Skip to content

XMCL Together Privacy Policy

Effective date: August 14, 2026 · Version: P2-2026-08-14

This policy explains how CI010, operating as an individual operator under the Voxelum and XMCL names ("XMCL Together", "we", "us"), processes information when you use an XMCL Together account or related online services at xmcl.app. It does not govern independent services you choose to connect, such as Microsoft, Mojang, third-party authentication servers, Modrinth, or CurseForge.

1. Information we process

Together website and service telemetry

Together pages and services may use Microsoft Azure Application Insights to record page views, service actions, approximate network and device information, browser information, and diagnostic events. The website also stores a language-preference cookie. Telemetry from the free, open-source launcher is covered separately by the XMCL Open-Source Project Privacy Notice.

Accounts and authentication

When you create or use an XMCL Together account, we process account identifiers, authentication-provider identifiers, session and refresh-token metadata, granted scopes, timestamps, and security information used to prevent replay or account abuse. We do not receive your Microsoft or other third-party account password.

Billing and subscriptions

We process account balances, currency and rate information, orders, subscription state, allowance periods, usage totals, refunds, disputes, idempotency identifiers, and audit records. Waffo Pancake processes payment-card and checkout information. XMCL receives transaction references, status, amount, currency, and signed webhook events, but does not receive or store full card numbers or card security codes.

AI features

If you invoke an AI feature, we process the prompt, conversation content, selected model, and launcher context you choose to provide. Context can include an instance name, game and loader versions, selected page, or local instance path. Requests are sent to our configured AI providers, currently Agnes and, when needed, DeepSeek. We measure token counts and weighted allowance usage for billing and abuse prevention. We do not use your prompts or outputs to train an XMCL model.

Multiplayer, signaling, and TURN

Together and RTC features process account and session identifiers, room or peer-routing metadata, IP addresses, timestamps, TURN credential identifiers, and aggregate ingress/egress usage. Cloudflare provides edge, signaling, TURN, and traffic analytics services. Peer-to-peer connectivity can reveal your public IP address to the other peer. XMCL signaling services route connection metadata; they are not intended to record Minecraft voice, video, or gameplay content.

Support and community communications

If you contact us, we process the information you submit, such as your contact details, account or transaction reference, diagnostic information, and the content of the request. Do not send passwords, access tokens, full payment-card data, or unrelated personal information.

2. Why we use information

We use information to:

  • provide, authenticate, secure, and troubleshoot XMCL services;
  • operate subscriptions, balances, allowances, payments, refunds, and support;
  • route multiplayer connections and measure TURN usage;
  • generate requested AI responses and account for AI usage;
  • prevent fraud, replay, abuse, and security incidents;
  • understand reliability and improve the website and launcher;
  • comply with payment, accounting, tax, legal, and dispute obligations.

Depending on your location, our legal bases include performing our agreement with you, our legitimate interests in operating and securing the services, compliance with law, and consent where required.

3. When information is shared

We share only what is reasonably necessary with:

  • Waffo Pancake, for checkout, payment processing, fraud review, refunds, and payment events;
  • Cloudflare, for Workers, edge delivery, DDoS protection, signaling, TURN, and traffic analytics;
  • Microsoft Azure, for hosting, MongoDB-compatible data storage, diagnostics, and Application Insights;
  • Vercel and GitHub, for website delivery, source hosting, releases, and issue-based support;
  • Agnes and DeepSeek, when you request AI functionality;
  • authentication and content services you choose to use, such as Microsoft, Mojang, Modrinth, CurseForge, or a custom authentication server;
  • maintainers and service operators who need access to investigate support, reliability, billing, or security issues;
  • authorities or other parties when required by law, necessary to protect users and the services, or involved in a reorganization of the service.

These providers may process information in other countries under their own terms and safeguards. We do not sell personal information or share it for cross-context behavioral advertising.

4. Retention

We keep information only as long as needed for the purposes above. Session credentials expire according to their configured lifetime. Operational telemetry, error reports, security records, AI usage measurements, and TURN measurements are retained on rolling schedules appropriate to diagnosis, abuse prevention, and billing. Account and subscription data is retained while the account is active.

Financial ledger entries, payment events, refunds, disputes, and related audit records may be retained after account closure when needed to preserve balances, prevent fraud, resolve disputes, or meet accounting, tax, payment-network, and legal requirements. Backups are removed through normal rotation. Third-party providers apply their own retention schedules.

5. Your choices and rights

You can:

  • avoid optional online features or disconnect third-party services;
  • change website language cookies through your browser;
  • cancel Together Home renewal from the account interface, effective at the end of the current period;
  • request access, correction, export, or deletion of eligible account information;
  • object to or restrict certain processing, or withdraw consent where applicable;
  • complain to your local data-protection authority.

Some information cannot be deleted immediately, including records required for security, fraud prevention, financial reconciliation, legal compliance, or the establishment and defense of claims. To make a privacy request, use the contact channels in Section 10 and do not put sensitive information in a public issue.

6. Security

We use access controls, scoped sessions, encrypted transport, signed payment webhooks, replay protection, provider secrets, and service monitoring. No system is completely secure. You are responsible for protecting your device, account sessions, and third-party credentials.

7. Children

XMCL is not directed to children under 13. Paid services and AI features are intended for users who can legally enter the agreement, or who use them with authorization from a parent or legal guardian. If you believe a child provided personal information without appropriate consent, contact us so we can investigate.

Third-party integrations and links are governed by their own privacy policies. XMCL is an independent open-source project and is not affiliated with or endorsed by Microsoft, Mojang Studios, or the providers of third-party Minecraft content.

9. Changes

We may update this policy as the services change. We will publish the new effective date and version here. When required, we will provide additional notice before a material change takes effect.

10. Contact

CI010 can be contacted through:

For account, billing, refund, or privacy requests, include only the minimum account or transaction reference needed to locate the record. We may ask you to verify control of the account through a private channel.