Legal

Privacy policy

Last updated 18 September 2026

This policy covers the Xol launcher, the Xol client that runs inside Minecraft, the Xol update service, and this website. Xol is an independent project run by an individual developer (“Xol”, “we”). It is written to be read: if something is unclear, ask at hello@xol.dev.

Summary. No advertising, no tracking, no analytics scripts, nothing sold or shared. Your Microsoft and Minecraft credentials stay on your computer. The launcher talks to the Xol service only to check for updates and notices, and sends a crash report only if you have switched that on.

Microsoft account sign-in

Sign-in happens on Microsoft's website in your own browser. Xol never receives your password. Xol requests two scopes, XboxLive.signin and offline_access, and uses the resulting tokens only to confirm that your account owns Minecraft: Java Edition, to read your Minecraft username and UUID, and to start the game so you can join servers.

Tokens, your username and your UUID are stored only on your device, encrypted by the operating system's secure store (Keychain on macOS, DPAPI on Windows). They are never sent to Xol, never logged, and never included in support files or crash reports. Removing the account in Xol deletes them. The full flow is described on the sign-in page.

When you sign in, your computer talks directly to Microsoft, Xbox Live and Minecraft Services. Their handling of your data is covered by the Microsoft Privacy Statement.

What the launcher sends to the Xol service

WhenWhat is sentWhy
Checking for updates, profile data and noticesYour Xol access key, launcher version, operating system (Windows or macOS) and CPU architectureTo offer the right installer and to confirm the key is valid
Downloading an updateA short-lived download tokenTo deliver the installer
Crash report, only if you enabled itLauncher version, OS, architecture, profile and Minecraft version, a short summary, and a redacted log excerptTo find and fix crashes

Crash reporting is off by default. When it is on, the report is redacted on your computer first: tokens, session strings, access keys, e-mail addresses, IP addresses and home-folder paths are removed, chat lines are dropped, and you can preview exactly what will be sent. The server applies the same redaction again on arrival. Reports are deleted after 30 days.

As with any internet service, the server sees the IP address a request comes from. Server logs are kept for 14 days for security and abuse prevention and are not used for anything else.

The Xol access key is a random string issued to testers. It is not linked to your Microsoft or Minecraft account by the launcher.

What the client does inside the game

The Xol client makes no network connections of its own. It reads local game state to draw the HUD and stores its settings in your instance folder. When you join a server it sends the standard client-brand label with the text Xol, the same message every Minecraft client sends with its own name.

Other connections the launcher makes

  • Mojang / Microsoft download servers, for the game, its libraries, assets and Java runtime.
  • Minecraft Forge and Modrinth, for the pinned, checksum-verified components some profiles need.

These are plain file downloads. Xol sends them nothing beyond what any download involves (your IP address and a user-agent).

This website

This site sets no cookies for visitors and loads no third-party scripts, fonts or trackers. The web server keeps standard access logs (IP address, time, page, browser user-agent) for 14 days for security, and page views are counted from those same logs: no script runs in your browser, no visitor profile is built, and nothing outlives the 14 days. The owner-only administration area uses a sign-in cookie, which visitors never receive. If you email us, we keep the conversation for as long as needed to help you.

Sharing

We do not sell, rent or share personal data. We would disclose data only if required by law, and the data described above is all there would be.

Your choices

  • Remove your account in Xol at any time; revoke Xol's access at account.microsoft.com.
  • Leave crash reporting off, or switch it off again in Settings ▸ Support.
  • Ask for a copy or deletion of anything tied to your access key or email address by writing to hello@xol.dev. We answer within 30 days.

Children

Xol is not directed at children under 13 and does not knowingly collect their data. Microsoft's own family settings govern whether a child account can sign in to third-party applications.

Changes

If this policy changes in a way that matters, the date above changes and the change is announced in the launcher. Earlier versions are available on request.