Lumine

Last updated August 27, 2026

Privacy Policy

This policy describes what the Lumine portal at lumineproxy.org and the Lumine API collect, what stays only in your browser, what Lumine keeps server-side for security, and when data is sent to third-party providers you choose to use.

Important Microsoft account note

Microsoft OAuth credentials are encrypted and held by the Lumine API. The portal receives username-only linked account metadata and sends that username when you request friends, Realms, realm addresses, or a proxy. Device codes are temporary workflow identifiers; the account-trade flow also consumes its credential server-side.

Security-first collection

Lumine collects account, IP, device, and sign-in evidence to operate the portal, protect accounts, and fight fraud or chargebacks.

Credentials stay server-side

The API bearer is held in an encrypted HttpOnly portal session. Microsoft OAuth credentials are encrypted by the API; browser storage contains only device continuity and convenience data.

Third-party services are optional but real

If you use Google sign-in, Microsoft account linking, Stripe checkout, the CPX survey wall, YouTube embeds, or social links, those providers also receive data under their own policies.

What we collect through the portal

Account and sign-in data

  • Lumine account email, password submission during sign-in or registration, and password-change or recovery requests. The portal does not store your plaintext password in browser storage.
  • Account profile and entitlement data returned to the portal, such as email verification state, whether a password exists, auth provider list, last login time, Stardust balances, daily reset timing, premium status, premium start and end timestamps, deletion markers, creation and update timestamps, and related account-security fields.
  • Recent sign-in history shown in the portal profile, including timestamp, auth method, client IP, IP source, observed request IP, user agent, opaque device or cluster ID, device match source, device risk score, and the resulting trust score or level when available.

Security and fraud-prevention data

  • Client IP address, observed upstream IP, sign-in timestamp, and user agent. A coarse IPv4 /24 or IPv6 /56 network cohort is converted to an opaque keyed hash for trust comparisons; the trust engine does not require an exact-IP match.
  • Browser and device signals used to build a fraud-prevention fingerprint: timezone, language, languages list, platform, screen size, color depth, pixel ratio, hardware concurrency, device memory, max touch points, and user agent.
  • For free-Stardust abuse prevention, complete device signals may be combined with a coarse IP network prefix and transformed server-side into an opaque keyed hash. This claim can pool the free daily allowance across repeat Lumine accounts, but it does not limit paid Stardust, memberships, or account creation.
  • Server-side authentication audit records for successful password and Google sign-ins or registrations. These records can include opaque recovery-token hashes, device/network claim hashes, trust score and level, contributing reason codes, and limited request context. Raw recovery tokens and raw browser-signal payloads are not persisted.
  • Authentication and registration rate-limit counters. When an opaque device recovery token is available, the strict auth bucket is device-based, with a looser IP safety cap for automation; clients without a device token fall back to the IP bucket. General traffic protections may still use IP addresses.
  • A server-issued access token can be bound to the opaque hash of this browser recovery token. Copying that access token to a browser that does not possess the matching recovery token will not authenticate.

