Privacy Policy
This describes what data the Orikon application and the orikon.pro website collect, why, where it is kept and how to have it deleted. We try to collect as little as possible.
What we collect
| Data | Why | Where |
|---|---|---|
| Login and password hash | signing in | our server |
| E-mail address | confirming the account and recovering access | our server |
| Discord id and nickname | only if you linked it: recovery codes and alerts | our server |
| Collection: prime parts, relics, mastery | syncing between your computers | your PC; our server when sync is on |
| warframe.market ingame name | showing which trading account a login belongs to | our server |
| Interface language | so mails and bot messages arrive in it | our server |
| IP address and request time | web server technical logs | our server, up to 30 days |
| Page view counter | how many people opened the site and how many pressed «Download» | our server: daily totals only, no addresses and no identifiers |
| Install id | a random number the app creates on your machine the first time it runs: it shows which step people stop at | our server, up to 180 days |
| Steps: installed, launched, signed up, first scan, first trade read | the fact and the date, and no more than one record per step per day | our server, up to 180 days |
| Which tabs of the app were opened, and whether a feature worked | so we can tell what people need from what is simply broken: the name of the tab and the date, at most one record a day. For example «opened the Syndicates tab on 11 September» or «a scan finished and read nothing». How long you spent there and what you looked at is not recorded | our server, up to 180 days |
| Screenshots after the first scans (beta only) | in the beta and on Beta Test accounts: a screenshot after the first three scans of the inventory, relics and rewards, to see what the app read and how it showed the result. See «Screenshots in the beta» below | our server, 30 days |
What we do NOT collect
Your warframe.market password never leaves your computer. It is kept locally, encrypted by Windows (DPAPI) — the file cannot be decrypted on another machine or under another user account. Only your ingame name is sent to our server.
The regular version does not collect screenshots. The screen image is processed on your computer for text recognition and is never uploaded. There is one exception, the beta, described below under «Screenshots in the beta».
We do not collect the contents of EE.log. Reading the
game log is off by default, happens locally, and its contents are never
transmitted — it contains personal data, which is why the feature is
optional.
The steps and tabs say nothing about what you do in the game. The steps above are «happened / did not happen» marks with a date: what you scanned, what you sold and who you traded with is neither sent nor stored.
The install id is not tied to your computer. It is a random number, not a hardware fingerprint: reinstall the app and the number is a different one, and the old one leads back to nothing.
There are no ads and no third-party trackers: no Google Analytics, no Yandex Metrica, no social network pixels. The page counter is ours and runs on our own server.
Screenshots in the beta
If you use the beta (the «test» update channel) or your account has the Beta Test privilege, the app sends us a screenshot after the first three scans of each kind: the inventory, relics and the reward screen. That is at most nine screenshots per install, and none are taken after that.
The screenshot shows the whole screen with the Orikon window on it, scaled down to about 1280 pixels wide, so it is clear what the app read and how it showed the result. Anything that was on the screen at that moment ends up in it, including chat and nicknames. The app tells you about this before the first screenshot.
Only the developer sees them. They are kept on our server for 30 days and deleted automatically. To switch it off: Settings → Beta: screenshots of the first scans to the developer; switching it off deletes the screenshots already sent from the server straight away.
Who we share with
We do not sell your data and do not pass it to third parties for their own purposes. Sharing happens only as far as running the Service requires:
- Hosting (Timeweb, Russia) — the server itself and the mail server that sends our messages;
- Discord — if you linked an account, our bot sends you direct messages; only the message text and your id are involved;
- warframe.market — price requests go straight from your computer.
How long we keep it
Account data — for as long as the account exists. Web server logs — up to 30 days. Beta screenshots: 30 days. The install id and the steps — up to 180 days, after which they are deleted; if you delete your account, the link between it and the id goes with it. One-time confirmation and recovery codes — 15 to 60 minutes, after which they stop working.
How to switch it off
In the app: Settings → Help us improve → off. The app then stops sending steps and asks the server to delete everything already sent from your id. Not «we will stop collecting from now on», but «and forget the rest», in one action, with no e-mail and no waiting.
Beta screenshots have a switch of their own: Settings → Beta: screenshots of the first scans to the developer. Switching it off likewise deletes the screenshots already sent from the server straight away.
The site page counter is switched off by an ad blocker or by blocking scripts: it is a script on the page. There is no separate button for it because it does not know who you are, so there is nothing in it to turn off.
Your rights
- Find out what data of yours we hold and get a copy of it.
- Correct inaccurate data.
- Delete your account together with all related data.
- Withdraw consent to processing — equivalent to deleting the account.
For any of these, write to [email protected] from the address on the account. We reply within 30 days.
Children
The Service is not intended for anyone under 13 and we do not knowingly collect their data. If you believe a child has given us their data, write to us and we will delete it.
Security
The connection to the server uses HTTPS. Passwords are stored as a salted PBKDF2 hash (120,000 iterations) — the original password cannot be recovered from it. No system removes risk entirely, so please use a unique password.
Changes
Changes are published on this page with a new version date. We will announce material changes in the app or by e-mail as well.