※1 If there is any issue or discrepancy with other terms pages, the Japanese Terms of Service shall prevail.
※2 These translations are generated by machine translation. For accurate terms, please refer to the Japanese version.
Nekorelay Privacy Policy
KuronekoServer (the “Organization”) handles information processed through its Minecraft Java Edition relay service, “Nekorelay” (the “Service”), appropriately under this Policy and in accordance with the Act on the Protection of Personal Information, the Guidelines for the Protection of Personal Information, etc. in the Telecommunications Business, and other applicable laws and regulations.
This Policy applies to persons who publish Minecraft servers using the Service (“Server Operators”), persons who connect to servers published through the relay (“Players”), visitors to related websites, and users of account features.
1. Roles of the Organization and Server Operators
- The Organization handles communication data and connection information to the extent necessary to relay communications between Players and Minecraft servers operated by Server Operators.
- Server Operators determine the purposes and methods for handling player information, chats, game data, logs, and other information collected or stored on their own Minecraft servers. Please review the privacy policy or similar policy of each Server Operator for information on how it is handled.
- If a Server Operator enables the PROXY protocol feature, the Organization’s relay forwards a Player’s real IP address to that server. This forwarding is performed according to the Server Operator’s configuration, and the Server Operator is responsible for handling the information after it is forwarded.
- The Service’s relays, API, authentication infrastructure, dashboard, and other facilities used to provide the Service are operated on servers managed by the Organization. The Service’s relays are not operated on equipment managed by Users.
2. Information Collected or Processed
2.1 Relay Assignment API and Website
- IP addresses, access times, request destinations, HTTP headers, and other technical information associated with communications.
- Approximate location information, including latitude and longitude, that Cloudflare infers from an IP address or similar information and attaches to a request.
- Relay assignment results, candidate relays used by the client, and configuration information.
- Language and display theme selected on the website. As a general rule, these are stored in the browser’s local storage.
2.2 Publishing Minecraft Servers and Relay Communications
- The Server Operator’s source IP address and port, connection time, assigned relay, public port, and connection status.
- Control information, including the requested port, whether the PROXY protocol is enabled, an optional tunnel name, authentication-token verification results, the applicable plan, and the connection limit.
- Operational statistics, including the number of active tunnels, assigned ports, current connections, login connections, server-list queries, transferred bytes, rejected connections, and similar information.
- A Player’s source IP address and port, connection destination, connection time, and other information necessary to relay communications.
- Initial handshake information used to confirm that the communication is Minecraft traffic. The protocol version, requested hostname, port, and next connection state are determined automatically.
- Communication data sent and received between Players and Minecraft servers. The Service relays this data in real time.
The Organization’s relays are not intended to analyze Minecraft usernames, UUIDs, chats, world data, or in-game actions. Even where this information is included in Minecraft communications, the relays generally do not interpret its contents and relay it as received.
2.3 Where Account Features Are Provided
Where account features are provided, the following information is collected according to the features used.
- Name or display name, email address, profile image, user ID, and account creation and update times.
- Password hashes, two-factor authentication secrets and backup codes, passkey public keys and device information, and other authentication information.
- External-account identifiers, authorization scopes, and tokens or similar information necessary for authentication in connection with Discord or GitHub login.
- Session IDs, session tokens, IP addresses, user agents, expiry times, and other session information.
- Contract or usage plan, applicable connection limits, and other entitlement information.
- Relay-token hashes, a partial string for display, optional names, creation times, last-use times, and expiry times. The Organization does not store the full relay token displayed only once at issuance in plaintext.
2.4 Inquiries and Reports
- Name, email address, and other contact information.
- The contents of inquiries, reports, infringement claims, objections, and vulnerability reports.
- IP addresses, public addresses, dates and times, logs, screenshots, and other materials provided by Users that are necessary for investigation and response.
3. Purposes of Use
The Organization uses collected or processed information for the following purposes.
- Providing the Service, including selecting a nearby relay, assigning public ports, relaying Minecraft communications, and applying connection limits.
- Identity verification and management of logins, two-factor authentication, passkeys, relay tokens, plans, and accounts.
- Operations monitoring, failure investigation, quality improvement, capacity planning, and statistical analysis.
- Detecting, investigating, and preventing unauthorized access, attacks, circumvention of restrictions, infringement of rights, and other misuse.
- Responding to inquiries, reports, infringement claims, security reports, and objections.
- Enforcing these Terms, complying with laws, responding to legal claims, and protecting the rights and safety of the Organization and third parties.
4. Handling of Communication Contents and Logs
- The Service relays Minecraft communications in real time and does not provide a function to record, archive, or permanently store communication contents.
- Minecraft handshakes are processed in memory only for the time necessary to identify the type of communication, then passed on for relay.
- Player and Server Operator IP addresses are necessary to establish and relay communications, but the purpose is not to record per-connection IP addresses in ordinary relay application logs.
- Operational statistics may include time-series information such as tunnel names or assigned ports, connection counts, transferred bytes, and similar information. This information is not made public, and access is limited to personnel and monitoring systems that need it for operations.
- The Organization keeps records of communication histories and other information concerning the secrecy of communications to the minimum necessary, and promptly deletes or de-identifies them after the purpose of use is achieved. This does not apply where retention is required by law, a lawful preservation request, an ongoing security investigation, or dispute handling.
5. Retention Periods
- Relay connection status and statistics while connected are generally retained in memory only while connected or while the relay process is running, and are deleted upon disconnection or restart.
