This explains what Ossa Client collects, why, who else is involved, and how to see or delete your data. We try to keep as little as we can.
The short version
- We only get your Discord ID, name and profile picture from Discord. No email, no messages, no servers.
- No ads, no analytics, no tracking, and we never sell your data.
- Payments go through Stripe. We never see your card.
- Shared mod packs are public, along with your Discord name and picture.
- Most of what the app works with stays on your computer.
- Ask in our Discord and we’ll send you your data or delete it.
The short version is here to help. The full text below is what actually applies.
01Who we are
Ossa Client is made by SuperCatCraze (“we”, “us”). We decide what data Ossa Client collects and why, so we’re responsible for it. This policy covers the Ossa Client desktop app, the website at bonelabcamera.com, Ossa+ and Ossa Mods. You can reach us in the Ossa Client Discord or by email at [email protected].
02What we collect
When you sign in with Discord, Discord only gives us your basic profile. We ask for the identify permission and nothing else. Here’s everything we keep:
| What | Why we keep it |
|---|---|
| Your Discord user ID, display name and profile picture link | To know which account is yours and show who’s signed in |
| When you first and last signed in | To run testing and tidy up old accounts |
| Your role (like tester or Ossa+), and whether you’re in our Discord server | To decide what you can use, and to give you the matching roles in our server |
| That you asked for access, when, and the message you wrote | So we can review requests |
| A ban, when it happened and why | To keep people who broke the rules out |
| Ossa+ status, start and end dates, and how you got it (paid, gift or given by us) | To turn Ossa+ on and off at the right times |
| Your Stripe customer and subscription IDs and payment amounts | To connect your payments to your account and let you manage billing. We never get your card details |
| Gift codes you bought, and the Discord name and ID of whoever claimed them | To make gifts work and show you who used yours |
| Creator codes, and the sales made with them | To run creator codes. Each sale records the buyer’s Discord ID and name unless they chose to hide it |
| Your synced settings and mod packs (Ossa+ only) | To put your look, avatar settings, favorites, Ossa Mods choices and mod packs on every PC you use |
| Mod packs you share, and who saved or installed them | To show the pack, count saves and installs, and let people find packs |
| A scrambled ID for each computer you use Ossa Mods on, and when you last used it | To limit Ossa Mods to 3 computers per account every 30 days. It’s worked out from an ID Windows gives your PC and can’t be turned back into it. It’s deleted after 30 days without use |
| Messages we send you in the app (like “your pack was approved”) | So you can read them |
| Feedback you send from the support page: what you wrote, any screenshot you added, and your Discord ID and name if you were signed in | So we can read it and act on it. It’s kept until we delete it, or you ask us to |
We don’t collect your email address, your Discord password, your servers or messages, your card number, or your precise location. We don’t store IP addresses, apart from a scrambled one kept for an hour when you send feedback, to stop spam. We don’t use analytics, ads or tracking.
03How we use it
We only use your data to run Ossa Client:
- To give you what you signed up for: signing in, testing access, Ossa+, gifts, sync and sharing packs.
- To keep Ossa Client safe and fair: stopping piracy of Ossa Mods, abuse, fraud and rule breaking, and moderating shared packs.
- To follow the law: for example, keeping records of payments.
If you’re in the EU or UK, our legal reasons are: performing our agreement with you (the first point), our legitimate interest in keeping Ossa Client safe (the second), and legal obligations (the third). We don’t sell your data, and we don’t use it for ads or profiling.
04What other people can see
- Shared mod packs are public. Anyone with a pack’s link can see its name, description, cover, mod list and how many people saved and installed it, plus your Discord name and profile picture.
- Signed-in testers can see the names and pictures of people who saved or installed a shared pack.
- If you buy a gift, you’ll see the Discord name of whoever claims it.
- If you use a creator code, the creator sees your Discord name, unless you tick “Hide my name from them”.
- In our Discord server, other members can see the roles Ossa Client gives you, like Tester or Ossa+.
