sten.wtf
SecureOperateAutomateTradePricing
Sign inOpen Dashboard
Privacy

Privacy Policy

What sten.wtf collects, why we hold it, how long we keep it, and how to get it removed. Written to be read rather than skipped.

Last updated: October 1, 2026

Contents

Who this coversInformation we collectVisits, devices and locationSecured account credentialsEmail and inbox dataPayments and cryptocurrencyAI featuresSTEN Vault clientQuarantineLinks storefrontsHow we use informationWho we share it withHow we protect itHow long we keep itYour rights and choicesChildrenWhere data is processedChanges and contact
01

Who this covers

This policy applies to sten.wtf — the dashboard, the API, the Discord bots we host on your behalf, the inbound mail service, transactional email we send you, Links storefronts, Quarantine, the STEN Vault Minecraft client, the bug tracker, and the marketplace when it is available. It describes how we handle information belonging to you, the account holder, and information about other people that those features necessarily process.

It does not describe how Microsoft, Mojang, Discord, Hypixel, DonutSMP, or any blockchain network handle data. When you connect those services to ours, their own policies continue to apply to them.

If you use the platform on behalf of an organisation, "you" means both you and that organisation.

02

Information we collect

We collect what the service needs to function. In practice that falls into these groups:

  • Account and identity — your sten.wtf login (email and/or Discord), Discord user ID, username and avatar if you sign in that way, password hash, two-factor secret, passkeys, notification preferences, and profile settings.
  • Minecraft account data — credentials, tokens, recovery codes and two-factor secrets for accounts you choose to secure or that land in your vault through a feature you enabled, plus the profile, cosmetics and statistics we retrieve for them.
  • Mail — messages delivered to inbox addresses you create on our domains, including their full content; and the address we use to send you product email.
  • Financial — crypto wallet addresses, deposits, withdrawals, invoices, coupons, subscription status, extra-product entitlements (bot slots, Links, API access, modules, Quarantine slots, AI Balance) and usage ledgers.
  • Platform activity — bots and modules you configure, Links you create, Quarantine sessions, STEN Vault devices and remote-control commands, marketplace listings and trades when that feature is on, support conversations, and bug reports you file.
  • Technical — IP addresses, timestamps, request logs, error diagnostics, and a first-party visit record described in the next section.

We do not buy personal data about you from third parties, and we do not run advertising or tracking networks on our pages. We do keep our own visit record so we can operate and understand the site.

03

Visits, devices and location

Every page load can write a first-party visit record. A random visitor identifier is kept in a first-party cookie named sten_vid, and copied into local storage, so the same browser stays one visitor when the IP address changes — including when you are not signed in. With it we store the path you opened (query strings removed), the referring site if the browser provides one, your language and timezone, how long the previous page stayed open, and the IP address and user-agent of the request. We derive device type, browser and operating system from the user-agent. When the IP changes we keep the previous address, a count of those changes, and a short list of recent paths, so we can operate the site and later show pages that match how you use it.

We look up an approximate location from the IP (country, region, city, and coordinates) using a geolocation provider, so operators can see where traffic comes from. That lookup sends the IP to the provider. Sign-in and security mail may also include an IP and a location hint.

The same visit also stores a snapshot of the browser, taken with no permission prompt. It includes screen and window size, pixel ratio, colour depth and orientation, processor cores, the memory and touch points the browser reports, platform and vendor, whether automation software is present, colour-scheme and motion preferences, whether cookies and site storage work, and how long the page took to load. It also includes a short hash of a canvas drawing and of a silent audio tone, the graphics chip the browser reports, which fonts from a fixed list are installed, a few speech-voice names, how many cameras and microphones the browser lists, and device identifiers when the browser exposes them — without asking you to allow the camera or microphone (names only if access was already granted) — plus local network addresses the browser reveals on its own. We do not read your files, the contents of site storage, or any cookie except sten_vid. Operators use the snapshot to tell devices apart. Product offers do not read it. It is stored with the visit record, including the copy in our private Bunny Storage bucket, and it is not sold.

