Privacy Policy
Last updated: 13 August 2026
The short version
There is no account to make and no server that stores your work. Your build is saved inside your own browser so that reloading the page does not lose it, and it travels inside the share link rather than being uploaded anywhere.
The site does use Google Analytics, to see how many people come here and whether they come back. It sets cookies. If you are in the EEA or the UK you are asked first, and analytics stays switched off until you say yes. You can turn it off again whenever you like.
That is the whole picture. The rest of this page is the detail, including what is planned and not yet in place.
Who this is
Hero Builder (herobuilder.io) is a free build planner for the game Hero Siege. It is run by one person, not a company, under the name Hero Builder.
Hero Builder is an unofficial fan tool. It is not affiliated with, endorsed by, or connected to Panic Art Studios, the developer of Hero Siege.
What the site collects about you
Hero Builder itself collects nothing, and that is a consequence of how it is built. It is a set of static files: HTML, a stylesheet, some JavaScript, and game data. There is no application server of ours, no database, and no code of ours running anywhere except inside your own browser. There is nowhere for us to put your information.
What does happen is measurement. Google Analytics is installed and reports how the site is used, which means Google receives data about your visit. That is set out in full under Analytics below. The other party that sees anything is the host, Cloudflare, covered further down.
Either way, there is:
- no sign up, no login, and no user account
- no contact form, comment box, or newsletter
- no email address, name, or payment detail requested at any point
- nothing you type or click inside the planner sent to us
- no selling of your information to anyone
What is saved on your device
Three things can end up in your browser's storage, and only the first is always there:
- Your build. One entry in local storage, under the key
herobuilder.build.v1. Described just below. - Your answer about analytics, if you were asked one, so that the question is not put to you again on every page.
- Google Analytics cookies, but only while analytics is running. See Cookies.
What the saved build holds
Exactly the same short piece of text that a share link carries, and nothing more: the description of the build you are working on, such as the class, the level, the gear, and the points you have spent. It contains no identifier, no timestamp, and nothing about you or your device.
What it is for
So that closing the tab or reloading the page does not throw away your work. That is its whole purpose. It is a functional store, not a tracking one: nothing reads it except the planner running in your own browser, and it is never transmitted anywhere.
How to get rid of it
It is yours, and you do not have to ask anyone to delete it:
- Clear site data for herobuilder.io in your browser settings. In most browsers this is under Privacy, then site or cookie settings. This removes the saved build immediately, and it removes the other two items in the list above at the same time.
- Use a private or incognito window, where it is discarded when you close the window.
- If a build ever fails to load, the page offers a Start fresh button, which deletes the saved build and reloads with an empty planner.
If your browser has storage disabled, the planner still works. It simply will not remember your build between visits.
Your build stays in your browser
This one is worth stating plainly, because it is unusual.
When you build something in the planner, the build is stored in the part of the address after the # symbol, which is called the fragment. Web browsers never send the fragment to the server. It is handled entirely on your machine.
The practical result: when you share a build link, the build itself is never sent to us. We do not receive it, cannot log it, and have no copy of it. There is no gallery of everyone's builds sitting on a server somewhere, because there is no server.
That holds for analytics too. Google Analytics records the address of the page you are on, and that address stops at the #. Your build is on the far side of it, so it is not part of what is sent.
The other side of that is worth knowing too. Because the build travels inside the link, anyone you give the link to can open the build, and so can anyone they pass it on to. Treat a build link as public once you have shared it.
What your browser downloads
When you open the planner, it downloads the page, the stylesheet, the code and the game data files from herobuilder.io itself.
One other request goes out: the Google Analytics tag, loaded from Google. That is the only third party your browser contacts here. There are still no external fonts, no embedded videos, no social media buttons, and no comment platform. The site is served with a Content Security Policy that names the places code and content may come from; anything not on that list is blocked rather than merely avoided.
Analytics
The site uses Google Analytics 4. The measurement ID is G-JCY9GESXTW.
What it is for
To see roughly how many people use the site, which pages are read and which are ignored, and whether anyone comes back. What we look at are counts and trends. It is not connected to any advertising, and there is no account or profile here it could be attached to.
What it collects
In ordinary terms:
- which pages you view, and when
- an approximate location worked out from your IP address. Country, usually a region or city. Not an address, and not precise.
- your device, screen size, browser and operating system
- the referrer, meaning the site or search that sent you here, if any
- whether this browser has been here before, from the cookie described below
It does not collect your name or your email, because the site never asks for either. It does not collect your build, for the reason given above.
