) and (c) GDPR do not apply either: our core activity is not large-scale regular monitoring, and we process no special categories of data.
2. The short version
- To play, you sign in with your Microsoft account. We learn your Minecraft UUID and your Minecraft name — nothing else about your Microsoft account. Your Microsoft tokens stay on your PC, encrypted with Windows DPAPI.
- We run no cookies, no advertising, no tracking pixels and no third-party analytics. The website needs no cookie banner because it sets no cookies.
- Usage statistics and crash reports are off until you say yes. Before you answer, nothing is written to disk and nothing leaves your PC.
- Purchases are made with Tebex Limited (UK), not with us. We never see your payment details.
- While you play, the launcher/mod tells our server which players around you use Pallas. That means we briefly receive the public UUIDs of other players — section 6 explains this, and you can switch it off.
3. What we process, why, and on what legal basis
3.1 Account and game start
| Data | Minecraft UUID, Minecraft name, Microsoft/Xbox/Minecraft tokens (stored on your device only), the session token our server issues |
| Purpose | Signing you in, starting the game, proving to our server that the UUID is really yours (Mojang hasJoined handshake) |
| Legal basis | Art. 6(1)(b) GDPR — performance of a contract (you asked for the service) |
| Storage | Session token: in memory on the server, 24 hours, never written to disk. Tokens on your PC: until you sign out, encrypted with Windows DPAPI |
| Recipients | Microsoft Corporation / Mojang Studios (see section 7) |
3.2 Presence, badges, cosmetics and emotes
| Data | Your UUID, your cosmetic/emote loadout, the emote you trigger, and — if you share a world — the public address of that shared world (e4mc). The address of the Minecraft server you are playing on is deliberately not transmitted |
| Purpose | Showing Pallas badges, cosmetics and emotes to and from other Pallas players |
| Legal basis | Art. 6(1)(b) GDPR for your own data; § 25(2) no. 2 TDDDG for the device access, because this is the feature you asked for |
| Storage | In memory only: "online" markers 90 seconds, loadouts 7 days, then gone |
| Switch it off | Settings → Privacy → "Show Pallas badges of other players" in the launcher, and the same switch in the in-game menu |
3.3 Entitlements (what you own)
| Data | Your UUID, the item, the time, the source of the grant, the Tebex reference |
| Purpose | Making sure you can actually use what you bought, on any PC you sign in from |
| Legal basis | Art. 6(1)(b) GDPR |
| Storage | For as long as the entitlement exists. Records that are also accounting records are kept for 10 years (§ 147 AO, § 257 HGB) |
3.4 Custom capes and the cape gallery
| Data | The cape image you upload, your UUID. Only if you actively publish it: additionally your Minecraft name and the publication date, both publicly visible |
| Purpose | Showing your cape to you and to other Pallas players; the gallery shows published capes to everybody |
| Legal basis | Art. 6(1)(b) for the private cape; Art. 6(1)(a) — your consent for publishing it in the gallery |
| Storage | Until you delete the cape or un-publish it; a published entry also expires after 730 days without a sign-in |
| Please note | Publishing puts your Minecraft name in public. Do not publish a cape that shows personal information or content you have no rights to. Published capes can be reported (in-app) and removed by us; you can withdraw the publication at any time in the launcher |
3.5 Crash reports — only with your consent
| Data | App and version, operating system, exit code, timestamp, and the last lines of the game console |
| Honest warning | Those console lines can contain your player name and file paths from your PC (for example C:\Users\<your Windows name>\…). They never contain your account, your password or any token. We remove player names, Windows user names and server addresses before sending, but we cannot promise that a log line never carries something else |
| Purpose | Finding and fixing the bug that crashed your game |
| Legal basis | Art. 6(1)(a) GDPR — consent. Off by default. Withdraw any time under Settings → Privacy |
| Storage | 90 days, then deleted. We do not store your IP address with the report |
3.6 Usage statistics — only with your consent
| Data | A random install ID, a session ID, your UUID, app version, operating system, interface language and time zone, plus events: GPU model, frames per second and 1 % lows, session length, which HUD widgets and features you used, exit code, crash flag |
