Privacy

Privacy

Operational telemetry

DC20Beyond collects first-party operational information to secure the service, diagnose failures, and understand whether its game tools work as intended.

What is collected

We collect matched page routes, response status and duration, account ID when signed in, a random browser-session ID, authentication outcomes, use of major game features, WebSocket health, browser performance measurements, coarse viewport and connection classes, and sanitized JavaScript error types.

Security identifiers

IP addresses and user-agent strings are encrypted and available only to specifically authorized administrators for security investigations. They are deleted after 180 days.

What is not collected

Telemetry does not contain passwords, authentication tokens, form values, query-string values, chat messages, campaign notes, character or NPC text, dice expressions, uploaded filenames, keystrokes, pointer movement, scroll tracking, advertising identifiers, or cross-site activity.

Retention

User-linked operational records are anonymized after two years. Daily aggregates may be retained indefinitely, contain no user, request, session, or network identifiers, and suppress dimension groups with fewer than five observations.

Access and export

Signed-in users can review the categories associated with their account and export their retained telemetry from Account Privacy. Analytics administrators require a separate permission, and their views and exports are audited.

Purpose and choices

This telemetry is always active because it is used to operate and secure DC20Beyond. It is not used for advertising, fingerprinting, sale, cross-site profiling, or automated eligibility decisions.