Privacy & Data Storage
What MysticSuite stores, what other Suite users can see, and how each server-backed category works.
Last updated October 2, 2026 · Applies to MysticSuite
At a glance
The short version
MysticSuite offers three separately controlled categories of server-backed player data: Emotes, Cosmetics & Wardrobe, and Jobs Lifetime. Selected data is associated with your Minecraft UUID and current player name. Emote relay authentication still occurs while connected even if all three optional categories are disabled. Cosmetics and Wardrobe features are available only while the Cosmetics & Wardrobe category is enabled.
Read about Jobs Lifetime synchronization, Emotes and Cosmetics & Wardrobe, and the Wardrobe Vault. Changing a category has category-specific effects; see Retention and your choices below.
Jobs Lifetime synchronization
Jobs Lifetime synchronization is optional and is disabled by default. When enabled, the Suite server stores:
- Your Minecraft UUID and current player name
- The data-contract version and account creation and update timestamps
- A normalized server or realm key and your aggregate lifetime job earnings for that server
- For later earnings updates, a randomly generated event ID, server key, update amount, and server-received timestamp
The event ID lets the server recognize a retried update and avoid adding the same earnings twice. Consecutive local earnings may be combined into one pending update, so these records are synchronization events rather than a complete history of individual jobs.
The first time synchronization is enabled, existing client totals are uploaded only if the server has no Jobs Lifetime record for that Minecraft UUID. If a server record already exists, the server’s totals are treated as authoritative and are loaded by the client.
This feature does not send the job type, job experience, play duration, raw chat or action-bar message, coordinates, inventory, or account balance. Jobs Lifetime totals are not broadcast through the live multiplayer relay or shown to other Suite clients. However, the highest totals are shown on the public website scoreboard; see Public scoreboard.
Disabling synchronization stops fetching totals and sending new updates. It does not delete the server-side account, totals, or previously accepted update records. Unsent updates remain in the local configuration and may be uploaded if synchronization is enabled again.
Local Jobs Lifetime storage
The client also keeps lifetime totals, the synchronization preference, and any unsent update IDs, server keys, and amounts in the Minecraft instance’s Suite configuration. This local information remains when synchronization is disabled unless the user removes or resets the local configuration.
Public scoreboard
The MysticSuite website shows a public scoreboard of the top lifetime job earners. It is built from Jobs Lifetime synchronization records, so if you have enabled Jobs Lifetime synchronization and your total is among the highest, you may appear on it.
For each listed player, the scoreboard publicly shows:
- Your current Minecraft player name
- Your rank and aggregate lifetime job earnings for each server or realm key, and a combined total across them
- The server or realm key the total belongs to
The scoreboard does not show your Minecraft UUID, update history, timestamps, job type, balance, or any other stored data. It is read from the existing Jobs Lifetime records; no additional player data is collected to produce it. Scoreboard results are refreshed about once a minute.
Disabling Jobs Lifetime synchronization stops new updates but does not delete your stored total, so it does not by itself remove you from the scoreboard. To be removed from the scoreboard, contact Suite support through the official Discord link below.
Emotes and cosmetics
Emote preference synchronization is optional. Cosmetics & Wardrobe is a separate consent category: accepting it is required to use those features. When a category is enabled, the corresponding selected information is saved in the Suite database.
Emotes
- Minecraft UUID and current Minecraft player name
- Default forward movement style, backward movement style, and flying style
- Favorite emote IDs
- Contract version and last-updated timestamp
Only the latest configuration is kept; there is no history of preference changes in this backup.
Cosmetics & Wardrobe
- Minecraft UUID and current Minecraft player name
- Contract version and last-updated timestamp
- Up to 512 collected cosmetic entries
- Equipped cosmetic layers and whether equipped armor is hidden
- Global tool cosmetic defaults and specific held-item replacement rules
Each collected entry can include its cosmetic ID, armor or tool category, source item identity, display name, render anchor, and a serialized Minecraft ItemStack. That stack may contain its base item type, custom item ID (including ExecutableItems identifiers), custom model data, item model, display name, lore, enchantments, attribute modifiers, custom components, and metadata added by server plugins.
The collected-cosmetics backup keeps one normalized copy of each qualifying cosmetic item. It does not remotely store your complete inventory, item quantities, coordinates, chat, balance, or passwords as part of this feature.
