Privacy policy
Effective date: 8 August 2026
This policy explains how BonusLoot collects and uses information in the BonusLoot Windows application and related account service. BonusLoot is operated by the BonusLoot team. Questions can be sent to cicibebe207168313@gmail.com.
Information we process
- Account information: email address, a display name when supplied, password hash, account session records, device identifier, device name, and application version.
- Site credentials: usernames and passwords that you enter for supported sites. These are stored locally in a Windows DPAPI-protected vault and are not sent to BonusLoot servers.
- Google account connection: when you enable email 2FA, BonusLoot requests the Gmail read-only scope. We use the connection only to find supported verification codes in your mailbox. We do not send, edit, or delete email.
- Operational information: membership, device activation, security, update, and automation activity needed to provide the service and protect accounts.
How Gmail access works
Google access and refresh tokens are kept in the local DPAPI vault. A short-lived access token is passed to the local worker only when an email 2FA workflow runs. BonusLoot does not store Gmail messages or forward mailbox contents to the licensing API.
Why we use information
We use account and device data to authenticate you, enforce membership and device limits, issue short-lived runtime leases, deliver updates, provide support, and detect abuse. We use Gmail read-only access only for the email 2FA feature you explicitly enable.
Sharing and retention
We do not sell personal information. Account, membership, security, and audit records are retained while needed to operate the account, meet legal obligations, resolve disputes, and prevent abuse. Local site credentials and Google tokens remain under your Windows user profile until you remove them or uninstall the application. We may use infrastructure providers to host the account service, subject to access controls.
Your choices
You can disconnect Google from BonusLoot Settings, remove saved site credentials, log out, or request account information or deletion through support. You can also revoke BonusLoot access from your Google Account security settings.
Changes
We may update this policy as the service changes. The effective date above will be updated when a material change is published.