Privacy Policy
3DX Hosting Companion is local-first. An online account is optional, and the local hosting tools remain available without one.
Data stored locally
Phrases, folders, turn-order settings, overlay settings, Room File source locations, and local backups are stored on your computer. They are not uploaded merely because the app is installed or opened.
Optional account information
If you choose to sign in with Google or Discord, the account service stores the provider’s permanent user identifier, your display name, optional email address and avatar, account tier, session records, and account timestamps. The app never receives or stores your Google or Discord password.
Signed-in accounts receive a random Friend Code. Friend requests and accepted friendships store the participating account identifiers and timestamps. Friends can see each other’s display name and avatar. OAuth accounts are not searchable, and friendship does not grant access to backups or automatically share content.
Optional cloud backups
Cloud backup requires an optional Companion account and runs only when you explicitly choose a backup action. Signing in alone does not upload phrases or Room Files. Phrase backups may contain folders, messages, commands, quickbinds, and phrase relationships. Room File backups contain the exact bytes of files you explicitly enable and submit. Backup objects are stored privately in Cloudflare R2 with ownership, filename, size, checksum, counts, and creation metadata as applicable. They are not made publicly accessible.
Optional Co-Hosting sessions
Co-Hosting requires two accepted friends and a direct invitation. When both users connect, the Host explicitly places a temporary copy of Game Host phrase folders, phrases, and turn-order state into the private room. The Co-Host can view and send the session copy and both users can update turn order. The app does not insert those phrases into the Co-Host's local phrase database. Room membership and timestamps are stored in the account database; synchronized room state is stored in a private Cloudflare Durable Object and deleted when the room ends or expires after 12 hours.
Optional public feedback
The in-app feedback form does not require an account. If you submit it, the entered title, description, optional in-game name, app version, and Windows version are published as an issue in the public GitHub repository. The form warns about public visibility and requires confirmation before submission. Phrases, Room Files, account details, and diagnostic logs are not attached. A random local installation identifier is used only to rate-limit submissions and is not published in the issue.
How information is used
Online information is used only to authenticate your account, maintain secure sessions, determine feature access, provide requested cloud services, prevent abuse, and troubleshoot service failures. It is not sold or used for targeted advertising.
Service providers
Cloudflare provides account API, database, file-storage, security, and operational infrastructure. Google or Discord processes the login you select under its own privacy terms. GitHub hosts public downloads, update information, and this website.
Retention and security
Cloud transfers use HTTPS/TLS encryption in transit. Cloudflare R2 automatically encrypts stored objects at rest using Cloudflare-managed keys. Backup access requires an authenticated Companion session, and the storage bucket is not public. Room Files are SHA-256 checked before storage and throughout restore to detect alteration. This is managed cloud encryption, not end-to-end encryption with a key held only by the user; the developer’s cloud account and Cloudflare operate the service infrastructure. No online service can guarantee that unauthorized access is impossible. Session tokens are stored as one-way hashes by the service, and the Windows app protects its refresh token for the current Windows user. Account records remain until you delete the account. Operational logs may be retained temporarily for security and troubleshooting.
Account deletion
Open Settings → Optional Companion account → Delete Cloud Account. This permanently removes the online account, login identities, sessions, and cloud backups. Local phrases, settings, and files on your computer are not deleted. If you cannot access the app, contact the developer through the public release repository.
Children
The Companion is intended only for adults eligible to use 3DXChat. The account service is not directed to children.
Changes and contact
Material changes will be reflected here and in public patch notes. Questions can be raised through the public release repository.