Privacy · DragoNightly
Privacy Policy
1. What this document is about
DragoNightly is a website and application for the Game Master: an interactive screen, a library of materials, and tools for preparing and running tabletop role-playing sessions. This page describes what data the site needs, why it is used, how long it is stored, and how to contact us about privacy.
We do not use advertising networks, third-party pixels, or marketing profiling. The site may use only functional cookies that are necessary for authentication, form protection, and account operation.
2. What data we collect
| Data | Purpose | Retention period |
|---|---|---|
| Registration, sign-in, password recovery, account confirmation, and service notifications. | Until the account is deleted. | |
| Login | A unique account identifier for signing in to the application. Assigned automatically at registration; can be changed in the profile. | Until it is changed or the account is deleted. |
| Name (optional) | Display in the site and application interface. | Until it is changed or the account is deleted. |
| Password hash | Verifying the password at sign-in. The password itself is not stored in plain text. | Until the password is changed or the account is deleted. |
| Session and CSRF | Keeping you signed in and protecting forms against request forgery. | Usually up to 24 hours or until you sign out. |
| Feedback | The message, the chosen contact method, and attached images are needed to respond to your request. | Until the request is handled and for a reasonable period to keep the correspondence history. |
| Download tokens | Issuing short-lived links to application builds for your platform. | When the token expires, usually 24 hours. |
| Technical logs | Security, error diagnostics, and protection against password brute-forcing, spam, and overload. | Usually up to 30 days, unless a longer period is needed to investigate an incident. |
3. Cookies
The site uses functional cookies, for example dragonightly_sid
for the session and service tokens that protect forms. Without them,
registration, sign-in, downloading builds, and submitting forms may not work.
Your consent to the cookie banner is stored in the browser's localStorage.
This is only so that the same message is not shown every time you open
the site.
4. Feedback and images
The feedback form can accept images. They are used only to review your request: for example, if you are showing an error, a screen layout, or an interface problem. Do not send documents, passwords, payment details, or other people's personal data through the form.
5. Security
- Passwords are stored only as a strong hash.
- Forms are protected with CSRF tokens and a captcha where needed.
- In production, service cookies must be transmitted only over HTTPS.
- Access to administrative data is limited to support and security tasks.
6. Data sharing
We do not sell personal data and do not share it with advertising networks. Data may be disclosed only when required by law or when necessary to protect the service and its users.
7. Your rights
You can request:
- access to your account data;
- correction of your email, login, or name;
- deletion of your account;
- clarification of what data is associated with your request or download.
Write to mail@dragonightly.ru. To protect your account, we may ask you to confirm that the request was sent by the data owner.
8. Changes to this policy
If the policy changes materially, we will update the date at the top of the document. For important changes, we may send a service notification to the account email.