Privacy Policy
Effective September 4, 2026
Overview
Time Stranger Team Architect is an unofficial fan-made Digimon team-building application. It lets users browse a game catalog, save a roster and team-building preferences, and generate ranked teams. This policy explains what information is accessed, how it is used and shared, how it is protected, and how users can request deletion.
Google user data
When you choose “Sign in with Google,” the application accesses only your Google account’s stable identifier, email address, display name, and profile image through the openid, email, and profile scopes. This information is used to create and identify your account, display your signed-in identity, keep your data separate from other users, and restore your saved roster and preferences. The application does not access your Google password, Drive files, contacts, calendar, messages, or other Google services.
Other information stored
- Builder information: roster entries, inclusion settings, guest assignments, Aegiomon fragment choices, scoring settings, and role requirements. Coolness edits stay local while you move the slider and are saved to your account when you finish the adjustment, so they are available across devices. Older browser-only ratings can be imported with your explicit choice.
- Generation information: generation jobs, selected parameters (including the current coolness ratings), ranked team results, progress, and error details.
- Operational information: hosting providers may process request logs, IP addresses, browser details, and diagnostic information needed to deliver and protect the service.
- Anonymous usage analytics: Vercel Web Analytics processes aggregated page-view information such as the visited route, timestamp, referrer, approximate region, browser, operating system, and device type. The application removes query parameters and replaces private generation identifiers before analytics events are sent. No custom analytics events are currently collected.
How information is used
Personal information and Google user data are used only to provide or improve user-facing application functions: authentication, account display, saved roster and preference storage, team generation, security, and troubleshooting. Google user data is not used for advertising, profiling, credit decisions, data brokerage, or training generalized artificial-intelligence or machine-learning models.
Sharing and disclosure
The application does not sell personal information or Google user data. Data is disclosed only to service providers that process it as necessary to operate the application: Google for authentication, Vercel for frontend hosting, request routing, and privacy-focused cookie-free aggregate Web Analytics, and Railway for the API, worker, and PostgreSQL database. These providers process information under their own terms and privacy policies. Information may also be disclosed when required by law or necessary to protect users, the service, or legal rights. It is not transferred to third parties for unrelated purposes. Read Vercel’s Web Analytics privacy information.
External catalog and model content
Digimon portraits are loaded from community-hosted GitHub URLs, and Digimon detail pages embed Nuffle’s DSTS Model Viewer. GitHub, Nuffle, and their infrastructure providers may receive ordinary web-request information, including an IP address and browser headers, when their content loads. The application does not intentionally send your Google profile data with those requests.
Storage and protection
Account, roster, and preference data are stored in a PostgreSQL database hosted by Railway. The application uses HTTPS in transit, secure HTTP-only session cookies, server-side OAuth credentials, access controls, and per-user query isolation. Access is limited to what is needed to operate and maintain the service. No method of internet transmission or storage can guarantee absolute security.
Retention and deletion
Completed, failed, and cancelled generation jobs and temporary results expire after 24 hours and are removed by scheduled cleanup. Queued requests expire after six hours. Sessions expire after seven days or 24 hours of inactivity; operational rate-limit counters expire within 48 hours. Account details, roster entries, settings, and saved teams remain until you delete them. Open your account menu to sign out, sign out everywhere, or permanently delete your account and its live application data. Provider backups may retain older copies until their configured backup retention ends. Revoking Google authorization does not automatically delete application data or revoke existing application sessions. Email the private contact below for assistance; never post identity details publicly.
Your choices
You may decline Google sign-in, stop using the application, revoke Google authorization, or request deletion. Depending on where you live, you may also have rights to request access to or correction of personal information.
Children
The service is not directed to children under 13, and the developer does not knowingly collect personal information from children under 13.
Changes
This policy may be updated when the application’s data practices or service providers change. Material changes will be reflected on this page and the effective date will be updated.
Contact
Email maxbrooks114@gmail.com for private security reports, privacy questions, and account-deletion assistance. Do not send passwords, session cookies, or Google tokens.