This is not advertising: The visit record and the browser snapshot are ours. We use them for operations, abuse investigation, and operator statistics. The visit record is also how we tailor the product; the snapshot is not, and product offers do not read it. Neither is sold, shared with ad networks, or used to build marketing profiles for anyone else. We do not run advertising or tracking networks. Clearing the sten_vid cookie and site data starts a new visitor identifier; it does not erase rows already stored. Visit events, including the snapshot, are copied to our private Bunny Storage bucket so the log is kept outside the live database.

04

Secured account credentials

This is the most sensitive information we hold, so it is worth stating separately and plainly.

When you secure a Minecraft account, we store the credentials required to keep that account usable by you: the email address and password, the two-factor secret, the Microsoft recovery code, and any tokens obtained during the flow. Secrets are encrypted at rest. InstaLogin uses those stored credentials to complete Microsoft's device-code login as an account you already own — never recovery codes, and never someone else's account.

Access log: Each vault row records who viewed it, copied a field, exported it, created a share link, or used InstaLogin. Share-page visitors who actually open the vault (not just the lock screen) are logged with a masked IP and city, and increment the public view count. We keep a rolling window of recent events, not an infinite history.

These records are scoped to your account. Other customers cannot read them. Our own staff do not access them as a matter of routine — access happens only where it is necessary to investigate a fault you have reported, to respond to a credible abuse report, or where the law requires it. We do not sell secured credentials, and we do not use them to play on, trade, or otherwise make use of your accounts except as you direct through the product (for example Quarantine or STEN Vault).

05

Email and inbox data

There are two mail systems, and they are not the same.

  • Inbound recovery inboxes — addresses you create on our domains receive real email. We store subjects, bodies, senders and verification codes so you can read them in the dashboard. We process them only to display them to you (including surfacing a verification code at the top of a message). We do not scan that content for advertising or profiling. Anyone who has the mailbox address and its inbox password can open that mail on our public security-mail hosts, including inbox.sten.wtf, without a sten.wtf login. Those hosts are part of sten.wtf and are subject to this policy and our Terms.
  • Transactional product email — if we have a real address for your sten.wtf account, we send mail through our email delivery provider: welcome, password reset, account restore, new and failed sign-in, new-location confirmation, email-change confirmation, licence and invoice mail, product updates, and occasional coupons. Password reset, restore, new-location confirmation and email-change confirmation always send. Other categories follow the toggles in Settings → Notifications (security, licence, billing, product; all on by default).

Changing the sign-in email in Settings does not take effect until you confirm a link mailed to the new address. Email you send us directly — support requests, abuse reports — is retained as part of the conversation record.

06

Payments and cryptocurrency

Payments are made in cryptocurrency. We store the addresses involved, transaction identifiers, amounts, invoice records, coupon codes you redeem, and the resulting balance, subscription or extra-product state.

Card details: We never see or store them. There is no card processing on this platform.

Blockchain transactions are public and permanent by design. Anything recorded on a public ledger is outside our control and cannot be deleted by us or by you — that is a property of the network, not a choice we made.

Where a third-party payment processor is involved in generating an invoice, the data required to create and settle that invoice is shared with them for that purpose alone.

07

AI features

The platform includes metered AI chat, an AI-assisted Module Builder, and ChatGuard (optional AI moderation on Discord servers where it is enabled). When you use these, the messages you send — and the context the assistant needs, such as the dashboard page you are on, or the last few channel messages for ChatGuard — are transmitted to the AI provider that serves the model.

We keep a record of usage for metering and billing: which model ran, token counts, and the resulting charge against your free credits or AI Balance. We keep conversation content only as needed to provide the feature and to investigate faults. ChatGuard stores classification decisions and strike state for the Discord users it acts on.

Do not paste secrets into an AI chat that the assistant does not need. The model provider processes what you send under their own terms.

