Legal

Privacy Policy

Last updated: August 5, 2026.

Introduction

This Privacy Policy explains how OnMe ("OnMe", "we", "us") collects, uses, discloses, and safeguards information when you use the OnMe website, dashboard, worker infrastructure, and related services (together, the "Service"). It applies to visitors, registered users, workspace members, and public profile page visitors. By using the Service you acknowledge the practices described here. If you do not agree with this policy, please do not use the Service.

OnMe is a fleet-management platform for Minecraft: Java Edition accounts and automated bot sessions, including connected-account authentication, server profiles, bot scheduling and automation, proxy/IP routing configuration, team workspaces, and an optional customizable public profile page. This policy is written to reflect exactly what the Service does, including the more sensitive features such as Microsoft/Xbox authentication cookie import and proxy-based connection routing, so you can make an informed decision before connecting any account.

Contact

OnMe acts as the data controller for the personal data described in this policy. For privacy requests, data subject rights requests, account questions, or purchase support, contact us at support@onme.lol. We aim to respond to legitimate privacy requests within a reasonable time and, where a statutory deadline applies (for example under the GDPR), within that deadline.

Data we collect

Account and authentication data. Email address, username, password hash (never the plaintext password), two-factor authentication (TOTP) configuration, selected avatar, email verification status, session and login metadata, and security logs (e.g. sign-in timestamps, IP address at login, device/browser information used for fraud and abuse prevention).

Billing data. Subscription plan, plan status (active, past-due, canceled), Stripe customer ID and checkout/session references, purchase history, and invoice metadata. OnMe does not receive or store full payment card numbers — card data is handled directly by Stripe.

Minecraft and Microsoft account data. Connected Minecraft Java usernames and UUIDs, connection type (Microsoft OAuth sign-in or imported authentication cookies), encrypted authentication credentials (Microsoft/Xbox token cache or imported session cookie material), account status (online, connected, error, banned), tags/labels you assign, skin data, and username-change history you initiate through the Service. See "Connected Microsoft and Minecraft accounts" below for detail on how cookie import and export specifically work.

Bot, server, and automation data. Server profiles you save (host, port, Minecraft version), bot session state and health, reconnect and health-check history, chat/activity logs generated by bot sessions, automation and scheduling rules (auto-connect, keep-connected, session duration limits, weekly connect/disconnect schedules), and anti-AFK/anti-cheat/hub-navigation configuration.

Proxy and connection routing data. Proxy configuration you select or supply (including proxy provider, connection mode, country filters, and rotation history), and, where you use OnMe's integrated proxy provider, usage of that integration on your behalf.

Team and workspace data. Workspace name, member list, roles (owner, admin, member), invite records (inviter, invitee email, status), and workspace-level plan/seat information.

Public profile page and media. If you use the customizable public profile page feature, the content you configure (display name, slug, bio, links, badges, colors, layout, fonts, animations) and any media you upload (avatar, banner, background images or videos, custom audio), stored as described in "Sharing & service providers" below.

Third-party connection data. If you connect Discord to your profile, the Discord profile fields described in "Discord" below. If you configure outbound webhooks, the destination URL you provide (Discord or Telegram).

Communications and support data. Messages you send to support@onme.lol, notification preferences, and records of support interactions.

Technical and usage data. IP address, browser and device information, pages visited, timestamps, and diagnostic/error logs generated by normal operation of the web app and worker infrastructure, used for reliability, security, and abuse prevention.

Sources of data

We collect data directly from you (account registration, dashboard configuration, uploads, support messages), automatically through your use of the Service (technical and log data), and from third parties you choose to connect (Microsoft/Xbox for Minecraft account verification, Discord for profile identity, Stripe for payment confirmation). We do not purchase personal data about you from data brokers.

Where the GDPR or a similar law applies, we rely on the following legal bases: performance of a contract (operating your account, dashboard, bot automation, billing, and workspace features you request), legitimate interests (securing the Service, preventing fraud and abuse, maintaining logs necessary for reliability, and improving the Service), consent (non-essential cookies, and connecting optional third-party accounts such as Discord), and legal obligation (retaining billing and tax records, responding to lawful requests). You may withdraw consent-based processing at any time without affecting the lawfulness of processing carried out before withdrawal.

