What MythicSim collects when you sim a character or sign in, who processes it, how long it is kept, and how to get it removed.
The short version
MythicSim collects as little as it can, uses it to run your sims and keep your account working, and shares it only with the services that make the site run. We do not sell your data and we do not share it with anyone for marketing.
This policy covers the MythicSim website (mythicsim.com and its Chinese language mirrors), the MythicSim Discord bot, and the MythicSim in-game addon (together, the "Service"). MythicSim is operated by an individual developer based in Victoria, Australia.
Simming without an account
You can use most of the site without signing in. When you submit a sim we store the /simc string you pasted and the results SimulationCraft produces. A /simc string contains your character name, realm, region, and the gear, talents and profession data the addon exported. It does not contain your Battle.net login or any payment details.
Every sim result has a URL. Anyone who has that URL can open it. Do not share a result link if you do not want the character on it to be seen.
We keep sim inputs and results so result links keep working. We may delete old sims at any time to free space, and we do not currently promise a fixed retention window.
Signing in
You can sign in with Discord, Battle.net, or Google. We never see your password for any of these. What we store depends on the provider:
- Discord: your Discord user id and username. This is what links Discord bot commands to your account.
- Battle.net: your Battle.net account id and BattleTag. During sign-in we also read the list of World of Warcraft characters on your account (name, realm, class, level, and for max-level characters the active spec, item level and last login) so the sim form can offer them as one-click targets. We do not keep the Battle.net access token after sign-in finishes.
- Google: your Google account id and email address. The email is used to identify you when you report a problem and for nothing else. We do not send marketing email.
Sims you run while signed in are attached to your account so they show up on your history page. A session cookie keeps you signed in for 30 days of inactivity.
Discord bot and guild tools
When a server invites the MythicSim bot, the bot only reads the slash commands sent to it. It does not read or store other chat messages.
Guild features (roster sims, loot ranking, enchant checks, group sessions) store the character names, realms and regions that a server member adds, the Discord id of whoever added them, and the sim results for those characters. Character gear and talents for these features are read from Blizzard's public Armory API.
In-game addon
The addon runs on your machine and only sends data when you paste its output into the site or link it to your account. When you link it, we store a hashed pairing token and a character label so your account page can show which addon is connected. We never store the token itself.
Analytics and cookies
We use two analytics tools to understand how the site is used and which features are worth building:
- Google Analytics 4 sets cookies (for example _ga) to count visits and pages viewed. Google processes this data under its own privacy policy.
- PostHog records page views and clicks so we can see where people get stuck. Session replay is disabled. Anonymous visitors are not profiled; once you sign in, events are tied to your account id so we can debug problems you report.
Beyond these, the site sets a cookie to remember your language choice and a session cookie when you sign in. Preferences such as your last used fight style are kept in your browser's local storage and never leave your device unless you run a sim.
You can block analytics cookies with your browser or an extension. The site keeps working without them.
Advertising
Content pages (rankings, guides and tier lists) show ads managed by Mediavine and served by its partners. Ad partners may set their own cookies and use your IP address and browsing activity on the page to choose which ads to show. Where the law requires it, a consent banner lets you refuse this before any ad cookies are set, and you can change that choice at any time from the "Update Privacy Settings" link (EU and UK) or the "Do Not Sell or Share My Personal Information" link (US states with privacy laws) that Mediavine adds to those pages.
Ads are never shown on sim submission or result pages, and ad partners do not receive your /simc string or sim results.
Mediavine's own privacy notice is at https://www.mediavine.com/legal-and-privacy-center/. The passage below is Mediavine's required disclosure and is reproduced as they publish it.
Mediavine Programmatic Advertising (Ver 1.1)
The Website works with Mediavine to manage third-party interest-based advertising appearing on the Website. Mediavine serves content and advertisements when you visit the Website, which may use first and third-party cookies. A cookie is a small text file which is sent to your computer or mobile device (referred to in this policy as a “device”) by the web server so that a website can remember some information about your browsing activity on the Website.
First party cookies are created by the website that you are visiting. A third-party cookie is frequently used in behavioral advertising and analytics and is created by a domain other than the website you are visiting. Third-party cookies, tags, pixels, beacons and other similar technologies (collectively, “Tags”) may be placed on the Website to monitor interaction with advertising content and to target and optimize advertising. Each internet browser has functionality so that you can block both first and third-party cookies and clear your browser’s cache. The "help" feature of the menu bar on most browsers will tell you how to stop accepting new cookies, how to receive notification of new cookies, how to disable existing cookies and how to clear your browser’s cache. For more information about cookies and how to disable them, you can consult the information at All About Cookies.