Wardrobe Vault
When Cosmetics & Wardrobe is enabled and a player assigns a Wardrobe Vault, the Suite server stores:
- Minecraft UUID and current player name
- Realm key and dimension identifier
- The exact block coordinates of both halves of the assigned double chest
- Creation and last-update timestamps
- Up to 54 cosmetic IDs currently observed in the wardrobe
The server stores cosmetic identifiers for the wardrobe contents, not the chest’s complete ItemStack data or item quantities. Complete serialized item information may separately exist in the player’s collected-cosmetics backup as described above.
To identify and protect claimed wardrobes, authenticated Suite clients requesting wardrobe information for the same realm and dimension can receive claimed chest coordinates together with the owner’s Minecraft UUID and player name.
Moving a wardrobe replaces the previous assignment and usable-item list. Unassigning it deletes the assignment and associated cosmetic-ID list.
Live multiplayer relay
Other connected Suite clients need temporary state to show your emotes and equipped cosmetics. Emote relay authentication can occur while all three server-backed categories are disabled. Active cosmetic relay data applies when Cosmetics & Wardrobe is enabled.
- Minecraft UUID and current player name
- Current realm or server key
- Currently playing emote
- Active cosmetic loadout and hidden-armor selections
- Tool replacement rules
This state stays in server memory and is removed when you disconnect. It is broadcast only to other connected Suite clients in the same configured realm. Your complete cosmetic collection is not broadcast; only active cosmetic stacks and replacements are sent.
Emote usage counts
When an emote is played manually, an aggregate counter records the emote ID, total play count, and first- and last-played timestamps. The counter does not contain Minecraft UUIDs, player names, IP addresses, or individual play histories. Walking, running, and flying styles do not contribute to these counts.
Player authentication
The live relay and player configuration endpoints use an authentication key for each Minecraft UUID. The server stores the UUID, a SHA-256 hash of the key, and its creation and last-used timestamps. It does not store the raw key.
The raw key is kept on your computer outside the Minecraft instance, so reinstalling an instance does not normally remove it. On Windows, the file is %APPDATA%\BlossomSuite\player-auth.json. Keys are separated by suite and Minecraft UUID so multiple accounts can be used.
Authentication enrollment currently occurs when the client connects to the live emote WebSocket, even if all three optional server-backed categories are disabled.
Security records and logs
If someone submits an invalid UUID or incorrect authentication key, the Suite database records the event timestamp and type, API route, claimed UUID and player name, direct source IP address, X-Forwarded-For value, and user-agent string. Valid requests are not written to this security-events table.
Separately, the reverse proxy, hosting provider, or service journal may log ordinary requests and IP addresses depending on its deployment configuration. Those logs are outside the application database.
Other Suite data
The BlossomSuite privacy page describes additional existing BlossomSuite API tables for dungeon reporting, donations, linked-account cooldowns, and vote-party state. Those tables are separate from the Emotes, Cosmetics & Wardrobe, and Jobs Lifetime categories described here.
Retention and your choices
Current application behavior:
- Emote backups remain until replaced or manually deleted.
- Collected-cosmetics backups remain until replaced or manually deleted.
- Disabling Cosmetics & Wardrobe clears the active loadout and removes the Wardrobe Vault assignment, but retains the collected-cosmetics backup.
- Wardrobe assignments and usable cosmetic IDs otherwise remain until replaced, unassigned, or manually deleted.
- Jobs Lifetime accounts, per-server totals, and accepted update events have no automatic retention limit.
- Disabling Jobs Lifetime does not delete its stored records.
- Authentication hashes remain until manually deleted or reset.
- Security events and aggregate emote counts have no automatic retention limit.
Changing a category has category-specific effects:
- Disabling Emotes stops preference synchronization but does not delete the saved emote configuration.
- Disabling Jobs Lifetime stops synchronization but does not delete stored totals or update records.
- Disabling Cosmetics & Wardrobe clears the active cosmetic loadout and requests deletion of the Wardrobe Vault assignment and its usable cosmetic-ID list. The collected-cosmetics backup remains stored.
The client may retry these cleanup requests if the server is temporarily unavailable.
There is no general self-service export or full-account deletion endpoint. Wardrobe unassignment is the limited self-service deletion action currently available. You can request manual deletion of other stored player data after completing account-ownership verification. Contact Suite support through the official Discord link below. Avoid posting authentication keys or other sensitive data publicly.
Contact Suite support ↗