Skip to main content

Privacy Policy

Your privacy matters to us. Learn how we protect your data.

Last updated: August 28, 2026

Our Privacy Commitment

DotaSense is built with privacy as a core principle. We believe in transparency and minimal data collection. This privacy policy explains what data we collect, how we use it, and your rights regarding your information.

Privacy-First Design: Core timer use does not require an account, and we do not sell personal data or use cross-site ad tracking.

What Data We Collect

1. Website Browser Storage

The DotaSense website uses localStorage and sessionStorage for limited site preferences, analytics controls, first-party session continuity, and browser timer preferences. Browser-stored data can include:

  • Site Preferences: Your selected theme, analytics opt-out choice, and browser timer mode, sound setting, and cue list
  • Anonymous Analytics State: A random visitor ID plus session timing and interaction counts
  • Attribution Context: Referrer and campaign values retained for the current browsing session
  • Interface State: Temporary dismissals or one-time client error-report guards

Browser storage stays on your device until the website reads it or you clear it. When analytics are enabled, the anonymous identifiers and session context used for first-party analytics may be included in requests described below; form-field values are not stored by interaction tracking. Browser timer setup links contain only the selected game mode and cue identifiers—not match time, Roshan or Aegis markers, account data, or personal information.

2. Website and Product Analytics

We use first-party server analytics and Vercel Analyticsto understand visits, downloads, and product usage. Analytics may include:

  • Page Views and Paths: Which DotaSense pages you visit and the path flow during a session
  • Download Events: When the app download button is clicked or a download redirect starts
  • Interaction Events: Link and button labels clicked on the website; we do not collect form field values for this
  • Session Context: Session duration, page count, interaction count, landing page, and exit page
  • Request Context: IP address, approximate IP-based city/region/country, user agent, browser, OS, device type, referrer, and UTM parameters

We use this analytics data internally to understand where users are coming from, what they download, and where the website or app experience can be improved. We do not use it for third-party ad targeting or cross-site tracking.

Raw analytics IP addresses and user-agent strings are removed after 14 days. Raw analytics events are deleted after 90 days. Aggregate reports may be retained longer because they no longer contain those raw request identifiers.

3. Desktop Application

The desktop application stores settings locally on your computer. This includes:

  • Application Settings: Saved in your system's application data folder
  • Custom Audio Files: Stored locally if you upload custom sounds
  • Pro Trial State: Trial start and expiration timestamps, plus whether paid access has previously been recognized, are stored locally to apply the time-limited feature entitlement
  • Window Position: Your preferred window location and size
  • Optional Local Game State: If you enable match-aware setup, Dota 2 sends selected match, map, player (including Steam ID/name where exposed), hero, ability, item, all-player, and draft fields to DotaSense over localhost
  • Optional Local Screen Capture: Draft and scoreboard assistance can capture selected on-screen regions for visual recognition on your computer

GSI payloads and captured screen regions are processed locally and are not uploaded by product analytics. They may leave your device only when you deliberately submit diagnostic material or use an online feature whose interface says that it sends data. The desktop app may also connect to backend services for analytics you opt into, premium licensing, subscriptions, collaboration, authentication, support, and update checks.

4. Optional Desktop Product Analytics

Desktop product analytics are off by default. If you enable “Share anonymous product analytics” in Settings → Privacy, DotaSense creates a pseudonymous installation identifier and sends session and feature-usage events. These can include app version, platform and user agent, language, timezone, screen and viewport dimensions, feature names, timer actions, GSI connection/setup outcomes, and limited match context such as hero, team, game phase, duration, and aggregate end-of-match stats.

Product analytics may record aggregate trial lifecycle, Pro-feature use, offer-view, and checkout-handoff events. Product analytics do not send raw GSI payloads, Steam IDs, match IDs, Dota installation paths, screen captures, custom audio, license keys, or payment details. Turning analytics off stops new collection, clears queued events, and removes the local analytics identifier.

5. Payment, License, Support, and Voluntary Tester Data

If you buy DotaSense Pro Monthly or Pro Annual, Stripe handles checkout, payment method details, invoicing, taxes, and subscription billing. We do not store full card numbers. We may receive and use limited Stripe checkout, customer, subscription, plan, and status identifiers so we can issue licenses, validate active subscriptions, open the billing portal, prevent abuse, and help with support or license recovery.

Support requests may include contact details you choose to provide, order or checkout references, license status, device/app version, screenshots, or diagnostic details needed to resolve the request.

