Privacy Policy
DeutschVersion 2.0 — Last updated: August 9, 2026
1. At a glance
- Our apps are free. Advertising pays for them.
- There is no account. We never ask for your name, your address, or payment details.
- Advertising runs through a mediation platform, so one ad slot can be filled by any of the partners named in section 5. Personalized ads run only if you agree to them.
- Anyone who tells us they are under 18 never receives personalized ads.
- This website sets no cookies and runs no analytics.
2. Who we are
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:
GKM Interactive UG (haftungsbeschränkt)
Wasserstraße 5, 37186 Moringen, GermanyManaging Director: Davin Gindorf
Registered at Amtsgericht Göttingen, HRB 207239
VAT ID: DE364802252Email: [email protected]
Imprint: mc-tools.app/imprint
We have not appointed a data protection officer. Art. 37 GDPR and § 38 BDSG require one where a controller's core activity is large-scale monitoring of individuals, where it processes special categories of data at scale, or where at least twenty people are permanently occupied with automated processing. None of these apply to us.
3. What this policy covers
This policy covers the following apps, wherever the stores make them available, and the website at mc-tools.app. One policy covers all of them because they are built from one codebase and behave the same way.
| App | Where | Identifiers |
|---|---|---|
| PvP Texturepacks for Minecraft | App Store and Google Play | com.gkminteractive.mc_mods · com.gkminteractive.mcMods |
| Car Mods for Minecraft | App Store and Google Play | com.gkminteractive.car_mods · com.gkminteractive.carMods |
| Best Maps for Minecraft | App Store and Google Play | com.gkminteractive.mc_apps.maps · com.gkminteractive.mcApps.maps |
| Shaders for Minecraft | App Store and Google Play | com.gkminteractive.mc_apps.shaders · com.gkminteractive.mcApps.shaders |
| Xray Packs for Minecraft | App Store and Google Play, no advertising on Android | com.gkminteractive.mc_apps.xray · com.gkminteractive.mcApps.xray |
| Oneblock & SkyBlock Maps for Minecraft | Google Play only | com.gkminteractive.mc_apps.oneblock_skyblock |
Apple and Google are separate, independent controllers for your relationship with their stores — the download itself, store reviews, and anything you pay them. What they do with that data is governed by their privacy policies, not this one.
4. What we process, why, and on what legal basis
Every purpose below needs a legal basis under the GDPR. Here is each one, the data it involves, and how long we keep it.
| Purpose | Data | Legal basis | How long |
|---|---|---|---|
| Run the app and deliver catalog content | Device model, operating system version, app version, language, IP address | Art. 6(1)(b) GDPR — performing our agreement with you | Request logs up to 30 days |
| Deliver a file you chose to download | IP address and the request itself, at our servers and at the host storing the file | Art. 6(1)(b) GDPR — performing our agreement with you | Request logs up to 30 days |
| Stability and crash diagnostics (Firebase Crashlytics) | Crash traces, device state at the time of the crash, pseudonymous installation ID | Art. 6(1)(f) GDPR — our legitimate interest in software that works | 90 days |
| Product analytics and ad revenue reporting (Firebase Analytics) | Pseudonymous app-instance ID, in-app events, which ad network filled a slot and what it paid, country or region | Art. 6(1)(a) GDPR — your consent, and § 25(1) TDDDG for the storage on your device. See section 5 on when this starts | Up to 14 months |
| Non-personalized advertising (Appodeal mediation) | Ad request data, coarse IP address, device and operating system, contextual signals about the screen you are on | § 25(1) TDDDG for the storage on your device; Art. 6(1)(f) GDPR — our legitimate interest in funding free apps | Controlled by each partner |
| Personalized advertising — consenting adults only | Advertising ID (Android Advertising ID or IDFA), ad interactions, the signals above | Art. 6(1)(a) GDPR — your consent | Until you withdraw consent or reset the advertising ID |
| Rewarded video in exchange for a download | The same ad request data, plus whether you watched the video to the end | Art. 6(1)(a) GDPR — your consent, since you start the video yourself | Controlled by each partner |
| Preventing invalid traffic and ad fraud | Ad request signals, device attestation from Google Play Integrity or Apple App Attest (Firebase App Check) | Art. 6(1)(f) GDPR — our legitimate interest in advertising integrity and in protecting our backend | Controlled by Google and Apple |
| Measuring which campaign brought you to us (AppsFlyer) | Advertising ID where available, AppsFlyer install ID, IP address, install and app-open events, Apple SKAdNetwork postbacks | Art. 6(1)(a) GDPR — your consent, and § 25(1) TDDDG. See section 5 on when this starts | Up to 24 months |
