This policy explains what data pluto collects, why we collect it, how long we keep it, who receives it, and your rights. The data controller is the operator of pluto, based in Sweden. Send privacy requests to legal@pluto.lgbt; we respond by email. You can also contact us through Discord, but a Discord account is not required.
pluto collects only the data needed to operate the machine-bound launcher. We do not collect the servers you join, how long you play, which features you use, your chat, your keystrokes, or your screen. Section 1 lists all the data we collect.
1. what we collect
- account data: username, email address, an Argon2id password hash, the date you registered, the date your email was verified, and your account's access flags. We never store your plaintext password and cannot recover it.
- hardware identity: four stable machine identifiers from your operating system, described in section 3. They are sent to us so we can bind your license, and we immediately convert them into keyed hashes. We store the hashes, never the raw values. We also give each machine binding a random device identifier, not derived from your hardware, and keep a record of changes to the binding: when it was created or reset, when a login was refused because the hardware did not match, and when one of the four components changed (which of the four, never its value). If a component's hash is also bound to another account, we note that for review.
- session and security records: login timestamps, a keyed hash of your IP address in audit entries, hashes of your session tokens together with a rotation family so a stolen token can be detected, launch-ticket nonces, the date of your most recent hardware reset, and enforcement actions such as suspensions or terminations. Logging in on this website sets one cookie that keeps you logged in: a random token that only our server can read, stored here as a hash. It lasts a week from the last time it was used (30 days at most) and is removed when you log out, reset your password or are banned. Your browser also keeps a plain note that you were logged in, so the site knows whether to check; it holds nothing about you and is removed when you log out.
- session records: while pluto runs, one live session per license: a session id, the build channel and version, a keyed hash of your IP address, when the session started, was last renewed and ended and why, and a public key your client generated for that launch (its private half stays in your computer's memory and is never sent to us). Requests the client makes during the session are signed with that key, and each carries a one-time identifier that we keep for a few minutes so a captured request cannot be replayed. If a second session tries to start while one is live from another address, we refuse it and record that.
- delivery records: which build, channel, operating system, and architecture you downloaded, the highest build number your account has acknowledged per channel, artifact sizes, and the release notes shown to you. These exist so downloads can be traced and supported. Each build you download also carries an identifier linked to your account, embedded in the file itself, so a copy shared outside your account can be traced back to it. For each build file we serve you we keep a record: the release and platform, a hash of the exact file, a canary token inside it, the kind of account it went to (player, beta, tester or staff), and a signature so the record cannot be altered later.
- detection and enforcement records: automated checks count things that normally stay small: launch tickets asked for, builds downloaded, device changes, sessions that replaced each other. A check that fires records an event (which check, when, and the counts involved). Some checks only record, to be reviewed by a person; a definite integrity failure reported by your client, or a copy of a build traced to your account, can suspend your license pending review. A suspension opens a case with a reference, keeps a snapshot of the evidence (the reports, hashes and times involved), and shows you the reference. You can appeal from your dashboard, and what you write is stored with the case along with an operator's decision and notes.
- your settings: if you use pluto's module settings, we store them with your account: for each profile (up to ten) and module, the values that differ from the defaults, its last five versions, and the profile names you choose. Every change is recorded in the security records (when, and from which session) without the values. Each value is checked against a fixed list of allowed settings and stored as plain data; it is never run. Free-text settings are for short labels, so don't put anything secret in them. You can share a snapshot of a profile's settings as a short code: anyone with the code can look inside it and import it into a new profile on their own account. Shared codes are never anonymous: whoever holds one sees your username and, if you have one, your profile picture, along with the code's label, when it was made, how many times others imported it, and which modules it changes and how many settings in each. The values themselves only reach their account if they import it. We store the profile name each code came from, record who exported and who imported it, and count imports by others (with the time of the latest) so you can see them. Codes don't expire: deleting one stops future looks and imports; deleting all of your settings (purge) removes their values, history, codes and extra profiles at once.
