Privacy policy
1. Operator and scope
PMA Electrical Solutions, LLC, based in New Jersey, United States, operates Frostsim at sim.frostdev.io, its optional accounts, its paid Frostsim Cloud plans and its Discord bot, and is responsible for the processing described here. Privacy requests: [email protected]. This policy does not cover independently operated copies of the open-source software.
2. Without an account: what stays on your device
Without an account, Frostsim parses addon exports and runs simulations in your browser. Pasted profiles, custom simulation scripts and simulation results are not uploaded. Characters, reports, drafts, gear selections, talents and preferences may be saved in your browser, where we cannot retrieve or restore them.
The simulation workspace loads no advertising or analytics SDK. Free public guide pages may display Google AdSense ads when advertising is enabled. Signed-in users with a paid plan, including Guild Cloud payers, do not receive ad code. We do not use your data for AI training.
On ad-supported guide pages, Google and its advertising partners may receive your IP address, browser and device information, the page you visit and advertising identifiers, and may use cookies or similar storage to deliver and measure ads. This may include personalized advertising where you permit it. We do not send your character exports, simulation results or account profile to Google. Read how Google uses information from partner sites and Google's privacy policy. Where required, Google's consent message asks for your advertising choices. Use “Ad privacy settings” on a guide page to revisit those choices. Guide ads stay off if Frostsim cannot determine account eligibility.
3. Information sent over the network
Your browser requests application files, engine binaries, game catalogs and media from Frostsim. The hosting and network infrastructure receives connection information such as IP address, time, requested URL, browser information and response status. Operational logs may record this information to deliver, troubleshoot and protect the service. We also use IP addresses briefly, in counters kept for at most a few minutes, to limit sign-in attempts and report-link views.
Character displays can request portraits from Blizzard and public character information from Raider.IO through Frostsim's proxy. These requests include region, realm and character name; portraits may load automatically unless disabled in the character controls. When you look up a character by name, on the website or with the Discord bot's /sim, Frostsim fetches that character's public Armory profile (equipped gear, talents, class, race and level) from Blizzard; the request includes region, realm and character name. Characters the Armory confirms this way, including names checked while you type, go into a shared search index of public Armory fields (name, realm, region, class, specialization, level and item level) that suggests them to anyone typing the name; it records nothing about who searched. They do not send your full addon export, custom script or simulation result. Game-data requests may also include item or spell identifiers, locale and region. External links, such as Wowhead or Raider.IO links, take you to services with their own privacy practices.
4. With an account
An account is optional. When you create and use one, we process:
- Sign-in: the user ID and display name (Discord username or BattleTag) of each sign-in you link. We ask Discord only for your basic profile (the
identifyscope) and Battle.net only for your account ID and BattleTag (openid). We never receive your password, email address or Discord messages, and we do not keep provider access tokens. - Account record: an account ID, display name, role, creation time, plan status and any support adjustments.
- Sessions: a session cookie (see section 7). We store only a one-way hash of it, with its creation, expiry and last-seen times.
- Saved characters: the addon export text you save to a character slot, which includes the character's name, realm, region, class, specialization, talents and equipment, plus a label you choose. For each character we keep a history of gear changes (up to 200) and simulation results (up to 500): the Quick Sims you upload from your device, cloud runs and patch re-sims.
- Cloud runs: when you run on Frostsim Cloud, the simulation request (your character profile and settings) is sent to our servers and run on a cloud server. We keep the request and the assembled run for 7 days, for support, and the result file for 1 day. We keep a usage record of each run (times, status, processor time, which character) while your account exists, to meter your allowance and bill correctly.
- Report links: when you create a hosted report link, the report is stored and anyone with the link can view it. It stays until you delete it, until you delete your account, or until 30 days after your plan no longer includes report links.
- AI explanations: when you press Explain on a result while signed in, we send that result to an AI model through OpenRouter and show you its answer. What is sent is the simulation's numbers, gear, abilities and talents, the items or rows being compared, or a failed run's error message and log, with your character's name and realm replaced by placeholders first. Nothing is sent until you press the button. We do not keep what was sent or answered. We keep a usage record (the kind of explanation, the model, token counts, cost and time) and, when the model saves them, short notes about a character for your later explanations, filed under an opaque code rather than the character's name. Only you can have your notes read back to the model, and they are deleted with your account.
- Security records: an audit log of important account events, such as account creation and deletion, administrative actions, integration calls and settings changes.
5. Payments
Paid plans are processed by Stripe. Stripe collects your payment details, email address, billing country or address and similar information at checkout under its own privacy policy. We do not receive or store full card numbers. We receive and keep a Stripe customer ID, your subscriptions (plan, term, status, billing period and the Discord server for a server plan), and the payment events Stripe sends us.
6. Discord bot and integrations
When someone uses the Frostsim bot, Discord sends us the interaction, including the member's Discord user ID, the server ID, the member's role IDs and permissions, and the command options. We use it to answer the command and to check the member's share of a server pool, and we keep the reply token for up to 15 minutes to post the result. The runs themselves are recorded as described in section 4. For a server with a plan, we store the role allowances the payer sets, and we read the server's name and role list from Discord to show them to the payer.
If you allow the Loothing Discord bot to sim your characters, Loothing can start cloud runs of your saved characters and receive their results. We record that permission and each call Loothing makes. You can withdraw it at any time in your account settings.
If a member adds takeaway:true to /sim or /compare, the finished result is sent to an AI model in the same way as an AI explanation (section 4), and the answer is added to the reply. Without that option nothing is sent.