| Selling and restoring the unlock (RevenueCat) | Anonymous purchase ID, store receipt, entitlement state, store country | Art. 6(1)(b) GDPR — performing the purchase you made | For the life of the purchase, then as tax law requires |
| Linking a purchase to the campaign that brought you (RevenueCat) | Device and advertising identifiers, AppsFlyer install ID, campaign attributes | Art. 6(1)(a) GDPR — your consent, and § 25(1) TDDDG. See section 5 on when this starts | For the life of the purchase |
| Remote configuration of app behavior | Pseudonymous installation ID, app version | Art. 6(1)(f) GDPR — our legitimate interest in shipping fixes without an app update | Duration of the request |
| Answering your support messages | Your email address and whatever you write to us | Art. 6(1)(b) and Art. 6(1)(f) GDPR | Until resolved, then deleted — up to 6 or 10 years where § 257 HGB or § 147 AO require it |
| Serving and securing this website | IP address, user agent, referrer, timestamp | Art. 6(1)(f) GDPR — our legitimate interest in a site that stays up | Up to 30 days |
| Remembering your light or dark theme choice | A single browser storage entry. It never leaves your device | § 25(2) TDDDG — strictly necessary for a function you asked for | Until you clear site data |
5. Advertising and your consent
Our apps cost nothing to download and nothing to use. Advertising is what pays for building and running them. If you would rather not see any, section 5 of our Terms of Service describes the one-time unlock that removes it.
Who serves the ads
We do not sell ad space ourselves. We use Appodeal, a mediation platform: for every ad slot it runs an auction between the partners below, and whichever one wins fills that slot and receives the ad request. Any of them can therefore receive your advertising ID where you have consented to personalization, your IP address, your device and operating system, coarse location at country or region level, and how you interacted with the ad. What each does next is governed by its own privacy policy.
| Partner | Its role | Its privacy policy |
|---|---|---|
| Appodeal | Runs the mediation and its own Bidon bidder, and presents the consent form | https://www.appodeal.com/privacy-policy/ |
| Google (AdMob) | Demand partner. Google Ireland Limited for users in the EEA, Google LLC elsewhere | https://policies.google.com/technologies/partner-sites |
| AppLovin | Demand partner | https://www.applovin.com/privacy/ |
| Meta Audience Network | Demand partner. Meta Platforms Ireland Limited for users in the EEA | https://www.facebook.com/privacy/policy/ |
| Unity Ads and ironSource | Demand partners, both operated by Unity | https://unity.com/legal/game-player-and-app-user-privacy-policy |
| Mintegral | Demand partner, part of the Mobvista group | https://www.mintegral.com/en/privacy/ |
| Liftoff (Vungle) | Demand partner | https://liftoff.io/privacy-policy/ |
| BIGO Ads | Demand partner | https://www.bigossp.com/guide/web/privacy_policy |
| DT Exchange | Demand partner, operated by Digital Turbine (formerly Fyber) | https://www.digitalturbine.com/privacy-policy |
| InMobi | Demand partner | https://www.inmobi.com/privacy-policy |
| Amazon Publisher Services | Demand partner | https://aps.amazon.com/aps/privacy-policy/index.html |
| BidMachine | Demand partner | https://bidmachine.io/privacy-policy/ |
How you are asked
In the EEA, the United Kingdom, and Switzerland you see a consent dialog before any advertising runs. It is presented by Appodeal's Stack Consent Manager, which is built on the Google User Messaging Platform, and it records your answer on your device. Rejecting is as easy as accepting. If you say no, the apps keep every feature — you get non-personalized ads instead, chosen from the screen you are on rather than from anything about you.
That dialog governs advertising, and no advertising runs before you have answered it. Our crash reporting, analytics and attribution components start with the app, before the dialog. You can object to those at the address in section 15.
Personalized ads use your device's advertising ID: the Android Advertising ID, or the IDFA on iOS. It is a resettable identifier that does not contain your name. Non-personalized ads use no advertising ID, but they still involve reading and writing to storage on your device, which is why § 25(1) TDDDG applies to them too.
On iOS, Apple's App Tracking Transparency prompt is separate from ours and comes from the operating system. If you decline it, we do not access the IDFA, whatever you told our own dialog.
Downloads play a rewarded video first. You start it yourself and can close it, and the same ad data is involved as for any other ad.
