Overview
Bloom Client is an independent, open-source Minecraft launcher and related account service operated by Parks. This policy explains what information is handled when you visit bloomclient.org, sign in to a Bloom account, or use a Bloom feature that connects to Bloom's servers.
Bloom does not sell personal information, run behavioral advertising, or use Google or GitHub account data to build advertising profiles.
Information collected
Account information
When you choose Google or GitHub sign-in, Bloom receives the basic profile information authorized by that provider: your name, email address, profile image, provider name, and provider account identifier. Bloom stores this information so it can create your account, show your profile, and recognize linked sign-in methods.
Authentication and security information
Bloom stores account sessions, sign-in timestamps, session expiration data, IP address, and browser or device user-agent information. Secure session cookies keep you signed in. Provider access and refresh tokens may be stored when required for sign-in or account linking; those tokens are encrypted at rest.
Information you submit
If you use a server-backed Bloom feature, Bloom may store the information needed to provide it—for example, a shared pack manifest, a cosmetic you upload, an account preference, or information included in a support request. Bloom does not upload your general Minecraft files or local launcher data unless a feature clearly asks you to submit specific information.
Local client information
Instances, settings, logs, Java selections, and AutoTune benchmark results are normally kept on your computer. Microsoft and Minecraft credentials are handled by the desktop client and are not the credentials used for Bloom website accounts.
Google user data
Bloom requests only the OpenID Connect identity scopes needed for sign-in: basic profile information and email address. Bloom uses that data only to create or access your Bloom account, display your account identity, secure sessions, and let you connect Google as a sign-in method.
Bloom does not request Google Drive, Gmail, Contacts, Calendar, or other unrelated Google data. Google user data is not sold, used for advertising, or transferred for unrelated purposes. Disconnecting Google removes that sign-in connection when another sign-in method remains available; deleting your Bloom account removes the Bloom account data described below.
How information is used
- Authenticate you and maintain secure sessions.
- Display and update your Bloom account profile.
- Link or unlink sign-in providers only when you request it.
- Operate features you deliberately use, such as pack sharing or cosmetics.
- Prevent abuse, enforce rate limits, investigate failures, and protect the service.
- Respond to support requests and important account or policy questions.
- Maintain, debug, and improve Bloom's reliability.
Retention and deletion
Account records are kept while your account is active. Sessions expire automatically and can be revoked from the dashboard. Operational security logs may be retained for a limited period to investigate abuse or service failures. Backup copies may remain for a reasonable recovery period before being overwritten.
You can delete your Bloom account from the dashboard. Account deletion removes the active account and its sign-in connections from Bloom's account database. Data controlled by Google, GitHub, Microsoft, Mojang, Modrinth, or another third party must be managed with that provider. Public material you independently posted to GitHub or Discord is also controlled by that service.
Security
Bloom uses HTTPS, secure HTTP-only cookies, encrypted OAuth tokens, provider authorization-code flows with PKCE, rate limits, and restricted server storage. No system is completely secure, so Bloom cannot guarantee that unauthorized access will never occur. Do not send passwords, Microsoft access tokens, signing keys, or other secrets through public support channels.
Your choices
- Choose whether to sign in with Google or GitHub.
- Review connected providers and active account sessions in the dashboard.
- Disconnect a provider when another sign-in method remains connected.
- Sign out, revoke other sessions, or delete your account.
- Decline optional server-backed features and keep using local launcher features where available.
For access, correction, or deletion questions that cannot be handled from the dashboard, use the contact method below.
Children's privacy
Bloom accounts are not directed to children under 13. If you are not old enough to manage an online account under the laws that apply to you, use Bloom only with permission from a parent or legal guardian. If Bloom learns that personal information was collected from a child without required consent, it will be deleted.
Changes to this policy
This policy may change as Bloom adds real features, providers, or legal requirements. Material changes will be posted here with a new effective date. The policy will not claim that a feature collects or protects information in a way the implementation does not support.
Contact
Privacy questions and requests can be submitted through the Bloom Support page or the project's public issue tracker. Never include account tokens, passwords, or other secrets in a public issue.