05Cookies
The website only uses cookies it needs to sign you in. There are no analytics or advertising cookies, so we don’t show a cookie banner.
| Cookie | What it does |
|---|---|
| cz_session | Keeps you signed in, for up to 14 days |
| cz_accounts | Remembers up to 5 accounts signed in on this browser, for up to 60 days |
| cz_oauth, cz_next, cz_appport | Used during a Discord sign-in. Gone within 10 minutes |
The website also saves a couple of small preferences in your browser, like which view you picked. Those never leave your browser.
06Services we use
These companies handle data for us or connect to Ossa Client. Each has its own privacy policy.
| Service | What for |
|---|---|
| Cloudflare | Hosts the website and stores account data. Like any host, it sees your IP address when you visit |
| Discord | Sign-in, and roles in our server |
| Stripe | Takes payments for Ossa+ and gifts. Stripe collects your payment details and email address itself |
| GitHub | Where app updates and BoneLib are downloaded from |
| Google Fonts and jsDelivr | Fonts and the 3D camera on the website. They see your IP address when those files load |
| Microsoft | Where .NET 6 is downloaded from, only if your mods need it |
| Thunderstore, mod.io and Nexus Mods | The app talks to them when you browse or download their mods, using your own mod.io or Nexus account if you link one |
07The desktop app
Most of what the app works with stays on your computer and is never sent to us:
- your settings, mod packs, which mods it installed, avatar pictures, backups of your BONELAB saves, and its logs;
- your sign-in tokens, so you don’t have to sign in every time;
- your mod.io and Nexus Mods keys, if you add them, encrypted with Windows’ own protection;
- your BONELAB folder, mods and save data, which it reads so it can show and manage them. It can also read r2modman and Thunderstore Mod Manager profiles, so you can bring them over.
It sends us:
- sign-in checks and, if you have Ossa+, your synced settings and mod packs;
- when you play with Ossa Mods, the scrambled computer ID described above, and a one-time key made from it that we use and don’t keep;
- update checks, when it opens and every few minutes while it’s open.
To remove everything the app keeps, uninstall it and delete its data folder.
08How long we keep it
- Account data: for as long as your account is in use, or until you ask us to delete it.
- Computer IDs: 30 days after you last used Ossa Mods on that PC.
- Synced settings: kept if Ossa+ ends, so they’re there if you come back, until you ask us to delete them.
- Shared packs: until you or we delete them.
- Payment records: as long as the law requires for tax and accounting. Stripe keeps its own records under its policy.
- Bans: as long as needed to keep the ban in place.
09Your choices and rights
You can ask us, in the Ossa Client Discord or by email at [email protected], to:
- send you a copy of the data we have about you;
- fix anything that’s wrong;
- delete your account and data. This also removes your shared packs. Cancel Ossa+ first. We may keep what the law requires, like payment records;
- stop using your data for something you object to.
We’ll answer within 30 days. We’ll check that it’s really you by talking to you from the Discord account that’s linked to Ossa Client.
You can also sign out at any time, and remove Ossa Client from Discord in User Settings, then Authorized Apps.
If you’re in the EU or UK, you can also complain to your local data protection authority. If you’re in California or another US state with privacy laws, you have the rights your state gives you. We don’t sell or share your personal information for advertising, and we won’t treat you differently for using your rights.
10Keeping it safe
Sign-in cookies can’t be read by page scripts, sessions are signed, computer IDs are scrambled, and card details only ever go to Stripe. Only SuperCatCraze can see the account list. No system is perfectly secure, though. If something goes wrong that affects your data, we’ll tell you, as the law requires.
11Where your data is
Ossa Client is run from the United States, and Cloudflare, Discord and Stripe may store data in the US and other countries. If you use Ossa Client from somewhere else, your data is moved to and stored in those countries, which may have different privacy laws from yours.
12Children
Ossa Client isn’t for children under 13, and we don’t knowingly collect data from them. If you’re a parent or guardian and think your child under 13 has an account, contact us in the Ossa Client Discord or by email at [email protected] and we’ll delete it. Anyone under 18 needs a parent or guardian to buy Ossa+ for them.
13Changes to this policy
If we change what we collect or how we use it, we’ll update this page and the date at the top. For bigger changes, we’ll also say so in the app, on the website or in the Discord before they apply.
14Contact
Privacy questions and requests: Email [email protected], or ask in the Ossa Client Discord.
