What we collect, where it goes, and who can see it.
MikeySS has two kinds of users: staff who have an account on this site, and players who run the scanner because staff asked them to. This page says what is collected from each.
last edited 2026-10-09
If you are a player running the scanner
The scanner runs once, on your Windows PC, after you type a PIN and agree to the scan. It shows you what it reads and what it sends before it starts. It does not install anything that keeps running afterwards.
The report that is sent to the server contains:
- Minecraft account names and IDs found in your launchers and game logs.
- Whether Discord is installed and open, and the username and ID number of the Discord account logged in on this PC. Your Discord password, login token, messages and servers are never opened. The email address Discord stores next to the username is not sent. The site looks that ID up, on Discord or through a public Discord lookup service, to get its public profile: the current name and picture anyone on Discord can see. Only the ID is sent for that.
- Whether Minecraft was open, when it was started, its window title, and one picture of the Minecraft window. Never the rest of your screen.
- The game's memory is read on your PC. What is sent from it: pieces of known cheat clients, names of cheat features that are loaded in the game, and the paths of jar files the game loaded from somewhere other than its own folders. Nothing else from the game's memory is sent.
- Java agents the game was started with, with their paths.
- The mods in your mods folder: file names, sizes, hashes and the result of each check. Each jar is opened on your PC and its code is read for the names cheats give their features. For a mod that is not published anywhere, the report also says whether its code is scrambled and which parts of the game it reaches into (attacking, the network connection, the mouse).
- The other mods folders on the PC, from every launcher and every drive: where they are, how many jars each holds and how many are published on Modrinth or CurseForge. Only flagged files are named.
- Resource packs that are turned on, x-ray packs in the folder, and installed game versions that carry a cheat's name.
- Programs Windows remembers you starting in the last 7 days, with their paths, and whether the file is still there.
- Jars, programs and archives your browser downloaded in the last 30 days: the file name and the site it came from.
- Your browser history of the last 30 days is checked on your PC against a list of known cheat sites. Only visits to a site on that list, and searches that name a cheat together with a word like client or download, are sent. Every other page and search stays on your PC.
- Programs set to start with Windows, and the names of scheduled tasks.
- Website names in the DNS cache that match a list of cheat sites. Other names are counted and not sent.
- Programs, jars and archives in your user folders, in ProgramData and in loose folders on the Windows drive are checked on your PC. In Program Files, the Windows folder and the large app data folders only jars, and programs added in the last week, are checked. Files that are only in the cloud are not opened. Only files that match or look like known cheat clients, and folders that known cheats create, are sent, with their full paths. Paths usually include your Windows user name.
- USB sticks, external drives and second drives that are plugged in during the scan: the drive's letter and name, and how many files it holds. The programs, jars and archives on them are checked on your PC. Only a file that looks like a cheat is named, with its path.
- Cheat-related strings found in the memory of Windows diagnostic services.
- Libraries loaded into the game that are not part of Java, with their paths, whether each is signed, and whether any part of the game is running code that did not come from a file.
- Programs in the Windows system folders and the temp folder that have no valid signature, with their paths.
- Mouse software settings: profile names, macros and when they were last changed.
- Lines from your PowerShell history that delete files, clear system records or stop Windows services. Other lines are not sent.
- Names and times of USB devices plugged in recently, and names of recently opened and recently run files.
- Whether logs, the USN journal, prefetch files or the recycle bin look cleared or tampered with.
- Whether the Windows services and settings that keep a record of what ran are switched off, and whether one of those services was restarted after the PC came on, with the time.
- The old and the new name of a program or jar that was renamed in the last 6 hours to something that does not look like a program.
- The names of other Windows accounts on the PC that were used in the last day. Nothing inside those accounts is opened.
- If your browser's "clear browsing data" was used in the last 2 days (Chrome, Edge, Brave, Vivaldi, Opera): which browser and when. Whether a browser was started in private mode. Nothing you opened in it is read.
- If the DNS cache looks emptied: how many names are in it and when the Windows tool that empties it was last run.
- The names of programs, archives and scripts you deleted in the last 2 days, with the folder they were in. This comes from the recycle bin and from the record Windows keeps of deleted files. Documents, pictures and other files are not listed.