How we use data

  • Create, verify, and authenticate accounts, including two-factor authentication.
  • Operate the dashboard, run worker jobs, and maintain bot sessions and automation schedules you configure.
  • Connect and verify authorized Minecraft and Microsoft accounts, and route bot sessions through the connection settings you choose.
  • Process payments, manage subscriptions, and provide billing support through Stripe.
  • Send transactional email (verification, password reset, billing, team invites, webhook-adjacent notifications).
  • Detect and prevent abuse, fraud, unauthorized access, and violations of these policies or of Minecraft/Microsoft/Discord terms.
  • Debug reliability issues, monitor infrastructure health, and maintain security logs.
  • Provide team/workspace collaboration features to the members you invite.
  • Host and serve the public profile page and media you choose to publish.
  • Comply with legal obligations and respond to lawful requests from authorities.

We do not sell your personal data, and we do not use your Minecraft account data, chat logs, or bot activity data to train third-party advertising or generative-AI models.

Cookies and similar technologies

The OnMe website uses a cookie/local-storage consent banner with three categories: Necessary (required for login, session management, and core site functionality — cannot be disabled), Functional (remembers preferences such as dashboard layout), and Analytics (intended to help us understand aggregate usage of the Service). Your choice is stored in your browser's local storage and can be changed at any time from the cookie preferences control on the site.

As of this version of the policy, OnMe does not operate a separate analytics or tracking script beyond the cookies strictly necessary to run the Service; the Analytics category exists so that if we introduce aggregate usage analytics in the future, it will only run for users who have consented, without requiring you to take further action. We will update this section if that changes.

Connected Microsoft and Minecraft accounts

OnMe supports two ways of connecting a Minecraft Java account, and you should only connect accounts you own or are expressly authorized to manage:

Microsoft sign-in. You authenticate directly with Microsoft through Microsoft's own OAuth sign-in flow. OnMe never sees or stores your Microsoft password. On success, we retrieve your Minecraft Java profile (username and UUID) from Microsoft's services and store an encrypted authentication token so the Service can maintain the bot session and automation features you configure. Tokens are refreshed automatically and can be disconnected by you at any time from the dashboard.

Authentication cookie import. As an alternative connection method, you may upload Microsoft/Xbox authentication session cookies exported from a browser where you are already signed in to your Microsoft account (as an individual file or a batch). This is not related to, and has no effect on, the cookies used on the OnMe website itself. We use the uploaded cookie material to verify, server-side, that the account is real and owns Minecraft Java, without asking for a password. The uploaded cookie material and any derived credential are encrypted at rest. If Microsoft's sign-in flow requires an interactive step, the import may be completed through an automated, secure browser session rather than by a human reviewing your credentials.

Cookie export. You may export the authentication credentials you previously imported for accounts you control, for your own backup or migration purposes, individually or in bulk. Exported files are generated on demand and are not additionally distributed by us.

You can disconnect a connected account, and request deletion of its stored credential, at any time from the dashboard or by contacting support@onme.lol.

Discord connection and webhooks

If you choose to connect Discord to your profile, OnMe requests only the identify OAuth scope from Discord — we do not request access to your servers, messages, or friends list. We use the resulting authorization once to retrieve your public Discord profile (user ID, username, display name, avatar, server tag if enabled, and public badges such as staff, partner, or Nitro tier) and store those fields so they can be displayed on your OnMe profile and account settings. The Discord access token itself is used only to make that one request and is not stored afterward. You can disconnect Discord at any time from Settings → Integrations.

Separately, you may configure outbound Discord or Telegram webhooks to receive event notifications (for example, when an account import completes or fails). These use a webhook URL you provide and control; OnMe only sends the notification payload to the destination you configured and does not otherwise exchange data with Discord or Telegram through this feature.

Proxies and IP routing

The Service lets you route Minecraft account connections through proxy configurations, including an integrated third-party proxy provider, your own custom proxy list, or a single static proxy. Where you use the integrated provider, OnMe requests proxy allocations from that provider on your behalf and records which proxy was used for which account/session for operational and support purposes. Where you supply your own proxies, we store the connection details you provide (including any credentials required to use them) in the same encrypted manner as other sensitive account data.

Proxy and IP routing features exist to give you control over how your own accounts connect to servers you are authorized to use; see "Acceptable use" in our Terms of Service for the responsibilities that come with this feature.

Workspaces and teams

If you belong to a team workspace, other members with sufficient permissions can see workspace-level information such as member list, roles, and aggregate resource counts (bots, accounts, servers), and — depending on their role — may be able to view or manage profile resources and settings within that workspace. Workspace owners and admins can invite members by email and manage roles and removals. We recommend only inviting people you trust with this level of access, and reviewing workspace membership periodically.

