Privacy Policy
Last updated: August 27, 2026
Translations are for convenience. If one conflicts with this policy, English controls.
This policy explains what TibiaNexus processes, what stays on your device, when optional features send data online, and your choices.
1. Local data
Settings, selected folder paths, hunt logs, screenshots, routes, notes, and most analysis data stay local unless you deliberately use an online feature. Sanitized local diagnostics are limited to 30 days and 1,000 entries. Packaged releases record warning/error diagnostics only, not verbose informational events. Screenshot cache keys use a path-derived identifier instead of the raw path; the Hunts parse cache keeps only relative paths and a one-way folder fingerprint; all local analysis/profile caches expire after 30 days, and the character cache is capped at 200 profiles.
Passive hotkeys are optional. Windows Raw Input is filtered at the native boundary so only configured virtual-key codes and modifiers reach the app. Unrelated keys, typed text, scan codes, and extra metadata are discarded and never logged or stored. A hotkey triggers only after Tibia is confirmed in the foreground.
2. Licensing, purchases, support, and website use
Paid access requires a license key, status and expiry, an app-generated device ID, activation and validation times, transfer state, and limited device metadata. Server-side keys are encrypted before persistence. Self-service deletion removes optional device names, app versions, contact data, linked coin orders, and audit events while retaining the minimum entitlement and purchase references needed for access, fraud prevention, accounting, refunds, and support.
Stripe handles cards. Tibia Coins orders may include character name, email, amount, receipt and fulfillment state, and a support note. License and support mail passes through the configured provider, currently Zoho SMTP. Those providers apply their own terms.
The public website records privacy-limited first-party analytics: coarse page categories, visit and page-view counts, visible engagement time, scroll-depth buckets, call-to-action, download, and checkout clicks, coarse acquisition categories, and explicit campaign labels. A random per-tab session ID expires after 30 minutes of inactivity, is hashed before persistence, and its working state is deleted within 48 hours. Daily aggregates are retained for up to 24 months. We do not store IP addresses or hashes, fingerprints, full referrer URLs, query strings, or advertising identifiers, and use no advertising trackers or remote web fonts. Short-lived keyed source pseudonyms are used only to enforce abuse-prevention rate limits and expire with their limit window.
3. AI-assisted features
If you choose managed translation, OCR, weekly-task extraction, or AI voice, selected text, images, instructions, or speech text is sent through our API to OpenAI. TibiaNexus does not persist those contents or outputs. Responses calls set store: false. OpenAI states API data is not used to train its models, but default abuse-monitoring logs may retain content for up to 30 days; speech has the same default period. Images undergo safety scanning, and seriously flagged content may be retained for review. See OpenAI API data controls.
We keep only monthly aggregate AI usage counts, never prompts or images, for up to 24 months.
4. Optional Boards
Boards are opt-in. A shared hunt can include place, mode, time, duration, XP, profit, loot, supplies, damage, healing, kills, tasks, levels, revisions, Wheel allocations, route geometry, and moderation state. The verified publisher character can be public. Other party-member names are replaced before upload and stored only as generic entries with role, vocation, and level.
Verification checks a one-time phrase in the public Tibia.com comment. Pending secrets expire. Public hunts remain until publisher deletion or moderation removal.
5. Public data and asset providers
Character, history, and event features may query Tibia.com, TibiaData, and GuildStats. Maps use TibiaMaps tiles from GitHub Pages; Field Guide assets may come from Firebase Storage; source links may open TibiaWiki/Fandom. These contacts can reveal ordinary network metadata such as IP address and user agent. We do not send them keys, hunt logs, or screenshots.
6. Retention
Closed feedback, completed or stale orders, closed reports, inactive licenses, and AI usage aggregates are removed after 24 months unless law, security, fraud, disputes, or accounting require longer. Expired verification challenges are deleted or cleared. Public Boards data remains until deletion or moderation. Backups may persist through normal rotation.
7. Your choices
Boards tools export and delete shared hunts, verification, pets and awards, sessions, feedback, and reports tied to the publisher. Licensed users have authenticated license-data export and deletion from the active device. You may ask support for access, correction, or deletion. We may verify the license, device, email, order, or character and retain legally required records.
8. Security
Service credentials stay server-side. License credentials are encrypted before persistence, local entitlement values use OS protection when available, HTTPS validates certificates, and support bundles exclude raw telemetry and machine/user IDs. No system is absolutely secure.
9. Contact
Email support@tibianexus.com for privacy requests or questions.