| Purpose | Understanding which features are used and where Pallas is slow |
| Legal basis | Art. 6(1)(a) GDPR — consent. Off by default. The question is asked once; "×" means "not now" and stores nothing |
| Storage | 180 days on our server in Germany, then deleted — a row-count total with no pseudonym is kept afterwards, so it never identifies you |
| How it is stored | Your UUID is replaced by an HMAC pseudonym before storage. That is pseudonymisation, not anonymisation — we still treat it as personal data, because we hold the key (Recital 26 GDPR) |
| No profiling | There is no automated decision-making with legal effect (Art. 22 GDPR). A/B variants of interface details have no legal effect on you |
3.7 Skin history (off by default)
| Data | Your Minecraft UUID, sent to crafty.gg, a third-party service |
| Purpose | Showing the history of skins you have worn |
| Legal basis | Art. 6(1)(a) GDPR — consent. Off by default; the launcher asks the first time you open Skins → Yours |
| Recipient | crafty.gg, an independent controller. Its website names no legal entity; its terms are governed by the law of the Australian Capital Territory, Australia. Privacy policy: https://crafty.gg/privacy-policy, contact hello@crafty.gg |
| Third-country transfer | Australia has no EU adequacy decision and we have no contract with crafty.gg. The transfer therefore rests on your explicit consent after this information (Art. 49(1)(a) GDPR). The risk: Australian law does not give you the rights the GDPR gives you, and we cannot enforce them there. You can withdraw the consent at any time by switching skin history off; nothing is sent while it is off |
3.8 Discord Rich Presence (off by default for the server address)
| Data | What you are doing ("In the launcher", "Playing"), a timestamp, and — only if you switch it on — the name of your world or the address of the Minecraft server you are on |
| Where it goes | To the Discord client on your PC, which forwards it to Discord Inc. (USA) and shows it publicly in your Discord profile. Your Discord friends see it |
| Legal basis | Art. 6(1)(a) GDPR — consent, by switching the feature on |
| Please note | If you turn on "Show server address", the address of a private friends' server may become publicly visible. That address can be personal data of somebody else. The option is off by default |
3.9 Buying cosmetics and emotes
| Your contract partner | Tebex Limited, Company No. 08129184, England & Wales — the merchant of record. Payment data goes to Tebex, never to us |
| What we send to Tebex | The Minecraft name of the recipient, an item reference, and your IP address (Tebex requires it for fraud prevention) |
| What we receive from Tebex | A purchase notification. From it we keep only: transaction ID, event type, time, package, amount, currency, country code, recipient UUID, reference. Buyer email address, real name and IP address from the raw notification are discarded on arrival and never stored |
| Legal basis | Art. 6(1)(b) GDPR (delivering what you bought) and Art. 6(1)(c) with § 147 AO, § 257 HGB (keeping accounting records) |
| Storage | Accounting-relevant fields: 10 years. Everything else: not stored |
3.10 Website pallasclient.com
| Cookies | None. No advertising, no Google Analytics, no Plausible, no Cloudflare Insights. Fonts are self-hosted, not loaded from Google |
| Browser storage | pallas.accounts (your UUID, name, skin image and a 30-day bearer token), pallas.mcname, pallas.signin. All of these are needed for the sign-in you asked for → § 25(2) no. 2 TDDDG, no consent banner required. The PKCE verifier lives in sessionStorage and is deleted immediately after sign-in |
| Sign-in | Your Microsoft token is exchanged on our server. The server stores nothing from this — the endpoint is stateless |
| Tebex script | js.tebex.io is loaded only when you click Buy, never on page load |
| Server logs | Our web server writes no access logs, so there are no IP address logs |
3.11 Updates and downloads
When the launcher checks for updates or downloads Minecraft, Java, Fabric or mods, your IP address and a user agent reach the servers involved (api.pallasclient.com, piston-meta.mojang.com, resources.download.minecraft.net, meta.fabricmc.net, api.modrinth.com, cdn.modrinth.com). That is unavoidable for any download. Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR — our legitimate interest in delivering security updates.
