Skip to content

Privacy policy

Last updated 17 September 2026

MCCatalog stores public Minecraft profile data to show skins and capes, and ordinary server logs to keep the site running. Nothing else. This page says exactly what that means and how to have a profile removed.

1. Who is responsible

MCCatalog, based in Denmark, runs MCCatalog and is the data controller for the processing described here. Contact: hello@mccatalog.com.

MCCatalog has no user accounts, sets no cookies of its own, runs no analytics or advertising scripts and sells no data. It processes two kinds of data: public Minecraft profile data, and the technical data any web server sees when you visit.

2. Minecraft profile data

MCCatalog indexes skins and capes that players have published to their public Minecraft profile. For each indexed player we store:

  • the Minecraft UUID and current username
  • the skin texture, its hash and whether the model is slim or classic
  • the Mojang cape and, when present, the custom OptiFine cape texture
  • when we first and last saw the profile and each skin, including previous skins we have observed

The data comes from Mojang’s public profile API (api.mojang.com, sessionserver.mojang.com and textures.minecraft.net) and from OptiFine’s cape server (s.optifine.net). Profiles enter the index when someone searches for a name on the site, when a name appears in our seed list of public usernames, or when the crawler refreshes an already indexed profile. We never ask for or store passwords, e-mail addresses, Microsoft account details, IP addresses of players or anything that ties a username to a real person.

A username and UUID can identify a person, so this is personal data. We process it under Article 6(1)(f) GDPR, legitimate interest: making the skins and capes that players already show to every other player in the game browsable and embeddable, in the same form the game itself distributes them. The data is public by design, we add no information about the person behind the profile and we do not use it for profiling or decisions about anyone. You can object at any time, see section 6.

Profiles stay in the index while the Minecraft profile exists and are refreshed regularly against Mojang. If a name is looked up but not found, nothing is stored. On request we delete a profile and its skin history and exclude it from future crawls.

3. Data about visitors

When you load a page, a render or an API response, our server and our network provider see your IP address, the URL you requested, the time, your browser’s user agent and the referring page. This is written to server logs and used only to run the service, defend it against abuse, apply rate limits and debug faults. The legal basis is Article 6(1)(f) GDPR, legitimate interest in operating a secure service.

Logs are kept for up to 14 days and then deleted. We do not combine them with profile data, build visitor profiles or share them with anyone except the providers named in section 4.

Searching for a player sends the name from our server to Mojang; your IP address is not forwarded. Renders and 3D previews are served from our own domain, so your browser does not contact Mojang or OptiFine when you use the site. Fonts are bundled with the site and not fetched from Google.

When another website embeds one of our images, your browser requests that image from us and the same technical data is logged. The operator of that website is responsible for their own page.

4. Providers and transfers

We use two infrastructure providers, both bound by data processing agreements:

  • Hetzner Online GmbH, Germany: hosting. All stored data lives on servers in the European Union.
  • Cloudflare, Inc., USA: content delivery, DDoS protection and TLS termination. Traffic passes through Cloudflare's network, which may include servers outside the EU. Cloudflare is certified under the EU-U.S. Data Privacy Framework and works under the European Commission's standard contractual clauses.

Cloudflare may set a strictly necessary cookie to tell automated traffic from people. It is not used for tracking. Mojang, Microsoft and OptiFine are sources of the profile data, not processors for us; we send them only the username or UUID being looked up.

5. Children

MCCatalog is a public reference and does not target children. It has no accounts and collects nothing beyond what is described above. Minecraft profiles of players of any age are public by Mojang’s design; a parent or guardian can ask for a profile to be removed using the process in section 6.

6. Your rights and removal

Under the GDPR you have the right to:

  • access the data we hold about you and receive a copy
  • have inaccurate data corrected
  • have your data deleted
  • restrict processing while a request is handled
  • object to processing based on legitimate interest
  • receive your data in a portable format

If you are the player behind a profile and do not want it on MCCatalog, write to hello@mccatalog.com with the username or UUID. To protect against requests from strangers we may ask you to confirm control of the account, for example by briefly changing the skin or cape and telling us what to look for. We delete the profile, its skin history and cached renders and exclude it from future crawls, and we answer within one month. Skin artists who want an artwork taken down should use the removal process in the terms.

You also have the right to complain to a supervisory authority: in Denmark that is Datatilsynet, the Danish Data Protection Agency, otherwise the authority in the country where you live.

7. Changes

If we change what we process or why, we update this page and the date at the top. Substantive changes are noted on the front page for a reasonable period.

See also the terms of use. Questions go to hello@mccatalog.com.