Privacy Policy

Effective date: September 12, 2026

1. Introduction

d2b ("the Platform", "we", "us") is a community-driven platform for sharing and discussing Dota 2 ideas. This Privacy Policy explains what data we collect, how we use it, and what rights you have over your information.

By using d2b you agree to the collection and use of information as described in this policy.

2. Information We Collect

2.1 Account Information

When you create an account we collect the following. You can register with an email address and password (email verification is required) or with Google sign-in where available:

  • Name and email address — provided during registration or via Google sign-in.
  • Nickname — your chosen display name on the Platform.
  • Profile links — optionally provided Steam profile URL and Dotabuff URL (free text, not verified, shown publicly if set).
  • Rank and role — your self-reported Dota 2 rank and main role.
  • Avatar image — your sign-in provider's profile photo (e.g. Google) when available, or an optionally uploaded profile picture (JPEG, PNG, or WebP up to 5 MB), hosted on our image infrastructure. An uploaded picture takes precedence when set.

2.2 Platform Activity

  • Ideas and content — ideas, votes, comments, and other content you submit, including whether an idea is public or private and whether it was AI-generated.
  • Progression data — experience points (XP) and level, calculated from your activity.
  • Feedback — messages submitted through our feedback page.

2.3 AI Chat & Voice Interactions

BrainBot chat messages, voice inputs, and idea-generation requests are transmitted to third-party AI providers for inference. Voice inputs are transcribed automatically before being processed as chat messages. We also send relevant conversation context (such as recent messages and the current strategy snapshot) so the assistant can respond.

  • Chat history is not stored on our servers. Conversation transcripts live in your browser session only. We store only anonymous usage counters to enforce free-plan chat limits.
  • Anonymous chat is allowed within free usage limits (currently 10 messages per 2-hour window) and uses a strictly-necessary anonymous identifier cookie.

2.4 Payment Information

Subscription payments are processed by Stripe. A Stripe customer record is created when you sign up so trials and subscriptions can work. We store a Stripe customer identifier linked to your account but do not store your credit card number or full payment details on our servers. See Stripe's Privacy Policy for how they handle your payment data.

2.5 Automatically Collected Data

  • Session and authentication cookies — used to keep you logged in. These are HTTP-only cookies with SameSite protections, strictly necessary for the Platform to function. The secure flag is enforced in production.
  • Preferences — theme choice, interface language, and sidebar state, stored in cookies or browser storage to remember your settings. No personal data is involved beyond the preference itself.
  • Error and performance data — we use Sentry to collect error reports, performance traces, and error-triggered session replays to help us diagnose and fix issues. This may include browser type, operating system, page URLs, and error stack traces. When you are logged in, reports may include your user ID, email, and nickname to help us reproduce account-specific issues. Replays mask text and block media.
  • Product analytics — we use PostHog to understand how the Platform is used (page views and product events such as starting chat, creating an idea, or starting checkout). Events do not include chat message text, idea body content, or passwords. When you are logged in, events are linked to your account id. Anonymous chat keeps PostHog's anonymous identifier until you sign in.
  • Hosting and network metadata — our hosting provider processes IP addresses and request metadata (such as edge connection headers) to operate, secure, and rate-limit the Platform.

3. How We Use Your Information

We use the data we collect to:

  • Provide, operate, and maintain the Platform and your account.
  • Run AI features, including chat responses, voice transcription, idea generation, and AI summaries, and enforce usage quotas.
  • Process subscription payments, trials, and billing entitlements.
  • Display your public profile information (nickname, rank, role, level, avatar) and your public ideas to other community members.
  • Send transactional emails such as email verification via our email delivery infrastructure.
  • Diagnose errors, monitor performance, and improve the Platform.
  • Measure product usage so we can see which features are used and where people get stuck.
  • Enforce our Terms of Service and protect against misuse.

We do not sell your personal data to third parties. We do not use your data for advertising.

4. Third-Party Services

We rely on the following third-party services to operate the Platform. Each has its own privacy policy governing how they handle data:

ServicePurpose
StripePayment processing & subscriptions
GoogleOAuth social sign-in
Cloudflare Hosting (Pages & Workers), database, image hosting, email delivery, queues, and security/rate-limiting
AI inference providers Chat responses, voice transcription, AI idea generation, and AI summaries. Chat inputs and relevant context are sent for inference and are subject to the provider's processing terms.
SentryError tracking, performance monitoring, and error-triggered session replay
PostHogProduct analytics (page views and product events)

The Platform also loads game and content assets from third parties where needed, such as OpenDota match data, Steam's content network for item images, generated avatars, and fonts. These sources receive only the requests necessary to fetch the asset (such as IP address and requested URL).

5. Cookies & Local Storage

We use a minimal number of cookies and browser storage mechanisms:

  • Session cookies — HTTP-only cookies with SameSite protections used for authentication (including a short-lived session cache). Strictly necessary. Secure in production.
  • Anonymous chat identifier — strictly-necessary cookie (30 days) used to enforce free chat limits for logged-out users.
  • Theme preference — stored in a cookie for up to 1 year to persist your selected theme. No personal data is involved.
  • Language and interface state — language choice and sidebar collapsed state stored in cookies or browser storage.
  • Product analytics — PostHog stores an anonymous identifier in browser storage (and a first-party cookie) so return visits can be counted. After you sign in, that identifier is linked to your account id. This is not an advertising cookie.

We do not use advertising cookies, tracking pixels, or third-party marketing cookies.

6. Data Sharing & Disclosure

We may share your information only in these cases:

  • Public profile — your nickname, avatar, rank, role, level, and submitted public ideas are visible to other users and may appear in search results. Private ideas are not shared publicly.
  • Service providers — with the third-party services listed above, solely to operate the Platform.
  • Legal requirements — if required by law, court order, or governmental authority.

7. Data Retention

We retain your account data for as long as your account is active. If you request deletion of your account, we will remove your personal data within 30 days, except where we are required to retain it for legal or billing purposes (such as Stripe subscription records).

Supporting retention windows:

  • Chat transcripts are not stored on our servers; only quota counters are kept.
  • Chat quota counters expire automatically (currently within 24 hours).
  • Error logs collected by Sentry are retained according to Sentry's data retention policies and typically expire automatically after 90 days.
  • Product analytics events collected by PostHog are retained according to PostHog's data retention for our project.
  • Email delivery records, queues, and backups expire on rolling windows and may persist briefly after a deletion request.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Correction — update inaccurate or incomplete data via your profile settings.
  • Deletion — request deletion of your account and associated data.
  • Portability — request an export of your data in a portable format.
  • Objection — object to certain processing of your data.

There is currently no self-serve account deletion or export in settings. To exercise any of these rights, please contact us through our feedback page (when logged in) or by email at support@d2brain.space. For logged-out requests, please use email.

9. Children's Privacy

The Platform is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete that information promptly.

10. Security

We take reasonable measures to protect your data, including:

  • HTTP-only authentication cookies with SameSite protections (secure flag enforced in production).
  • Passwords hashed using industry-standard algorithms (we never store plaintext passwords).
  • Payment data handled entirely by Stripe — never stored on our servers.
  • HTTPS encryption for all data in transit.

No system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Platform. Your continued use after changes are posted constitutes acceptance of the updated policy.

12. Contact

If you have questions or concerns about this Privacy Policy or how your data is handled, please reach out through our feedback page or by email at support@d2brain.space. For privacy, deletion, or export requests when logged out, please use email.