AI chat and the Module Builder are optional — not using them means none of that data is created. ChatGuard only runs where a bot operator has it enabled.

08

STEN Vault client

STEN Vault is our Fabric Minecraft client. Signing in uses sten.wtf OAuth (with a pairing check so a phishing link cannot mint vault tokens). The client lists accounts in your vault and applies a session minted on our servers — passwords, TOTP and recovery codes never leave sten.wtf for this purpose.

While it is running it sends a signed presence heartbeat (device id, Minecraft and mod version, selected account, server host, hardware summary, IP and city) and can upload screenshots (automatic on a short interval, or on command from the dashboard). The dashboard can queue commands the client polls: chat, movement, look, join, switch account, disconnect, and a SOCKS5 proxy you supply. Telemetry on the client cannot be turned off; unsigned or replayed reports are dropped.

Screenshots and chat: Shots are stored for you, with a rolling cap of recent images, so the Mod page can show what the client sees. They may include other players' skins, nametags and chat. Remote chat and movement are actions you take in-game; we store the command long enough to deliver it.

Unofficial local builds require a pairing code. Crash and reject events are counted so we can tell a broken client from abuse. Bug reports you file at the native tracker are stored so we can act on them.

09

Quarantine

Quarantine runs a Minecraft session for a vault account you choose: Hypixel SkyBlock isolation, or DonutSMP AFK. Starting a session uses a stored session token or completes launcher login as that owned account. We store session state, the mode and settings you pick (including auto-enroll and skip filters), playtime we fetch from the relevant game API, and any SOCKS5 proxy you provide — proxy URLs can include a username and password.

Auto-enroll, if you turn it on, can fill free slots from your vault and/or start a session after a successful secure, skipping accounts that meet thresholds you set. Extra concurrent slots are a paid product.

These sessions play on third-party servers under your accounts. We do not sell the playtime or the session. Stopping the session or closing the account ends it; we are not responsible for how those game servers treat the connection.

10

Links storefronts

Links are gift or checkout pages you create that resemble a named store. We store the link configuration (type, hosts, offer, branding, bot assignment, custom presets) against your account.

A visitor who completes the storefront flow is sent through a real Microsoft device-login. The resulting Minecraft session is stored as a secured account in your vault. We also record visit and result events needed to operate the link.

Visitors are not sten.wtf customers: If you are completing someone else's Link, the operator of that link is who the resulting account is stored for. Do not complete a storefront unless you intend that outcome. Customers are responsible for using Links lawfully — phishing and unauthorised account access are prohibited in the Terms.

11

How we use information

We use what we collect to:

  • Operate the service — secure accounts, run your bots and modules, deliver inbound mail, send product email, process payments, settle balances, run Links, Quarantine and STEN Vault, and show you the dashboard.
  • Keep the platform working — diagnose faults, monitor availability, and investigate errors you or our systems report.
  • Protect the platform and its users — detect abuse, fraud, phishing and unauthorised access.
  • Understand use of the site through the first-party visit record, including anonymous visitors whose IP changes, so we can operate the site and tailor what we show. The browser snapshot stored with that record is for operators telling devices apart. Product offers do not read it.
  • Communicate with you about your account, billing, security matters, and material changes to the service, according to the mail toggles above.
  • Comply with legal obligations.

We do not sell your personal information. We do not share it with third parties for their own marketing, and we do not build advertising profiles.

12

Who we share it with

We share information only in these situations:

  • Service providers who make the platform run — hosting and infrastructure, our encrypted off-site backup provider, our email delivery provider, IP geolocation lookups, AI model providers for the features you invoke, payment infrastructure, and game-statistics providers (Hypixel/SkyBlock/DonutSMP lookups used to value and display accounts). Each receives only what their function requires. First-party visit logs are also stored with Bunny Storage, our private object-storage provider.
  • Other users, where you direct it — publishing a shared account page, listing on the marketplace, completing a trade, or a Links storefront discloses what that action necessarily discloses.
  • Microsoft, Mojang, Discord, and the game servers you connect to (Hypixel, DonutSMP, or a server you join through STEN Vault), because those features cannot work without talking to them.
  • Legal requests, where we are compelled by valid legal process, and where we believe disclosure is necessary to prevent serious harm.
  • A successor, if the service is transferred to another operator — in which case this policy travels with the data or you are told before anything changes.

