PML 2 Privacy Policy
Last updated: October 1, 2026
RYCB Studio ("we") respects and protects the privacy of our users. This policy explains in detail how we collect, use, store and protect your personal information. Please read it carefully before using PML 2 (Portal ME Frp Launcher 2, "the Software").
Important notice
Note: We use Sentry for error tracking and performance monitoring in order to improve the stability of the Software. If you want to read the privacy policy of 幻缘映射 ME Frp, please visit ME Frp (幻缘映射) Privacy Policy.
1. What we collect
1.1 Personal data
- Registration / sign-in information (such as user name and email address)
1.2 Device and usage data
- Device identifiers (such as IMEI, MAC address) , IP address, operating system version
- How the Software is used (such as feature clicks, session duration, error logs)
- Telemetry collected through Sentry: when the Software errors or crashes we may collect:
- Device model and operating system version
- Crash stacks and error logs
- Application version and runtime environment information
This data is stored on Sentry's servers. It is collected to improve stability and does not include sensitive information such as your account credentials or tunnel contents.
1.3 Other data
- Content you submit yourself (such as feedback or uploaded files)
2. How we use information
The information we collect is used to:
- Provide the core features (such as account verification, data sync and tunnel management)
- Improve the experience (such as bug fixes, feature improvements and UI refinements)
- Security and compliance (such as authentication, fraud prevention and anomaly detection)
- Statistical analysis, or, after anonymisation, business decisions
- Telemetry collected through Sentry is used exclusively for error monitoring and performance analysis, helping us locate and fix problems in the Software
3. Sharing and disclosure
We do not sell user data, but we may share it:
- With your explicit consent
- To meet legal obligations or respond to a lawful request from a government body
- When necessary to work with third-party providers (such as cloud services or payment platforms), who must follow equivalent privacy standards
- With one specific third party (Sentry): to provide error monitoring we share the necessary device information and error logs with Sentry.io (Functional Software, Inc.). Sentry acts as a data processor; its servers are located in the European Union and it complies with the applicable data protection regulations. See the Sentry privacy policy for details.
4. Storage and security
4.1 Where and how long
- Our own business data is stored mainly on servers in mainland China, kept for the shortest period the law requires
- Telemetry collected through Sentry is stored on servers in the European Union (EU), subject to Sentry's standard data retention policy
4.2 Security measures
- We use encryption, access control and similar measures to protect data
- We maintain data security management rules and operating procedures
- Note, however, that the internet is never 100% secure and we cannot guarantee absolute security
5. Your rights
You have the right to:
- Access, correct or delete your personal information (some data cannot be deleted because of compliance requirements)
- Withdraw consent or restrict processing (this may affect some features). You can disable telemetry collection in the Software settings
- Submit a request by email; we will respond within 7 days
Contact: [email protected] | [email protected]
6. Third-party services
The Software may embed third-party services whose privacy policies are independent of ours; we recommend reading them separately. The third-party services we use are mainly open-source libraries, plus Sentry (a commercial service) for error monitoring.
6.1 Open-source libraries used
| Name | Licence | Website | Description |
|---|---|---|---|
| .NET | MIT | Website ‖ .NET Foundation ‖ GitHub | The runtime the Software is built on |
| Avalonia UI | MIT | Website ‖ GitHub | The UI framework |
| Downloader | MIT | GitHub | Multi-threaded downloads inside the app |
| FluentAvalonia | MIT | GitHub | The theme library |
| RestSharp | Apache 2.0 | Website ‖ GitHub | Network communication and API access |
| Markdown.AIRender (modified and published by us) | MIT + redistribution | Original GitHub repo | Renders Markdown content (such as announcements) |
| Message.Avalonia | MIT | GitHub | In-app message display |
| AvaloniaEdit | MIT | GitHub | Syntax highlighting for configuration files |
| LiveCharts2 | MIT | Website ‖ GitHub | Line charts (for example traffic statistics) |
| NPinyin | MIT | GitHub | Chinese characters to pinyin |
| YamlDotNet | MIT | GitHub | Reads YAML files |
| Tomlyn | BSD-2-Clause | GitHub | Reads TOML files |
6.2 Libraries we develop ourselves
| Name | Status | Description |
|---|---|---|
| MEFrpLauncherX.Core | Open source | The core library, including network requests and other core code |
| MEFrpLauncherX.Fonts | Open source | The font library, containing every font the app ships (HarmonyOS Sans, JetBrains Mono and others). Note: each of those fonts carries its own licence |
| RYCB.PML2.Extensions.MinecraftExtension | Open source | An extension providing Minecraft-related support |
| RYCB.PML2.Mixin.TerminalHelper | Open source | An extension providing console-related support |
| RYCB.PML2.MEFrpCaptchaLib | Closed source | The CAPTCHA library used for invisible human verification. Note: its code is obfuscated; any reverse engineering of this library is prohibited |
| SecretLib | Closed source | The plugin core library, used to unpack and package plugins. Note: its code is obfuscated; any reverse engineering of this library is prohibited. All related intellectual property belongs to us |
6.3 Error monitoring service
| Name | Type | Privacy policy | Description |
|---|---|---|---|
| Sentry | Commercial | Privacy policy | Collects crash reports, error logs and performance metrics so we can find and fix problems quickly |
6.4 Certificate assistant (new in 26.4)
The "Certificate assistant" is an optional local tool in PML 2 that requests SSL certificates for domains you own, so you can create HTTPS tunnels. It is unrelated to the certificate service of 幻缘映射 ME Frp.
