Privacy & data
This page is GENERATED from the code: the event catalogue and the permissions come from the files that implement them, not from what anyone remembers. If an event is added tomorrow, the figure below changes by itself.
Your copy of the game never leaves your device. Extraction happens entirely in your browser: the files are read from your disk and stay in the browser's local cache. There is no server receiving them.
What leaves and what doesn't
| Leaves | Under what permission | |
|---|---|---|
| Your Ultima V files | No | — · never sent |
| The game's sound | No | — · never sent |
| Your saved games | Not uploaded | — · they live in your browser |
| Visit analytics and a recording of your session — including what you type and the game screen | Yes, by default | analytics checkbox, on by default; turn it off whenever you like |
| The list of keys you pressed | Only if you turn it on | session checkbox, off by default |
The 2 permissions are independent. We record the session by default: analytics and recording start as soon as you arrive, on every page of the site, without waiting for you to answer the notice. You can turn it off at any time, and then we stop and delete your identifiers. "Save my game" is separate and stays off until you turn it on.
🔴 The recording row and the saves row must be read together. Your save files are never uploaded; but the session recording does take the game screen as your browser draws it, and what you type, and if you enable the second permission the list of keys you pressed leaves as well, from which a session can be rebuilt. Saying only "your saves never leave" would be true to the letter and misleading in substance.
Analytics and session recording: what is sent, and to whom
It is sent to PostHog, at https://eu.i.posthog.com — a third-party service, not a server of ours. That is what can be checked from outside, and it is what we say: the destination. What that third party does afterwards we have not measured and will not claim.
This is what it gets, unless you decline:
- The recording of your session: how you use the site, what you type (unmasked) and the game screen as your browser draws it from your files. This is the only channel images leave by; it goes to the project's private space and is never published.
- What the service collects on its own: the pages you open and when you leave, clicks and field changes, and unhandled program errors.
- 21 events of our own: step names —where people come in and where they drop out—. The list comes from the catalogue in the code, which is the only place they are declared.
No name, no account, no person profile.
The 21 events, one by one
portada_vistabyo_vistoconsentimiento_dadobyo_carpeta_elegidabyo_fuente_invalidabyo_extraccion_iniciadabyo_extraccion_okbyo_extraccion_fallobyo_jugarbyo_primera_partidabyo_momento_anadidobyo_partida_jugadajuego_arrancadocharacter_createdjourney_resumedgame_savedmanual_save_createdsave_loadedsave_deletedsave_importedsave_exported
What this page looks at, and what it cannot see
So as not to sell you more certainty than there is, this is the exact scope of what is derived:
- It does see the event catalogue, the panel's checkboxes, the recipient, and whether these pages' entry point calls analytics or not. All four are read from the code on every build of the site.
- It does not derive the list of what the service collects on its own or of the recording: that is written from the configuration in
game/src/web/sdk-posthog.ts, which is where you can check it. - It does not see what third-party code might send, nor what your own browser or your extensions do on their own.
- 🔴 And a limit of our own: the internal forwarder the saves panel uses accepts the event name as free text; what keeps the list above complete is a check that runs on every build and leaves the site red if an event outside the catalogue shows up.
How to change your mind
That is the real panel above, the same one you get the first time: each permission separately and save, or "Reject everything" in one click. Declining breaks nothing on the site or in the game. If you decline with the page open, the recording stops at that moment —in the site's other tabs too— and the identifiers the service keeps in your browser are deleted; whatever had already been sent up to that instant is not deleted from here. If you can't see the panel, you have JavaScript disabled — in which case nothing is being sent either, because what sends is JavaScript.
From any other page on the site the same panel opens with the "My permissions" link in the footer.
Your choice is stored in your own browser (openu5-consentimiento), not on a server. Clearing the site's data clears it, and everything goes back to the default: analytics and recording on, "Save my game" off. If you had declined, you will need to decline again. And if your browser does not let the choice be stored (some browsers' private mode), declining only holds on the page where you pressed it.
The records table: the one thing that goes through a server of ours
Everything above happens in your browser or goes to a third party. There is one exception, and this is it: if you enable the session permission and press "upload" on a replay, that replay goes to a server of ours (this site's own functions, on Cloudflare), and two things of yours are stored there:
- The alias you type (up to 24 characters; letters, digits, space and
-_.), together with the key list, the turn count and the engine version. It is public: it appears in the table and on each replay's page. It is kept in two stores (RECORDS_KV, the full record, andRECORDS_DB, the index that sorts the table) and it has no expiry and no delete button: to withdraw an upload, open an issue in the repository with the replay id and we remove it by hand. - A digest of your IP address, not the address: to cap uploads at 10 per hour, the server computes
SHA-256(salt + IP)with a secret deployment salt and uses the first 32 characters as the key of a counter that deletes itself after two hours (RECORDS_KV, with expiry). The IP is never written anywhere, the counter is not linked to any record or alias, and without the salt configured the server computes nothing.
None of this happens without the session permission: without it there is no upload button. The server code is demo-byo/src/records-servidor.ts, and those two stores are the only ones it declares.
Erasing everything, and exactly what goes
Your extracted copy and your saves live in this site's storage, in your browser. They go with the «Erase my files from this browser» button on the loading page, or by clearing the site's data from the browser itself.
That button asks first whenever there is something that cannot be recovered, and shows the exact inventory of what will go: your extracted copy, your saved games, your recordings and this browser's settings —language, permissions, skin and sound—, with consent named among them. Extracted assets are regenerated by dropping the folder again; a forty-hour save is not. With no saves and no recordings it asks nothing, because there is nothing to lose.
The pages under /mejoras, /diferencias and this one emit none of our own catalogue events: their entry point (consentimiento-doc.js) does not call analytics, and that can be checked in the published file. But they are recorded, like the rest of the site: the service logs the visit, the clicks and the session recording, unless you have declined.
Check it yourself
The engine is published under GPL-3.0-or-later at github.com/kokoima/openu5. The event catalogue is game/src/web/eventos.ts and the panel game/src/web/panel-consentimiento.ts: that is where everything this page summarises lives.