- integrity reports: the client checks that it has not been modified and is not being debugged or injected into, for example by looking at the settings Java was started with, environment variables used to inject libraries, on Windows the name of the program that launched the game, and the integrity of its own code. These checks run on your computer. If one fails, or the launcher cannot start pluto for another reason, it stops and, if you are logged in, sends us a short report: a code for what stopped it, the build channel and version, your account, and a keyed hash of your IP address. So we can work out what went wrong, each report also carries your operating system with its version and architecture, your Java version and vendor, the game version, the number of processor cores, the memory limit Java was given, and how long the game had been running. When the launcher stops a launch, its report adds the launcher and Fabric versions, how far the launch got and how long each step took, the types and messages of the errors behind the stop, where in the code they happened, and the launcher's last 30 log lines. Before sending it, the launcher strips out the paths of your home, temporary, and game config folders, your computer's account name, and anything that looks like a password, key, or token. Reports never include the names of your other programs, your files, or the values of your settings, apart from that memory limit. From time to time while your session renews, the server also asks your client to prove a random part of its copy is the file it was given: a hash of that region under a one-time value. The answer carries nothing beyond the hash; a wrong answer is recorded as an integrity event, and no answer is simply asked again later.
- email verification codes: when you register or log in we email you a six-digit code. We store a hash of the code, your email address, its purpose, and when it expires and was used.
- support records: what you send us by email or in a Discord ticket, including the account identifiers needed to resolve it.
- payments: processed by third-party processors, including cryptocurrency processors. We receive confirmation, amount, timestamp, currency, and any payer identifier the processor passes back for reconciliation. We never see card numbers, bank credentials, or wallet seeds.
- bot checks: counts and coarse timings from the captcha on our own pages, described in section 11.
- signup location check: when you register, we look up the country your IP address belongs to in a geolocation database kept on our own servers, so no third party sees the lookup, and store the country with your account. We use it to meet sanctions law: sign-ups from comprehensively sanctioned regions can be refused, and sign-ups from anonymizing networks such as Tor can be held for a person to review. IP geolocation by DB-IP.
- profile picture (optional): if you upload one, your browser crops and re-encodes it to a 256 by 256 pixel image before sending it, and we strip any remaining embedded data (such as camera or location details) before storing it with the date it was set. Only you can see it, while logged in, with one exception: if you share a settings code, anyone holding that code sees it next to your username. It is never public or analysed, and you can remove it at any time.
- username history: when you change your username we record the old name, the new name, and the date. This keeps your old name reserved for you for 45 days and lets us match support and security records across a rename.
What we do not collect: the addresses or ports of the servers you connect to, your playtime, feature-usage counters, crash reports, browsing history, chat, typed content, or screen and audio capture. The integrity report described above says only how long the game had been running when it was sent, and when the launcher stops a launch it carries the error details listed there rather than a crash report. There are no advertising trackers and no analytics SDKs on this site, and we do not sell personal data or share it with data brokers.
Apart from the integrity report described above, nothing about the programs on your computer is sent to us, and that report names no programs other than pluto, the game, Fabric, Java, and your operating system.
2. purposes and legal bases
- performing the contract (GDPR Art. 6(1)(b)): your account, your license, binding it to one machine, delivering builds, checking entitlement, and support. Reading the machine identifiers, running the integrity checks, and storing your session locally are necessary for the service you asked for, so we rely on the exemption for strictly necessary device access rather than on consent. Accepting these terms is not treated as consent to this processing.
- our legitimate interests (Art. 6(1)(f)): keeping the service stable and secure, preventing license and payment abuse, protecting the client against tampering, cracking, and unauthorised redistribution (integrity reports and build identifiers), preventing impersonation (username history), investigating misuse, enforcing one license on one device with one live session at a time, and keeping audit and delivery records. Our interest is operating a paid, machine-bound service that cannot work if licenses are freely shared, and supporting customers whose builds are failing. We have balanced that against your rights by storing keyed hashes rather than raw identifiers, keeping delivery records narrow, and never using this data for advertising or profiling for anyone else. You may object under section 6, and we will stop unless we show compelling grounds that override your interests, or the processing is needed for a legal claim.
- legal obligation (Art. 6(1)(c)): tax, accounting, and other records we must keep by law, the signup location check we need to meet sanctions law, and disclosures compelled by valid legal process.
Where your jurisdiction does not use GDPR terminology, equivalent concepts apply: we process your data to perform our contract, to protect the service, and to meet legal duties.