Withdrawing your consent
The dialog is asked once. You can withdraw or change your answer at any time afterwards, in any of these ways:
- Android — Settings → Privacy → Ads → Delete advertising ID. Personalized ads stop.
- iOS — Settings → Privacy & Security → Tracking, and turn off tracking for the app.
- Either platform — clearing the app's storage resets the stored consent record, so the dialog appears again on the next start.
- Email us at the address in section 15 and we will action the withdrawal for you.
Withdrawing consent takes effect from the moment you withdraw it. It does not affect the lawfulness of anything we did while it was in place.
6. Who receives your data
These are the providers involved in running the apps and this website, beyond the advertising partners already named in section 5. Each one is bound either as our processor, or — in Appodeal's case and that of each demand partner — acts as an independent controller for its own advertising purposes.
| Provider | Its role | What it does for us |
|---|---|---|
| Firebase (Google Ireland Limited) | Processor, under Google's data processing terms | Crashlytics for crash reports; Analytics for which features get used and what the ads earned; Remote Config for changing app behavior without an update; App Check for proving a request came from a real, unmodified app |
| Appodeal | Independent controller for its own advertising purposes | Runs the auction, presents the consent form, measures whether an ad was seen or watched, detects invalid traffic |
| AppsFlyer | Processor, under a data processing agreement | Tells us which ad campaign led to an install, and receives Apple's SKAdNetwork postbacks on our behalf |
| RevenueCat | Processor, under a data processing agreement | Records that you bought the unlock, restores it on a new device, holds the store receipt |
| Google Cloud Platform | Processor, under a data processing agreement | Backend services, the content catalogs, delivering downloads |
| Cloudflare | Processor, under a data processing agreement | Content delivery, protection against attacks, serving this website |
Apart from the providers above and in section 5, we disclose data only where the law requires it, or where we need to establish, exercise, or defend a legal claim. Section 11 explains what "selling" and "sharing" mean for the advertising described here, because under US state law those words cover more than an exchange of money.
One boundary worth stating. Our processors act on our instructions and are bound by contract. The advertising partners are not processors — each decides for itself what it does with an ad request, is its own controller for that, and answers for it under its own privacy policy. We choose who is in the mediation stack and we can remove a partner, but we do not control and are not responsible for what an independent controller does with data once it has received it.
7. Sending data outside the EU
Our providers and advertising partners are spread across the world, and several process data outside the European Economic Area — most in the United States, some elsewhere, including countries the European Commission has not found to offer an adequate level of protection.
Where the recipient is certified under the EU–US Data Privacy Framework, the European Commission's adequacy decision of 10 July 2023 applies, and the transfer needs no further authorization.
Otherwise we rely on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, together with technical and organizational measures such as encryption in transit. You can ask us for a copy of the clauses at the address in section 15.
8. How long we keep data
We keep each kind of data only as long as the purpose it was collected for requires. Nothing is kept indefinitely:
- Crash reports: 90 days.
- Analytics: up to 14 months, after which the underlying records expire automatically.
- Server, download and CDN logs: up to 30 days, then deleted.
- Attribution data: up to 24 months.
- Purchase records: for as long as the unlock can be restored, then as long as German commercial and tax law requires.
- Advertising data: held by each partner under its own retention rules. Resetting your advertising ID severs the link to your device.
- Support email: kept until your request is resolved and then deleted, unless German commercial or tax law (§ 257 HGB, § 147 AO) requires us to keep the correspondence for 6 or 10 years.
9. Children and mixed audiences
Minecraft has a young audience, and so do we. Our apps are declared to Google Play as reaching a mixed audience — children as well as older users — and that carries specific obligations we follow.
The apps ask your age once, on a neutral age screen at first start, and remember the answer on your device. We do not send that number anywhere.
Anyone who gives an age under 18 is treated as a child for advertising. For that user the apps only ever request non-personalized ads and set the child-directed and under-age-of-consent flags on every ad request, so no advertising ID is used to personalize anything. That is stricter than either COPPA or Art. 8 GDPR requires.
Art. 8 GDPR sets the age at which a child can consent on their own behalf. In Germany that age is 16. Elsewhere in the EU it ranges from 13 to 16. Below that age, consent has to come from whoever holds parental responsibility.
In the United States, COPPA applies to children under 13. We ask for no name, no email address and no account from anyone, so we hold nothing that identifies a child. What a child's device does send is the diagnostic and attribution data described in section 4, and it sends it from app start — before the age screen is answered, as explained in section 5. After the answer, no advertising identifier is used to personalize anything for a user under 18. The retention periods in section 8 are the written retention policy COPPA requires: we state the purpose each category is collected for, we delete it at the end of the period, and we keep nothing about a child indefinitely.
