Privacy
MCD2 Crossover and this website · last updated 7 October 2026
MCD2 Crossover collects no data. It has no accounts of its own, no analytics, ads or tracking, and sends nothing about you or your Mac to its author.
Your Microsoft sign‑in
- You sign in on Microsoft’s own website, with a one‑time code. The app never sees your password.
- The renewal token stays in macOS Keychain, in an item that doesn’t sync to iCloud. It reaches the app’s helper through a pipe, never a command line or a log.
- The current session sits in
~/Library/Application Support/DungeonsCrossOver, readable only by your user account. A small background task in your account renews it shortly before it expires, so the game can sign in when you start it from Steam. - Sign Out deletes the Keychain item and the session. It doesn’t revoke a token Microsoft has already issued; you can do that from your Microsoft account’s security page.
What it stores, only on your Mac
- Your choices: the selected bottle and game copy, and the app language, in
~/Library/Application Support/DungeonsCrossOver. - In the game’s folder: the compatibility files setup adds, backups of every file it replaces, and a record of what it changed. Steam’s launch option for Minecraft Dungeons II, with a backup of the previous one.
- Troubleshooting logs, only when you start recording. Recording stops after an hour, even with the app closed. Save Logs… writes a ZIP where you choose. It leaves out passwords, tokens, session data, game saves, account identifiers, your folder paths and full web addresses; you decide whether to attach it to a bug report.
When it goes online
- Signing in and renewing: Microsoft’s and Xbox’s sign‑in services. Microsoft’s privacy statement applies.
- During setup: it downloads Microsoft’s portable Xbox runtime from NuGet, curl’s Windows build from curl.se, and, if Visual C++ is missing, Microsoft’s installer from Microsoft. The runtime and curl are checked against fixed fingerprints before they’re used.
- The game itself talks to its own servers as it normally would.
- Help opens this project’s GitHub page in your browser. The app doesn’t check for updates by itself.
This website
- The newest release. The page asks GitHub’s public API once per visit which release is the newest, to show its version, size and download link. Your browser keeps that until you close the tab.
- The replica in Try it runs entirely in your browser. Nothing is installed, and nobody signs in.
- Nothing else: no cookies, analytics, trackers, or fonts and scripts from other sites. The site and the downloads are hosted by GitHub; GitHub’s privacy statement applies there.
Contact
Questions: open an issue on GitHub.