3. hardware identifiers
On Windows we read the machine GUID, the baseboard serial, the processor ID, and the computer-system product UUID. On Linux we read the machine ID, the DMI product UUID, the board serial, and CPU identifying fields from /proc/cpuinfo. On macOS we read the platform UUID, the platform serial, the board ID, and the hardware model. We never read your files, browsing history, or content to do this.
The four values are sent to us over TLS. Our server normalizes them, computes a keyed hash of the whole set and a keyed hash of each value, and stores only those hashes. A later login is accepted if the whole-set hash matches, or if at least three of the four individual hashes match, so replacing any one of these components does not lock you out. The whole-set value is a plain SHA-256 digest that your own machine also computes; the stored hashes are HMAC-SHA256 under a server-side secret. Binding happens at first login and self-service resets open weekly.
These hashes are keyed digests rather than password hashes. They remain personal data while linked to your account and are not anonymous.
4. how long we keep it
- account data and hardware binding: for the life of the account, then deleted or anonymized, with up to 30 days for recovery;
- session tokens: 7 days, then expired and purged;
- launch tickets: 90 days;
- session records: 30 days after the session ends; the one-time request identifiers: a few minutes;
- website log-in cookies: a week after they were last used, and never more than 30 days after you logged in;
- device-change records and detection events: 12 months;
- cases, their evidence snapshots and appeals: 12 months after the case is closed, and until it is closed if it is still open;
- records of the build files issued to your account: 12 months after the file was last fetched;
- your settings: for the life of the account, with each module keeping its last five versions; deleting a profile deletes its settings, and closing the account deletes them all;
- bot-check challenges: minutes, then deleted automatically;
- code-audit challenges (random region hashes of the file you were given): about two minutes, then deleted automatically;
- email codes: 10 minutes, or until used, and removed shortly afterwards;
- security, delivery, and integrity records (logins, downloads, resets, integrity reports with their diagnostics, and username changes): 12 months, then deleted automatically. If one is needed for a specific legal claim, we keep a copy of that record until the claim is resolved;
- signup location checks: 12 months;
- payment and tax records: 7 years, as Swedish accounting law requires, or 10 years for EU VAT records where those apply;
- profile picture: until you remove it or close your account, then deleted from our database at once;
- username history: 12 months after each change;
- support correspondence: 24 months after the matter closes.
If you ask us to close your account, we delete or anonymize the data above without undue delay, except where we are required or permitted to keep it, for example tax records, or the minimal hardware hashes needed to prevent abuse of the same machine. To ask, email legal@pluto.lgbt.
5. who receives your data
infrastructure providers. The site and the licensing service run on infrastructure in the EEA (Sweden), and email is relayed from infrastructure in the EEA (Germany). They act as processors on our documented instructions, under confidentiality and purpose limits.
payment and cryptocurrency processors. They act as processors for processing payments, and for some fraud-prevention and legal-compliance steps they act as independent controllers. Each publishes its own privacy notice, which also applies to you when you pay.
discord. If you contact us on Discord, Discord receives whatever you post there and acts as an independent controller for its own platform. If you never use Discord, we send nothing to it.
nothing else on this website. Our typefaces are served from our own servers, and we do not load fonts, analytics, advertising, or tracking scripts from anyone else.
Apart from that, we disclose personal data only: to processors as described; where valid, binding legal process or applicable law requires it, after checking its validity and scope and telling you unless we are forbidden to; to establish, exercise, or defend a legal claim; or in connection with a merger, acquisition, or asset sale, with protection continuing under this policy.
6. your rights
Under the GDPR and UK GDPR, and to the extent equivalent rights apply under laws including the CCPA/CPRA (California), PIPEDA (Canada), and comparable regimes, you may ask us for access to, correction of, portability of, restriction of, and erasure of your personal data, and you may object to processing based on legitimate interests. Send the request to legal@pluto.lgbt. Requests can also be made through Discord, but email is sufficient and no Discord account is required. We verify identity in proportion to how sensitive the request is, and we respond within one month, extendable by two months for complex requests with notice.