If you are a parent or guardian and you want to know what we hold about your child, or you want it deleted, email us at the address in section 15. Exercising these rights costs nothing, and section 10 explains how we handle a request and the limits that apply to it.
10. Your rights
Under the GDPR you have the following rights, free of charge:
- Art. 15 — Access. Ask what we process about you and get a copy.
- Art. 16 — Rectification. Have inaccurate data corrected.
- Art. 17 — Erasure. Have data deleted where there is no longer a reason to keep it.
- Art. 18 — Restriction. Have processing paused while a dispute is resolved.
- Art. 20 — Portability. Receive data you gave us in a machine-readable format.
- Art. 21 — Objection. Object at any time to processing based on our legitimate interest, on grounds relating to your particular situation.
- Art. 7(3) — Withdrawal. Withdraw consent at any time, as described in section 5.
One practical limitation, which we would rather explain than leave you to discover. Almost everything we process is pseudonymous: we hold no name, no email address, and no account for you. Art. 11 GDPR covers this case — where we genuinely cannot identify you, we cannot answer an access or deletion request from a bare description, and we are not required to collect more data just so that we could. If you can give us the identifier involved, such as your advertising ID, we can act on it.
Three further points the GDPR itself provides for, so that you know where you stand. Where we have reasonable doubts about who is asking, we may ask for what we need to establish that it is you (Art. 12(6)). We answer within one month, and may extend that by up to two further months where a request is complex or where there are several of them, telling you within the first month if we do (Art. 12(3)). And where a request is manifestly unfounded or excessive, particularly because it repeats, we may charge a reasonable fee or decline to act, and we will say why (Art. 12(5)).
Asking us to delete something we are required to keep — accounting records, for example — is the one case where we will say no and point you at the retention periods in section 8.
You can also lodge a complaint with a supervisory authority — in your country of residence, your place of work, or where you think the infringement happened. Ours is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
https://www.lfd.niedersachsen.de
11. US state privacy rights
If you live in California, Colorado, Connecticut, Texas, Utah, Virginia, or another state with comparable privacy legislation, this section applies to you.
In the past twelve months we have collected these categories of personal information: identifiers, including device identifiers, advertising identifiers, and IP addresses; commercial information, meaning the fact of a purchase; internet and network activity, meaning in-app events and ad interactions; coarse geolocation at country or region level; and inferences drawn for advertising, such as interest categories. We collect no sensitive personal information as the CPRA defines it.
We want to be exact about one word. We do not trade your data for money. But personalized advertising through the partners in section 5 is "sharing" for cross-context behavioral advertising under the CPRA, "targeted advertising" under the other state laws, and — because those partners use the data for their own purposes and pay us for the inventory — it also meets the CPRA's broad definition of a "sale". We say so plainly rather than rely on a narrow reading.
You have the right to know what we collect, to have it deleted, to have it corrected, and to opt out of that selling and sharing. The routes in section 5 are how you opt out today, and emailing the address in section 15 works for any of these rights. We will not give you a worse experience for exercising any of them — the apps work the same either way. An authorized agent may act for you with written permission, and you may appeal a refusal by replying to our decision.
Minors are a separate case, and we go further than the statutes do. California requires opt-in before selling or sharing the personal information of a consumer under 16, and several states now restrict targeted advertising to anyone under 18. We do not knowingly sell or share the personal information of a user who tells us they are under 18 at all, and the child-directed flags described in section 9 are applied to every ad request from that user.
12. Automated decision-making
We make no decisions about you by automated means that produce legal effects or similarly significantly affect you, within the meaning of Art. 22 GDPR. Ad personalization is profiling for advertising, and it happens only where you have consented to it.
13. Security
Data travels over encrypted connections, access to our systems is restricted to the people who need it, and our providers are bound by data processing agreements. We hold no accounts, no passwords and no payment details, so there is no credential store to breach. No method of transmission or storage is completely secure, and we do not claim otherwise.
14. Changes to this policy
We update this policy when what we do changes, and the version and date at the top always reflect the current text. Where a change is material we will give reasonable notice before it takes effect — normally at least 30 days, in the apps or on this page — unless a change has to take effect sooner because the law or a provider requires it. Where a change needs your consent, we will ask you again rather than assume it.
15. Contact us
Privacy and legal: [email protected]
Product support: [email protected]