- Whether the PC looks like a virtual machine, your drive letters, and when the PC last started.
- The scanner's version, and hardware IDs: one-way hashes of a Windows identifier and of the serial numbers of your motherboard and drives, used to tell staff when two scans came from the same PC. The serial numbers themselves never leave your PC.
While it runs, the scanner tells the server which step it is on, so staff can see how far along the scan is.
After the report, the scanner also uploads the .jar and .zip files from your mods folder, so staff can inspect them. Files over 15 MB are skipped and at most 40 files are sent.
To check a mod against its published version, the scanner sends the mod's hash or file name to Modrinth, and a fingerprint of the file to CurseForge. If the server has set up VirusTotal, the hash of an unknown mod is sent there too. To put a current name to a Minecraft account ID, the scanner asks Mojang. These services see the request come from your IP address, like any site you visit. They are not told your name or what the lookup is for.
To show your skin next to your scan, the site looks up your Minecraft account name or ID with a public skin service (mc-heads.net). The site does this itself; staff browsers never contact that service.
When a staff member opens a scan, the scan text and the names of the mod files are sent to an AI service (Space Bunny, on OpenCode) so it can write a plain-language overview. The jar files themselves are not sent, and the provider says that text is not kept and is not used for training.
The scanner does not record keystrokes, take pictures of anything but the Minecraft window, open your documents, read which pages you visited, send passwords or login tokens, or stay running after the scan.
Who can see a scan
- The staff team that created your PIN. Other servers using MikeySS cannot see it.
- The people who run this site, when they need to for support or to investigate abuse.
- If the team has set up Discord alerts, a short message about the finished scan is posted to their Discord channel.
Scans are not sold, not shared with advertisers and not published.
If you have a staff account
We store what you give us and what you do in the console:
- Your name, email address and a hash of your password. We cannot read the password itself.
- Whether your email address has been confirmed, and whether you have two-step login switched on.
- The team you belong to and your role in it.
- A login session, with the IP address and browser it was created from.
- A mark for each browser you have logged in from with an emailed code, so that browser is not asked again every time.
- A log of actions in the console, such as creating a PIN or banning a player, with the time and your account.
- If you pay for a plan: the plan, the price, the coin, the payment address and whether the payment arrived. The payment itself goes through NOWPayments. We never see a wallet's keys.
We send you email in three cases: a code when you sign up, a code when you log in from a new browser or have two-step login switched on, and a link when you ask to reset your password. The codes are stored as a hash and stop working after 15 minutes, a reset link after 30. The mail is sent through Resend, which gets your email address and the text of that mail to deliver it. We do not send newsletters or advertising.
The site uses a cookie to keep you logged in, one to remember which team you have open, one that marks a browser you have logged in from, and a short-lived one while a login is waiting for its code. There is no advertising or tracking.
If you play with the MikeyAC mod
Some servers ask players to install the MikeyAC mod. The mod talks to this site, and the site passes its messages on to the server you are playing on. For that we handle:
- Your Minecraft account name and ID. To show the account is yours, the mod logs it in with Mojang the same way joining a server does. Your Minecraft login token only ever goes to Mojang, never to us.
- Which of the team's servers you are on, for as long as you are on it.
- The messages between the mod and the server. They are held only until the other side picks them up, a few minutes at most. We pass them on and do not read them.
- What the server's anticheat reports about your session, such as a failed check. That is kept in the team's console, like a scan.
Where it is stored and who handles it
The site and its database run on Railway, and scan reports, pictures and mod files are kept in storage there. Visits to the site and the scanner's uploads pass through Cloudflare on the way. Both see the data they carry or hold, and your IP address, to do that job. They are service providers to us, not partners we share data with.
How long it is kept
Scans stay in the team's console until the team or the site removes them. How far back a team can look depends on its plan. Login sessions expire after 30 days. The mark for a browser you have logged in from lasts a year, or until you reset your password.
Asking for your data or having it removed
If you were scanned and want the report removed, ask the staff of the server that scanned you first: they hold the scan. You can also contact us through the server's staff with the PIN you used and we will find it.
Staff can ask for their account to be deleted the same way.