Privacy policy
Last updated: 8 October 2026
This policy explains what personal data Lookout handles, why, and what you can do about it. It describes what the Lookout mod, the Lookout app, this website and the Lookout API actually do. Features marked "when launched" are not live yet; their part applies from the day they start.
Who is responsible
The publisher of Lookout, a private individual in France (see the legal notice), is the data controller. Contact for anything about your data: contact@lookoutmc.fr.
In short
- The website sets no cookies and loads nothing from other sites. If you pick a colour in the footer, your browser remembers that choice (local storage, never sent to us); clearing your browser data removes it.
- Lookout never reads your Minecraft account, login or tokens.
- To show stats, the mod sends the Minecraft IDs of the players in your lobby to our API. Your IP address is used to limit abuse and is not stored by us.
- Crash reports are off unless you turn them on.
What we process, and why
1. Stats in your tab
- Data
- The Minecraft UUIDs of the players in your lobby, the Lookout version and client (for example "forge/0.1.0"), and your IP address.
- Why
- To fetch those players' public Hypixel Bed Wars statistics and show them in your tab, and to stop one user from using up the shared Hypixel limit (rate limiting by IP address).
- Legal basis
- Legitimate interest (GDPR art. 6.1.f): providing the service you installed, and keeping it available for everyone.
- Kept for
- Your IP address is only held in memory for rate limiting, never written to a database. Statistics are cached by player UUID for up to 72 hours, then deleted. Cloudflare's technical request logs, which may include your IP address, are kept for up to 3 days.
- Who receives it
- Cloudflare (our host and processor). Hypixel receives player UUIDs from our server, never data about you.
1b. The "players this month" counter
- Data
- A random number made up by the mod when it is installed (not linked to your account, your name or your IP address), and the day it was last seen. Downloads are counted as a plain total.
- Why
- To show on this website how many people use Lookout.
- Legal basis
- Legitimate interest (GDPR art. 6.1.f). You can turn it off in the mod (General > Count me as a player).
- Kept for
- 60 days after it was last seen, then deleted.
- Who receives it
- Cloudflare (our host and processor).
2. Nicked-player check
- Data
- The in-game names of players Hypixel does not know (usually 0 to 3 per game).
- Why
- To tell whether a name exists, one of the signals that a player is nicked. Lookout never tries to find out who is behind a nick.
- How
- Your own computer asks Mojang's public API directly (Mojang blocks our servers). Mojang (Microsoft) sees the request and your IP address under its own privacy policy. Nothing goes through us.
3. Website visits and app downloads
- Data
- Your IP address and technical request details (page or file asked for, browser or app version).
- Why
- To deliver the pages, the installer and app updates, and to protect them against attacks.
- Legal basis
- Legitimate interest (GDPR art. 6.1.f).
- Kept for
- Up to 3 days in Cloudflare's logs. No analytics, no cookies, no profiling.
4. Crash reports (when launched, opt-in)
- Data
- A random install ID, the Lookout, Java and Windows versions, the client (Lunar or Forge), and the error trace limited to Lookout's own code. No names, no UUIDs, no chat.
- Why
- To find and fix crashes.
- Legal basis
- Your consent (GDPR art. 6.1.a and art. 82 of the French Data Protection Act). Asked once in the first-launch wizard with equal Yes and No buttons; nothing is sent before you answer or if you say no. You can turn it off at any time in the settings.
- Kept for
- 90 days.
5. Discord account and bot (when launched)
- Data
- Your Discord ID, username and avatar, the Minecraft UUID you link, your personal tags and synced settings.
- Why
- To sync your settings and personal tags, and to send the optional session recap.
- Legal basis
- Contract (GDPR art. 6.1.b): the account features you ask for.
- Kept for
- Until you unlink your account, then deleted within 30 days.
- Who receives it
- Cloudflare (host) and Discord (which runs the login and the bot).
6. Cheater reports and tags (when launched)
- Data
- About the reported player: Minecraft UUID and name, the reason, the evidence (for example a video link), the date, the reviewer's decision. About the reporter: Discord ID.
- Why
- To warn players about cheaters with tags that a human has reviewed.
- Legal basis
- Legitimate interest (GDPR art. 6.1.f) in fair play. To protect reported players, only reports reviewed and accepted by a person become tags, every tag shows its level ("reported" or "confirmed") and its date, and any reported player can appeal.
- Kept for
- Rejected reports: deleted after 30 days. Tags: 12 months from the last confirmation, then deleted.
- Appeal
- Write to contact@lookoutmc.fr with your Minecraft name or UUID. The tag is reviewed by a different person, and we answer within one month.
7. Messages you send us
- Data
- Your email address and your message.
- Why
- To answer you. Legal basis: legitimate interest.
- Kept for
- 1 year after our last exchange.
Files kept only on your computer
The mod and the app keep a few files on your PC. They are never sent to us: your settings (lookout.json), your personal tags on other players (lookout-tags.json), your tag provider keys such as Urchin (keys.json, each sent only to its own provider), the "met again" counter (lookout-encounters.json: the UUIDs, or the shown names of nicked players, you shared games with, deleted after 7 days), the update and rollback state (%LOCALAPPDATA%\Lookout) and backups of the Lunar settings Lookout changed. Uninstalling Lookout and deleting these folders removes them.
Cheater tags from other providers
If you add your own key from a tag provider such as Urchin, the mod sends the UUIDs of your lobby to that provider to get its tags. That provider is responsible for its data under its own policy.
Data outside the European Union
Cloudflare, Discord and Microsoft are based in the United States. Transfers rely on the EU-US Data Privacy Framework for certified companies, and on the European Commission's standard contractual clauses otherwise. Hypixel only receives Minecraft UUIDs from our server.
Your rights
You can ask to access, correct or delete your data, object to its use, restrict it, or receive it in a portable format. Where you gave consent, you can withdraw it at any time. Write to contact@lookoutmc.fr; we answer within one month. You can also complain to the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr.
Children
In France, children under 15 need a parent's agreement to give consent online. Lookout's crash reports and Discord features are for people aged 15 or more, or younger with a parent's agreement.
Security
Connections are encrypted (HTTPS). The Hypixel key stays on our server, never in the mod. The app only installs updates signed with Lookout's key.
Changes
We update this page when Lookout changes, and update the date above. Important changes are announced in the app.