MyBattlemap
Privacy Policy
Last updated: 11 September 2026 · Web 2.0.0 · Android version 1.0.0 (2)
1. Who is responsible and how to contact us
The controller is Tobias Schmitz, Am Mühlanger 1, 82178 Puchheim, Germany. MyBattlemap / TobyTune is the public developer name. For privacy questions and requests, contact support@mybattlemap.com.
2. Android app: local use
This policy covers MyBattlemap Free V1 (com.mybattlemap.app). The Android app works without an account or login. It contains no advertising, user tracking, analytics SDK or crash-reporting service. MyBattlemap does not operate a server for your maps or projects and does not upload imported maps, fog states or settings.
You select PNG, JPEG or WebP images through the system file picker. The app reads the selected file, including any metadata contained in that file, and stores a local copy. It does not scan your photo library or other files. If you choose a cloud-backed file provider, that provider may download the selected file under its own terms; MyBattlemap does not initiate a project upload.
Local project storage contains the map image, map name and dimensions, project title, randomly generated project and asset identifiers, modification time, fog brush strokes, water masks and layer settings, grid settings, audio preset, volume, mute state and the last opened project. These identifiers organise local projects; they are not advertising or device identifiers.
Projects are stored in the app’s local IndexedDB database. Capacitor also stores technical app-version information locally. The app does not set tracking cookies or use localStorage for project data. Browser/WebView storage and cookie capabilities exist, but no app code sets cookies or calls a cookie service.
3. Audio, demo assets and offline operation
The Android package includes the beach demo, coastal audio loop, interface code and icons. Fonts use the device’s installed fonts. Map viewing, water and fog effects, audio and local saving require no connection to MyBattlemap servers. The internal https://localhost address serves packaged files inside the app; it is not a remote server. Android does not register the PWA service worker.
4. Permissions and external links
The release declares INTERNET and an app-specific signature permission for protected internal receivers. It requests no camera, microphone, location, contacts or broad photo/storage permission. File access is limited to the file you select through the system picker.
Tapping the website, privacy or asset-credit links opens an external browser. The linked destinations are www.mybattlemap.com, opengameart.org and creativecommons.org. They receive normal browser connection data when you visit them. No project data is attached to these links. Their subsequent processing is governed by the destination’s policy. These pages are not required for offline play.
Android, the system WebView, your browser, file providers and Google Play may process data independently under your device and account settings. MyBattlemap does not integrate Google Analytics, Firebase, advertising or remote crash-reporting SDKs. Capacitor command-line telemetry belongs to development tools on the developer’s computer and is not included as app telemetry.
5. Web app / PWA
The web version at app.mybattlemap.com is delivered through Cloudflare Pages. On initial loading and when preparing or updating the offline version, your browser downloads the app files, the beach demo and all five ambience sounds (Coast, Forest, Night Forest, Rain and Thunderstorm) from app.mybattlemap.com. These files are stored in the browser’s Cache Storage for offline use. The sounds are downloaded even if you have not selected or played them yet. Audio is not streamed from external services. Playback starts only after a user action.
For online navigation, the service worker checks the network first and uses the cached app if the network request fails. Once the app displays “Offline bereit” (“Offline ready”), the app, beach demo and all five sounds are available offline on that device. Initial loading, subsequent online visits and updates expose normal connection data to the hosting service, including your IP address, requested URL, request time and technical browser information. Section 6 provides further hosting information.
Multi-scene projects with up to ten scenes, imported map images and asset blobs, fog strokes, water masks, grid and ambience settings, sound selection, volume, mute state and the last opened project and active scene are stored locally in this browser’s IndexedDB. Map images, asset blobs, fog strokes, water masks and complete projects are not uploaded to us, Cloudflare or other services. There is no user account, project backend or cloud synchronisation. The optional DM Remote function transmits only the control and status data described below. The web app code does not set cookies. When you select German or English using the language switch, the web app stores only the language code “de” or “en” under the key “mybattlemap.language” in localStorage for app.mybattlemap.com. This preference is reused on subsequent visits until you change it or clear the site data; it has no fixed expiry date. Without a valid saved choice, German is used for a German browser language and English for all other browser languages. If local storage is blocked, a selected language applies only to the current session. The language preference is not transmitted to us or other services and is not stored in your projects. It is independent of the language preference on the separate website www.mybattlemap.com. The web app does not use sessionStorage. It contains no analytics, advertising, telemetry or tracking features.
DM Remote is optional and requires an Internet connection on the tabletop device and the controlling smartphone. Cloudflare Workers and Durable Objects relay temporary remote sessions. Only necessary session and authentication values, scene IDs, scene names and order, the active scene, audio preset, volume, mute and playback status, fog commands, Player View, connection and busy status, and command results are transmitted. Scene names may be based on imported filenames. No map preview, map image, asset blob, fog stroke, water mask or complete project is transmitted. The tabletop remains the authoritative source of the project. Normal local and prepared offline use remains possible without Remote.
