Builder’s Gate

한국어

Privacy Policy

Builder’s Gate (the “Service”) treats personal information with care and complies with the Personal Information Protection Act. This policy explains what information the Service collects, why it collects it, and when it deletes it.

The Service is a personal fan tool for planning Baldur’s Gate 3 builds. From visitors who are not logged in, the server receives almost no personal information — except for community-post view counts only, for which it briefly uses a short hash made from the access IP address — Article 2. Access statistics are collected directly in the browser by Google Analytics — Article 4.

Article 1 (Purpose of processing)

The Service processes personal information only for the following purposes. If a purpose changes, we will notify you in advance and obtain consent.

Article 2 (Information processed)

When you log in, we receive only the following from Google or Discord. We do not receive your email address.

The following are also stored while you use the Service.

If you use the Service without logging in, builds remain only in the browser (localStorage) and are not sent to the server.

Exception — community-post views. When a community post is opened, a short hash is stored by the server to count “how many people viewed it.” This value is not the original IP address, and even for the same person may change after a day. We do not store the IP itself, but tracing it back is not theoretically impossible, so we honestly describe it as “pseudonymization,” not “anonymization.” This value is not used for any purpose other than counting views and is not given to third parties. The retention period is in Article 3.

Exception — anonymous comments. If you comment without signing in, the server stores a short hashof your IP address, plus a hash of the 4-digit passwordyou use to edit or delete that comment. Neither is the original value — we never store your IP address or your password as-is. The IP hash is used only to block spam and flooding, and even for the same person it may change after a day.For the same reason as view counts, we call this “pseudonymization,” not “anonymization.”The password hash is used only to confirm edits and deletions of that comment— it never creates an account and is never used to sign in anywhere. We also use Cloudflare Turnstile to block bots, and Cloudflare processes connection information under its own policy when it does. Retention is covered in Article 3.

Article 2-2 (Public profile)

Only when it is created directly with “Create profile” on the profile screen will the following be made public. If you do not create a profile, nothing is made public, and a user’s post on the community is shown as “Anonymous builder”.

Publication begins only after the user confirms it directly. Before saving, the “Create profile” screen shows how many public builds will be linked to this account now and asks for confirmation — the profile is not created without confirmation.

Names received from Google or Discord are not made public. The “display name” in Article 2 appears only as a suggested value in the input field when a profile is first created, and is not visible to others unless the user saves it as-is.

With “Stop sharing,” you can withdraw publication at any time. When you withdraw it, the display name, bio, preferred role, avatar, and theme are deleted immediately. Published public builds remain, but their author changes back to “Anonymous builder.” Unique address (@handle) is not deleted and remains reserved — if the same user creates a profile again later, they can return only through that address, and no one else can take it in the meantime.

Article 2-3 (Private follows and in-site notices)

When a logged-in user follows a public author, we store the two account numbers and the time of the follow. The follow relationship is private, and can be viewed only on your “Following” screen. We do not publish the follower count or list, and do not show the author who followed them.

When someone follows you, leaves a like, comment, or interest (bookmark) on your post, or a followed author first publishes a new build document, we create an in-site notice. Notifications store the recipient and acting account IDs (guest comments have no account ID), notification type, related post and comment IDs, an identifier to prevent duplicate notifications, creation time, and read time.

New follow and interest notifications do not identify the person who acted. Only you can see your bookmark list. Like, comment, and new-build notifications may show the display name, handle, avatar, and theme of a currently public profile. Names received from Google or Discord are not shown in notifications.

Notifications and unread counts are visible only to the recipient. Post notifications link to the post; comment notifications show an excerpt of the currently visible comment and link to it. If a post is taken down or its author’s profile is no longer public, the old title, author name, and comment body are not shown. Deleted or hidden comment bodies are not shown again in notifications. We do not send email, browser push notifications, or Discord messages.

Article 3 (Retention periods)

PostHog page-view and action records are retained for the period specified by the project’s PostHog plan. The service operator can view statistics in the analytics dashboard. For privacy inquiries, use the contact listed in Article 10.

Article 4 (Provision to third parties)

The Service does not sell your personal information to third parties. We do not give account information or saved builds to third parties.

Advertising is currently paused. Allowing analytics does not activate advertising scripts or advertising cookies. A separate advertising consent system will be put in place before advertising resumes.

To understand how the Service is used, we perform access analytics with Google Analytics (Google Analytics 4) — only for users who have accepted cookie consent (Article 9). As with advertising, Google runs the measurement directly — we do not receive and pass on the user’s information; Google receives it directly from the user’s browser. It records usage statistics such as viewed screens, access times, device and screen size, and approximate location, and does not connect them to a logged-in account.

We use PostHog to analyze page views and device and browser types on public pages. We send page-view records to PostHog’s US region only after you consent to analytics. In the builder, we record successful creation, manual saves, first autosaves, share-link copies, imports, and publication to the community board through a collection endpoint on this site. We also record builder entry, the first display of each panel, and attempts and failures during share preparation, copying, and publication. We additionally send only the panel name, sharing stage, and predefined failure type; we do not send the original error message. Autosaves are recorded only once per build per open page. We do not send build names, contents, or identifiers, or logged-in accounts. Action records include the interface language and a temporary identifier that disappears when the page is closed. We do not send input content, screen recordings, URL query parameters or fragments, or referrer URLs.

