PRIVACY & PRODUCT BOUNDARIES
Clear answers,
before you connect.
Loomlight’s catalog works without login. If you choose to connect Bungie or sync saved looks, here is exactly what changes.
01Can you use Loomlight without connecting Bungie?
Yes. The searchable shader and universal ornament catalog works without a Bungie connection. Connecting is optional and adds ownership filters, equipped-fashion summaries, cross-browser saved-look sync, and explicitly confirmed experimental appearance changes.
02What does Loomlight receive when you connect Bungie?
Bungie’s OAuth exchange gives Loomlight an opaque Bungie membership identifier plus access and refresh tokens. When you use a connected feature, Loomlight requests only the profile components needed for that feature, such as collectible ownership or equipped armor and sockets.
Bungie’s membership response can also contain profile fields such as a display name. Loomlight does not select, show, log, or save the display name.
03Where are your Bungie tokens and membership identifier kept?
They are sealed together in an encrypted, secure, HTTP-only session cookie in your browser. Browser JavaScript cannot read that cookie, and Loomlight does not store the tokens or raw membership identifier in its synced-looks database. The cookie lasts for at most 90 days and may end sooner if Bungie’s refresh token expires or you disconnect.
04What is stored when you save or sync a look?
Saved looks are local to your browser by default. They contain the name you give the look and public catalog data such as armor, ornament, and shader hashes, names, icons, class, and slot.
If you deliberately enable sync, Loomlight stores the same privacy-safe look data in its database so another connected browser can retrieve it. Sync is limited to 50 live looks per connected account.
05How does Loomlight associate synced looks with you?
The server derives a one-way owner key from the opaque membership identifier returned by Bungie OAuth and a Loomlight-only secret. The database receives that derived key—not your display name, Bungie name, raw membership identifier, or OAuth tokens.
This key is scoped to Loomlight’s saved-look sync. It is not a public username and is not sent to the browser.
06What do disconnect, stop syncing, and delete synced copies do?
- Disconnect Bungie clears the Loomlight session cookie.
- Stop syncing leaves the current browser’s local looks and the existing server copies in place.
- Delete synced copies removes the server copies while keeping the current browser’s local looks.
Clearing this site’s browser storage can also remove the local copies, so export any looks you want to keep before clearing site data.
07Can Loomlight change your Guardian in game?
Only when you choose an owned cosmetic, review the requested change, and confirm it. Loomlight uses Bungie’s experimental appearance endpoint and resolves character and item identifiers on the server for that request; it does not return or save them.
Applying a whole look is sequential, not atomic. Some slots may succeed while another fails, and Loomlight reports those partial results without claiming a rollback.
08Are Loomlight’s rough previews exact?
No. Rough WebGL previews are directional experiments and appear only for renderer profiles validated against an in-game reference. When a profile has not been validated, Loomlight uses official Bungie icons and explains that a rough preview is unavailable.
09Is Loomlight affiliated with Bungie?
No. Loomlight is an independent project. Destiny, Destiny 2, and Bungie names and imagery belong to their respective owners. Loomlight is not made, endorsed, or supported by Bungie.