Without cookies you may not be able to take full advantage of the Website content and features. Please note that rejecting cookies does not mean that you will no longer see ads when you visit our Site. In the event you opt-out, you will still see non-personalized advertisements on the Website.
The Website collects the following data using a cookie when serving personalized ads:
- IP Address
- Operating System type
- Operating System version
- Device Type
- Language of the website
- Web browser type
- Email (in hashed form)
Mediavine Partners (companies listed below with whom Mediavine shares data) may also use this data to link to other end user information the partner has independently collected to deliver targeted advertisements. Mediavine Partners may also separately collect data about end users from other sources, such as advertising IDs or pixels, and link that data to data collected from Mediavine publishers in order to provide interest-based advertising across your online experience, including devices, browsers and apps. This data includes usage data, cookie information, device information, information about interactions between users and advertisements and websites, geolocation data, traffic data, and information about a visitor’s referral source to a particular website. Mediavine Partners may also create unique IDs to create audience segments, which are used to provide targeted advertising.
If you would like more information about this practice and to know your choices to opt-in or opt-out of this data collection, please visit National Advertising Initiative opt out page. You may also visit Digital Advertising Alliance website and Network Advertising Initiative website to learn more information about interest-based advertising. You may download the AppChoices app at Digital Advertising Alliance’s AppChoices app to opt out in connection with mobile apps, or use the platform controls on your mobile device to opt out.
For specific information about Mediavine Partners, the data each collects and their data collection and privacy policies, please visit Mediavine Partners.
Server logs and abuse prevention
Our hosting providers (Vercel and Cloudflare) log the IP address, browser and requested page for every request. We use the IP address to rate limit sim submissions and problem reports, and to block abuse. We do not use it to identify you. Logs are kept for a short period by those providers and then discarded.
Public game data
Pages such as the top players rankings show character names and performance figures that are already public on Warcraft Logs and Blizzard's Armory. This is game data about characters, not data about MythicSim users. If a character you control appears there and you want it removed, contact us and we will exclude it.
Who processes your data
We share data only with services that run the Service on our behalf:
- Vercel (website hosting) and Cloudflare (network, DNS and tunnelling).
- Neon (database) and self-hosted storage for sim inputs and results.
- Discord, Blizzard Entertainment and Google as sign-in providers.
- Google Analytics and PostHog for analytics.
- Mediavine and its partners for advertising on content pages.
- Stripe for payments, once paid tiers are live. Card details go to Stripe directly and never touch our servers.
Sim workers run in Australia. Hosted services listed above run in the United States and elsewhere, so your data may be transferred outside the country you live in. Where GDPR applies, those transfers rely on the provider's standard contractual clauses or on the transfer being necessary to provide the Service you asked for.
We may disclose data if the law requires it, or transfer it as part of a sale or handover of the Service. We will note any such change here.
Retention
- Account data: for as long as you have an account.
- Sims and results: until we prune them. There is no fixed window today.
- Guild rosters and sessions: until the server that created them removes them or the bot is removed from the server.
- Analytics: per the retention settings of Google Analytics and PostHog, then aggregated or discarded.
- Access logs: a short period set by the hosting provider.
Your rights and deleting your data
You can ask us to show you the data we hold on you, correct it, or delete your account and everything attached to it. Use the Report a problem link in the footer, or message us on Discord, and say which sign-in provider you used. We aim to respond within 30 days. Deleted data may persist in backups for up to 90 days.
If you live in the European Union, the United Kingdom or another region with a general data protection law, you also have the right to object to or restrict processing, to data portability, and to complain to your local data protection authority. We rely on our legitimate interest in running and improving the Service for analytics and abuse prevention, on your consent for advertising cookies, and on the need to provide the Service you requested for everything else.
Security
All traffic to the site uses HTTPS. Sign-in goes through the provider's own OAuth flow so we never handle passwords. Addon pairing tokens are stored hashed. No system is perfectly secure; if you believe your data has been exposed, contact us and we will investigate.
Children
The Service is not directed at children under 13 and we do not knowingly collect their data. If you believe a child under 13 has an account, contact us and we will remove it.
Contact
Use the Report a problem link at the bottom of any page, or join the MythicSim Discord server linked in the header. Either reaches the developer directly.
Change history
- First published.