We also use Cloudflare Web Analytics to view access statistics. This does not set cookies and is access analytics that does not identify individuals (viewed screens, access times, approximate location, and device and browser type), so it is collected on every screen without consent — because it differs from tracking that requires consent, such as advertising and Google Analytics (Article 9). It is not connected to a logged-in account. We do not receive or store it separately; Cloudflare processes it only as statistics.

Article 5 (Entrusted processing)

For operating the Service, we entrust processing to the following providers.

Storage may be located outside the country. We entrust no processing beyond the items listed above.

Article 6 (User rights and how to exercise them)

You may request access, correction, deletion, or suspension of processing at any time.

Article 7 (Destruction)

When the retention period expires or the processing purpose ends, we destroy the information without delay. Electronic files are deleted in a manner that cannot be recovered.

Logging out, taking down a post, and withdrawing a public profile each stop login or publication; they do not delete the account and all saved records. Request deletion of account, session records, or posting records through the contact in Article 6. When processing a deletion request, we will explain the scope and completion status for the server originals and backups.

Article 8 (Measures to ensure security)

Article 9 (Cookies)

The changes concerning first-party analytics consent and paused advertising take effect when the site version containing these features is published.

First-party cookies maintain your login and store your analytics consent choice. The consent cookie is not used for tracking.

If you allow analytics, Google Analytics stores usage-statistics cookies such as _ga. Withdrawing consent in Analytics settings stops further collection and deletes those cookies that this site can remove. Declining does not affect the service features.

PostHog is configured not to store identifiers in cookies or local storage on this site. It still runs only after analytics consent, and further collection stops when consent is withdrawn.

Cloudflare Web Analytics does not set cookies — so access statistics include it without consent and even when cookies are blocked (Article 4).

The first-party analytics consent banner stores your choice in the bg3_consent cookie for 180 days. This cookie only remembers acceptance or rejection and does not identify you. You can change or withdraw your choice at any time through Analytics settings on the page.

You can refuse cookies in your browser settings, but login will not be maintained.

Article 10 (Personal Information Protection Officer)

For inquiries, complaints, or requests for relief related to personal information, please use the contact above. We will check and reply as soon as we receive them.

Article 11 (Relief for rights violations)

If you need advice or wish to report a personal-information violation, you may contact the following:

Article 12 (Changes to this policy)

This change concerning PostHog analytics takes effect when the site version containing this feature is published.

This notification revision takes effect on the day it is posted on the site. (Previous versions: September 1, 2026 · August 25, 2026 · August 21, 2026 · August 16, 2026 · August 15, 2026 · August 12, 2026)

What changed this time — New follow notifications and notifications for likes, comments, and interest (bookmarks) on posts were added to the existing new-build notifications. The people who follow or bookmark are not identified; profiles and comment bodies in like and comment notifications are shown only within their current public visibility. Articles 2-3 and 3 describe the information processed, its visibility, and the deletion of notifications older than 90 days when notifications are checked.

This revision also takes effect when it is posted. This avoids a period in which the follow and notice features would turn on before the policy applying to the same version. We did not meet the seven-day advance-notice requirement.

The previous revision (August 25, 2026) began counting community-post views. Regardless of whether a person is logged in, when a post is opened the server stores a short hash made from the access IP address to calculate “how many people viewed it” — the original IP address is not stored, and records older than 3 days are deleted when the post is viewed again (at that moment they may actually remain for up to 4 days, and a post with few views may keep them longer until its next view — the accumulated view count itself remains until the post is deleted). Details of the information and retention period are in Articles 2 and 3. The introductory sentence “the server receives no personal information” was also revised to reflect this exception.

That revision also took effect when it was posted. View counting was deployed with the new version to which that revision applied; delaying its effective date would have created a period in which the feature was already running while the policy lagged behind. We did not meet the seven-day advance-notice requirement.

The earlier revision (August 21, 2026, Google Analytics) also took effect when posted — access analytics began with the new version to which that revision applied, so its effective date had to be its deployment date. A cookie-consent banner was added on the same day for the same reason.

The revision before that (August 16, 2026, public profiles) also took effect when posted — we did not meet the seven-day advance notice. The key change in that revision was removing Google and Discord account names that had been shown as community-post author names. Those names had been public even though users had not given them for use on this site. We decided that stopping the existing disclosure now was better than continuing it for another seven days. Conversely, that revision introduced the new publication (the public profile), which begins only when the user creates and confirms it on the screen; if the user does nothing, it is shown as “Anonymous builder.”

The still earlier revision (August 15, 2026, advertising) also did not follow the same process; including this one, it is five times in a row. In the future, if the content changes, we will announce it on this page starting 7 days before it takes effect and, when we cannot do that, we will explain here why.