Who receives it
Google. Google Analytics is run by Google, who process this data for us and under their own terms. What Google does with data collected from sites that use its services is described in the Google privacy policy and in how Google uses information from sites that use its services.
Your choice about analytics
If you are in the EEA or the UK, you are asked before any analytics cookie is set. Analytics storage starts denied and stays denied until you grant it, so until you answer yes, nothing is stored on your device for analytics and no analytics cookie exists.
Saying no is a real answer, not a formality. The planner behaves identically either way, and nothing is withheld from you for declining.
Outside the EEA and the UK you may not be asked. The opt outs below work wherever you are.
How to withdraw consent or opt out
- Use Cookie choices on the planner. It reopens the question so you can change your answer, and it keeps your saved build. The same control sits at the foot of the build summary.
- Clear site data for herobuilder.io in your browser settings. That deletes the analytics cookies and the record of your answer, so you are asked again on your next visit and can answer differently. It clears your saved build as well.
- Block cookies for this site, or switch on your browser's tracking protection. Most browsers have this built in. The planner does not need cookies to work.
- Install Google's Google Analytics opt-out browser add-on, which stops Google Analytics on every site you visit, not only this one.
- Use a private or incognito window. Anything set is discarded when you close it.
Cookies
The site sets no cookies of its own. Google Analytics sets cookies, and they are the only cookies here.
Their names begin with _ga. What they hold is a randomly generated number that lets Google tell one browser apart from another, which is how a second visit is counted as a second visit rather than a new person. No name, email or account is attached to it, because the site has none to attach. Google's default is for them to last up to two years unless you clear them.
They are set only while analytics is running, which for visitors in the EEA and the UK means only after you have said yes. See Your choice about analytics above.
Hosting and server logs
The site is hosted on Cloudflare Pages. This happens whether or not analytics is running, so it should not be glossed over.
Like every web host, Cloudflare receives the technical information your browser sends with each request. That normally includes your IP address, your browser and operating system (the user agent), which file you asked for, and when. Cloudflare uses it to deliver the site and to protect it against attacks and abuse.
That processing is Cloudflare's, as the infrastructure provider. We do not receive these logs, do not store them, and do not build any profile from them. What Cloudflare does with them is described in the Cloudflare privacy policy. The analytics described above is a separate thing: it runs in your browser and does not read these logs.
Advertising
No ads are served on this site today, and no ad network is contacted.
You may notice empty boxes in the layout where ads would sit. Those are deliberately reserved space and nothing more. They hold their size so that adding advertising later cannot make the page jump around while you are reading it. Nothing is loaded into them.
Planned: advertising
This is not in place yet. It is set out here so that the plan is not a surprise, not because it is happening now. Everything above describes the site as it actually is today.
The intention is to add advertising, most likely Google AdSense, to help cover the cost of running the site.
Being straightforward about what that would mean:
- It will introduce further cookies, or similar storage, placed by the advertising provider rather than by us.
- The advertising provider will receive information about your visit directly, including your IP address, and may use it to select ads.
- For visitors in the EEA and the UK, you will be asked before any of that storage is set, in the same way as for analytics, and refusing will be a real option rather than a formality.
- This page will be rewritten to describe exactly what is used, and the "last updated" date at the top will change, before any of it goes live. It will not be switched on quietly and documented afterwards.
Two things will not change: your build will still live in the URL fragment and still never be sent to us, and the autosave will remain a single first-party key holding nothing but the build.
Your rights
Rather than reciting a list of rights copied from somewhere else, here is the honest position.
We hold no personal data about you ourselves. There is no account, no record, and no file with your name on it. A request to us to access, correct or export your personal data would find nothing to act on. That is not a refusal, there is simply nothing there.
Data about your visit does exist, in three places:
- Your own browser. The saved build, your answer about analytics, and any analytics cookies. All of it is on your machine and under your control. You do not need our permission or cooperation to read or delete any of it.
- Google Analytics. Held by Google and governed by the Google privacy policy linked above. What we look at are counts and trends. Clearing the analytics cookies breaks the link between your browser and anything collected before, and the opt outs above stop further collection.
- Server logs, held by Cloudflare as the host, not by us, and governed by the Cloudflare privacy policy linked above.
If you want to ask about any of that, the contact address is at the bottom of this page.
Children
The site is not aimed at children, and it asks nobody of any age for personal information. Nothing here is set up to identify an individual visitor.
Changes to this policy
This page will be updated when the site changes, and in particular before advertising is introduced. The date at the top always reflects the current version. Material changes will be made here before the change takes effect, not after.
Contact
Questions about this policy, or about how the site works, can be sent to [email protected].