Privacy Policy

What Valley Client does with your data, in plain language, and what we never do with it.

General information

This Privacy Policy explains what personal data Valley Client collects when you use the Valley Client launcher, the Valley Client modification for Minecraft: Java Edition, and our website (together, the Services), why we collect it, who we share it with, and the rights you have over it.

Valley Client is the data controller for the processing described here. Wherever this policy says “we”, “us” or “our”, it means Valley Client. Our contact details are in the last chapter.

This policy sits alongside our Terms of Service, which govern your use of the Services. Words defined in the Terms carry the same meaning here.

The short version: we collect what we need to run the Services, including your account, what you bought, and enough technical data to fix crashes. We do not sell your personal data, and we do not run targeted advertising.

What we collect

We collect only what a category below describes. Some of it you give us directly; some is produced by the Services as you use them.

DataWhy we process it
Account data: your Minecraft UUID and username, your email address, and the Valley Client account you sign in with.To create and run your account, to sign you in, to apply what you own, and to contact you about the Services.
Purchase records: what you bought, when, the amount, and the state of a Valley+ subscription. Card details go to our payment provider, never to us.To give you what you paid for, to handle refunds and chargebacks, and to keep the accounting records the law requires.
Cosmetic and profile settings: the capes, cosmetics and preferences applied to your character.To render your character to you and to other players on Valley.
Technical and diagnostic data: client and launcher version, operating system, Java version, hardware class, crash reports and error logs.To keep the Services working across versions and hardware, and to find and fix crashes.
Usage data: which features and mods you enable, session length, and how you move through the launcher.To understand which parts of the client are worth building on, in aggregate.
Connection data: your IP address and the approximate region derived from it.To deliver the Services, route you to a nearby server, and defend against abuse and denial-of-service attacks.
Voice chat audio: what you say while voice chat is active.To transmit your voice to the players you are speaking to. Audio is relayed, not recorded. See the voice chat chapter.
Support and community messages: what you send us by email, through a ticket, or in our Discord, including your Discord handle.To answer you, and to keep a record of what was reported and how it was resolved.
Website data: pages visited and referrer, collected in aggregate.To see which pages are useful. See the cookies chapter for what is and is not set.

We do not ask for and do not want special category data, anything revealing health, beliefs, ethnicity, political opinions or sexual orientation. Please do not send it to us.

How we use your data

We use personal data to operate, maintain and improve the Services: to authenticate you, to apply your purchases and cosmetics, to answer your questions, to send service messages such as a receipt or a security notice, and to investigate breaches of our Terms.

We also use aggregated or anonymised data (figures that can no longer be linked to you) to measure how the Services perform and to decide what to build next. Aggregated data is not personal data, and this policy does not restrict how we use it.

What we do not do

  • We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
  • We do not run targeted advertising inside the client or on our website.
  • We do not make decisions about you by automated means alone that would have a legal or similarly significant effect on you.
  • We do not read the content of your private conversations on third-party servers.

Voice chat

When voice chat is active, your microphone audio is transmitted through our relay to the players entitled to hear it. Audio is processed in transit and is not recorded, stored or used to train anything.

We keep technical metadata about a voice session (that it happened, when, for how long, and the accounts involved) so that we can investigate abuse reports and keep the relay working. We do not keep the audio itself.

Anything you say on voice chat can be heard, and can be recorded, by the other players present. Treat it as a public space: do not read out an address, a payment detail or a password.

Who we share data with

We share personal data only where it is needed for a purpose in this policy, and only with recipients bound to protect it. We do not sell it.

  • Mojang Studios and Microsoft: to authenticate your Minecraft account. This is what lets you sign in and play, and it is governed by their own privacy terms.
  • Our payment provider: to take a payment and handle refunds and chargebacks. They receive your payment details directly; we receive only the record of the transaction.
  • Hosting, storage and content delivery providers: the infrastructure the Services run on.
  • Error reporting and analytics providers: to collect crash reports and aggregate usage figures.
  • Communication tools: the email and ticketing services we answer you with, and Discord where you contact us there.
  • Professional advisers and authorities: where we are required to disclose data by law, or where we need to establish or defend a legal claim.
  • A buyer or successor: if the Services are sold or merged, in which case we will tell you before your data becomes subject to a different policy.

Each provider acts on our instructions as a processor, under a written agreement that limits what they may do with the data.

Servers, mods and other people's software

When you join a Minecraft server, you connect to a system we do not operate. That server can see your IP address, your username and what you do while you are connected, and it handles that data under its own rules. The same applies to mods and resource packs you install from third parties.