- Operational statistics and process logs stored in monitoring systems are retained for the minimum period necessary for failure response, capacity planning, and misuse prevention, then deleted or aggregated after those purposes are achieved.
- The relay assignment API does not store IP addresses or approximate location information in the application’s database. However, Cloudflare, as a service provider, may process communication information for security and service provision.
- Account information is retained while the account exists and for the period necessary after deletion for legal compliance, misuse prevention, or dispute handling. Session information may be retained until expiration, logout, or invalidation.
- Inquiries, reports, and response records are retained after the response is complete for the period necessary for recurrence prevention, protection of rights, and legal compliance.
6. External Transmission and Service Providers
The Service may transmit information to, or have information processed by, the following external services to provide the Service.
Cloudflare
The relay assignment API, related websites, and authentication features, when provided, use Cloudflare services. Cloudflare may process IP addresses, network routes, request information, approximate location information, and other information necessary for service provision and security.
- Provider: Cloudflare, Inc.
- Purpose of use: Provision of websites, APIs, authentication, and databases; protection of communications; and misuse prevention.
- Cloudflare Privacy Policy
Modrinth
Plugins or Mods distributed by the Operations Team automatically connect to the Modrinth API to check for updates, generally no more than once every 24 hours. In doing so, the IP address, installed Nekorelay version, type of Minecraft loader, HTTP headers, and similar information are sent to Modrinth.
- Provider: Rinth, Inc.
- Purpose of use: Checking for and distributing Nekorelay updates.
- Modrinth Privacy Policy
Discord
If a Server Operator optionally configures a Discord Webhook, the assigned public address, connection limit, and, if configured, the server display name are sent to the Discord channel designated by that Server Operator. The Webhook URL is stored in the Server Operator’s environment and is not sent to the Organization’s API or relay.
In addition, where Discord login is selected for account features, information necessary for authentication is exchanged with Discord.
- Provider: Discord Inc.
- Purpose of use: Server-publication notifications and account authentication when selected.
- Discord Privacy Policy
GitHub
Where GitHub login is selected for account features, account information necessary for authentication is exchanged with GitHub.
- Provider: GitHub, Inc.
- Purpose of use: Account authentication when selected.
- GitHub General Privacy Statement
Infrastructure Providers
The Organization may use domestic or overseas hosting providers and other service-provider facilities contracted for and managed by the Organization for relay servers, networks, DNS, monitoring, and data storage. The Organization allows providers to handle information only to the extent necessary to provide the Service and provides necessary and appropriate oversight.
7. Provision to Third Parties
- The Organization will not provide personal data to third parties without the individual’s consent except in the following cases.
- Where required by law.
- Where necessary to protect a person’s life, body, or property and obtaining the individual’s consent is difficult.
- Where the individual designates the recipient, or where necessary due to the nature of the Service to deliver communications to the Minecraft server selected by the individual.
- Other cases permitted by the Act on the Protection of Personal Information.
- Allowing the service providers described in the preceding section to handle information to the extent necessary to perform their entrusted work may not constitute provision to a third party under the Act on the Protection of Personal Information.
- The Organization does not sell personal information.
8. International Handling
Cloudflare, Modrinth, Discord, GitHub, and facilities of relay or hosting providers may be located outside Japan, and information may be processed or stored outside Japan. The Organization takes necessary measures in accordance with applicable laws, including selecting service providers, concluding contracts, and controlling access. Please review the privacy policy of each external service for its own handling of information.
9. Cookies and Local Storage
- Related websites may use the browser’s local storage to save language and display-theme preferences.
- Where account features are provided, cookies are used to maintain login status and security. If essential cookies are disabled, login features may not be available.
- Related websites currently do not use cookies for advertising purposes or third-party analytics tools. If they are introduced in the future, the Organization will update this Policy and provide necessary notice or obtain consent.
10. Security Measures
The Organization takes reasonable security measures, including the following, to prevent unauthorized access to, leakage, loss, or alteration of handled information.
- Encryption of website and API communications through TLS and similar technologies.
- Access restrictions for monitoring endpoints, databases, and administrative features.
- Appropriate protection of authentication information and relay tokens.
- Hashing relay tokens and not storing full tokens in plaintext.
- Measures against misuse based on communication size, concurrent connection counts, timeouts, and Minecraft traffic identification.
- Limiting personnel who can access information and appropriately supervising service providers.
However, this does not guarantee complete security of Internet communications or information storage. Server Operators should also appropriately manage configuration files, relay tokens, Discord Webhook URLs, accounts, and Minecraft servers.
11. Disclosure, Correction, Suspension of Use, and Deletion
- Individuals may request, pursuant to law, notice of the purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of provision to third parties of their personal data held by the Organization.
- When making a request, the Organization may ask for information necessary to verify identity and identify the information at issue.
- The Organization may be unable to fulfill all or part of a request where it does not retain the connection information, where an individual cannot be associated with anonymous or short-lived communications, where another person’s rights would be harmed, where retention is required by law, or in other cases provided by law. In that case, the Organization will explain the reason to the extent permitted by law.
12. Changes to This Policy
The Organization may amend this Policy in response to changes in laws, the Service, or its handling of information. If material changes are made, the Organization will provide notice through the official website or another appropriate means by the effective date.
13. Contact
For inquiries, requests, or complaints concerning the handling of personal information, please contact:
- Operator: KuronekoServer (voluntary organization; registered telecommunications carrier H-04-01770)
- About the Organization
- Email: support[at]krnk.org (replace [at] with @ when sending)
To report misuse or infringement of rights, contact abuse@krnk.org.
Established: 2026/08/09 / Last updated: 2026/08/10
