Privacy, in plain language

Privacy Policy

Effective August 28, 2026 · Last updated August 28, 2026

1. Introduction

Build Heartopia is a fan-made guide, item database, and community resource for Heartopia. It is not affiliated with, endorsed, sponsored, or specifically approved by XD Entertainment Co., Ltd. This policy applies to build-heartopia.com.

2. Information visitors provide

You can browse without an account. The feedback form accepts a report type, title, details, and optional bug or error steps. It does not request a name or email address. Do not include sensitive personal information in free text.

3. Bug reports, feedback, and suggestions

Submitting the form creates a private ticket containing your text, a random submission key, page or catalog context, and available browser and device diagnostics. Diagnostics include browser, platform, languages, timezone, device and screen details, connection state, accessibility preferences, cookie-capability status, and a same-site source page. The form has no file upload and cannot send a reply.

4. Information collected automatically

Web-server and hosting infrastructure may receive routine request data such as IP address, time, requested URL, status, referrer, and user-agent. When feedback is submitted, the application converts the request IP address to a keyed one-way hash for abuse controls.

Build Heartopia sends a small first-party page-view record to its own server when you open a page or move to another page in the application. The record contains the page path without its search terms, selected public item-category filters when present, the referring website’s domain when available, the time, and broad device, browser, and operating-system families parsed by the server. After a catalog search settles, the site may also record the search surface, broad query-length and result-count ranges, whether there were zero results, and the number of active category filters. Search text is never collected. The full user-agent string is not written to the analytics database.

The server uses the request IP address with those broad technical fields to create separate keyed identifiers for the day, week, and month. Those identifiers rotate with each period and are used only for aggregate visitor and session estimates. The raw IP address is not written to the analytics database. Country is recorded only when a trusted hosting layer supplies a broad two-letter country code; the site does not send an IP address to a geolocation service.

Known crawler, monitoring, link-preview, and obvious automation user agents are excluded. Requests with missing or unusually short user-agent information are classified as suspicious and excluded from the internal traffic totals. These checks are estimates and cannot identify every automated request.

Build Heartopia does not use Google Analytics, advertising pixels, session replay, cross-site tracking, browser fingerprinting, or individual visitor profiles. Catalog data and images are fetched from the same Build Heartopia origin.

5. Browser storage, favorites, and collection checklists

Favorites are item IDs stored in localStorage under build-heartopia:guest-favorites:v1. Collection-checklist progress is stored under build-heartopia:collection-checklists:v1 as collection keys and checked item IDs. Both stay on your device and are not transmitted to Build Heartopia. Checklist images are created in your browser and are shared or downloaded only when you choose those actions. Search and filter state is not kept as saved search history.

6. Cookies and similar technologies

The current application does not set or read cookies. It does not use advertising, persistent analytics identifiers, or cross-site tracking technologies. The first-party traffic count does not use cookies or browser storage. Reading the browser’s “cookies enabled” capability for a submitted diagnostic report does not create or read a cookie.

Local storage is not a cookie and is used only when you ask the site to save a favorite or checklist item. Build Heartopia therefore does not currently show a cookie-consent banner.

7. How information is used

Information is used to deliver the site, save favorites and collection-checklist progress locally, review feedback, diagnose problems, measure aggregate traffic and understand which pages and sections are used, limit abusive submissions, and protect and improve Build Heartopia.

8. Third-party service providers

Build Heartopia uses hosting and server infrastructure to deliver the site and run the private feedback and analytics databases. The analytics system is first-party and does not send usage events to an analytics vendor. The repository does not identify the hosting vendor, server region, or its independent log-retention practices.

Quicksand loads from Google Fonts, so your browser sends Google normal HTTP request metadata. Google states that Google Fonts requests are unauthenticated, do not set or log cookies, and do not log IP addresses. No active CAPTCHA, email, upload, advertising, social-widget, or embedded-video provider was found.

9. Data retention

Favorites and checklist progress remain until removed or browser data is cleared. The feedback service has no automatic deletion schedule for tickets, diagnostics, submission keys, or the IP-derived hash stored with a ticket; those records remain until manually removed. Separate rate-limit attempts are pruned after 48 hours as later submissions are processed. The proposed analytics retention is 90 days for detailed pseudonymous events and longer for daily aggregate counts. An automatic deletion and aggregation job is not active until its backup and deletion procedure is separately approved. Server-log and backup retention is not confirmed.

10. Data sharing

Feedback tickets are not public. Information is handled by the site operator and the infrastructure needed to host and secure Build Heartopia. Aggregate analytics are available only through a password-protected internal dashboard. Google receives the request metadata described above when it serves the site’s font, but submitted feedback and analytics events are not sent to Google.

Information may be disclosed when reasonably necessary to comply with law, protect people or the site, investigate abuse, or complete a service transfer.

11. Sale and targeted advertising

Build Heartopia does not sell or rent personal information, use submitted feedback for targeted advertising, show ads, build advertising profiles, or track visitors across unrelated websites.

12. Data security

Build Heartopia uses HTTPS, same-origin feedback submission, request validation, size limits, origin checks, a password-protected aggregate analytics dashboard, restricted server-side storage outside the public web root, and keyed hashes rather than writing raw IP addresses to the feedback or analytics databases. No method of transmission or storage is completely secure, so we cannot promise absolute security.

13. Children’s privacy

Build Heartopia is a general fan resource and is not intended to knowingly collect personal information from children under 13. Children under 13 should not submit the feedback form.

14. International visitors

If you submit feedback from another jurisdiction, it is processed where the site’s infrastructure operates and may be subject to different laws. Global availability alone does not make every regional privacy law applicable.

15. Privacy choices and deletion requests

You may remove favorites or checklist marks or clear site data, browse without an account, and choose not to submit feedback. To request deletion of a feedback ticket, use the feedback form and include the BH-###### ticket reference.

17. Changes to this policy

Updates will be posted here with a revised Last updated date.

18. Contact information

A dedicated reply-capable privacy email is not yet configured. Until one is supplied, use the feedback form, select General feedback, and begin the title with Privacy request. The form provides a ticket reference but cannot send a reply.

19. Effective date

This policy is effective August 28, 2026 and was last updated August 28, 2026.