Voluntary product-research or founding-tester forms may include the name or handle and contact route you provide, an invitation or campaign reference, Windows version, broad Dota role and play frequency, the workflow you want to test, optional context, and your consent to test-related contact. We use these details only to select and manage the requested test, collect first-use feedback, and conduct the stated follow-up. Joining a test does not subscribe you to general marketing or authorize a public quote. You can withdraw test-contact permission through the same private route used for the invitation and request deletion of the related intake details.

What We DON'T Collect for Core Timer Use

No name, email, or phone required for the core timer
No Dota 2 account credentials or Steam password
No tracking cookies or third-party cookies
No ad tracking profiles or third-party tracking cookies
No browsing history or cross-site tracking
No protected-memory access or code injection; optional GSI, screen-region data, and configured input helpers are processed locally as described above

How We Use Your Data

The minimal data we collect is used exclusively for:

  • Providing the Service: Storing your preferences to deliver a personalized experience
  • Improving the App: Understanding visits, downloads, session flow, and feature usage through internal analytics
  • Performance Optimization: Identifying performance issues and improving load times
  • Bug Fixes: Understanding where errors occur to improve stability
  • Voluntary Product Research: Selecting and managing requested product tests, collecting feedback, and conducting the stated follow-up
  • Pro Access: Issuing, validating, recovering, and supporting paid Pro subscription licenses

We do NOT use your data for advertising, marketing, or selling to third parties.

Data Sharing & Third Parties

We do NOT sell or rent your data. We use a small number of service providers only to operate the app:

  • Vercel Analytics: Privacy-friendly analytics service that does not use cookies or track individuals. See Vercel's Privacy Policy.
  • Supabase: Used by desktop features such as analytics, authentication, collaboration, or backend-powered app services. Website analytics may be stored in Supabase for internal review.
  • Discord: Used for internal analytics and support alerts, including website visit, session, download, and feedback notifications sent to private team channels.
  • Stripe: Used for optional Pro Monthly and Pro Annual subscriptions, checkout, billing, invoices, taxes, the billing portal, and payment-related workflows.

Core timer localStorage data stays on your device. Optional online features may send limited data to DotaSense, Stripe, Supabase, or hosting providers as described above.

Data Security

We take data security seriously:

  • HTTPS Encryption: All web traffic is encrypted using industry-standard TLS/SSL
  • Minimal Server Data: Core timer settings are local; optional service data is limited to the feature being used
  • Backend License Validation: license signing secrets stay on the web backend and are never shipped in the desktop app
  • Regular Updates: We keep dependencies updated to address security vulnerabilities

Your Rights & Control

Since we collect minimal data, you have full control:

  • Clear localStorage: You can clear your browser's localStorage at any time through your browser settings to remove all saved preferences
  • Opt Out of Analytics: Use browser extensions like uBlock Origin or Privacy Badger to block analytics, or enable Do Not Track in your browser
  • Delete Desktop App Data: Uninstalling the desktop app or clearing app data removes local preferences
  • Desktop Analytics Choice: Product analytics are off by default. Enable or revoke consent at any time in Settings → Privacy
  • Payment, License, Account, Support, or Product-Research Requests: Contact us for service data tied to optional online features; for a private product test, use the same private route as the invitation

Children's Privacy

DotaSense is designed for Dota 2 players, who must be 13 years or older according to Steam's Terms of Service. We do not knowingly collect data from children under 13. Since we don't collect personal information for core timer use, we have no way to verify age. Optional payment, license, support, or account features may process limited personal data.

Transparency

We document privacy-sensitive behavior so you can understand what the app does:

  • Release Notes: Changes are published through the release history and website changelog
  • Privacy Documentation: This policy describes what stays local and what online services are used
  • Security Review: Security-sensitive licensing code is kept server-side instead of embedded in the desktop app
  • Support Channel: Questions and requests can be sent through the repository or support link

International Users & GDPR

DotaSense is available worldwide. For users in the European Union:

  • GDPR-Aware: Our minimal data collection approach is designed to reduce personal data processing
  • Limited Personal Data: Core timer use does not require an account, while optional analytics, premium, support, or authentication features may process limited personal data
  • Right to Access: Local timer data is stored on your device; payment, license, account, support, or voluntary product-research data can be requested through the applicable contact channel
  • Right to Erasure: Clear browser localStorage or app data for local data; contact us for payment, license, account, support, or voluntary product-research requests
  • Data Portability: Export localStorage data through browser developer tools, and contact us for service data tied to optional online features

Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.

Major changes that affect your privacy will be prominently announced on our homepage.

Contact Us

If you have questions about this privacy policy or our data practices, please contact us:

We typically respond to privacy inquiries within 48 hours.

Have Questions?

We're committed to transparency. Reach out if you have any privacy concerns.