The short version
- Signing in does not create an account. We keep no list of the players who sign in.
- Your Minecraft access token never leaves your game except to go to Mojang. It is never sent to us.
- The sign-in token we issue lasts one day and is kept in memory only, never in a file.
- Profile data fetched for the viewer is cached for minutes, not stored.
- We don't sell or share data, and we don't run advertising or analytics on this site or in the mod.
What the mod keeps on your computer
These files live in the PhantomAddons folder inside your Minecraft config folder. You can delete any of them; the mod recreates what it needs.
| What | Why | How long |
|---|---|---|
| Your settings | Remember how you configured each feature. | Until you change or delete them |
| Recently viewed profiles | Reopen a profile instantly without asking again. | Up to 24 hours |
| A list of the last five players you opened in the viewer | The recent players menu. | Until you clear it |
| Skin references for players you viewed | Show the right skin immediately. | Up to 3 days |
| Reference data (item lists, collections, icons, prices) | Avoid downloading public data every time. | 30 minutes to 24 hours |
| An old Discord API key, if you entered one in an earlier version | Kept so it isn't lost. This version no longer uses or shows it. | Until you delete it |
The sign-in token is not on this list because it is never written to disk.
What our servers receive
When you sign in
The mod tells Mojang that your account is joining a random one-time ID, then sends our server your Minecraft username and that ID. Our server asks Mojang whether the join really happened, using a small relay (see below), and replies with a signed token that contains your Minecraft UUID, your name and an expiry time. We do not store the token, your username or the ID. The only exception is an account we have blocked: its UUID goes on a block list.
When you look up a player
The mod sends the name or UUID you searched for. Our server fetches that player's public SkyBlock data from Hypixel and caches the result for 10 minutes so repeat lookups don't call Hypixel again. The Kuudra summary used by auto-kick and party listings is cached for up to 6 hours. After that the cached data is discarded.
Counters and limits
We keep hourly totals of how many requests arrived, how many were served from cache and how many went to Hypixel. They contain no names. Request limits are applied per account for a few seconds to a minute at a time and aren't stored by us beyond that.
Logs kept by our hosting providers
Our hosting providers, Cloudflare and Vercel, process every request and keep their own standard logs for a limited time. These can include the address of the request (such as the player name in a lookup) and your IP address. We may look at them to fix problems, and we don't use them to profile anyone or share them.
Older versions
Earlier versions of the mod used API keys from a Discord bot. For anyone who still has such a key, the server holds the Discord user ID linked to it and when it was last used. This is being phased out as people update.
Services the mod and our servers talk to
| Service | What for |
|---|---|
| Mojang (session servers and skins) | Confirming your sign-in, and loading player skins. |
| Hypixel API | SkyBlock profile data. Our server makes these requests; the key never reaches the mod. The mod itself fetches public resources (items, collections, bazaar) directly. |
| PlayerDB | Turning a player name into a UUID, from our server. |
| Cloudflare | Hosts our API and this site. |
| Vercel | Hosts the relay that talks to Hypixel and Mojang for us. It sees your username and the one-time sign-in ID in the request, which stops working within seconds. |
| GitHub | Mod releases, update checks, icon data, and community-maintained SkyBlock data files. |
| Price sources (Hypixel bazaar, lb.tricked.pro, Coflnet) | Item prices for profit tracking and the missing-accessories list. The mod asks these directly. |
Your choices
- Turn the profile viewer off in the Profile Viewer tab of
/pa. The mod then makes no requests to our server for it. - Delete the PhantomAddons folder in your
configfolder to remove everything the mod stores. - To ask about data, or to report a problem, message us in the Discord or open an issue on GitHub.
Changes
If this page changes, the date at the top changes with it. PhantomAddons is not affiliated with, endorsed by, or sponsored by Hypixel Inc., Mojang Studios or Microsoft.