Some decisions are made automatically, for example when a machine binding does not match and a login is refused, when a second session is refused while one is live, when a build is revoked, or when your client reports a definite integrity failure and your license is suspended pending review. A suspension is not a ban: a person reviews the case, and you can appeal from your dashboard or ask for a human review of any of these at legal@pluto.lgbt, quoting the reference you were shown, and we will provide one. You can complain to your supervisory authority at any time, without contacting us first. In Sweden that is the IMY (Integritetsskyddsmyndigheten). Erasing data that an active license depends on ends the license.
7. transfers outside the EEA
Our infrastructure is in the EEA. Recipients outside the EEA include Discord (United States) and payment and cryptocurrency processors operating in several countries. Where personal data reaches a country without an adequacy decision, we rely on standard contractual clauses or another lawful transfer mechanism, and we can describe the mechanism in use on request to legal@pluto.lgbt, with security-sensitive detail redacted.
8. security and breach notification
Data is protected with TLS 1.3 in transit. At rest, passwords are protected with Argon2id, a deliberately slow and memory-hard algorithm; hardware and IP identifiers are protected with keyed HMAC-SHA256 digests, which are not slow by design because they are not password hashes. Session tokens are short-lived with rotating refresh, reused refresh tokens revoke the whole session family, downloads are tied to single-use launch tickets, each launch signs its requests with a key that exists only in that launch's memory, release artifacts are signed by per-channel keys, and the launcher stores session material in your operating system keychain where available. Access is limited to what each task needs. These measures cannot eliminate all security risks.
If we discover a personal-data breach, we notify the competent supervisory authority within 72 hours of becoming aware of it unless it is unlikely to result in a risk to your rights and freedoms, and we notify affected people without undue delay where the risk is high. Suspected security issues can be reported to legal@pluto.lgbt at any time.
9. children
pluto is not directed at children, and you must be at least 18 to hold an account or buy anything. If we learn an account is held by someone under 18, we close it and delete its personal data, except where retention is legally required. We do not knowingly collect data from children.
10. data stored on your device
The launcher stores a session token in your operating system keychain where available, and otherwise in a local file, plus cached build manifests and signing keys, your username, and the short-lived launch ticket for the current session. For each launch the client generates a signing key that is kept only in memory and never written to disk. The client extracts build files to a temporary folder and removes them on exit or when enforcement stops it, and it can write a snapshot of its own interface to your game folder. Clearing the application data removes all of it. Server-side copies expire or can be revoked as described above. This website uses one cookie, the log-in cookie described in section 1, one plain note in local storage that you were logged in, and, while you log in, a note in this tab (session storage) of the username you typed and that a code was sent, so a refresh does not lose your place. That note never holds your password and goes when you finish or close the tab. It uses no cross-site tracking.
11. captcha checks
Registration, login under attack, and password resets on this site are guarded by pluto captcha: a memory-hard proof of work solved in your browser, plus counts of ordinary interaction, meaning the number of pointer samples, key presses and clicks or taps, changes in pointer direction, a coarse size bucket for the area you moved over, the time between your first and last input, and the moment of your first input. Pointer positions are rounded to a coarse grid in your browser and immediately reduced to those counts, then discarded: no raw coordinates and no key values are sent. The signals are used only to detect automated abuse. We do not build biometric templates and do not try to identify you from them. Logging in to the launcher under attack uses the same proof of work, solved by the launcher on your computer, and sends no interaction counts at all. Challenges expire within minutes, are single-use, and the interaction record is checked in memory at the moment it is submitted and never written to the database. Each challenge stores a keyed hash of the network address that requested it until the challenge expires; expired challenges are removed on the next challenge request. We also keep keyed hashes of email addresses and send timestamps to enforce a rolling 24-hour verification-email limit. These entries are removed after that window on the next email request. The legal basis is performing the contract and our legitimate interest in preventing automated abuse, as described in section 2.
12. changes to this policy
Material changes are announced in the Discord and emailed to the address on your account at least 14 days before taking effect. Continued use after the effective date means you accept the change. Where the law requires fresh consent for a new purpose, we ask for it before we start that processing.
13. how to reach us
Privacy requests, questions, and complaints go to legal@pluto.lgbt. General and billing questions go to contact@pluto.lgbt. We monitor both monday to friday, 09:00 to 18:00 CET, and aim to reply within two business days. If you are unhappy with our answer, you can complain to your supervisory authority.