Privacy Policy
Last updated September 17, 2026
This covers the CrazeLabs desktop app and the website at bonelabcraze.com. The short version: we keep the least we need to run sign-in and the tester list, we don't sell anything, and we don't use ads or trackers.
1. What we collect
When you sign in with Discord, Discord gives us your basic profile (the identify permission only). We keep:
| What | Why |
|---|---|
| Your Discord user ID | To know which account is yours |
| Your Discord display name and avatar link | To show who's signed in, in the app and on the site |
| When you first and last signed in | To run the tester list |
| Your role (free, tester, developer, admin) | To decide what you can use |
| That you asked for access, when, and the message you wrote, if any | So we can review requests |
We don't get your email address, your Discord password, your servers or your messages.
3. What the app keeps on your computer
These stay on your computer, in CrazeLabs' data folder. We never receive them:
- sign-in tokens for the accounts you've added, so you don't sign in every time;
- a mod.io access token, if you paste one in, encrypted with your operating system's own protection. If you link the mod.io sign-in BONELAB saved, CrazeLabs reads it when needed and doesn't copy it;
- your settings, mod packs, which mods CrazeLabs installed, avatar thumbnails, backups of your BONELAB save from before CrazeLabs changed it, and an update log.
CrazeLabs reads your BONELAB folder, its mods and its save data so it can show and manage them. That stays on your computer too.
4. Who the app talks to
- bonelabcraze.com (us): to check who's signed in and their role, and to check for and download updates.
- Discord: in your browser, when you sign in. Avatars load from Discord's image servers.
- Thunderstore: to list, show and download mods.
- mod.io: to browse, subscribe to and download mods, as your linked mod.io account. mod.io's own privacy policy covers what it does with that.
- GitHub: update files are downloaded from GitHub, which our update service points to.
Like any website, these services see your IP address when your computer connects to them.
5. Where it's kept and who can see it
Account data is stored with Cloudflare, which hosts the website. Only SuperCatCraze can see the account list. We don't sell, rent or share your data with anyone else, except when the law requires it.
6. How long we keep it
We keep your account data while your account is in use. If you ask us to delete it, we will, and you'll need to sign in again to use CrazeLabs.
7. Your choices
- See or delete your data: ask in the CrazeLabs Discord and we'll send you what we have or delete it.
- Sign out: in the app, use Sign Out in the account menu. On the site, use Sign out.
- Remove CrazeLabs' access to Discord: Discord, User Settings, Authorized Apps.
- Remove everything the app kept: delete CrazeLabs' data folder (CrazeLabs menu, Open Folder, CrazeLabs Data).
8. Children
CrazeLabs isn't for children under 13, and you need to be old enough to use Discord where you live. If we find out an account belongs to someone under 13, we'll delete it.
9. Changes
If we change what we collect or how we use it, we'll update this page and the date at the top, and say so in the app or the Discord if it's a big change.
10. Contact
Privacy questions go to the CrazeLabs Discord.