3.12 Security and abuse prevention
We keep short-lived rate-limit counters in memory (roughly 10–40 seconds per IP address) to stop abuse. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in keeping the service available. Nothing from this is written to disk.
4. Legitimate interests we rely on (Art. 13(1)(d) GDPR)
We have written down a balancing test for each processing based on Art. 6(1)(f):
- Presence check of other players' UUIDs — see section 6.
- Skin history — see section 3.7.
- Rate limiting and abuse prevention — see section 3.12.
- Delivering security updates — see section 3.11.
You can object to any of these at any time under Art. 21 GDPR (support@pallasclient.com). For presence, the switch in the launcher and in the in-game menu is the fastest way.
5. Consent — how to give it and how to take it back
Usage statistics, crash reports, skin history, Discord Rich Presence and the public cape gallery run only on your consent. Before you answer the question, nothing is written to disk and nothing is sent.
You can withdraw every one of these at any time, as easily as you gave it: Settings → Privacy in the launcher, one click per item. Withdrawal takes effect immediately, deletes the local install ID and the queued events, and stops any transmission in progress. Withdrawal does not affect the lawfulness of what happened before it (Art. 7(3) GDPR).
6. Players who do not use Pallas (Art. 14 GDPR)
Please read this even if you have never installed Pallas.
When somebody plays with Pallas, the mod sends us the public Minecraft UUIDs of the players in their tab list — up to 200, plus up to 24 recently seen ones, every 2.5 to 30 seconds.
- Why. Only to check which of those players also use Pallas, so that the Pallas badge, cape or cosmetic can be rendered. There is no other purpose.
- **What we do not receive. The address of the Minecraft server is deliberately not** transmitted. We do not run any geo-IP lookup. We do not build profiles.
- Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest is making the feature work at all; without the check, a Pallas player could not see another Pallas player. The interference is low: the UUID is public information visible to every player on the same server anyway, we hold it for at most 90 seconds in memory, and we never write it to disk.
- How long. In memory, 90 seconds. Loadouts of Pallas users: 7 days. Then gone.
- Source of the data. From the tab list of the Minecraft server you were both on — not from you.
- Why we did not write to you individually. Art. 14(5)(b) GDPR: we hold nothing but a UUID for 90 seconds and have no way to contact you. This section is the substitute the law provides for that case.
- Your rights. You can object at any time under Art. 21 GDPR (support@pallasclient.com). You can also ask any Pallas player you play with to turn the feature off — the switch is in their launcher and in their in-game menu.
The same applies to cape textures: when a Pallas player renders you, your UUID is sent to us once to ask whether a Pallas cape exists for it.
7. Who receives data (Art. 13(1)(e) GDPR)
| Recipient | Role | Where | What they get | Safeguard |
|---|---|---|---|---|
| Hetzner Online GmbH | processor | Germany | hosting of all Pallas servers | processing agreement under Art. 28 GDPR |
| Cloudflare, Inc. | processor | USA / global | DNS, website hosting (Pages), email routing | EU-US Data Privacy Framework + standard contractual clauses in the Cloudflare DPA |
| Microsoft Corporation / Mojang Studios | independent controller | USA | your Microsoft sign-in, Xbox and Minecraft profile calls | EU-US Data Privacy Framework |
| Tebex Limited | independent controller for the sale; processor for the recipient name we pass on | United Kingdom | purchase, payment, invoicing | UK adequacy decision of 19 December 2025, valid until 27 December 2031 — no additional clauses needed |
| Discord Inc. | independent controller | USA | Rich Presence activity, only if you enabled it | EU-US Data Privacy Framework |
| Rinth, Inc. (Modrinth) | independent controller | USA / Canada | IP address and user agent when mods are downloaded | — |
| crafty.gg (operator not named on its site) | independent controller | Australia | your UUID, only if you enabled skin history | none — no adequacy decision; your explicit consent under Art. 49(1)(a), see section 3.7 |
We do not sell data, and we run no advertising network.
