Privacy Policy
Last Updated: September 18, 2026 • Effective Date: September 18, 2026 • Associated Domain: nodeclient.app
1. Overview & Commitment to User Privacy
NodeClient ("we", "our", or "the Client") is an open, modern desktop launcher for Minecraft Java Edition. NodeClient utilizes NodeAuth as its authentication module to verify Minecraft ownership via Microsoft Xbox Live OAuth 2.0.
We believe in strict data minimization and user sovereignty. We do not sell, rent, monetize, or harvest user data. NodeClient operates locally on your machine and only interacts with external APIs that are strictly required to launch and play Minecraft.
2. NodeAuth & Microsoft Account Authentication
To authenticate your Minecraft account, NodeClient employs NodeAuth, which utilizes the official Microsoft identity platform (OAuth 2.0 with PKCE):
-
Direct Transmission to Microsoft: During login, your credentials are submitted exclusively and directly to Microsoft servers (
login.live.comanduser.auth.xboxlive.com). NodeClient and NodeAuth never receive, intercept, or log your Microsoft password. -
Local Token Encryption: Session tokens and refresh tokens received from Microsoft and Mojang are stored strictly on your local disk using your operating system's native hardware-backed credential storage:
- Windows: Windows Credential Manager (DPAPI)
- macOS: Apple Keychain Services
- Linux: Secret Service API / GNOME Keyring / KWallet
- Zero Remote Server Storage: NodeClient maintains no centralized database of user accounts, email addresses, or authentication tokens. If our web servers were ever compromised, your Minecraft accounts remain completely secure because no credentials exist on our servers.
3. Local Logs, Crash Reports, and Telemetry
NodeClient operates with privacy-by-default telemetry settings:
-
Local Game Logs: Standard Minecraft game logs (
latest.log, crash dumps) are generated locally on your machine within your launcher directory. These files are never automatically uploaded. - Optional Crash Reporting: In the event of an unhandled launcher crash, you will be prompted with a dialog asking whether you wish to send an anonymized crash report to our issue tracker. Such reports contain only system metrics (e.g., OS version, Java version, GPU model, and stack trace) and never contain personal names, email addresses, or authentication tokens.
-
Analytics & Tracking: Our public website (
https://nodeclient.app/) uses zero tracking cookies, zero marketing trackers, and zero third-party behavioral analytics.
4. Third-Party Services & Integrations
When you use specific features within NodeClient, the launcher may communicate with the following third-party APIs:
- Mojang & Microsoft APIs: For skin textures, profile metadata, and game asset downloads (
api.minecraftservices.com,launchermeta.mojang.com). - Modrinth & CurseForge APIs: When searching or downloading community mods and modpacks through our integrated browser.
- Adoptium / Eclipse Temurin: To download verified, open-source Java runtimes (Java 8, 17, 21) required to run Minecraft instances.
- Discord RPC (Optional): Displays your active game status on Discord if enabled in settings. Can be disabled with one click.
5. Children’s Online Privacy Protection (COPPA)
NodeClient is designed for gamers of all ages. Because NodeClient collects zero personal information, requires no account registration on our website, and stores no data on remote servers, we fully comply with the Children’s Online Privacy Protection Act (COPPA) and international child safety standards. Microsoft parental controls and Xbox Family settings remain fully enforced during the NodeAuth sign-in flow.
6. Your Rights (GDPR / CCPA) & Data Deletion
Because all personal data and login sessions are stored exclusively on your device, you maintain 100% control over your data at all times:
- Logout / Deletion: Clicking "Remove Account" in the NodeAuth launcher tab immediately erases the local encrypted OAuth tokens from your operating system's keychain.
- Complete Removal: Uninstalling NodeClient and deleting the local launcher folder removes all profiles, configurations, and instances permanently.
- Revoking Access: You can revoke NodeAuth's access to your Microsoft account at any time via Microsoft's official security management portal (account.live.com/consent/Manage).
7. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or NodeAuth, please contact our team: