01
What appears publicly
Player pages may show a public pseudonymous owner ID, display name, rank, match summaries, and observed teams. A public owner ID is an opaque game-record identifier—not a Steam ID and not a Companion account identifier.
02
Public game records
Rankings, match history, team observations, and game-reference details come from publicly available game pages and records. Viewing core batomon.com pages never requires your game password, account cookie, authentication ticket, or Companion login.
03
Local favorites and shared URLs
Build Lab favorites, names, and imported build codes stay in browser-local storage and are not written to batomon.com servers by the favorites feature. A build explicitly opened in a share URL is public to anyone who receives it and may be temporarily cached for delivery. Clear site storage to remove local favorites.
04
Cookie-free usage analytics
Our self-hosted Umami service records page use, Web Vitals, and a small allow-listed set of product actions without analytics cookies. The tracker honors Do Not Track and runs only on batomon.com. Search strings and URL fragments are excluded; player and run paths, titles, and internal referrers are reduced to generic labels. Interaction events contain no player, search, build, comp, Companion account, or free-text content. Only the build-share event may include data, limited to the sharing method. Clicking a Companion installer link records only the fixed event name companion-download with no custom data.
Like any web service receiving a request, the self-hosted analytics endpoint necessarily receives ordinary network metadata such as an IP address and user agent at transport. Batomon does not add those values, email, account, session, device, run, or URL-query data to product-event payloads.
Private operator reporting may show aggregate Companion page visits and installer clicks. Separate Cloudflare operational telemetry and account, browser-session, verified-game-device, first-upload, and normalized-run totals are aggregate backend snapshots only: they are never joined to Umami browser analytics, public player/profile data, or row-level identifiers, and are not person-level conversion.
05
Feedback widget
We load the IssueProbe feedback widget from issueprobe.com. It is the only third-party script on this site. IssueProbe receives a report only when you choose to submit one; simply opening a page sends nothing.
When you send a report, IssueProbe receives your report text plus bounded browser evidence that helps reproduce the problem: console messages, network activity, and browser-state metadata, meaning names, presence, and sizes only. The values of cookies, form fields, and local storage are never collected, under any setting. Please still avoid typing verification codes or tokens into the report itself, since that text is sent as written.
A screenshot is only included if you explicitly agree, and you see a preview first. If you decline, the report is sent with no image. Screenshots are kept for 30 days, after which the image is deleted. IssueProbe never emails or messages you, and a person reviews every draft before any reply.
06
What we do not do
We do not sell or rent personal data. We do not ask for game passwords, Steam tickets, game account cookies, or game authentication headers. Companion verification codes, upload access/refresh tokens, and browser-session tokens never belong in match data, browser JavaScript, analytics, logs, or support messages.
Retention
Different data, clear limits
Companion login challenges and sessions: challenges are deleted or redacted after 24 hours. Expired or revoked upload access-token rows are deleted after seven days; upload refresh-token rows after 30 days. Website browser sessions expire after 30 days and expired or revoked rows are removed by the daily bounded cleanup.
Companion raw uploads: raw upload JSON is removed 30 days after successful normalization while bounded hashes and status records may remain.
Companion normalized matches: retained until account deletion or a valid deletion request. Non-identifying aggregate statistics may remain only when they cannot reasonably be tied back to the account.
Public game records: match and ranking history may be retained indefinitely so long-term trends and accepted public-profile opt-outs remain consistent.
Backups: service backups are kept for 14 days.
Favorites and pending uploads:favorites stay in the browser. The Companion pending queue stays on the player's device until acknowledged, removed by the player, or removed with the local Companion data.
Usage analytics: cookie-free analytics history may be retained for product trend comparison. It excludes search strings, build contents, comp identities, and raw player/run routes.