Last updated: 1 August 2026
Privacy notice
This notice explains how STREFA CLIENT handles account information when you use Microsoft authentication and Minecraft: Java Edition services.
Information processed
The launcher processes the Minecraft profile name, profile identifier, ownership status, profile skin information and authentication tokens required to sign in and launch the game. It does not request or collect your Microsoft password.
Authentication and storage
Authentication takes place in the system browser using OAuth 2.0 Authorization Code with PKCE and a temporary localhost callback. Refresh credentials are stored locally in Windows Credential Manager. Short-lived Xbox and Minecraft access tokens are retained only in the application process memory.
STREFA Social and friends
When you open the friends screen, the server verifies your Minecraft identity and stores your Minecraft UUID, current profile name, friend relationships, requests, blocks, last-seen time, presence and optional status message. A Minecraft access token is used only for verification and is not stored by the STREFA server. Sharing the current server is off by default.
Sharing and sale
STREFA CLIENT sends authentication data only to the Microsoft, Xbox Live and Minecraft endpoints required for sign-in, entitlement verification and profile retrieval. The project does not sell personal information.
Removing access
Removing a Microsoft account from STREFA CLIENT deletes its local credentials. The friends screen also provides a separate action that permanently deletes the STREFA Social profile, friendships, requests and blocks from the server. Microsoft consent can be revoked separately in Microsoft account settings.
Contact
Questions and privacy requests can be sent to excer1337@gmail.com.