legal
privacy policy
last updated: september 2026
This policy describes what personal data pluto collects, the purposes and legal bases for processing it, how long it is kept, with whom it is shared, and the rights available to you. The data controller is the operator trading as “pluto”; full controller particulars required by applicable law are provided at checkout and on your receipt. References to “we” mean the controller. All privacy contact runs exclusively through tickets in the pluto Discord at https://discord.pluto.lgbt; there is no email, postal, or telephone privacy contact.
1. data we collect
- account data: username, email address, and a one-way Argon2id password hash. We never store plaintext passwords and cannot recover them.
- hardware identity: salted HMAC hashes of stable machine identifiers, plus per-component hashes used solely for drift tolerance (so replacing one part does not lock you out). We store hashes, never the raw identifiers, and they cannot be reversed into them.
- session and security records: login timestamps, hashed IP records in audit logs, token families for session rotation, license-ticket nonces, hardware-reset history, and enforcement actions (suspensions, terminations, chargeback flags).
- service quality and security records: routine operational records generated as the launcher and client run, limited to what is needed to keep the service stable, compatible, and abuse-free (build and channel identifiers, client and launcher versions, operating system and architecture, session start and end times with aggregate playtime, the network addresses and ports of multiplayer servers you connect to while the client is active, crash and error reports with stack context, update check-ins and download outcomes, and aggregate feature-usage counters). These records contain no chat content, no keystrokes, no screen or audio capture, no files, and no browsing history. Where a field is not needed for licensing, fraud prevention, or stability, it is aggregated or discarded at collection.
- support records: what you send us in Discord tickets, including any account identifiers needed to resolve the ticket.
- payments: processed by third-party processors (including cryptocurrency processors). We receive confirmation, amounts, timestamps, and any payer identifiers the processor passes back for reconciliation; we never receive card numbers, bank credentials, or wallet seeds.
What we do not collect: no advertising trackers, no analytics SDKs, no sale of personal data. The marketing site sets no cookies, runs no fingerprinting, and stores nothing on your device beyond what your browser ordinarily caches.
2. purposes and lawful bases (GDPR Art. 6)
- contract (Art. 6(1)(b)): account administration, licensing, build delivery, update distribution, subscription management, and support, which is processing necessary to perform the contract you entered by purchasing and using pluto.
- legitimate interests (Art. 6(1)(f)): fraud, license-abuse, and attack prevention (hardware binding, ticket nonces, audit and enforcement records); service stability and compatibility (service quality and security records, crash analysis, capacity planning). Our interests are operating a paid, machine-bound service that cannot function if licenses are freely shared, and keeping it working across Minecraft versions and platforms. We have balanced these interests against your rights by collecting hashes rather than raw identifiers, aggregates rather than content, and the minimum fields capable of achieving each purpose; we never use this data for advertising, profiling for third parties, or sale. You may object under section 6, and we will stop unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims.
- consent (Art. 6(1)(a)): where strictly necessary data on your device is accessed for licensing and integrity purposes (ePrivacy consent), obtained when you accept the terms and log in, and withdrawable by deleting your account, which ends the license. Should a future client release add a setting limiting service-quality records to the minimum required for licensing, enabling it will be treated as a partial withdrawal of consent for the broader records, effective prospectively.
- legal obligation (Art. 6(1)(c)): tax, accounting, and other records we are required by law to keep, and disclosures compelled by valid legal process.
Where your jurisdiction does not use GDPR terminology, equivalent concepts apply: we process your data to perform our contract with you, to protect the service against fraud and abuse, with your consent where required, and to comply with the law.
3. hardware identity, specifically
The launcher reads stable machine identifiers (per OS: OS install id, board serial, CPU id, system UUID, and never browsing history, files, keystrokes, or content) and they are hashed server-side with a secret salt before storage. Matching a second machine requires at least 3 of 4 components to agree, so a disk or RAM swap does not lock you out. Binding occurs on first login; self-service resets open weekly. This processing is necessary to enforce the one-machine license and is retained under contract and legitimate interests as described above.
