Skip to policy
Bloom Client
The clientChangelogSupportTeamCommunity
Sign in
LEGAL

Privacy Policy

A direct explanation of the information Bloom uses to run accounts, the website, and connected client services.

Effective
October 6, 2026
Applies to
Bloom Client and bloomclient.org
On this page
OverviewInformation collectedGoogle user dataHow information is usedSharing and providersRetention and deletionSecurityYour choicesPolicy changesContact
Read the Terms of Service →
01

Overview

Bloom Client is an independent, open-source Minecraft launcher and related account service operated by Parks. This policy explains what information is handled when you visit bloomclient.org, sign in to a Bloom account, or use a Bloom feature that connects to Bloom's servers.

Bloom does not sell personal information, run behavioral advertising, or use Google or GitHub account data to build advertising profiles.

02

Information collected

Account information

When you choose Google or GitHub sign-in, Bloom receives the basic profile information authorized by that provider: your name, email address, profile image, provider name, and provider account identifier. Bloom stores this information so it can create your account, show your profile, and recognize linked sign-in methods.

Authentication and security information

Bloom stores account sessions, sign-in timestamps, session expiration data, IP address, and browser or device user-agent information. Secure session cookies keep you signed in. Provider access and refresh tokens may be stored when required for sign-in or account linking; those tokens are encrypted at rest.

Information you submit

If you use a server-backed Bloom feature, Bloom may store the information needed to provide it—for example, a shared pack manifest, a cosmetic you upload, an account preference, or information included in a support request. Bloom does not upload your general Minecraft files or local launcher data unless a feature clearly asks you to submit specific information.

Local client information

Instances, settings, logs, Java selections, and AutoTune benchmark results are normally kept on your computer. Microsoft and Minecraft credentials are handled by the desktop client and are not the credentials used for Bloom website accounts.

03

Google user data

Bloom requests only the OpenID Connect identity scopes needed for sign-in: basic profile information and email address. Bloom uses that data only to create or access your Bloom account, display your account identity, secure sessions, and let you connect Google as a sign-in method.

Bloom does not request Google Drive, Gmail, Contacts, Calendar, or other unrelated Google data. Google user data is not sold, used for advertising, or transferred for unrelated purposes. Disconnecting Google removes that sign-in connection when another sign-in method remains available; deleting your Bloom account removes the Bloom account data described below.

04

How information is used

  • Authenticate you and maintain secure sessions.
  • Display and update your Bloom account profile.
  • Link or unlink sign-in providers only when you request it.
  • Operate features you deliberately use, such as pack sharing or cosmetics.
  • Prevent abuse, enforce rate limits, investigate failures, and protect the service.
  • Respond to support requests and important account or policy questions.
  • Maintain, debug, and improve Bloom's reliability.
05

Sharing and service providers

Bloom shares information only when needed to provide the service, follow your direction, protect Bloom or its users, or comply with law. Current infrastructure and integration providers may include:

  • Google and GitHub for the sign-in method you choose.
  • Cloudflare for DNS, proxying, transport security, and abuse protection.
  • Bloom's VPS hosting provider for the website account service and server-backed features.
  • Microsoft, Mojang, Modrinth, and GitHub when the client makes a request to those services for a feature you use.

Those providers process information under their own terms and privacy policies. Bloom does not give providers more information than is reasonably needed for the relevant request.

06

Retention and deletion

Account records are kept while your account is active. Sessions expire automatically and can be revoked from the dashboard. Operational security logs may be retained for a limited period to investigate abuse or service failures. Backup copies may remain for a reasonable recovery period before being overwritten.

You can delete your Bloom account from the dashboard. Account deletion removes the active account and its sign-in connections from Bloom's account database. Data controlled by Google, GitHub, Microsoft, Mojang, Modrinth, or another third party must be managed with that provider. Public material you independently posted to GitHub or Discord is also controlled by that service.

07

Security

Bloom uses HTTPS, secure HTTP-only cookies, encrypted OAuth tokens, provider authorization-code flows with PKCE, rate limits, and restricted server storage. No system is completely secure, so Bloom cannot guarantee that unauthorized access will never occur. Do not send passwords, Microsoft access tokens, signing keys, or other secrets through public support channels.

08

Your choices

  • Choose whether to sign in with Google or GitHub.
  • Review connected providers and active account sessions in the dashboard.
  • Disconnect a provider when another sign-in method remains connected.
  • Sign out, revoke other sessions, or delete your account.
  • Decline optional server-backed features and keep using local launcher features where available.

For access, correction, or deletion questions that cannot be handled from the dashboard, use the contact method below.

09

Children's privacy

Bloom accounts are not directed to children under 13. If you are not old enough to manage an online account under the laws that apply to you, use Bloom only with permission from a parent or legal guardian. If Bloom learns that personal information was collected from a child without required consent, it will be deleted.

10

Changes to this policy

This policy may change as Bloom adds real features, providers, or legal requirements. Material changes will be posted here with a new effective date. The policy will not claim that a feature collects or protects information in a way the implementation does not support.

11

Contact

Privacy questions and requests can be submitted through the Bloom Support page or the project's public issue tracker. Never include account tokens, passwords, or other secrets in a public issue.

© 2026 Bloom Client
PrivacyTermsSupport