Privacy at batomon.com

Public pages stay open. Companion is optional.

Core batomon.com pages need no account. Batomon.com Companion is a separate optional feature that uses a verified email and internal account for consented game uploads and a private normalized-match dashboard. We never ask for or publish a raw Steam ID.

Effective: August 7, 2026.

Core public pages need no accountCompanion uses a verified emailCompanion and public profiles stay isolatedPersonal data is never sold or rented

Optional game connection

Batomon.com Companion

Connecting in the sanctioned game mod or signing in at /companioncreates or resumes the same email-verified internal account. The private dashboard shows only that account's normalized Companion matches and never connects it to a public leaderboard profile.

Account and identity

Companion stores a normalized verified email and an internal account ID. The game uses a separate upload device session; the website uses a dedicated 30-day browser session stored only as an HttpOnly cookie. A second HttpOnly cookie, retained for up to 365 days, binds each email challenge to that browser. Both surfaces show only a masked email. We do not collect a game account ID, game display name, Steam/provider ID, opponent identity, or native game-run ID in Companion uploads.

What eligible uploads contain

Uploads can contain match, economy, shop, board, and aggregate combat data, plus the game/build/Balance/mod and consent versions needed to validate it. Companion uses a random Companion run ID. The sample is self-selected by connected players and must not be presented as every Batomon match or every player.

Uploads off means transmission off

Match uploads default to enabled after connection. Turning them off stops network transmission, but eligible completed matches continue entering the local pending queue. Turning uploads back on retries that queue. Pre-consent runs and runs already in progress when consent begins are never added retroactively.

Strict dataset isolation

Companion account and match records are never joined, reconciled, or matched to public leaderboard/profile records. A queued match stays bound to the internal account and device session active when that run began; switching accounts never reassigns it.

01

What appears publicly

Player pages may show a public pseudonymous owner ID, display name, rank, match summaries, and observed teams. A public owner ID is an opaque game-record identifier—not a Steam ID and not a Companion account identifier.

02

Public game records

Rankings, match history, team observations, and game-reference details come from publicly available game pages and records. Viewing core batomon.com pages never requires your game password, account cookie, authentication ticket, or Companion login.

03

Local favorites and shared URLs

Build Lab favorites, names, and imported build codes stay in browser-local storage and are not written to batomon.com servers by the favorites feature. A build explicitly opened in a share URL is public to anyone who receives it and may be temporarily cached for delivery. Clear site storage to remove local favorites.

04

Cookie-free usage analytics

Our self-hosted Umami service records page use, Web Vitals, and a small allow-listed set of product actions without analytics cookies. The tracker honors Do Not Track and runs only on batomon.com. Search strings and URL fragments are excluded; player and run paths, titles, and internal referrers are reduced to generic labels. Interaction events contain no player, search, build, comp, Companion account, or free-text content. Only the build-share event may include data, limited to the sharing method. Clicking a Companion installer link records only the fixed event name companion-download with no custom data.

Like any web service receiving a request, the self-hosted analytics endpoint necessarily receives ordinary network metadata such as an IP address and user agent at transport. Batomon does not add those values, email, account, session, device, run, or URL-query data to product-event payloads.

Private operator reporting may show aggregate Companion page visits and installer clicks. Separate Cloudflare operational telemetry and account, browser-session, verified-game-device, first-upload, and normalized-run totals are aggregate backend snapshots only: they are never joined to Umami browser analytics, public player/profile data, or row-level identifiers, and are not person-level conversion.

05

Feedback widget

We load the IssueProbe feedback widget from issueprobe.com. It is the only third-party script on this site. IssueProbe receives a report only when you choose to submit one; simply opening a page sends nothing.

When you send a report, IssueProbe receives your report text plus bounded browser evidence that helps reproduce the problem: console messages, network activity, and browser-state metadata, meaning names, presence, and sizes only. The values of cookies, form fields, and local storage are never collected, under any setting. Please still avoid typing verification codes or tokens into the report itself, since that text is sent as written.

A screenshot is only included if you explicitly agree, and you see a preview first. If you decline, the report is sent with no image. Screenshots are kept for 30 days, after which the image is deleted. IssueProbe never emails or messages you, and a person reviews every draft before any reply.

06

What we do not do

We do not sell or rent personal data. We do not ask for game passwords, Steam tickets, game account cookies, or game authentication headers. Companion verification codes, upload access/refresh tokens, and browser-session tokens never belong in match data, browser JavaScript, analytics, logs, or support messages.

Retention

Different data, clear limits

Companion login challenges and sessions: challenges are deleted or redacted after 24 hours. Expired or revoked upload access-token rows are deleted after seven days; upload refresh-token rows after 30 days. Website browser sessions expire after 30 days and expired or revoked rows are removed by the daily bounded cleanup.

Companion raw uploads: raw upload JSON is removed 30 days after successful normalization while bounded hashes and status records may remain.

Companion normalized matches: retained until account deletion or a valid deletion request. Non-identifying aggregate statistics may remain only when they cannot reasonably be tied back to the account.

Public game records: match and ranking history may be retained indefinitely so long-term trends and accepted public-profile opt-outs remain consistent.

Backups: service backups are kept for 14 days.

Favorites and pending uploads:favorites stay in the browser. The Companion pending queue stays on the player's device until acknowledged, removed by the player, or removed with the local Companion data.

Usage analytics: cookie-free analytics history may be retained for product trend comparison. It excludes search strings, build contents, comp identities, and raw player/run routes.

Deletion, opt-out, or questions

Tell us which boundary your request concerns.

Public profile: send the batomon.com profile URL or public pseudonymous owner ID—not a Steam ID. We can suppress an accepted profile from display and future updates while retaining the minimum suppression marker.

Companion account: request account and normalized match deletion from the verified email associated with the account. Never send a verification code, access token, refresh token, game credential, or raw upload. We will explain any non-identifying aggregate or backup copy that remains temporarily.

Email privacyprivacy@batomon.com