4. retention
- account data and hardware binding: life of the account, plus 30 days for recovery, then deleted;
- session tokens: 7 days from issuance, then expired and purged;
- audit, enforcement, and fraud-defence records: 12 months, then deleted, unless needed longer for an ongoing dispute or legal claim;
- service quality and security records: raw records 90 days, then aggregated or deleted; aggregates kept 24 months for stability analysis;
- payment and tax records: as required by applicable tax and accounting law (typically 6 to 10 years);
- support tickets: 24 months after closure.
On account deletion we erase or anonymize data without undue delay except where retention is required or permitted under this section (for example tax records, or hashes strictly necessary to defend against fraud or establish legal claims).
5. sharing and disclosure
Processors under contract only: dedicated hosting infrastructure in Germany (EU/EEA), payment processing, and community tooling (Discord) where you contact us. Processors act solely on our documented instructions and are bound to confidentiality, purpose limitation, and appropriate security. We do not sell personal data, share it with advertising partners, or supply it to data brokers. We disclose data to third parties only: (a) to processors as described; (b) where required by valid, binding legal process or applicable law, after assessing validity and scope and notifying you unless prohibited; (c) to establish, exercise, or defend legal claims, including against fraud, chargeback abuse, redistribution, or infringement; or (d) in connection with a merger, acquisition, or asset sale, subject to continued protection under this policy and applicable law.
6. your rights
Under the GDPR/UK GDPR, and to the extent applicable equivalent rights under laws including the CCPA/CPRA (California), PIPEDA (Canada), the Privacy Act 1988 (Australia), and comparable regimes, you may request access to, correction of, portability of, restriction of, and erasure of your personal data, and may object to processing based on legitimate interests or withdraw consent at any time with prospective effect. To exercise any right, open a ticket in the Discord from the account or contact point associated with the data; we verify identity proportionate to the sensitivity of the request and respond within one month (extendable by two months for complex requests, with notice). Erasure of data necessary to an active license ends the license; hashes strictly necessary to defend against fraud or to establish legal claims may be retained where the law permits. Automated decisions with legal or similarly significant effect are not applied to accounts; enforcement actions involve human review on request. You may lodge a complaint with your supervisory authority (your national data protection authority, the IMY in Sweden or the ICO in the UK); we ask that you contact us first so we can resolve the matter.
7. international transfers
Infrastructure currently operates in Germany, with a planned relocation to Sweden; both are inside the EEA, so routine operation involves no third-country transfer. Where personal data leaves the EEA, UK, or a jurisdiction requiring equivalent protection, transfers occur only with an appropriate safeguard, whether an adequacy decision, standard contractual clauses, or another lawful mechanism, documented and available on request via a Discord ticket, subject to redaction of security-sensitive detail.
8. security and breach notification
TLS 1.3 in transit; salted slow hashes at rest (passwords and hardware identifiers are never stored raw); short-lived access tokens with rotating refresh; per-release encrypted artifacts; OS-keychain session storage on your device; least-privilege access among staff. No system is perfect. If we discover a personal-data breach likely to result in risk to your rights, we notify the competent supervisory authority within 72 hours of awareness where required, and notify affected users without undue delay where the risk is high, via the Discord and your account contact point. Suspected issues may be reported through a Discord ticket at any time.
9. children
pluto is not directed at children and purchase requires 18+. Account holders under 16 must have a parent or guardian hold the account and consent on their behalf. We delete accounts we learn are held by under-13s (or below the applicable minimum age in your jurisdiction), together with associated personal data except where retention is legally required.
10. data on your device; cookies
The launcher stores a session token in your OS keychain (or a locked-file fallback), cached manifests, and the verified build while installed. Clearing the application data removes them; the server-side copies expire or can be revoked as described above. The marketing site uses no cookies, no local storage beyond normal browser caching, and no cross-site tracking.
12. captcha
Account creation, login under attack, and password resets are guarded by pluto captcha: a memory-hard proof of work solved in your browser plus counts of ordinary interaction (pointer samples, key presses, their duration). It collects no content, no coordinates, no keys, and nothing biometric. Challenges expire within minutes, interaction records are evaluated in memory and never stored, and solved challenges are single-use. The legal bases are contract and our legitimate interest in preventing automated abuse, as described in section 2.
13. changes
Material changes are announced in the Discord at least 7 days before taking effect; continued use after the effective date constitutes acceptance. Where the law requires fresh consent for a new purpose, we obtain it before processing for that purpose.