Skip to content

Legal

Privacy policy

What we store, why we store it, and how to get rid of it.

Last updated 14 March 2026

We keep the smallest amount of data that lets your sessions stay online, and we are specific about it rather than vague.

The one thing worth repeating: we never receive your Microsoft password. Linking a Minecraft account happens on Microsoft’s own sign-in page, and what we store afterwards is an encrypted refresh token.

  1. 1. What we collect

    Only what running your sessions requires.

    • Account details: your email address, an optional display name, and a hash of your TetherMC password. We never store the password itself.
    • Sign-in sessions: an opaque token, stored hashed, plus the time it was created and last used, so sessions can be listed and revoked.
    • Linked Minecraft accounts: the in-game name, the account UUID, and an OAuth refresh token, encrypted before it is written to the database.
    • Server configurations you create: label, hostname, port, platform and optional version.
    • Session activity: connection state changes, disconnect reasons, latency samples, macro and scheduler runs, and CAPTCHA events.
    • Server chat your sessions observe, while your plan’s retention window is open.
    • Billing records: the plan, its status, and the payment processor’s identifiers. Card details go to the processor, never to us.
    • Operational logs: request metadata and errors, with tokens, cookies, passwords and full email addresses redacted before anything is written.
  2. 2. What we never collect

    We never ask for, accept, or store a Microsoft or Mojang password. There is no field for one anywhere in the product, and the linking flow could not use one if you supplied it — it works through Microsoft’s OAuth consent screen and returns a refresh token.

    We do not run third-party advertising or analytics trackers, and we do not sell or rent your data.

  3. 3. Why we hold it

    To run the service you asked for: keeping sessions connected, reconnecting them, showing you their state, and enforcing your plan’s limits.

    To keep accounts secure: detecting abuse, rate-limiting, and letting you and our administrators revoke access.

    To bill you correctly and keep the records that requires.

    To answer support requests you send us.

  4. 4. How long we keep it

    Chat and activity logs are deleted when your plan’s retention window closes — three days on Trial, seven on Lite, thirty on Standard, ninety on Pro. Lifetime grants retain logs indefinitely.

    Encrypted refresh tokens are kept until you unlink the Minecraft account or delete your TetherMC account, whichever comes first.

    Account and billing records are kept while your account exists, and afterwards only as long as tax and accounting rules require.

    Sign-in sessions expire on their own and are removed when they do.

  5. 5. How it is protected

    OAuth refresh tokens are encrypted with AES-256-GCM. The key lives in the environment, never in the database, so stolen database rows are not usable credentials on their own.

    Passwords are hashed with a memory-hard algorithm. Session tokens are stored hashed, so a database copy does not let anyone log in as you.

    Every query that touches customer data is scoped to the account that owns it, and every request is authorised on the server. Access to production data is limited to the people who operate the service, and administrative actions are recorded in an append-only audit log.

  6. 6. Who else sees it

    The Minecraft servers you choose. When a session connects, that server sees your in-game name, your IP as seen from our worker, and anything your session sends. We cannot control what a server logs.

    Microsoft, during account linking and whenever a token is refreshed.

    Our payment processor, for paid plans, which handles card data directly.

    Our hosting and email providers, as processors, to the extent needed to run the service.

    Nobody else, unless the law compels us or you ask us to.

  7. 7. Your controls

    From Settings you can change your password, sign out other sessions, request an export of your data, and delete your account. Deleting your account stops your sessions and removes your stored credentials.

    You can unlink an individual Minecraft account at any time from the Accounts page; that removes its stored refresh token immediately.

    Depending on where you live you may also have rights to access, correct, or object to our handling of your data. Ask and we will help.

  8. 8. Cookies

    We set one essential cookie, an httpOnly session cookie, so you stay signed in. It is not used for tracking or advertising, and there is no consent banner because there is nothing optional to consent to.

    Your theme preference is stored in your browser’s local storage and never sent to us.

  9. 9. Children

    TetherMC is not intended for children under 13, or under the minimum age of digital consent where you live if that is higher. If we learn that an account belongs to a child below that age we will delete it.

  10. 10. Changes and contact

    If we change what we collect or why, we will update this page and tell you before a material change takes effect.

    Privacy questions and data requests go to support@tethermc.local.