Skip to content
PARACAUSALREPORT
Privacy / data boundaries

What stays here, what leaves, and why.

This notice describes the data paths used by the public site, Google advertising, Bungie-connected inventory, and the optional companion that runs on a user’s own computer.

Effective August 12, 2026

Overview

Paracausal has no general-purpose user-account database. Public report searches send a Bungie Name to Paracausal’s server so it can request the matching public Destiny profile and activity history. Private inventory features require a separate Bungie sign-in. Some preferences and companion features store data in the browser on the device being used.

Normal web hosting necessarily receives technical request information such as an IP address, user agent, requested URL, response status, and time. Hosting and security infrastructure may process that information to deliver the site, diagnose failures, and protect the service. Paracausal does not ask users to publish a real-world identity in order to use the public tools.

Google AdSense and cookies

Paracausal uses Google AdSense to request and display advertising. Google and its advertising partners may use cookies, web storage, IP addresses, device or browser identifiers, ad impressions, interactions, approximate location, and browsing information to deliver, measure, limit, personalize, or prevent fraud in ads, subject to Google’s own policies and the user’s consent or regional settings.

Ads can cause the browser to communicate directly with Google-controlled domains. Paracausal does not receive a copy of a user’s Google account password or Google advertising profile. Users can review or change ad personalization in Google My Ad Center, learn how Google uses information from partner sites in Google’s partner-sites notice, and manage cookies through their browser. Blocking advertising cookies may reduce personalization or prevent an ad from loading.

Bungie Platform and OAuth data

Public lookups

When a user searches a Bungie Name, Paracausal sends it to Bungie and retrieves only the profile, character, raid, dungeon, and definition data Bungie makes available through the relevant public endpoints. Results can include a Bungie display name, membership identifiers, character class, power, emblem, activity identifiers and times, completion status, and basic kill, death, and assist values.

Authorized inventory

When a user chooses “Sign in with Bungie,” Bungie handles the credential screen and returns authorization tokens to Paracausal. Tokens, selected Destiny membership details, a display name, and an anti-forgery value are stored in an encrypted, Secure, HttpOnly browser cookie. Authorized responses can include characters, Vault and character inventory, equipment state, item instance identifiers, stats, sockets, and transfer status. Inventory API responses are marked private and not stored by browser or shared caches.

Tokens are used only to perform the Bungie requests initiated by the connected features. A user can disconnect in Paracausal to clear the site session cookie, and can revoke the app from Bungie’s own account settings. Bungie’s handling of data is governed by Bungie’s policies.

Storage on this browser

Stored itemPurposeDuration
Today favorites and completed checkmarksRemember a personal reset checklist on this device.Local storage until the user clears site data.
Companion chat messages and conversation identifierRestore up to the latest 30 displayed messages for the local Command Center.Local storage until “clear chat” or site-data removal.
Local companion bearerPair only the current browser tab with the loopback companion.Session storage for the tab; removed on disconnect or invalidation.
Encrypted Bungie web sessionKeep an authorized Bungie connection without exposing tokens to page scripts.Until sign-out, invalidation, cookie deletion, or Bungie refresh-token expiry.

This browser-held state is separate from advertising cookies. Users can inspect or delete it using the browser’s site-data controls. Clearing it removes preferences or sessions on that browser but does not delete records held independently by Bungie, Google, a model provider, or the local companion.

Optional local companion

The Command Center can talk directly from the browser to an optional service at 127.0.0.1, the loopback address of the same computer. Pairing requests and the bearer token travel between that browser tab and the local process; the hosted Paracausal service is not the bridge for those companion requests.

The local companion can expose account summaries, inventory, build evaluation, chat, provider settings, and guarded action previews. Model-provider credentials are managed by the local companion, not stored in Paracausal browser storage. If a user configures a hosted model provider, prompts and the account or inventory context needed for an answer can leave the computer for that provider; a local model keeps that path local. The chosen provider’s policy controls its processing and retention.

Retention and disclosure

Public Bungie report responses are cacheable briefly to improve reliability; they are generated from Bungie rather than kept as a permanent Paracausal profile. Authorized Bungie responses use private, no-store responses. Browser data remains according to the table above. Operational hosting or security records may persist for the period needed by the hosting infrastructure to deliver, secure, and troubleshoot the service.

Information may be disclosed when necessary to operate the services described here, comply with law, prevent abuse, or protect users and the service. Paracausal does not represent Bungie, Google, Today in Destiny, a hosting provider, or any model provider as its employee or agent.

User controls

  • Use public pages without connecting a Bungie account.
  • Use Bungie’s privacy settings to control which Destiny profile and activity details its public APIs expose.
  • Disconnect the Bungie session in Paracausal and revoke authorization from Bungie account settings.
  • Clear Today preferences, Command Center chat, cookies, or all site data through the interface or browser controls.
  • Disconnect or stop the local companion; closing the tab ends its tab-scoped browser session.
  • Choose a local model instead of a hosted provider, or do not use companion chat.
  • Manage Google ad personalization and browser cookie permissions using the controls linked above.
No invented inbox

Paracausal does not publish a monitored privacy email or contact form at this time. This notice will be updated before one is represented as available.