KLP Launcher

Privacy Policy

Last updated: 11 August 2026

KLP Launcher is a desktop program that runs on your own computer. Almost everything it does — managing instances, downloading game files, launching the game — happens locally and never passes through our servers. This page states exactly what leaves your machine, where it goes, and where things are stored. Every sentence here corresponds to specific behaviour in the launcher. Should you find any statement that does not match actual behaviour, please contact us and we will correct either this page or the implementation.

Accounts and sign-in

The launcher never handles, displays or stores your Microsoft password.

Sign-in uses Microsoft's official device code flow: the launcher shows you a verification URL and a short code, and you complete the sign-in in your own browser, on Microsoft's own page. Your password never passes through any field in the launcher.

After a successful sign-in, what the launcher stores are the tokens returned by the Microsoft and Minecraft services (refresh token, access token, expiry, Xbox user id), so that you do not have to sign in again next time. If any sign-in method requires you to type a password, that password is used only for that one request to the corresponding sign-in service and is cleared from memory and from stored data as soon as the request finishes. It is never persisted and never uploaded.

Where tokens are stored

This differs by platform, and is set out below in full:

That is to say: on Windows and Linux, or whenever the portable build is used, any program able to read your data directory can read those tokens. Copying a portable folder onto removable storage carries the tokens with it. This is an inherent cost of portable mode rather than an oversight, but you should be aware of it.

In every case, these tokens are never sent to our servers. They only go to the official Microsoft, Xbox Live and Minecraft endpoints, to sign you in to the game itself.

What we do not collect

What the launcher asks our servers for

The launcher makes three kinds of request to api.klp-launcher.com. All of them fetch content downward and carry no identifying information about you:

As with any network request, our server sees your IP address while handling these. We do not use it for profiling and do not associate it with any account.

The AI assistant

The AI assistant does not go through our servers. The launcher connects directly to the model service endpoint you enter in settings, using your own API key. Conversations, logs and mod lists are never received by this project, so there is nothing for us to retain.

The trade-off is that this content does go to the model provider you chose. How they handle and retain it is governed by your agreement with them and is outside our control. The list below should therefore be read as a disclosure of what is handed to a third party.

What may be sent when you ask a question or ask it to diagnose a problem

The launcher currently performs no redaction on any of this. Logs, crash reports and paths normally contain your home directory name (for example C:\Users\YourName\…), so if your system username is your real name, it will appear verbatim in what is sent to the model provider. This is what the current implementation does, and it is stated here explicitly rather than left vague.

Where conversations are stored

Only on your own computer, under ai/sessions/ in the data directory, one file per conversation. There is no place on our servers where conversations are kept — the server has no endpoint that receives them at all.

How to disable it

The AI assistant only works once you have entered a model service endpoint, a model name and an API key in settings. Leave them empty and it cannot run, so nothing is sent. If you have already configured it and want to stop using it, clear those fields. The API key is stored in the same place as account tokens (the Keychain on macOS in installed mode, an 0600 local file otherwise); it is not written into the settings file and is not included when settings are exported.

Third-party services

The launcher contacts the following services in response to what you do. Each has its own privacy policy, in respect of which this project can give no undertaking.

Children's privacy

The launcher does not separately collect information from children and has no account system of its own. Game accounts are managed by Microsoft; parental controls and age-related rules are governed by Microsoft's policies.

Changes to this policy

When features change and data flows change, this page changes with them and the date at the top is updated. If a change ever leaves this page out of date, that is an oversight on our part; please write in so that it can be corrected.

Contact

For privacy questions, correction requests, or if you find a sentence on this page that does not match the actual implementation:
please email admin@klp-launcher.com.

← Back to home