Skip to content
Valen
Pricing Docs Changelog Download
Get Valen
Pricing Docs Changelog Download Get Valen
Legal

Privacy Policy

What we collect, who else sees it, how long we keep it.

Last updated: 29 July 2026

On this page
  1. 1. Summary
  2. 2. Who is responsible
  3. 3. What we collect
  4. 4. Hardware identifiers
  5. 5. What we do not collect
  6. 6. Why we collect it
  7. 7. Payments
  8. 8. Who else sees it
  9. 9. Retention
  10. 10. Cookies
  11. 11. Your rights
  12. 12. Security
  13. 13. Children
  14. 14. Changes
  15. 15. Contact

1. Summary

A licence key, a hashed hardware identifier, order and consent records, and whatever Stripe needs to process payment. No advertising, no analytics, no trackers, and no reading of your files, chat or keystrokes.

2. Who is responsible

Valen is the controller of the data described here. Contact: support@valen.cx.

3. What we collect

When you buy

  • Your email address, collected by Stripe at checkout.
  • A payment reference. We never receive or store your card number.
  • The order record: plan, amount, currency, time, and the key issued for it.
  • The checkout policy version, consent timestamp, terms acceptance and immediate-supply acknowledgement recorded with the order.

When you use the client

  • Your licence key, sent on every launch to authenticate you.
  • A SHA-256 hash of your hardware identifier — see section 4.
  • Security records such as IP address, timestamp, route and outcome, with a masked licence reference rather than the full key.

If you ask to be told about the launch

  • Your email address, and the date you gave it. Nothing else — no name, no IP address, no record of what you looked at. It is used for exactly one message telling you Valen is on sale, and then the address is deleted. It is never sold, never shared, and never added to a newsletter. Ask at support@valen.cx and we will remove it sooner.

When you contact support

We receive the email address, message, attachments and any order, licence, device or troubleshooting details you choose to include. We use them to answer support and refund requests, investigate security issues and handle disputes. We do not need passwords, Minecraft session tokens or full payment-card numbers.

4. Hardware identifiers

The loader reads a device value so one key runs on one machine. On Windows it reads the system MachineGuid; on other supported systems it uses a composite of account and system details. The loader hashes that value with SHA-256 before sending it, and our server hashes the received value with SHA-256 again before storing or comparing it. No separate salt is used. The raw system value is not stored in our database or logs.

The resulting binding hash is linked to your licence and kept for as long as the licence is bound to that machine. A hash is a persistent identifier here, not anonymous data, so it may be personal data under applicable law. Hardware changes, an operating-system reinstall, a virtual machine, or a different operating system can produce a different value. Everything else identifying about an application request is deleted within 24 hours, subject to the limits in section 9.

5. What we do not collect

The client sends a licence key and a hardware identifier. That is all. It does not:

  • read, upload or scan files on your computer;
  • record keystrokes, screenshots or microphone input;
  • collect your Minecraft credentials or session token;
  • report the servers you play on, your chat, or your gameplay;
  • track you across other websites.

6. Why we collect it

  • To deliver what you paid for — issuing and authenticating your key. Legal basis: performance of our contract.
  • To stop piracy and abuse — machine binding, ban enforcement, rate limiting and service security. Legal basis: legitimate interest. We use a persistent binding because a licence key alone cannot reliably prevent sharing. The safeguards are that the raw device value is not retained, the stored value is hashed, logs use masked references, and account decisions can be reviewed through support. You can object to this processing by email, although we may then be unable to run a machine-bound licence.
  • To support you — answering tickets, resetting bindings. Legal basis: performance of our contract.
  • To record checkout choices — the policy version, terms acceptance and immediate-supply acknowledgement attached to an order. Legal basis: performance of our contract and, where required, consent or another legal obligation.
  • To keep books — transaction records for tax. Legal basis: legal obligation.
  • To tell you it launched — the one email you asked for, if you left an address before release. Legal basis: consent, which you gave by submitting the form and can withdraw at any time.