7. Cookies and browser storage
The simulation workspace does not set advertising or analytics cookies. Google AdSense on free guide pages may use advertising and consent cookies as described in section 2, subject to your choices and applicable requirements. With an account, Frostsim sets two strictly necessary cookies: __Host-fs_sid, which keeps you signed in for up to 30 days, and __Host-fs_oauth, which protects a sign-in in progress for up to 10 minutes. Both are first-party, secure and not readable by page scripts.
Functional storage: localStorage entries prefixed frostsim. keep drafts, selected settings, character display choices, interrupted-run recovery information, whether you are signed in (frostsim.account) and where your runs go (frostsim.placement). The frostsim IndexedDB database holds local characters, setups and reports. These support the features you use.
Application and media caches: service-worker and browser caches store the application, engine, game data and retrieved media to support loading, reuse and offline operation. Cached assets can be large; browser eviction may remove them.
Your storage choice: frostsim.storage-choice.v1 remembers whether you rejected optional storage or allowed diagnostics.
Optional diagnostics: off by default. Only after you choose “Enable diagnostics”, frostsim.trace retains up to 60 recent diagnostic entries, such as events, timings and error details, on this device. These entries are not automatically transmitted. Turning diagnostics off deletes existing saved trace entries. Use “Cookie settings” in the website footer to change this choice at any time. No storage popup is shown automatically, and this choice is not acceptance of the terms of use or consent to unrelated processing.
Local records have no automatic expiry unless the relevant feature removes or replaces them. Delete individual records through the app, or clear all site data for sim.frostdev.io in your browser settings; export anything you want to keep first.
8. Sharing links and support
Share links that hold data in the URL fragment (the part after #) are not sent to Frostsim in normal requests, but anyone with the complete link can read its contents, and they cannot be revoked centrally. Hosted report links are described in section 4.
If you contact us, we receive the contact details, message and files you choose to send, and use them to respond and resolve the issue.
9. Purposes and legal bases
We use the information above to provide the features you ask for (accounts, saved characters, cloud runs, report links, the Discord bot and integrations), to meter allowances and take payments, to keep the service secure and prevent abuse, to support you, and to meet legal obligations such as tax and accounting. Where the GDPR or similar law applies, we rely on performance of our contract with you for account, plan and bot features; our legitimate interests in operating, securing and improving the service and in serving a Discord server's payer and members; your consent for optional diagnostics and for the Loothing integration; and legal obligations for payment and tax records.
10. Service providers and transfers
We use these providers, each only for the purpose described:
- Stripe (payments and billing).
- Google AdSense and its disclosed advertising partners, only on eligible ad-supported guide pages, for advertising, measurement and consent management.
- Hetzner Online (cloud servers in Germany that run cloud simulations, and temporary build servers).
- Cloudflare (R2 storage for cloud results, report links and engine files).
- Discord (sign-in and the Discord bot) and Blizzard (Battle.net sign-in, game data and portraits).
- Raider.IO (public character information you request).
- OpenRouter and the AI model provider it routes each request to, only when you press Explain or add
takeaway:trueto a Discord command. We ask for providers that do not collect prompts for training, but a provider's own logging is under its own policy. - Loothing, only if you enable the integration.
- Our hosting provider, for the web server, database and cache.
These providers may process information in the United States, the European Union and other countries. Where the law requires safeguards for international transfers, we rely on appropriate mechanisms such as the EU Standard Contractual Clauses or a provider's certification under the EU-US Data Privacy Framework. We may disclose information where legally required or reasonably necessary to protect legal rights and address abuse.
11. Retention
- Account, saved characters, their history, subscriptions and run usage records: while your account exists.
- Cloud run requests: 7 days. Cloud results: 1 day. Run progress lines: 1 hour.
- AI usage records: while your account exists, then detached from it (they keep no content). AI notes about a character: until you delete your account.
- Sessions: until you sign out or they expire (30 days).
- Report links: as described in section 4.
- Database backups: 14 days, so deleted data leaves our backups within 14 days.
- Security and audit records: as long as reasonably necessary for security, fraud prevention and legal claims. When you delete your account, they are detached from it.
- Payment records: Stripe keeps them as financial law requires. We keep our billing records for as long as tax and accounting law requires.
- Server-side game-data caches: temporary. The Raider.IO profile cache lasts one hour. Character search index entries: at most 30 days after the Armory last confirmed the character.
- Operational logs: kept according to our infrastructure's log rotation.
12. Your choices and rights
You can use Frostsim without an account. With an account, you can download a copy of your account data, unlink a sign-in method, withdraw the Loothing permission, delete saved characters and report links, and delete your account from the account settings. Deleting your account removes your account, characters, history, report links, stored results and integration permissions, and deletes your Stripe customer record, which cancels your subscriptions.
Depending on where you live, you may have rights to access, correct, delete, receive a portable copy of, restrict or object to processing of your personal information, and to withdraw consent without affecting earlier processing. Contact us at the address in section 1. We may need proportionate information to verify a request. We cannot identify or delete records stored only in your browser, or recover copies of shared links held by others. You may also complain to your local data protection authority. Exercising your privacy rights will not result in unlawful discrimination.
13. Children, security and changes
Frostsim is not directed to children under 13 and does not knowingly collect their personal information. If you believe a child gave us personal information, contact us so we can delete it. We use reasonable safeguards, such as encrypted connections, hashed session tokens, isolated cloud servers and least-privilege access, but no service can guarantee absolute security.
We will update this policy when our practices change and show the revised date. Material changes will receive additional notice where required, and new optional tracking would require an updated notice and any legally required choice before it starts.