Microsoft, Google, Minecraft, and Discord data

  • Google sign-in data when you choose Google auth, including the Google ID token and the email claim the portal may read from that token before forwarding it to Lumine auth routes.
  • Microsoft usernames for linked accounts and OAuth credentials encrypted server-side with authenticated encryption. Microsoft access and refresh tokens are not returned to normal browser linking, Minecraft, proxy, or account-trade flows.
  • Temporary Microsoft device authorization data for connect and account-trade flows, including the device code, user code, verification URI, expiry, and poll status. Before account-trade acceptance, the trade credential stays in a user-bound server authorization; after acceptance, the token is stored server-side in an owner-bound processing record so downstream trade processing or reconciliation can complete.
  • Minecraft friends data requested through the portal, including gamertag, XUID, online state, game title, game state, and rich presence.
  • When timed Eclipse uses free Stardust, Lumine resolves the stable Xbox XUID from the submitted Microsoft token and transforms it into an opaque keyed hash so the same Xbox identity cannot receive another free allowance through a repeat Lumine account. The raw XUID is not stored in the free-claim record.
  • Minecraft Realms data requested through the portal, including realm ID, name, state, message of the day, world type, days left, owner, slots, and resolved realm join address.
  • When you choose account linking, Lumine stores your Discord user ID, username, optional display name and avatar URL, link and unlink timestamps, and role-synchronization results. It does not receive your Discord password or direct messages.
  • A link code is short-lived, single-use, and stored only as a keyed cryptographic hash. The Discord bot submits the code together with the Discord identity that invoked /link so Lumine can verify account control.
  • The 30 Stardust promotion is limited once per Lumine account and Discord identity. Lumine retains an opaque keyed claim derived from the Discord ID, plus the financial ledger entry, to prevent unlink/relink or deleted-account reward farming. The opaque claim does not expose the original Discord ID.

Proxy, configuration, and support data

  • Proxy targets and session data such as remote server address, realm code, realm ID, friend target, region, proxy type, connection state, assigned address, port, server code, start time, shutdown reason, shutdown error, and shutdown timestamp when returned to the portal.
  • When a proxy starts, Lumine may record proxy-start analytics including the client IP, selected region, proxy type and tier, target label, account or username, port, and timestamp. For a routable client IP, the API may send that IP to ipwho.is and store the returned approximate country, country code, and city for analytics. This lookup does not control the proxy region or connection decision.
  • Preferred region, selected tier, last proxy start configuration, selected proxy configuration ID, saved proxy configuration snapshots, and settings blobs used to resume or recreate portal-driven starts.
  • Resource pack metadata and uploaded resource pack content stored locally in your browser when you use the resources flow, including file name, size, type, add time, and data payload.
  • Support or legal emails you send to Lumine, including your contact details and the contents of your message.
  • Password-reset and account-deletion email token flows used from the portal, including the one-time tokens you open and submit and the exact deletion confirmation phrase you type.

Reward programs and creator submissions

  • When you open the CPX survey wall, Lumine sends CPX the session information needed to identify your Lumine account, including an external account identifier, username, and email. CPX and its survey partners may collect survey answers, device, IP, approximate location, and demographic information under their own terms and privacy policy. Lumine receives provider postback identifiers, offer and status information, reward amounts, and reversal or adjustment events for the reward ledger.
  • When you visit a Lumine referral link or sign up through one, Lumine may store the referral code, link type, click time, attributed inviter and invited account IDs, attribution status, connected proxy playtime, qualification and reward timestamps, inviter quota state, and Stardust ledger references. The current program automatically awards 30 Stardust to each person after the invited account reaches 10 connected minutes, with a limit of 10 qualified referrals per inviter in a 30-day quota window; there is no seven-day bonus at this time.
  • To prevent referral farming, Lumine may compare opaque device-claim identifiers, opaque browser recovery identifiers, and opaque coarse network-prefix hashes already used by its security systems. Referral abuse audit events can record which signal categories matched, the reason for a rejection or quota block, and limited account/link identifiers. Lumine does not store raw browser-signal payloads in these referral records.
  • When you submit creator content for review, Lumine may store the video file, original filename, format, description or other submission details, your account email, an optional Discord handle, timestamps, and review or reward status. Submissions may be streamed to authorized moderation staff or service providers through a shareable submission URL; do not include credentials or sensitive information in a submission.

Exact browser storage used by the portal

The portal uses an HttpOnly cookie for authentication and uses JavaScript-visible cookies, local storage, session storage, and IndexedDB only for device continuity, temporary workflow identifiers, proxy convenience, and account recovery flows.

