Skip to legal content
DICompanion
Partners
Sign inCreate account

DI Companion legal information

Privacy Policy

This policy describes the personal data and browser data processed by the current DI Companion implementation.

Effective date:
Required configuration is pending before production launch.

1. About this policy and the operator

The legal operator name is not configured. This information must be completed before production launch.

This policy applies to DI Companion accounts, character profiles, and related service infrastructure.

2. Data we process

DI Companion limits stored data to what the current product uses:

  • Account and profile data: Firebase UID, email, optional display name, optional profile picture and its Firebase Storage path and download URL, email-verification status, account role and plan, onboarding status, theme, language, and timestamps.
  • Character data: character ID, name, class, server, Paragon level, Combat Rating, Resonance, primary-character status, saved loadouts, manually entered gear, attributes, magic properties, essences, gems, skills, sets, Paragon configuration, manual statistics, notes, patch and source metadata, and timestamps.
  • Browser preferences: selected EN, RU, or JA locale and the corresponding first-party locale cookie.
  • public.legal.privacy.sections.data.items.4
  • Infrastructure providers may process IP address, user agent, request, diagnostic, and security-log data needed to deliver and protect the service.
  • The payment foundation may create authenticated direct-crypto and card-conversion orders and process limited order, provider-settlement, and public blockchain transaction metadata for server-side verification. If a provider-hosted card flow, whether sandbox or live, is separately approved and enabled, DI Companion sends the provider the account email, a hashed account identifier, client IP address, order identifier, selected fiat currency, merchant wallet, and session parameters required to open and verify the hosted flow. DI Companion does not receive or store private keys, payment-card details, CVV, selfies, or KYC documents. The DI-owned staging card simulator requests no card data, contacts no payment provider, and moves no funds.
  • Activity tracking stores the selected server region, server and schedule-profile identifiers, timezone fallback, optional server name, optional local-time display choice, self-reported faction, clan and warband membership, ignored activities, cycle-scoped completion state, reminder choices, and the last in-app occurrence shown.
  • If a user voluntarily connects the separate activity-notification bot, DI Companion stores the Telegram user ID and private chat ID, optional public username and first name, Telegram language code, connection and consent timestamps, per-activity reminder choices, delivery status, and Telegram message ID. The bot token and webhook secret are never exposed to the browser. A random one-time token is returned only to the authenticated browser in the Telegram deep link, expires after 10 minutes, and is stored by DI Companion only as a cryptographic hash.
  • The partner program processes application details, a server-owned partner status and referral code, signed referral-token identifiers, hashed anonymous attribution and anti-fraud identifiers, campaign subid labels, masked referred-user email, conversion aggregates, first eligible payment evidence, commission records and program-rule acceptances. Partners never receive another user's full email, raw IP address, authentication token or payment credentials.

3. Authentication and passwords

Firebase Authentication handles DI Companion email/password registration, login, the verified-email account flag, and password reset. DI Companion sends a server-generated one-time code through a transactional email provider and sets the Firebase verified-email flag only after server-side validation. The application passes passwords directly to the Firebase SDK and does not write plaintext passwords to Firestore, custom localStorage, or application logs.

Firebase SDK authentication state may use local or session browser persistence depending on the sign-in choice. Optional Google sign-in is available only when enabled.

4. Purposes of processing

Data is processed only for current product functions and related operation:

  • creating, authenticating, and verifying DI Companion accounts;
  • maintaining the user profile and selected locale;
  • creating, editing, deleting, and selecting a primary character, managing its class-specific builds, equipment and configuration, and comparing saved builds;
  • creating or verifying a payment order requested by the authenticated user;
  • protecting, diagnosing, and maintaining the service;
  • sending one limited administrator notice after an account email is confirmed when the Telegram Cloud Functions are enabled and configured;
  • showing personalized activity schedules, cycle progress, badges, and one-time in-app reminders while DI Companion is open;
  • linking a Telegram account only after an explicit user action and delivering only the per-activity reminders that the user enables;
  • operating the partner program, attributing a new registration after a valid referral, preventing referral fraud, producing partner aggregates and calculating one commission from an eligible first payment.

