Skip to legal content
DICompanion
ToolsBuildsClanServicesPremium
Sign inCreate account

DI Companion legal information

Privacy Policy

This policy describes the personal data and browser data processed by the current DI Companion implementation.

Effective date:
Required configuration is pending before production launch.

1. About this policy and the operator

The legal operator name is not configured. This information must be completed before production launch.

This policy applies to DI Companion accounts, character profiles, public tools, the browser cart, and related service infrastructure.

2. Data we process

DI Companion limits stored data to what the current product uses:

  • Account and profile data: Firebase UID, email, optional display name and photo URL, email-verification status, account role and plan, onboarding status, theme, language, and timestamps.
  • Character data: character ID, name, class, server, Paragon level, Combat Rating, Resonance, primary-character status, and timestamps.
  • Browser preferences: selected RU or EN locale and the corresponding first-party locale cookie.
  • Browser cart data: service identifiers, quantity, current unit price, and related cart fields stored only in localStorage.
  • Infrastructure providers may process IP address, user agent, request, diagnostic, and security-log data needed to deliver and protect the service.
  • The payment foundation may create authenticated orders and process limited order and public blockchain transaction metadata for server-side verification. It does not store private keys, payment-card details, or KYC documents. Card payments, support messages, advertising, and analytics trackers are not enabled.

3. Authentication and passwords

Firebase Authentication handles DI Companion email/password registration, login, verification, and password reset. The application passes passwords directly to the Firebase SDK and does not write plaintext passwords to Firestore, custom localStorage, or application logs.

Firebase SDK authentication state may use local or session browser persistence depending on the sign-in choice. Optional Google sign-in is available only when enabled.

4. Purposes of processing

Data is processed only for current product functions and related operation:

  • creating, authenticating, and verifying DI Companion accounts;
  • maintaining the user profile and selected locale;
  • creating, editing, deleting, and selecting a primary character;
  • restoring the local browser cart and creating or verifying a payment order requested by the authenticated user;
  • protecting, diagnosing, and maintaining the service;
  • sending a limited administrator registration notice only if the prepared Telegram Cloud Function is later enabled and configured.

5. Cookies and local storage

The current application uses browser storage for functional purposes, not advertising:

  • di-companion-locale in localStorage and a first-party locale cookie remember the RU or EN choice;
  • di-companion-services-cart in localStorage restores the cart;
  • Firebase Authentication uses its SDK browser persistence for the signed-in session.

6. Service providers and disclosures

DI Companion currently relies on the following third-party infrastructure where the feature is enabled:

  • Google Firebase for Authentication, Cloud Firestore, Cloud Functions, and related hosting infrastructure;
  • Google sign-in as an optional authentication method;
  • Telegram, only if the prepared administrator notification function is deployed and configured; that notice contains email, locale, verification status, and registration date and time, but not the Firebase UID;
  • No card payment processor, advertising network, or product analytics provider is integrated. When direct blockchain verification is enabled, configured node or indexer providers may process public transaction lookup data.

7. International processing

Google, Firebase, and any enabled third-party provider may process data through infrastructure outside the user's country. Firebase Authentication currently processes customer data in the United States. Other Firebase data locations depend on the configured Firebase environment and provider infrastructure.

8. Retention

DI Companion does not currently apply an automatic fixed deletion period. Retention is based on the following criteria:

  • account, profile, character, payment-order, and transaction-verification records remain while needed to operate the account, verify access, prevent duplicate use, or meet security and legal needs;
  • locale and cart data remain in the browser until changed, cleared by the user, or removed with browser storage;
  • authentication persistence remains until sign-out, session end, or browser storage removal according to the selected sign-in mode;
  • provider logs and any enabled Telegram administrator messages follow the relevant provider and administrator retention settings.

9. Your rights and account deletion

Depending on applicable law, a user may have rights to request access, correction, deletion, restriction, objection, or a copy of personal data. Identity may need to be verified before a request is completed, and some information may be retained where required by law or for security.

Characters can be edited and deleted in the account. Full account deletion is not currently self-service and requires a manual privacy request through the contact address below.

10. Security

DI Companion uses Firebase Authentication, HTTPS in supported hosting environments, strict Firestore ownership rules, and client/server separation for private data and secrets.

No system can guarantee absolute security. Users should protect their DI Companion credentials, keep their email account secure, and report suspected unauthorized access through the privacy contact.

11. Game-account credentials

The current DI Companion data model does not collect or store Blizzard or Battle.net passwords, two-factor authentication codes, recovery codes, authentication cookies, or game session tokens in Firestore, localStorage, Pinia persistence, character profiles, or cart records.

Do not place game-account credentials in character names, server names, payment-order fields, or any other DI Companion field. Payment verification does not require game-account credentials; any future game-account access workflow requires a separate security and privacy review.

12. Minors

DI Companion paid services are intended only for users aged 18 or older. The current application does not request date of birth and is not designed for child profiling.

If personal data is believed to have been provided by a child contrary to applicable requirements, contact the operator so the situation can be reviewed and appropriate action taken.

13. Policy updates

This policy may be updated when product features, providers, or legal requirements change. The effective date on this page will identify the current version. Material changes should be reviewed before continuing to use affected features.

14. Contact

Privacy and account-deletion requests must be sent to the configured privacy contact. Include enough information to identify the DI Companion account, but do not send passwords, two-factor codes, recovery codes, or tokens.

The contact address is not configured. It must be published before production launch.

DICompanion

Planning tools for Diablo Immortal players.

ToolsBuildsClanServicesPremium
DisclaimerPrivacy Policy

DI Companion is an independent and unofficial service.

Diablo® and Diablo® Immortal™ are trademarks of Blizzard Entertainment, Inc. and/or their respective rights holders.

DI Companion is not affiliated with, sponsored by, endorsed by, or supported by Blizzard Entertainment, Inc.

References to game titles, game-related terms, and other intellectual property are used solely for descriptive and identification purposes to the extent permitted by applicable law. All respective rights remain with their owners.