Cookies set by the portal

__Host-lumine-session

Production-only encrypted, HttpOnly, Secure, SameSite=Strict Lumine API session. Maximum age: 24 hours; unavailable to browser JavaScript.

lumine_device_recovery

Browser recovery token used to reconnect a browser to the same device identity. Max age: 365 days.

lumine_proxy_configs

Saved proxy configuration list and settings snapshots stored in a browser cookie. Default max age: 365 days.

lumine_proxy_config_selected

Selected proxy configuration ID stored in a browser cookie. Default max age: 365 days.

Local storage keys

lumine_device_recovery

Copy of the browser recovery token used for device identity continuity until you clear browser storage.

lumine_xbl_device_code

Temporary Microsoft device-code auth cache kept until the code expires or is cleared.

lumine_account_trade_xbl_device_code

Temporary account-trade device-code authorization identifier kept until submission, expiry, or clearing. It is not an OAuth access or refresh token.

resourcePacks

Locally saved resource pack metadata and payloads you upload in the portal until you clear them.

lastProxyStart

Last proxy start settings such as account, proxy type, target, and tier until you clear it.

lumine_preferred_region

Preferred proxy region selection until you clear it.

lumine:onboarding-finished

Boolean onboarding completion marker until you clear it.

Session storage keys

lumine_chunk_reload_attempt

Single-session marker used to recover from chunk-load errors.

lumine_password_reset_token

Password-reset token held in session storage after you open a reset link.

lumine_delete_account_token

Account-deletion token held in session storage after you open a delete link.

IndexedDB stores

lumine-device-context / markers / recovery-token

Recovery token mirror used for durable client device identity.

How we use information

  • Create, authenticate, secure, and recover Lumine accounts.
  • Operate Microsoft-connected and Minecraft-connected features such as friends, Realms, realm join address resolution, and account linking.
  • Connect Discord accounts, issue the one-time community reward, and synchronize Eclipse Discord roles with current membership status.
  • Start, resume, stop, and manage proxies and related dashboard state.
  • Produce service analytics, including proxy-start analytics with approximate IP-derived location, and improve operations and capacity planning.
  • Provide optional survey, offer-wall, referral, Stardust reward, and creator-submission programs, including validating provider events, measuring referral qualification, preventing reward farming, and reviewing submitted content.
  • Link purchases and premium windows to the correct Lumine account, manage billing redirects, and respond to disputes or chargebacks.
  • Prevent fraud, enforce browser or device restrictions, investigate abuse, and protect the service and other users.
  • Respond to support, policy, security, and legal requests.

Automated trust scoring and account-abuse decisions

When you register or sign in, the Lumine API calculates a rules-based trust score from 0 to 100. This is security and fraud-prevention profiling, not advertising profiling. The calculation uses a combination of signals rather than treating an IP address as proof of identity.

Signals can include whether an opaque browser recovery identifier is present and familiar to the account, whether the browser/device signal set is complete, prior devices and coarse network cohorts used by the account, browser-family familiarity, account age, verified Google authentication, recent device velocity, device or device/network reuse across Lumine accounts, and an upstream device-risk value when a trusted Lumine service supplies one. A familiar device is strong positive evidence. An IP or network match is only a supporting signal. Device reuse across accounts and unusually fast device changes are stronger negative evidence.

The score is assigned a trusted, monitored, or restricted level. Registration itself is not denied solely because of this score. The level controls session lifetime, and only trusted sessions can start Eclipse. A monitored or restricted user can sign in from a familiar device, use their verified Google account, or ask support for review; Free proxies remain available throughout. Free Eclipse allowances are also pooled through opaque Xbox and device/network claimant hashes so opening a repeat Lumine account does not create another copy of the same promotion.

These rules can produce false positives on shared computers or unusual device setups. To ask for a human review, correction, or explanation of a trust-related restriction, contact [email protected]. Include the request ID shown with the error when available. Support can review the recorded signals and account history; after human review, support can set a temporary trusted override that expires within 30 days and takes effect when you sign in again. If you still control the account but are using a new browser, the dashboard can send a one-time email-verified device recovery link. The link must be opened in the same browser that requested it, replaces the account's previous trusted device, signs out other sessions, and is rejected when that browser is already bound to another active Lumine account. This recovery path does not permit account sharing. A device-claim exemption or trust override does not remove the separate Xbox or per-account promotional limit.