8. Transfers outside the EU/EEA (Art. 13(1)(f), Art. 44 ff. GDPR)
- USA (Microsoft, Discord, Cloudflare, Modrinth): these transfers rest on the EU-US Data Privacy Framework adequacy decision. That decision is in force today. An appeal against it is pending before the Court of Justice (C-703/25 P); where a provider also offers standard contractual clauses in its data processing agreement, those clauses are our fallback.
- United Kingdom (Tebex): covered by the adequacy decision of 19 December 2025, valid until 27 December 2031. No further safeguards needed.
- crafty.gg: destination unknown — see section 3.7. The feature is off by default; if you never switch it on, no transfer happens.
Our own transfer impact assessment is documented internally (docs/legal/TRANSFERS.md).
9. How long we keep things (Art. 13(2)(a) GDPR)
| Data | Retention |
|---|---|
| Session token on our server | 24 hours, in memory only |
| "Online" marker, other players' UUIDs | 90 seconds, in memory only |
| Cosmetic/emote loadouts | 7 days, in memory only |
| Entitlements (what you own) | as long as the entitlement exists |
| Accounting records from purchases | 10 years (§ 147 AO, § 257 HGB) |
| Crash reports | 90 days |
| Usage statistics | 180 days |
| Custom cape | until you delete it |
| Public gallery entry | until you un-publish it, or after 730 days without a sign-in |
| Server backups | 30 days, encrypted |
| Browser sign-in token on the website | 30 days, on your device |
| Web server access logs | not written at all |
10. Your rights (Art. 13(2)(b)–(d), Art. 15–21 GDPR)
You have the right to:
- access the data we hold about you (Art. 15),
- rectification of wrong data (Art. 16),
- erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on legitimate interests (Art. 21) — in particular the presence check in section 6,
- withdraw consent at any time (Art. 7(3)) — see section 5.
How to use them. Write to support@pallasclient.com with your Minecraft name or UUID. We answer within one month (Art. 12(3) GDPR); if a request is unusually complex we may extend that by two months and will tell you why.
What erasure covers. On request we delete your cape file, your entry in the public gallery (including your name), your entitlement records (we write a tombstone so a backup restore cannot bring them back), and your usage statistics. Two things we cannot delete: accounting records we must keep by law (Art. 17(3)(b) GDPR, § 147 AO), and crash reports, which carry no identifier we could search by — which is exactly why we no longer store your IP address with them.
Do you have to give us data? (Art. 13(2)(e)) To sign in and play, yes — without your Minecraft UUID there is no way to check what you own. Usage statistics, crash reports, skin history, Discord presence and the public gallery are entirely voluntary; the launcher works identically if you decline all of them.
Automated decision-making (Art. 13(2)(f)): none.
11. Complaints
You can complain to a supervisory authority at any time. The one responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI) Postfach 3163 65021 Wiesbaden Germany https://datenschutz.hessen.de
You may also complain to the authority where you live or work.
12. Young people
You must be 16 or older to give consent for usage statistics, crash reports, skin history, Discord Rich Presence or the public cape gallery (Art. 8 GDPR; Germany has not lowered the age limit). If you are younger, please ask a parent or guardian first — and do not turn those options on without their agreement. The launcher does not ask your age; all of these options are off until you turn them on yourself.
Signing in and playing does not depend on any of this.
13. Security (Art. 32 GDPR)
- All connections use TLS; the mod refuses any non-HTTPS endpoint.
- Your Microsoft tokens are encrypted on your PC with Windows DPAPI (current-user scope). They are never sent to us.
- Session tokens are random 24-byte values, kept in memory only, and travel in a header — never in a URL, where proxies and referrers would leak them.
- Launcher updates are signed (minisign/Ed25519) and verified before installation; downloaded mods are pinned by SHA-512.
- Backups are encrypted.
- Our incident process is written down: see
docs/INCIDENT.md(data breaches, Art. 33/34 GDPR) anddocs/CRA-MELDERUNBOOK.md(Cyber Resilience Act).
14. Changes to this policy
We update this policy when the product changes. The version date at the top always tells you which text is current. Substantial changes are announced in the launcher and on the website before they take effect.
15. Contact
Privacy questions, requests under section 10, objections: support@pallasclient.com
Security vulnerabilities: security@pallasclient.com — see our Security Policy.