Privacy notice
HexJourney · last updated 27 September 2026
In short: HexJourney runs in your browser. The maps you draw, their points of interest and the exploration on top of them live on your device. Two things are exceptions and are described below, because they are the whole point of being honest about this: a shared session, which puts a copy of the map on our server for as long as the session lasts, and Google Drive, if you choose to connect it. We do not profile you, there is no account to create, and outside a live session there is nothing of yours we hold.
Who is responsible
The data controller is TirateIniziativa, which runs this project as non-commercial fan content. Contact: [email protected].
What stays in your browser
Your maps are saved in your browser's own database (IndexedDB), and a few small entries sit in local storage. None of these are cookies and none of them are transmitted.
| entry | what it holds | why |
|---|---|---|
hexplorer (IndexedDB) |
the maps you saved: terrain, roads and rivers, regions, points of interest, the fog and the exploration, and the background image if you loaded one | so your work is still there after you close the tab — it is the very service you asked for by using the app |
hexjourney.lastVisitDay |
a date, e.g. 2026-09-27 |
so the same visit is not counted twice on the same day |
hexjourney.gmToken.… |
the key that proves you are the DM of a session you opened | so that reopening the tab puts you back in charge of your own session instead of locking you out of it |
hexjourney.drive.v1 |
whether you connected Google Drive, and the identifiers of the two folders there | so you are not asked again every time, and the folders are found again even if you rename them. It holds no token and opens nothing on its own |
You can clear all of it whenever you like from your browser's site-data settings. It does not require telling us, because we know nothing about it.
If you export a JSON file or a PNG, your browser produces them and they go wherever you send them.
Shared sessions: the one copy we hold
When a DM opens a session to play with their table, the map has to reach the players, and for that it passes through our server. While the session is alive, the server holds a copy of the map — the world, the fog, the party's position and the background image — and rebroadcasts each change to whoever is connected. Players' names, if they give one, exist only for the duration of the session.
It is not kept. When the last person disconnects, a timer starts: an hour later, if nobody has come back, the session and everything in it are deleted. No account, no history, no backup. Until a session is opened, nothing of your map ever leaves your device.
A session code is short and is meant to be shared with your own table. Anyone who has it can watch the map, so treat it the way you would treat the link to a private call.
What else reaches us: the visit counter
On the start screen there is a public visit counter. When you open the app, your browser sends
our server a request that says only "one more visit". The server keeps
monthly totals only — for example 2026-09: 412 — plus the running
total. No IP addresses, identifiers, cookies, device or referrer information are stored, and
there is no way, not even for us, to trace those numbers back to a person. The "once a day"
de-duplication happens in your browser, using the date described above, and is never sent.
Hosting
The site, the sessions and the counter run on Cloudflare infrastructure (Cloudflare, Inc., United States), acting as data processor. Like any hosting provider, Cloudflare transiently processes the technical data needed to deliver pages and protect the service from abuse, including the request's IP address. See Cloudflare's privacy policy.
Google Drive, if you connect it
Connecting Google Drive is optional and never automatic: it starts only when you press “Sign in with Google”, and until you do, the site does not contact Google at all — not even the sign-in script is loaded. Once you have connected it, the script does load when you open the page, so that the permission can be renewed without asking you again; disconnect and it stops loading.
If you do connect it:
-
one permission is requested, the
drive.filescope, which grants access solely to files this app created and to nothing else in your Drive: the rest of your files stay invisible to us; - no name, email address or other profile data is requested. Writing a file into the Drive of whoever authorised it does not require knowing who they are;
- maps travel straight from your browser to Google, never through us: we keep no copy and never see them;
-
the access token is kept in the
ti_drivecookie described below, so that a single sign-in serves every TirateIniziativa tool. It expires within an hour, together with the permission itself, and is deleted as soon as Google turns it down. Besides it, all that stays in the browser is the fact that you said yes, plus the folder identifiers, which open nothing on their own; -
files are created in the
TirateIniziativa_AppDataStoragefolder of your Drive. They are yours: move, rename or delete them whenever you like, and “Disconnect” revokes the permission without touching them. Deleting a save from inside the app puts it in your Drive bin, where it stays recoverable for thirty days.
Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Transfers, retention, minors
The monthly visit totals contain no personal data and are kept indefinitely, since their purpose is to show how often the tool has been used. A shared session is kept only while it is alive, plus the hour of grace described above. The data in your browser is kept by you, for as long as you like. The service is not specifically directed at children and does not knowingly collect data about them — it does not knowingly collect data about anyone.
Your rights
Regulation (EU) 2016/679 gives you rights of access, rectification, erasure, restriction, objection and portability. In practice there is almost no personal data here to exercise them against: what you draw is on your device and you delete it yourself, and a session deletes itself. If you think something is wrong you can write to the address above, or lodge a complaint with the Italian Data Protection Authority.
Cookies
One cookie, and only if you connect Google Drive. Until you do, this site sets none at all — neither technical nor profiling, neither first- nor third-party. The local-storage entries described above are not cookies and never leave your device.
| cookie | what it holds | why | how long |
|---|---|---|---|
ti_drive |
the access permission Google issued for the drive.file scope — no name, no email address, no profile |
so that one sign-in covers every TirateIniziativa tool: it is set on tirateiniziativa.com, so the home page and each tool find the permission already granted instead of asking you again |
exactly as long as the permission itself, one hour at most. It is also deleted the moment Google turns it down, and when you press “Disconnect” |
It is a strictly necessary cookie: it exists only to deliver the function you asked for by pressing “Sign in with Google”, it is not used to profile you and it is never shared with anyone. That is why no consent banner is shown — connecting Drive is itself the consent, and it can be withdrawn at any time with “Disconnect”.
What it costs, said plainly. Unlike the local-storage entries above, a cookie
travels: the browser attaches it to every request to tirateiniziativa.com. We do not
read it on the server and we do not record it — no server-side code of ours looks at
cookies at all — but it does leave your device, which those entries never do. We accepted
that because it is the only way a single sign-in can serve every tool. If you would rather it did
not exist, do not connect Drive, or press “Disconnect”: it is deleted immediately and
the app goes on working exactly as before.