Session values and the latest small control state are held temporarily in the remote service’s memory. Only an expiry timestamp and its expiry alarm are stored in Durable Object storage; no project or command history is stored there. A session lasts at most approximately four hours and can be ended on the tabletop device. Host disconnection or a service restart ends the session. Expiry records are removed at session end or by the scheduled expiry cleanup; after an interruption, cleanup may occur later. The QR link contains a temporary access secret in its URL fragment. The remote page removes the fragment from the displayed URL after reading it and keeps the pairing values only in memory, not in localStorage, IndexedDB or cookies. Anyone holding the pairing link can control that session, so share it only with your DM.
Cloudflare necessarily processes IP addresses and technical network information when establishing and relaying Remote connections. Transport encryption terminates at Cloudflare; Remote is not end-to-end encrypted. To limit abusive session creation, Cloudflare processes short-lived request counters associated with the connection’s IP address and the session-creation endpoint. These are technical abuse-prevention measures, not user analytics. No account, advertising, analytics or tracking is added by the Remote function, and our Worker does not write application logs. Cloudflare may retain technical security and operational data under its own arrangements; the session expiry is not a promise that all provider network records are deleted after four hours. Section 6 provides information about Cloudflare and international processing.
If you select “Protect local storage”, the web app requests persistent browser storage where supported. The browser may grant or refuse this request; refusal does not prevent local use. Persistent Storage can reduce automatic browser eviction but is not a backup and cannot prevent loss after clearing site data, losing or resetting a device, or removing a browser profile. Projects and offline files can still be lost. No cloud copy is created by this request.
Website, privacy and asset-credit links open external pages only when you select them. This creates normal connections to the destination; no project data is attached to these links. Section 4 provides information about external links. Clearing site data for app.mybattlemap.com removes local projects and offline files. Your browser or operating system may also remove local data; see Section 8.
6. Public website and hosting
The public website www.mybattlemap.com is a separate service hosted on Cloudflare Pages. Delivering HTTPS pages necessarily involves your IP address, requested URL, request time and technical request information such as browser headers and, where supplied, referrer information. Cloudflare processes traffic to deliver and secure the service. The website code contains no advertising or analytics script, contact form, remote font service or embedded video service. Images, styles and scripts are hosted with the website.
When you choose a language, the website saves only that preference in your browser under mybattlemap.language. Direct language URLs work without this storage. No tracking cookie is set by the website code. Hosting security features can involve additional technical processing depending on the hosting configuration.
Cloudflare is the hosting provider; IONOS provides the domain and the support mailbox. Neither receives local Android projects from MyBattlemap. Cloudflare’s international infrastructure can involve processing outside the EEA. Information about its processing and transfer safeguards is available in Cloudflare’s privacy policy and data processing addendum.
7. Support email and legal bases
If you email support@mybattlemap.com, we and our mailbox provider IONOS process your email address, message, voluntarily supplied attachments and email metadata to handle your request. Sending an email is voluntary and separate from local app use. Please send only information needed for your request.
Where personal data is processed under our responsibility, the legal basis is Article 6(1)(b) GDPR for providing requested app functions and handling contractual requests, or Article 6(1)(f) GDPR for secure website delivery and responding to other enquiries. These legitimate interests are operating a reliable website and answering your questions. Article 6(1)(c) GDPR applies where a legal retention obligation exists.
8. Retention and deletion
Local projects have no automatic expiry. You can remove the app’s local copies by clearing MyBattlemap’s app storage in Android settings or uninstalling it. In the web version, clear site data for app.mybattlemap.com to remove projects and offline caches. Clearing the public website’s site data removes its language preference. Free V1 has no individual-project deletion control. Original files outside the app are unaffected. Storage can also be lost through browser eviction, device resets or operating-system behaviour; this is not a backup service. Android cloud backup is disabled in the manifest, but device migration behaviour can depend on the device manufacturer.
Support correspondence is retained for handling and following up your request, then deleted when no longer needed, unless legal obligations require longer retention. Technical hosting data is retained only as needed for delivery, security, troubleshooting and applicable obligations under the provider’s arrangements. A fixed account-specific hosting-log retention period has not been verified; no particular number of days is promised here.
9. Your rights
Subject to the GDPR’s conditions, you have rights of access, rectification, erasure, restriction, data portability and objection to processing based on legitimate interests. Where processing relies on consent, you may withdraw it for the future. You may complain to a competent data protection supervisory authority, including the authority where you live or work. Contact support@mybattlemap.com to exercise rights relating to data we hold. We cannot remotely read or delete projects stored only on your device.
MyBattlemap does not use automated decision-making or profiling. This policy will be updated if the app’s data handling changes.
Cloudflare Privacy Policy · Cloudflare Data Processing Addendum · Impressum