Early access. Scripts may be buggy or not behave as expected yet.
QuietClient

Privacy Policy

Last updated: September 13, 2026

1. Overview

This Privacy Policy explains what QuietClient collects when you use this website, the QuietClient software, and the QuietWork bot hosting service, why we collect it, and who else sees it. It covers quiettone.space and every service reachable from it. We collect only what the service needs to work and to stop licenses from being shared. We do not sell your data and we do not run advertising or profiling of any kind.

2. Account Information

There is no password or registration system of our own. You sign in with Discord, and Discord gives us your user ID, your username, the URL of your avatar image, and the email address on your Discord account. Those four values and the date your account was created are what we store. We never see or receive your Discord password.

3. Device Identification

Your license is locked to your hardware. When QuietClient starts it sends a set of hardware identifiers, which we store as a device slot along with a device name you can recognise. Each plan allows 2 devices at a time. A device slot that has not been seen for 30 days is deleted automatically and frees its space for a new one. The identifiers we store are:

  • CPU identifier
  • Motherboard identifier
  • Disk identifier
  • Network adapter MAC address
  • Operating system install ID

4. Session Data

While QuietClient is running it holds one session on your account and sends a periodic heartbeat so we know it is still alive. For each session we store a hash of the session token, never the token itself, along with the device slot it belongs to, when it started, when it expires, and the IP address it connected from. A session whose heartbeat stops for more than four minutes is deleted.

5. Sharing Detection

To catch accounts being shared or resold, we keep a log of session events such as one device being evicted by a login from another. Each event records the time, the device slot, the IP address, and the /24 network that IP belongs to. Only the last seven days are examined, and an account is flagged only on an extreme pattern: more than twenty evictions across at least three different networks, with the devices repeatedly alternating. This data is used for license enforcement and nothing else.

6. Payments

Payments run through NOWPayments in cryptocurrency. We never see, receive, or store card numbers, bank details, or wallet keys. What we send NOWPayments is the order ID, the amount in USD, the coin you picked, and a short description of what is being bought. What we keep on our side is the order and its line items, the amount, the coin, and the payment status. Payments now buy account credit rather than an individual item; the balance and every movement of it are held on our side only, in USD.

7. Bot Hosting

If you rent a bot slot, we store the bot's name, the Minecraft username it plays as, the server address you told it to join, its configuration and module presets, and its current status. Console output is a special case: it lives only in the memory of the relay process, capped at the last 200 lines per bot, so that it can be replayed into your dashboard when you open the console. It is never written to the database, and it is gone as soon as the relay restarts.

8. Live View

If your slot has the live view add-on, the bot's screen is encoded as images and streamed to the dashboard sessions watching it. Frames are not recorded, not written to disk, and not added to the console history. A viewing session ends after two hours, or after sixty seconds without a heartbeat from the viewer, whichever comes first.

9. Linked Microsoft and Minecraft Accounts

To play as your own Minecraft account, a bot needs access to it. You link it through the Microsoft device code flow, meaning you enter a code on Microsoft's own site and we never see your Microsoft password. We store your Minecraft username, your Minecraft UUID, and the Microsoft refresh token encrypted at rest with AES-256-GCM. That token is used for one purpose only, obtaining the session your bot needs to join the server you chose. Unlinking the account deletes the stored token.

10. Connection Sharing

QuietShare is optional. If you run it, your bot's Minecraft connection is tunnelled through your own PC so that the bot leaves from your home IP instead of ours. Only your own bots can use your connection, never another customer's, and only the bot's Minecraft socket travels through it, not your own browsing. QuietShare dials out to us and listens on no port of its own, so it is not an open proxy. We store a machine identifier for the computer running it, a label you choose, and a hash of its credential token, and it touches neither your device slots nor your QuietClient session. What the tunnel means for your privacy, stated plainly:

  • To route the connection at all we are told the address and port your bot is joining, and that address is already stored as part of the bot configuration
  • We copy the bytes between your PC and the bot, but we do not read, parse, decode, or store them, and none of it reaches the database or the console history
  • The tunnel is not end to end encrypted by us. Each leg runs over TLS, but the TLS ends at our server, so the traffic passes through our process unless the destination server negotiates its own encryption
  • Our web server access log records the IP address QuietShare connects from, the same as for any other visit to the site
  • Destinations on private, loopback, and link-local ranges are refused, so the tunnel cannot be used to reach devices on your home network

11. Downloads

Each download is logged with your account, the build you took, the time, and the IP address. Every jar handed out is watermarked with a record embedded in the file so that a leaked build can be traced back to the account that downloaded it. That record identifies only the download itself, plus a short integrity check — your account, the build and the time it happened are looked up from that in our own records, not stored again inside the file.

12. Cookies

The site sets three cookies, all of them strictly necessary. None of them are used for advertising, tracking, or profiling.

  • qc_session, the encrypted session cookie that keeps you signed in
  • qc_csrf, the token that protects forms against cross-site request forgery
  • qc_oauth_state, a ten minute value that protects the Discord login redirect

13. Analytics

We use Umami Cloud, hosted in the EU data region, for page view counts. Umami is cookieless, does not fingerprint visitors, and does not collect personal data. It tells us how many people opened a page, not who they were.

14. Third Parties

Your data reaches these services and no others. Each one is governed by its own privacy policy:

  • Discord, for sign-in and identity
  • NOWPayments, for cryptocurrency payment processing
  • Microsoft and Mojang, only if you choose to link a Minecraft account to a bot
  • Umami, for cookieless page view analytics

15. Data Retention

Most short-lived data cleans itself up on a schedule:

  • Device slots are deleted after 30 days without use
  • Sessions are deleted about four minutes after the last heartbeat
  • Pairing codes are deleted once they expire
  • Console output is held in memory only and is lost when the relay restarts
  • Live view frames are never stored at all
  • Account data, orders, and the session event log are kept until you delete your account

16. Your Choices

You can remove a device slot or end your active session from the dashboard at any time. Deleting your account from the Account page removes your user record and everything attached to it: subscription, wallet balance and its transaction history, device slots, sessions, event log, orders, bots, bot slots, presets, linked Minecraft accounts, and download history. Deletion happens immediately and cannot be undone. Records already held by Discord or NOWPayments are governed by their own policies, and you should contact them directly for those.

17. Security

Session tokens and bot tokens are stored only as hashes. Microsoft refresh tokens and proxy credentials are encrypted at rest. All traffic to the site runs over HTTPS. No system is perfect, and we cannot guarantee absolute security, but we do not keep data we do not need.

18. Age Requirement

This service is for adults. You must be at least 18 years old to create an account, buy a license, or use QuietClient and QuietWork. We do not knowingly collect data from anyone under 18. If you believe an account belongs to someone under 18, contact us and we will remove it along with everything attached to it.

19. Changes

We may update this Privacy Policy as the service changes. The date at the top of this page always shows when it was last revised. Continued use of the service after a change means you accept the updated policy.

20. Contact

If you have any questions about this Privacy Policy, or you want to ask what we hold about you, reach out to us on our Discord server.