Processed on your machine, never uploaded to us:
- The domain and subject alternative names (SANs) you enter
- Your ACME account email address
- The issued certificate (
fullchain.pem) and private key (privkey.pem) - Your DNS provider API token / key (encrypted and stored locally when automatic verification is enabled)
Third parties involved (only as required by the issuance flow):
| Name | Type | Privacy policy | Notes |
|---|---|---|---|
| Let's Encrypt | Non-profit CA | Privacy policy | Receives the domain and ACME account email to complete domain validation and issuance; its Staging environment is used by default |
| The DNS provider you choose | Depends on your choice | Governed by that provider's policy | Only when you enable automatic DNS verification, your machine submits or deletes the TXT record through its API |
| lego (ACME client) | Open-source tool | Repository | Downloaded to your machine on demand; its output and account key stay in a local directory |
6.4.1 DNS account vault (26.4 phase B)
To support "one-click automatic requests", the certificate assistant can store DNS provider credentials as a locally encrypted DNS account:
- Location and encryption: the account file is
%AppData%/PML2/certs/dns_accounts.dat, encrypted with AES-256; the encryption key lives in%LocalAppData%/PML2/keys/and is bound to the current Windows user by DPAPI, so copying the files to another machine or user cannot decrypt them. - Never transmitted: the token / key is not uploaded to ME Frp, RYCB Studio or any third-party service, and is never written to logs, crash reports or analytics.
- Process isolation: during issuance the credential is injected into the local lego child process as an environment variable only, and becomes invalid when that process exits. Credentials shown in the UI or logs are always masked.
- Least privilege: we recommend creating a dedicated token following each provider's least-privilege
guidance (for Cloudflare,
Zone → DNS → Editis enough). Never enter an account password or a global API key. - Delete at any time: you can delete any account under "Settings → DNS accounts"; certificates already issued keep working.
We do not collect, upload or retain your domains, email address, tokens or certificate private keys through the certificate assistant; the information above is used only to complete issuance on your machine. The related logs are sanitised: ordinary logs contain neither tokens nor private key paths.
7. Cookies and similar technologies
The Software does not use cookies or similar tracking technologies.
8. Protection of minors
We take the protection of minors' personal information seriously. If you are under 18, you must obtain written consent from a parent or legal guardian before using the Software.
9. Policy updates
We may revise this policy; updated versions are published on the official site, and continued use means you accept the changes.
For significant changes we will notify you by:
- Publishing a notice inside the Software
- Sending an explanation by email
- Posting an announcement on the official website
10. Contact us
If you have questions about this privacy policy, or wish to exercise your rights, contact us:
- Email: [email protected] | [email protected]
- Official website: https://www.rycb.tech/
We will reply within 7 business days of receiving your request.
11. Governing law and dispute resolution
The interpretation and application of this privacy policy, and any disputes arising from it, are governed by the laws of the mainland region of the People's Republic of China. If any dispute arises between you and us, we will first try to resolve it amicably; if that fails, either party may bring the dispute before the competent people's court where we are located.