Sharing and service providers

We do not sell or rent your personal data. We share data only as needed to operate the Service, with providers bound by appropriate confidentiality and data-processing terms:

  • MongoDB — primary database storage for accounts, workspaces, bots, servers, and related records.
  • Stripe — payment processing, subscription billing, and the self-service billing portal.
  • Resend — transactional email delivery (verification, password reset, billing, team invites).
  • Cloudflare R2 — object storage for user-uploaded media, such as public profile page backgrounds, banners, and audio.
  • Microsoft identity platform — authentication and Minecraft Java profile verification for connected accounts.
  • Discord — OAuth identity verification for the optional profile connection, and delivery of webhook notifications you configure.
  • Telegram — delivery of webhook notifications you configure, where you choose Telegram as the destination.
  • Proxy infrastructure providers (including our integrated provider) and, where applicable, proxy providers or proxies you supply yourself — used solely to route the bot/account connections you configure.
  • Hosting and infrastructure providers for the web application and worker processes.

We may also disclose information where required by law, to enforce these policies, to protect the rights, property, or safety of OnMe, our users, or others, or in connection with a merger, acquisition, or sale of assets, subject to continued protection of your data under a policy at least as protective as this one.

International data transfers

OnMe and the service providers listed above may process data in countries other than your own, including countries that may not have data protection laws equivalent to those in your jurisdiction. Where we transfer personal data internationally, we rely on the transfer mechanisms available under applicable law (such as standard contractual clauses or an equivalent safeguard offered by the receiving provider) to protect that data.

Security

Passwords are stored as Argon2id hashes and are never stored or logged in plaintext. Sensitive imported credentials — including Microsoft/Xbox authentication tokens and imported cookie material — are encrypted at rest using AES-256-GCM. Two-factor authentication (TOTP) is available and recommended for all accounts. Access to dashboard features requires authentication, sessions use secure cookie settings where supported by your browser and our infrastructure, and administrative access to production systems is restricted to personnel who need it to operate the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to apply industry-standard safeguards proportionate to the sensitivity of the data involved.

Retention

We retain personal data for as long as your account is active or as needed to provide the Service. After account deletion, we remove or anonymize account, bot, server, and connected-credential data within a reasonable operational period, except where retention is required for billing/tax records, fraud and abuse prevention, security investigations, dispute resolution, or other legal obligations — in which case we retain only what is necessary for that purpose and for the period required by applicable law. Backups that contain deleted data are rotated out over time in the ordinary course of our backup cycle. You can request deletion at any time by contacting support@onme.lol.

Children's privacy

The Service is not directed to children and is not intended for use by anyone below the minimum age required to form a binding contract in their jurisdiction (generally 16, or 13 where local law permits with parental consent). We do not knowingly collect personal data from children below that age. If you believe a child has provided us with personal data, contact support@onme.lol and we will take appropriate action, including deletion.

Your rights

Depending on your location, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; restrict or object to certain processing; receive a portable copy of data you provided; and withdraw consent where processing is based on consent. You can exercise most of these directly in the dashboard (profile details, connected accounts, notification preferences, workspace membership, billing cancellation) or by contacting support@onme.lol for anything that isn't self-service. If you are in the European Economic Area, the United Kingdom, or another jurisdiction with a data protection authority, you also have the right to lodge a complaint with your local supervisory authority.

Automated decisions

Some abuse-prevention and reliability logic operates automatically — for example, automatically pausing or restricting a bot session that appears to breach a connected server's limits, or flagging suspicious sign-in patterns. These mechanisms are designed to protect the Service and other users; we do not use fully automated decision-making to produce legal or similarly significant effects about you (such as permanent account termination) without the ability to contact support@onme.lol for human review.

Data breaches

If we become aware of a security incident that results in unauthorized access to or disclosure of your personal data, we will investigate and, where required by applicable law, notify affected users and/or the relevant supervisory authority without undue delay.

Minecraft relationship

OnMe is not affiliated with, endorsed by, or sponsored by Mojang Studios, Microsoft, Xbox, or Minecraft. Minecraft- and Microsoft-related data is processed only to provide the account connection, automation, and compatibility features you request; references to Minecraft are used solely in a descriptive, nominative sense.

Changes

We may update this policy as the Service changes or as legal requirements evolve. Material changes will be reflected by an updated "Last updated" date at the top of this page, and where required by law, we will provide additional notice (such as email) before the change takes effect. Continued use of the Service after a change is posted means you accept the updated policy.