Lumine

Last updated August 14, 2026

Privacy Policy

This policy describes what the Lumine portal at lumineproxy.org and the Lumine API collect, what stays only in your browser, what Lumine keeps server-side for security, and when data is sent to third-party providers you choose to use.

Important Microsoft account note

Microsoft OAuth credentials are encrypted and held by the Lumine API. The portal receives username-only linked account metadata and sends that username when you request friends, Realms, realm addresses, or a proxy. Device codes are temporary workflow identifiers; the account-trade flow also consumes its credential server-side.

Security-first collection

Lumine collects account, IP, device, and sign-in evidence to operate the portal, protect accounts, and fight fraud or chargebacks.

Credentials stay server-side

The API bearer is held in an encrypted HttpOnly portal session. Microsoft OAuth credentials are encrypted by the API; browser storage contains only device continuity and convenience data.

Third-party services are optional but real

If you use Google sign-in, Microsoft account linking, Stripe checkout, YouTube embeds, or social links, those providers also receive data under their own policies.

What we collect through the portal

Account and sign-in data

  • Lumine account email, password submission during sign-in or registration, and password-change or recovery requests. The portal does not store your plaintext password in browser storage.
  • Account profile and entitlement data returned to the portal, such as email verification state, whether a password exists, auth provider list, last login time, Stardust balances, daily reset timing, premium status, premium start and end timestamps, deletion markers, creation and update timestamps, and related account-security fields.
  • Recent sign-in history shown in the portal profile, including timestamp, auth method, client IP, IP source, observed request IP, user agent, opaque device or cluster ID, device match source, device risk score, and the resulting trust score or level when available.

Security and fraud-prevention data

  • Client IP address, observed upstream IP, sign-in timestamp, and user agent. A coarse IPv4 /24 or IPv6 /56 network cohort is converted to an opaque keyed hash for trust comparisons; the trust engine does not require an exact-IP match.
  • Browser and device signals used to build a fraud-prevention fingerprint: timezone, language, languages list, platform, screen size, color depth, pixel ratio, hardware concurrency, device memory, max touch points, and user agent.
  • For free-Stardust abuse prevention, complete device signals may be combined with a coarse IP network prefix and transformed server-side into an opaque keyed hash. This claim can pool the free daily allowance across repeat Lumine accounts, but it does not limit paid Stardust, memberships, or account creation.
  • Server-side authentication audit records for successful password and Google sign-ins or registrations. These records can include opaque recovery-token hashes, device/network claim hashes, trust score and level, contributing reason codes, and limited request context. Raw recovery tokens and raw browser-signal payloads are not persisted.
  • Authentication and registration rate-limit counters. When an opaque device recovery token is available, the strict auth bucket is device-based, with a looser IP safety cap for automation; clients without a device token fall back to the IP bucket. General traffic protections may still use IP addresses.
  • A server-issued access token can be bound to the opaque hash of this browser recovery token. Copying that access token to a browser that does not possess the matching recovery token will not authenticate.

Microsoft, Google, and Minecraft data

  • Google sign-in data when you choose Google auth, including the Google ID token and the email claim the portal may read from that token before forwarding it to Lumine auth routes.
  • Microsoft usernames for linked accounts and OAuth credentials encrypted server-side with authenticated encryption. Microsoft access and refresh tokens are not returned to normal browser linking, Minecraft, proxy, or account-trade flows.
  • Temporary Microsoft device authorization data for connect and account-trade flows, including the device code, user code, verification URI, expiry, and poll status. Trade credentials stay in a short-lived, user-bound server authorization until confirmed submission.
  • Minecraft friends data requested through the portal, including gamertag, XUID, online state, game title, game state, and rich presence.
  • When timed Eclipse uses free Stardust, Lumine resolves the stable Xbox XUID from the submitted Microsoft token and transforms it into an opaque keyed hash so the same Xbox identity cannot receive another free allowance through a repeat Lumine account. The raw XUID is not stored in the free-claim record.
  • Minecraft Realms data requested through the portal, including realm ID, name, state, message of the day, world type, days left, owner, slots, and resolved realm join address.

Proxy, configuration, and support data

  • Proxy targets and session data such as remote server address, realm code, realm ID, friend target, region, proxy type, connection state, assigned address, port, server code, start time, shutdown reason, shutdown error, and shutdown timestamp when returned to the portal.
  • Preferred region, selected tier, last proxy start configuration, selected proxy configuration ID, saved proxy configuration snapshots, and settings blobs used to resume or recreate portal-driven starts.
  • Resource pack metadata and uploaded resource pack content stored locally in your browser when you use the resources flow, including file name, size, type, add time, and data payload.
  • Support or legal emails you send to Lumine, including your contact details and the contents of your message.
  • Password-reset and account-deletion email token flows used from the portal, including the one-time tokens you open and submit and the exact deletion confirmation phrase you type.

Exact browser storage used by the portal

The portal uses an HttpOnly cookie for authentication and uses JavaScript-visible cookies, local storage, session storage, and IndexedDB only for device continuity, temporary workflow identifiers, proxy convenience, and account recovery flows.

Cookies set by the portal

__Host-lumine-session

Production-only encrypted, HttpOnly, Secure, SameSite=Strict Lumine API session. Maximum age: 24 hours; unavailable to browser JavaScript.

lumine_device_recovery

Browser recovery token used to reconnect a browser to the same device identity. Max age: 365 days.

lumine_proxy_configs

Saved proxy configuration list and settings snapshots stored in a browser cookie. Default max age: 365 days.

lumine_proxy_config_selected

Selected proxy configuration ID stored in a browser cookie. Default max age: 365 days.