5. Cookies and local storage

The application uses browser storage for functional preferences and partner attribution in the current session:

  • di-companion-locale in localStorage and a first-party locale cookie remember the EN, RU, or JA choice;
  • public.legal.privacy.sections.storage.items.2
  • Firebase Authentication uses its SDK browser persistence for the signed-in session;
  • a signed referral token and random attribution key are kept only in sessionStorage and disappear when the browser session ends.
  • public.legal.privacy.sections.storage.items.5
  • public.legal.privacy.sections.storage.items.6

6. Service providers and disclosures

DI Companion currently relies on the following third-party infrastructure where the feature is enabled:

  • Google Firebase for Authentication, Cloud Firestore, Cloud Functions, and related hosting infrastructure, plus Google Fonts for delivery of the Japanese interface font;
  • Google sign-in as an optional authentication method;
  • Telegram, when configured, for separate administrator notices and the user-facing activity bot. The activity bot receives the private chat and public bot-profile fields provided by Telegram and receives reminder text selected by the user; it does not receive the user's email or Firebase UID in messages;
  • The DI-owned staging card simulator does not contact a payment processor or move funds. If a provider-hosted card flow, whether sandbox or live, is separately approved and enabled, DI Companion sends the selected provider the account email, a hashed account identifier, client IP address, order identifier, selected fiat currency, merchant wallet, and hosted-session parameters. The provider processes card and KYC data on its own interface and shares order and settlement metadata with DI Companion. No advertising network or product analytics provider is integrated. Configured blockchain node or indexer providers may process public transaction lookup data.

7. International processing

Google, Firebase, and any enabled third-party provider may process data through infrastructure outside the user's country. Firebase Authentication currently processes customer data in the United States. Other Firebase data locations depend on the configured Firebase environment and provider infrastructure.

8. Retention

DI Companion does not currently apply an automatic fixed deletion period. Retention is based on the following criteria:

  • account, profile, character and saved-build records, including manually entered build details, patch and source metadata, activity preference and progress, payment-order, and transaction-verification records remain while needed to operate the account, personalize activity tracking, verify access, prevent duplicate use, or meet security and legal needs;
  • locale data remains in the browser until changed, cleared by the user, or removed with browser storage;
  • authentication persistence remains until sign-out, session end, or browser storage removal according to the selected sign-in mode;
  • one-time bot-link records expire after 10 minutes, webhook deduplication records after 7 days, and delivery records after 30 days from an occurrence; disconnecting removes the Telegram connection and subscriptions and disables the stored reminder choices; Telegram copies of delivered messages and provider logs follow Telegram and chat retention settings;
  • session referrals expire at session end; temporary click receipts, attribution claims, anti-fraud rate limits and hashed unique-visitor records use configured TTLs, while immutable referral, first-payment, commission, audit and terms-acceptance records remain as needed for integrity, fraud prevention and legal obligations;

9. Your rights and account deletion

Depending on applicable law, a user may have rights to request access, correction, deletion, restriction, objection, or a copy of personal data. Identity may need to be verified before a request is completed, and some information may be retained where required by law or for security.

Characters and their saved builds can be edited and deleted in the account. Telegram consent can be withdrawn by disconnecting in the profile or sending /stop to the activity bot; this disables all Telegram reminders. Full account deletion is not currently self-service and requires a manual privacy request through the contact address below.

10. Security

DI Companion uses Firebase Authentication, HTTPS in supported hosting environments, strict Firestore ownership rules, and client/server separation for private data and secrets.

No system can guarantee absolute security. Users should protect their DI Companion credentials, keep their email account secure, and report suspected unauthorized access through the privacy contact.

11. Game-account credentials

The current DI Companion data model does not collect or store Blizzard or Battle.net passwords, two-factor authentication codes, recovery codes, authentication cookies, or game session tokens in Firestore, localStorage, Pinia persistence, or character profiles.

Do not place game-account credentials in character names, server names, payment-order fields, or any other DI Companion field. Payment verification does not require game-account credentials; any future game-account access workflow requires a separate security and privacy review.

12. Minors

DI Companion paid services are intended only for users aged 18 or older. The current application does not request date of birth and is not designed for child profiling.

If personal data is believed to have been provided by a child contrary to applicable requirements, contact the operator so the situation can be reviewed and appropriate action taken.

13. Policy updates

This policy may be updated when product features, providers, or legal requirements change. The effective date on this page will identify the current version. Material changes should be reviewed before continuing to use affected features.

14. Contact

Privacy and account-deletion requests must be sent to the configured privacy contact. Include enough information to identify the DI Companion account, but do not send passwords, two-factor codes, recovery codes, or tokens.

The contact address is not configured. It must be published before production launch.

DICompanion

Planning tools for Diablo Immortal players.

Partners
DisclaimerPrivacy Policy

DI Companion is an independent and unofficial service.

Diablo® and Diablo® Immortal™ are trademarks of Blizzard Entertainment, Inc. and/or their respective rights holders.

DI Companion is not affiliated with, sponsored by, endorsed by, or supported by Blizzard Entertainment, Inc.

References to game titles, game-related terms, and other intellectual property are used solely for descriptive and identification purposes to the extent permitted by applicable law. All respective rights remain with their owners.