We do not control and are not responsible for the privacy practices of servers, mod authors, or any site we link to. Read their policies before you trust them with anything.

Cookies and similar technologies

Our website uses the minimum storage it needs to work. That includes remembering whether you chose the light or dark theme, which is kept in your browser's local storage and never sent to us.

Where we use analytics, it is configured to measure pages in aggregate rather than to follow you between sites. If we ever introduce cookies that are not strictly necessary, we will ask for your consent first and give you a way to withdraw it.

You can clear or block storage in your browser settings. Blocking it may mean the site forgets your theme, but nothing else will break.

Children

The Services are not directed at children under 13, and we do not knowingly collect personal data from them. In some countries the minimum age of digital consent is higher (up to 16), and the higher age applies where it does.

If you are a parent or guardian and believe a child in your care has given us personal data, write to privacy@valleyclient.com and we will delete it and close the account.

How long we keep it

We keep personal data only as long as we need it for the purpose we collected it for, then delete it or anonymise it.

  • Account data: for as long as your account exists, and for a short grace period afterwards so an accidental deletion can be undone.
  • Purchase records: for as long as tax and accounting law requires, typically five years, even after your account is closed.
  • Crash reports and diagnostic logs: normally up to 90 days.
  • Connection logs: normally up to 30 days, longer where we are investigating an incident.
  • Support messages: for up to two years, so we have the history if you write again.
  • Voice audio: never stored.

Where we need to keep a record of an enforcement action, for example that an account was banned, we keep the minimum needed to make the ban effective.

Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls that limit who on the team can reach what, and separation of production systems from everything else.

No system is perfectly secure, and we cannot guarantee absolute security. Please use a unique password, enable two-factor authentication on your Microsoft account, and tell us as soon as you think someone else has access to yours.

If a breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority, and you, within the time the law requires.

International transfers

We are based in the European Economic Area, and we prefer providers who host there. Some of our providers operate elsewhere, which means your personal data may be transferred outside the EEA or the UK.

Where that happens, we rely on a lawful transfer mechanism: an adequacy decision for the destination country, or the European Commission's Standard Contractual Clauses together with any additional safeguards the transfer needs. You can ask us for details of the mechanism used for a particular provider.

Your rights

Depending on where you live, you have some or all of the following rights over your personal data. They are free to exercise, and using one will never cost you access to the Services.

  • Access: a copy of the personal data we hold about you, and an explanation of what we do with it.
  • Rectification: correction of data that is wrong or incomplete.
  • Erasure: ask us to delete your data, and we will where we no longer have a reason to keep it.
  • Restriction: a pause on processing while a dispute about accuracy or lawfulness is resolved.
  • Portability: the data you gave us, in a structured, machine-readable format, or sent to another provider.
  • Objection: to processing based on a legitimate interest, including a general objection to profiling.
  • Withdrawal of consent: at any time, where consent is what we relied on.
  • Complaint: to your local data protection authority. In Denmark that is Datatilsynet.

How to make a request

Write to privacy@valleyclient.com from the email address on your account, or ask us through our support page. Tell us which right you want to use and what data it concerns; a specific request is faster to answer than a general one.

We answer within one month. If a request is complex, or if you have made several, we may extend that by up to two further months and will tell you why. We may ask you to confirm your identity before we act, so that nobody can use these rights to reach someone else's data.

If we refuse a request, we will explain why and tell you how to challenge it.

Regional rights

EEA and United Kingdom

The rights above are your GDPR and UK GDPR rights. You may also lodge a complaint with a supervisory authority in the country where you live or work, or where you believe an infringement took place.

United States

If you live in a US state with a comprehensive privacy law (such as California, Colorado, Connecticut, Virginia, Texas or Oregon), you have rights to know, to correct, to delete, and to opt out of the sale or sharing of your personal information and of targeted advertising.

We do not sell personal information and we do not process it for targeted advertising or cross-context behavioural advertising, so there is nothing to opt out of. You can still exercise your other rights using the process in the previous chapter, and you may designate an authorised agent to do it for you.

We will not discriminate against you for exercising any of these rights.

Changes to this policy

We may update this policy as the Services change or the law does. The revised version is posted on this page with a new “last updated” date, and takes effect when it is posted.

Where a change materially affects how we handle your personal data, we will make a reasonable effort to tell you in advance (in the launcher, by email, or in our Discord) and, where the law requires it, ask for your consent.

Contact us

For anything in this policy, including a request about your rights, write to privacy@valleyclient.com. For help with the client itself, our support page and our Discord will get you an answer faster.

The data controller is Valley Client. If you are not satisfied with our answer, you may complain to your local data protection authority; in Denmark that is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby.