Privacy policy
Last updated: 2026-09-29
Bloomery is a launcher that runs on your own computer. There is no Bloomery account, no Bloomery server, and no analytics. We do not collect, receive or store your data. This page describes exactly what the application keeps on your machine and which third-party services it talks to when you use it.
1. What Bloomery stores on your computer
Everything Bloomery keeps is written to your local configuration directory (~/.config/bloomery
on Linux and macOS, %USERPROFILE%\.config\bloomery on Windows) and to
the game folder you choose.
| File | Location | Contents and purpose |
|---|---|---|
setting.json |
configuration directory | Your game folders, the selected account, the Java list, download source, proxy and window/memory preferences. |
accounts.json |
configuration directory |
Account list. Offline accounts store a name and an optional UUID. A
Microsoft account stores the game name, UUID and XUID returned by
Minecraft services, an OAuth refresh token, and a short-lived Minecraft
access token with its expiry. The file is created with owner-only
permissions (0600).
|
logs/latest.log |
configuration directory | Diagnostics for troubleshooting: the command that ran, library and asset counts, download summaries. Tokens and passwords are never written to the log. |
versions/, libraries/, assets/
|
your game folder | The game itself: version manifests, the client jar, libraries, native libraries, assets and your worlds. |
2. What leaves your computer, and to whom
Bloomery contacts only the services needed to install and start the game. No data is sent to the authors of Bloomery.
| Service | Why |
|---|---|
login.microsoftonline.com |
Sign-in with the OAuth 2.0 device authorization grant, and refreshing the sign-in later. Your credentials are entered on Microsoft's page, never in Bloomery. |
user.auth.xboxlive.com,
xsts.auth.xboxlive.com
|
Exchange the Microsoft sign-in for an Xbox Live token and an XSTS token. |
api.minecraftservices.com |
Obtain a Minecraft access token and read your profile (game name, UUID) and game ownership. |
piston-meta.mojang.com,
piston-data.mojang.com,
libraries.minecraft.net,
resources.download.minecraft.net
|
Version list, client jar, libraries, native libraries and game assets. |
| BMCLAPI mirror (optional) | Only if you switch the download source to the mirror in your settings. |
| Your own HTTP proxy (optional) | Only if you configure one; Bloomery sends the same requests through it. |
3. What Bloomery never does
- It never asks for, sees or stores your Microsoft password.
- It never writes access tokens, refresh tokens or device codes to log files.
- It collects no telemetry, no usage statistics and no crash reports.
- It contains no advertising and no third-party tracking code.
- It sells, rents or shares your data with anyone — there is no data on our side to share.
- This website loads no external fonts, scripts, images or analytics.
4. Deleting your data
-
bloomery auth logout <name> --type microsoftremoves the stored account, including its tokens. - Deleting the configuration directory removes every setting, account and log.
- You can also revoke Bloomery's access to your Microsoft account at account.live.com/consent/Manage.
-
npm uninstall -g bloomeryremoves the application; deleting your game folder removes the installed game data.
5. Children
Bloomery is not directed at children under the age of digital consent in their country. Minecraft accounts and their use are governed by Microsoft's and Mojang's own terms.
6. Changes to this policy
This policy is versioned with the source code in the Bloomery repository; the date at the top changes when it does. Material changes are noted in the release notes.
7. Contact
Questions about this policy, or requests to delete data held about you: xiangyuanhulian@outlook.com. You can also open an issue in the project repository.
If you write to us, we receive your email address and the message, and use them only to reply. There is no mailing list and no other use.