Privacy
Operational telemetry
DC20Beyond collects first-party operational information to secure the service, diagnose failures, and understand whether its game tools work as intended.
What is collected
We collect matched page routes, response status and duration, account ID when signed in, a random browser-session ID, authentication outcomes, use of major game features, WebSocket health, browser performance measurements, coarse viewport and connection classes, and sanitized JavaScript error types.
Security identifiers
IP addresses and user-agent strings are encrypted and available only to specifically authorized administrators for security investigations. They are deleted after 180 days.
What is not collected
Telemetry does not contain passwords, authentication tokens, form values, query-string values, chat messages, campaign notes, character or NPC text, dice expressions, uploaded filenames, keystrokes, pointer movement, scroll tracking, advertising identifiers, or cross-site activity.
Retention
User-linked operational records are anonymized after two years. Daily aggregates may be retained indefinitely, contain no user, request, session, or network identifiers, and suppress dimension groups with fewer than five observations.
Access and export
Signed-in users can review the categories associated with their account and export their retained telemetry from Account Privacy. Analytics administrators require a separate permission, and their views and exports are audited.
Purpose and choices
This telemetry is always active because it is used to operate and secure DC20Beyond. It is not used for advertising, fingerprinting, sale, cross-site profiling, or automated eligibility decisions.