That is the complete list. There is no category of sharing we have left out of it.

13

How we protect it

Credentials, bot tokens and secrets are encrypted at rest. Traffic to the platform is encrypted in transit. Access to production data is limited to the operators who need it to run the service. STEN Vault device reports are HMAC-signed with a per-device secret and rejected if they are unsigned, stale or replayed.

Backups are encrypted and stored off-site with a provider-side encryption key, using access credentials scoped to that backup store alone.

You can add two-factor authentication and passkeys to your sten.wtf account, and we strongly recommend both. Privacy settings in the dashboard let you mask sensitive values on screen — useful when streaming or sharing a display. Streamer mode is a display control; it does not delete data.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your data, we will tell you what happened, what was involved, and what to do about it.

14

How long we keep it

We keep information for as long as your account is active, and then only as long as we have a reason to.

  • Deleted vault accounts go to a recycle bin and are recoverable for seven days, after which they are permanently purged automatically. Failed-flow leftovers are hard-deleted and never sit in that bin.
  • Inbound mail is retained while the receiving address exists. Removing the address ends retention for it.
  • Transaction, invoice and coupon-redemption records are kept longer, as financial records generally must be.
  • Credential access events, STEN Vault screenshots and device telemetry, and diagnostic logs are retained on a rolling basis (a cap of recent rows), not forever.
  • Visit records, including the sten_vid link, the browser snapshot, and the copy kept in private object storage, persist until they are no longer useful for operations or you request deletion of your account data.
  • Encrypted backups roll over on their own schedule, so recently deleted data may persist in a backup for a short period after deletion.

Closing your account removes your data on the timelines above, except where we are required to keep a record for legal or financial reasons.

15

Your rights and choices

You can, at any time:

  • Access and update your information from the dashboard, including notification mail toggles, passkeys, sessions and API keys.
  • Export your account data.
  • Delete individual secured accounts — recoverable for seven days — or request deletion of your entire account and its data.
  • Control what is shown publicly: leaderboard participation, shared page branding, and on-screen masking of sensitive values.
  • Withdraw from optional features such as AI chat, Quarantine auto-enroll, or Links simply by not using them or by turning them off.

Depending on where you live, you may also have statutory rights to a copy of your data, to correction, to erasure, to restrict or object to processing, and to complain to a data protection authority. We honour these requests regardless of where you are — we do not think geography should decide whether you can get your data back.

To make a request, contact us through the channels in the final section. We may need to verify that the request comes from you before we act on it.

16

Children

The service is not directed at children and is not intended for anyone under 13, or under the minimum age of digital consent where they live if that age is higher.

We do not knowingly collect information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

17

Where data is processed

The service is operated from, and data is processed and stored on, infrastructure that may be located in a different country to your own. Using the platform involves your information being transferred to and processed in those locations. Some providers we use (email delivery, AI models, geolocation, game statistics) may process data in further countries.

We apply the same protections described in this policy wherever data is held.

18

Changes and contact

We may update this policy as the service changes. The date at the top of this page always reflects the current version, and we will give notice of material changes through the platform rather than changing it quietly.

For privacy questions, data requests, or account deletion, reach us through our support channels or the Discord server linked in the footer.

Abuse reports: [email protected] — see the Abuse Reporting section of our Terms of Service.

These rules sit alongside our Terms of Service, which cover what you may and may not do with the platform.

Read the TermsBack to Home
Pricing
$15.99 / mo
Migration
Duration Match Active
Infra
AES-256 Encrypted
BlogFAQDocsLeaderboardLeaderboardPrivacyTermsDiscord
sten.wtf — secure, automate, trade.