Privacy Policy
The short version
- You can browse the site and use its tools without an account. You only need one to save or submit.
- If you sign in, you do it with Google. We never see or store a password.
- We keep your Google ID and email address privately. Your email is never shown to anyone else.
- We use no cookies, no ads and no third-party trackers. We don't sell your data.
- We count visitors with a one-way hash that is deleted after two days. We never store your IP address.
- You can delete your account at any time.
Who we are
Hiim PD2 (hiimpd2.com) is a free, fan-made resource for Project Diablo 2 players. "We", "us" and "our" in this policy mean Hiim PD2. You can reach us at hiimpd2@gmail.com. This policy explains what data the site handles and why.
What we deliberately don't collect
We built the site so that it doesn't need the following, and we don't collect them:
- Passwords. Sign-in is handled by Google.
- Cookies. The site sets no cookies of any kind.
- Advertising IDs. There are no ads and no ad networks.
- Precise location. We only record roughly which city a visit came from, never your exact location. See Analytics below.
- Your IP address. We never store it. See Analytics below.
- Your Google profile photo. We don't store it.
What we collect and why
If you only browse, we collect anonymous visit counts (see Analytics). If you sign in, we also keep:
- Your Google account ID and email address, to recognise you when you sign in, to help you recover your account and, if needed, to contact you about your submissions.
- A display name you choose. It starts as your Google first name and you can change it.
- Your Discord username, only if you add one.
- Your role (user, moderator or admin) and the dates your account was created and last used.
- What you create: builds, custom items, favorites, +1 votes, reports and submissions (map clears, boss kills and builds, with the video links and notes you enter).
- Issue reports, if you use "Report an issue": the category, summary and details you write, the page address you report from, your browser's user-agent string (shortened), your account ID and your display name at the time, plus the ticket's status, moderator notes and dates. Only you, moderators and admins can see them. We count how many you send per day to limit spam; that count is deleted after two days. No email address is stored with a report.
- Moderation records: when a moderator approves or rejects a submission, hides a build or changes a tier, we log who did it and when.
Our servers keep short technical logs (the page requested, the result and how long it took) for 14 days to fix problems. They don't contain your IP address.
Signing in with Google
When you sign in, Google tells us your Google account ID, your email address and your name. We keep your Google ID and email address. We use your name only to suggest a display name.
Your email address is used only to help you recover your account and to contact you about your submissions. It is never shown publicly, never shown to other users and never shared.
Google's own handling of your sign-in is covered by Google's Privacy Policy.
Your Discord username
Adding a Discord username is optional. If you add one, it is visible to other signed-in users so they can contact you about your builds and submissions. It is never shown to visitors who aren't signed in. Our server removes it from every response to someone who isn't signed in.
You can change or remove it at any time on your account page.
What is public
Anyone, signed in or not, can see:
- your display name and the +1 count on builds you make public;
- your display name and times on approved clears, tier lists and leaderboards;
- builds you set to "unlisted", if they have the link.
These are not public: your email address, your favorites list, which builds you gave a +1, your reports and your private builds. Moderators can see who voted on a build when they are looking into vote abuse.
We don't send email
The site never sends you email: no notifications, no marketing and no newsletters. Whether your submission was approved or rejected, with the moderator's note, is shown on your account page. If a moderator hides one of your builds, a notice is shown on the build. There is nothing to opt out of.
Analytics: counting visitors without tracking them
We don't use Google Analytics or any third-party tracker. Each page sends one small, anonymous message to our own server when it loads, and some pages send a named event (for example, "build saved"). This uses no cookies, no local storage and no device ID.
From each message our server counts, per day:
- which page was viewed or which event happened;
- roughly where the visit came from: the country, the state or region, and the nearest city, as estimated by our hosting provider (Amazon CloudFront) from your connection. We keep only the city name and map coordinates rounded to about 10 km, counted once per visitor per day and added into totals. We never use GPS or anything more precise;
- the kind of site that linked you here (such as Google, Reddit or YouTube), not the full address;
- your browser's main language.
To count unique visitors, the server mixes your IP address with a secret value and your rough device type (such as "Windows / Chrome") and turns that into a one-way hash. The IP address itself is never stored, and the hash can't be turned back into it. Each hash is deleted after two days. The daily counts are deleted after about 13 months.
Local storage
The site stores a few things in your browser's local storage, on your device only:
- your sign-in session token, while you are signed in. Signing out removes it;
- Planner drafts, so you don't lose unsaved work.
The analytics message uses no local storage at all. You can clear local storage in your browser at any time.
Sharing
We don't sell your data, and we don't use it for advertising. We share it only with the services that run the site:
- Amazon Web Services (AWS) hosts the site and stores its data in the United States.
- Google handles sign-in.
We may also disclose data if the law requires it.
Retention and deleting your account
We keep your account data until you delete your account. You can delete it from your account page.
Deleting your account removes your email address, Discord username, builds, custom items, favorites, votes and pending submissions. Approved clears stay on the tier lists and leaderboards, but without your name.
Moderation records may keep your account ID after deletion so we can keep an honest history of moderation decisions. They don't hold your email address.
Issue reports are anonymized when you delete your account: we remove your account ID, your display name and your browser's user-agent string from them, and they show as sent by "deleted user". The category, summary, details, page address, status, moderator notes and dates stay, so we can finish fixing what you reported. Your daily report count is deleted too.
Security
The site is served only over HTTPS. Secrets such as signing keys are kept in encrypted storage, not in our code. Every change to your data needs a valid sign-in, and moderator and admin rights are checked on every request. No system is perfectly secure, but we keep what we store small so there is less to lose.
Your rights
You can:
- see and change your display name, and Discord username on your account page;
- delete your account and the data listed above;
- ask us for a copy of the data we hold about you, or ask us to correct it.
Email hiimpd2@gmail.com for anything you can't do yourself. We will reply within 30 days.
Children
Hiim PD2 is not for children under 13, and they must not create an account. If we learn that a child under 13 has an account, we will delete it. If you think this has happened, email hiimpd2@gmail.com.
Users outside the US
The site is run from the United States and its data is stored there. If you use it from another country, your data is sent to and handled in the United States. Where your local law gives you rights over your data, such as in the EU or UK, contact us and we will help you use them.
Changes
If we change this policy, we will update the effective date and version at the top. For important changes, signed-in users will be asked to agree to the new version the next time they visit.
Contact
Questions about this policy or your data: hiimpd2@gmail.com.