7. Payments and Stripe

Checkout is handled by Stripe. Card details go directly to them and never reach our servers. Stripe acts as an independent controller for the data it collects, under its own privacy policy.

We do not control or have complete visibility into what Stripe collects or how long it keeps it. Its policy and terms govern that processing. Our service receives the email, payment reference, plan, amount, currency, purchase time, payment status and checkout consent fields needed to match and fulfil an order. The processor may also collect names, billing details, tax information, payment-method, device and fraud-prevention data; this service does not write those extra fields to the licence database. We never receive or store your full card number.

For what Stripe does with your data, see their Privacy Policy and their Terms of Service.

8. Who else sees it

We do not sell personal data or share it for advertising. Our processors are:

  • Stripe — payment processing and processor-hosted receipts or invoices.
  • Railway — runs the API and website, and therefore stores the database and logs.
  • The support mailbox provider — receives messages sent to support.

We also disclose data where legally required, or where necessary to bring or defend a legal claim, including a payment dispute.

9. Retention

  • Application request records — identifying rate-limit and request data under our control is deleted within 24 hours. Hosting, network, security and backup logs may have separate retention periods set by their providers, and may remain where needed for security or law.
  • Hardware identifier hash — for as long as the licence is bound to that machine.
  • Licence and consent records (key, order, policy version, consent, ban status, expiry and creation date) — for the life of the licence, and afterwards where needed to enforce a ban, handle a dispute or meet a legal obligation.
  • Order and payment records — as long as tax law requires, typically seven years.
  • Launch notification addresses — until the launch email is sent, then deleted.
  • Support correspondence — while needed to resolve the request, then deleted when no longer needed, subject to legal, security and dispute records.

10. Cookies

This site sets no tracking or advertising cookies and runs no analytics. The only thing stored in your browser is a valen-theme entry remembering light or dark. Stripe sets its own cookies on its checkout page.

11. Your rights

If you are in the UK or EEA, and in many other places, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its use, or port it elsewhere. Email support@valen.cx and state whether the request is an access, correction, deletion, restriction, objection or portability request. We normally respond within one month where that legal deadline applies; the deadline may be extended by up to two further months for complex or numerous requests where the law permits it.

We may ask for enough information to verify the request, such as the checkout email, order reference or licence key. Do not send a password, Minecraft session token or full payment-card number. Deleting your licence record ends your licence — we cannot authenticate a key we no longer hold. Banned keys, consent evidence and completed transactions may be retained after a deletion request to enforce bans, resolve disputes and meet tax or other legal obligations.

You may complain to your local data protection authority.

12. Security

Traffic between the client, the site and our servers is encrypted in transit, and the client payload is encrypted on top of that. Access to the licensing database is limited to the operators of the service. To report a suspected security issue, email support@valen.cx with “Security report” in the subject and do not include passwords, session tokens or full card numbers. If a breach affects your data we will notify you and the relevant authority as required.

13. Children

Valen is not intended for children under 13 and we do not knowingly collect their data. People aged 13–15 may use it only where a parent or guardian accepts the Terms of Service on their behalf. We do not collect age or parental-verification data at checkout. Email us if you believe we collected data from someone under 13, and we will delete it subject to any legal or security record we must retain.

14. Changes

The version and effective date at the top identify this copy. We may update this policy as the service or law changes and will announce material changes on the site where feasible before they take effect. The policy version and consent details recorded with an order identify the notice that applied to that purchase. Ask support for the copy that applied to an earlier order.

15. Contact

Privacy questions, data requests, security reports and complaints go to support@valen.cx. Include your order reference where relevant, and do not send passwords, session tokens or full payment-card numbers.

Valen

A Minecraft 1.8.9 ghost client

Product
  • Pricing
  • Download
  • Changelog
  • Docs
Legal
  • Terms of Service
  • Privacy Policy
  • Refund Policy
Support
  • support@valen.cx
© 2026 Valen

Not affiliated with, endorsed by or associated with Mojang Studios, Microsoft, or any Minecraft server. Minecraft is a trademark of Mojang Studios.