Privacy Policy
The default application stores language, simulator history, crafts, loadouts and watchlists in the user's browser.
Last updated 30 August 2026Local data
Local storage remains on the device unless the user clears it. LootGap does not receive watchlists, inventory rows, simulator history or other device-local tool state in the current architecture.
Optional analytics
First-party product analytics is sent only after the user chooses Allow optional. Query strings and URL fragments are excluded, client-generated anonymous/session identifiers are pseudonymized with SHA-256 before database persistence, and source-side scheduled maintenance is configured to delete raw analytics events older than 30 days. Production scheduling and regional retention requirements must still be verified before launch.
Server security
A hosting provider may process routine request metadata for security and reliability. LootGap's public API rate limiter transiently uses the trusted edge network address to derive a coarse SHA-256 bucket slot; the raw address is not written to the application rate-limit table, and multiple unrelated users may share a slot by design. Hosting-provider logs, retention and regional details remain operator/control-plane verification work before launch.
Advertising and consent
AdSense is disabled until a legitimate publisher ID and required consent controls are configured. Optional advertising storage must not run before applicable consent.
Your choices
Users can choose essential-only consent, change language, reset individual tools or clear browser storage. Essential-only consent prevents LootGap's first-party product analytics event sender from running.