When information is shared

We do not sell or rent your personal information. We share information only as needed to run Lumine, complete features you request, process billing you choose to start, maintain security, or comply with legal obligations.

  • With Lumine API routes and infrastructure when the portal needs to complete an account, security, billing-linking, or proxy action you requested.
  • With Google if you use Google sign-in.
  • With Microsoft and Xbox-linked flows if you use Microsoft account connection, friends, Realms, or related Minecraft features.
  • With Stripe if you open checkout or billing management for Stardust or Lumine Eclipse.
  • With ipwho.is when a proxy starts and a routable client IP is available, solely to obtain approximate country, country code, and city for service analytics. The current integration requests only those location fields and does not use the result to select a proxy node.
  • With CPX Research and its survey or research partners when you open the CPX wall. CPX operates the survey experience under its own terms and privacy policy and may collect additional information directly from you.
  • With YouTube if you load the embedded tutorial or click through to YouTube.
  • With moderation, storage, queue, or hosting providers when you submit creator content and related metadata for review or program operation.
  • With Discord when you open its links or invoke the Lumine bot to link or unlink an account and synchronize an Eclipse role; with TikTok, Instagram, or other social services when you choose to open those links.
  • With service providers, hosts, CDNs, or legal authorities when reasonably necessary for security, abuse prevention, legal compliance, chargeback defense, or protection of users and the service.

CPX's own rules and privacy policy apply when you use its wall: CPX user terms and CPX privacy policy.

Retention and your choices

Cookie retention and browser-storage behavior are listed above. Some items expire automatically, while others stay until you clear browser storage, overwrite them, disconnect an account, or remove saved portal data.

The separate successful-auth audit collection is configured to expire records after 90 days. The user record keeps only the 20 most recent successful sign-in events until they are displaced by newer events or the account is deleted. Opaque free-allowance claim documents expire after 45 days. Account-level opaque device bindings and claimant IDs remain with the account until deletion unless support corrects them. Support trust overrides expire within 30 days; their review timestamps and note remain with the account until cleared or account deletion. Retired exact-IP account-lock fields are erased during API database setup. In-memory rate-limit counters expire after their configured windows, which are generally minutes rather than days. Raw Discord link records are removed when an account is purged. The opaque Discord reward claim and Stardust ledger entry are retained for promotion-abuse prevention and financial integrity.

Proxy-start analytics, reward-provider events and ledgers, accepted account-trade processing records, creator- submission files, and billing or financial records are not covered by the 90-day successful-auth audit TTL. Retention varies by record and may continue as reasonably necessary for operations, analytics, reward accounting, trade processing, moderation, fraud or chargeback defense, and legal obligations. We do not promise one universal deletion period for these records.

Referral attribution records, referral quota records, and Stardust ledger entries may be retained for reward accounting, abuse investigations, and financial integrity. Referral abuse audit events are configured to expire after 180 days unless a longer retention is required for a dispute, investigation, legal obligation, or ledger reconciliation.

You can review recent sign-ins in the dashboard, request password reset emails, request account deletion, clear unlink server-held Microsoft accounts from the portal flows that manage them, remove saved resource packs or proxy configurations, or contact Lumine for support or policy requests.

Do Not Track, children, and third-party tracking

The portal does not currently change its behavior in response to a browser "Do Not Track" signal. The portal is primarily built around first-party account, proxy, and security features rather than third-party tracking, but third-party services you choose to load or open, including the CPX survey wall, may set cookies or collect data under their own policies.

Lumine is not intended for children under 13, and we do not knowingly collect personal information from children under 13 through the portal. If we learn that we have done so, we will take reasonable steps to remove that data.

Contact

Support questions can be sent to [email protected]. Policy or legal questions can be sent to [email protected].