Local storage keys

lumine_device_recovery

Copy of the browser recovery token used for device identity continuity until you clear browser storage.

lumine_xbl_device_code

Temporary Microsoft device-code auth cache kept until the code expires or is cleared.

lumine_account_trade_xbl_device_code

Temporary account-trade device-code authorization identifier kept until submission, expiry, or clearing. It is not an OAuth access or refresh token.

resourcePacks

Locally saved resource pack metadata and payloads you upload in the portal until you clear them.

lastProxyStart

Last proxy start settings such as account, proxy type, target, and tier until you clear it.

lumine_preferred_region

Preferred proxy region selection until you clear it.

lumine:onboarding-finished

Boolean onboarding completion marker until you clear it.

Session storage keys

lumine_chunk_reload_attempt

Single-session marker used to recover from chunk-load errors.

lumine_password_reset_token

Password-reset token held in session storage after you open a reset link.

lumine_delete_account_token

Account-deletion token held in session storage after you open a delete link.

IndexedDB stores

lumine-device-context / markers / recovery-token

Recovery token mirror used for durable client device identity.

How we use information

  • Create, authenticate, secure, and recover Lumine accounts.
  • Operate Microsoft-connected and Minecraft-connected features such as friends, Realms, realm join address resolution, and account linking.
  • Start, resume, stop, and manage proxies and related dashboard state.
  • Link purchases and premium windows to the correct Lumine account, manage billing redirects, and respond to disputes or chargebacks.
  • Prevent fraud, enforce browser or device restrictions, investigate abuse, and protect the service and other users.
  • Respond to support, policy, security, and legal requests.

Automated trust scoring and account-abuse decisions

When you register or sign in, the Lumine API calculates a rules-based trust score from 0 to 100. This is security and fraud-prevention profiling, not advertising profiling. The calculation uses a combination of signals rather than treating an IP address as proof of identity.

Signals can include whether an opaque browser recovery identifier is present and familiar to the account, whether the browser/device signal set is complete, prior devices and coarse network cohorts used by the account, browser-family familiarity, account age, verified Google authentication, recent device velocity, device or device/network reuse across Lumine accounts, and an upstream device-risk value when a trusted Lumine service supplies one. A familiar device is strong positive evidence. An IP or network match is only a supporting signal. Device reuse across accounts and unusually fast device changes are stronger negative evidence.

The score is assigned a trusted, monitored, or restricted level. Registration itself is not denied solely because of this score. The level controls session lifetime, and only trusted sessions can start Eclipse. A monitored or restricted user can sign in from a familiar device, use their verified Google account, or ask support for review; Free proxies remain available throughout. Free Eclipse allowances are also pooled through opaque Xbox and device/network claimant hashes so opening a repeat Lumine account does not create another copy of the same promotion.

These rules can produce false positives on shared computers or unusual device setups. To ask for a human review, correction, or explanation of a trust-related restriction, contact [email protected]. Include the request ID shown with the error when available. Support can review the recorded signals and account history; after human review, support can set a temporary trusted override that expires within 30 days and takes effect when you sign in again. A device-claim exemption or trust override does not remove the separate Xbox or per-account promotional limit.

When information is shared

We do not sell or rent your personal information. We share information only as needed to run Lumine, complete features you request, process billing you choose to start, maintain security, or comply with legal obligations.

  • With Lumine API routes and infrastructure when the portal needs to complete an account, security, billing-linking, or proxy action you requested.
  • With Google if you use Google sign-in.
  • With Microsoft and Xbox-linked flows if you use Microsoft account connection, friends, Realms, or related Minecraft features.
  • With Stripe if you open checkout or billing management for Stardust or Lumine Eclipse.
  • With YouTube if you load the embedded tutorial or click through to YouTube.
  • With Discord, TikTok, Instagram, or other social services only if you choose to open those links.
  • With service providers, hosts, CDNs, or legal authorities when reasonably necessary for security, abuse prevention, legal compliance, chargeback defense, or protection of users and the service.

Retention and your choices

Cookie retention and browser-storage behavior are listed above. Some items expire automatically, while others stay until you clear browser storage, overwrite them, disconnect an account, or remove saved portal data.

The separate successful-auth audit collection is configured to expire records after 90 days. The user record keeps only the 20 most recent successful sign-in events until they are displaced by newer events or the account is deleted. Opaque free-allowance claim documents expire after 45 days. Account-level opaque device bindings and claimant IDs remain with the account until deletion unless support corrects them. Support trust overrides expire within 30 days; their review timestamps and note remain with the account until cleared or account deletion. Retired exact-IP account-lock fields are erased during API database setup. In-memory rate-limit counters expire after their configured windows, which are generally minutes rather than days.

You can review recent sign-ins in the dashboard, request password reset emails, request account deletion, clear unlink server-held Microsoft accounts from the portal flows that manage them, remove saved resource packs or proxy configurations, or contact Lumine for support or policy requests.

Do Not Track, children, and third-party tracking

The portal does not currently change its behavior in response to a browser "Do Not Track" signal. The portal is primarily built around first-party account, proxy, and security features rather than third-party tracking, but third-party services you choose to load or open may still collect data under their own policies.

Lumine is not intended for children under 13, and we do not knowingly collect personal information from children under 13 through the portal. If we learn that we have done so, we will take reasonable steps to remove that data.

Contact

Support questions can be sent to [email protected]. Policy or legal questions can be sent to [email protected].