Privacy policy
Last updated 7 October 2026
A2 Tools (a2tools.app) is a community project: guides, a lookbook, and the website side of the A2Tools DPS Meter. It is not affiliated with NCSOFT or AION 2. This page says what the site collects when you use it, why, who else handles it, what other people can see, and what you can change or delete. It covers the website and the parts of the DPS meter that talk to it. What the meter does on your own computer is described in the meter's own privacy notes.
The short version: you can browse without an account. An account holds what you need to sign in and the things you choose to save. Fight logs show your character name and mask everyone else's. There are no ads, no analytics or tracking cookies, and nothing is sold.
- Signing in
- Your account
- Cookies and browser storage
- The DPS meter and your account
- Fight logs
- Feedback and logs sent to the developer
- Supporters and payments
- What other people can see
- Who else handles your data
- IP addresses
- How long things are kept
- Your choices
- Contact and changes
Signing in
You can sign in four ways. Each gives the site only what is listed.
| Method | What the site receives and keeps |
|---|---|
| Discord | Your Discord user id, username, display name and avatar. The site asks only for the
identify permission, so it does not receive your email address, servers or messages. Discord's
access token is used once to read your profile and is not stored. |
Your Google account id, email address and whether Google has verified it, your name
and profile picture (permissions openid email profile). If the address is verified and
matches a verified address already on an A2 Tools account, Google is linked to that account. | |
| Email and password | Your email address and a hash of your password (PBKDF2-HMAC-SHA256, 600,000 iterations, a random salt per password). The password itself is never stored. You confirm the address through a link that works once and expires after 24 hours. |
| Passkey | The passkey's public key and id, a name you choose, the time it was added and last used, and a use counter. The private key never leaves your device, and the site asks for no attestation, so it learns nothing about the device itself. |
You can link several methods to one account and remove any of them, as long as one is left.
Your account
An account holds:
- An account id, a display name and a username (from your sign-in method unless you change them), and an avatar: your Discord or Google picture, or one you upload.
- For each sign-in method: the details in the table above, and when it was added and last used.
- What you add yourself: a guide-author profile (bio, region, server, faction, class, combat power, links you give as proof), your guides and their revisions, saved characters (name, class, server, faction), and settings such as whether new fight logs are public or private.
- Your role on the site (member, guide author, editor or admin), when you joined and when you were last seen.
- Supporter status and payments, if you support the project (see below).
Email is used only for the account messages you trigger: confirming an address, and resetting a password (a link that works once and expires after an hour). There is no newsletter or marketing email.
Cookies and browser storage
| Name | What it is for | How long |
|---|---|---|
a2s | Keeps you signed in. It is signed by the server so it cannot be forged, and holds your account id, names, avatar and role. It is not encrypted: anyone with your browser can read what is in it. HttpOnly, Secure, SameSite=Lax. | 7 days, or until you sign out |
a2st | Protects a Discord or Google sign-in from being forged while you are away at the provider (a random value the provider must hand back). | 10 minutes |
lang | The language you picked. | 1 year |
The fight-log viewer remembers some display settings and your language in your browser's local storage; they stay on your device. There are no analytics, advertising or tracking cookies.
A session cannot be cut short from the server once issued: signing out removes the cookie from your browser, and a session left on another device ends when its 7 days run out. A banned account gets no session at all.
The DPS meter and your account
To connect the meter, it shows a short code and opens a2tools.app/link; you approve it while
signed in. The meter then holds a token for your account. The site keeps only a hash of that token, the
device name the meter gave, what it may do, and when it was created and last used. Tokens do not expire
on their own: you can revoke one any time from your account page, and it stops working at once.
A connected meter can read your basic profile and supporter status, keep your saved characters in sync, store its own settings and history on the site (up to 200 items of 256 KB each), and upload fight logs.
Fight logs
When you upload a fight, the meter sends an evidence slice: the game packets of that one fight that the parser reads, with every character name replaced by a code before it leaves your computer, plus the names the meter showed you. The server works out every number from the slice itself, checks that no name was left in it, and refuses the upload if one was.
- A log shows your character name in full, and other players' names masked (for example
Se****e). Your account name and email are never shown on a log. - The slice is stored but never served. It still contains each party member's in-game roster id, which is why it stays private.
- Public logs are listed, searchable by the uploader's character name, and can appear on the leaderboards with your character name, region, server, class, DPS, combat power and gear score. Private logs are not listed or ranked, but anyone you give the link to can open them: the link is the key.
- Every player's class, damage, level, gear score and combat power, without names, count toward the public class statistics.
- The site records which meter and version made a log, and the results of its checks on the slice, to keep incomplete logs off the leaderboards.
Feedback and logs sent to the developer
The feedback button sends your message, an optional reply address, the page you were on, your language, screen size and browser (user agent), your account id if you are signed in, and, if you leave the box ticked, a screenshot of the page taken in your browser. All of it is stored and emailed to the developer, with your reply address as the reply-to. It is kept until the developer deletes it.
"Send logs to dev" in the meter uploads up to three of your packet logs for a bug report. These are raw game traffic and include character names. Only site admins can open them, and they are deleted after 30 days. No account is needed; if you are signed in, your account id is attached.
Supporters and payments
Payments go through Ko-fi; the site never sees card or bank details. Ko-fi tells the site about each payment: the name and email you gave Ko-fi, your message, the amount and currency, and the tier or subscription. The site keeps those details and Ko-fi's full notification. A payment is matched to your account by the claim code from your account page in the message, or by a verified email address that is on your account. Supporter status is shown publicly: a gold name on your logs and the leaderboards, and a badge on guide bylines.
What other people can see
- On logs and leaderboards: as described under Fight logs.
- On guides: the author's display name, server, faction and combat power, and their avatar.
- Avatars and images uploaded to guides are public at their address, including an avatar you have since replaced.
- Admins can see what is needed to run the site: member lists and their sign-in methods (including email addresses), connected meters, passkey names, logs, supporter history, feedback and developer reports.
Who else handles your data
| Service | What for |
|---|---|
| Cloudflare | Runs the site and stores its database and files (Workers, D1, R2). Cloudflare also keeps request logs for operating and securing the service. |
| Discord, Google | Sign-in, if you use them. Your browser loads Discord and Google profile pictures from them. |
| Resend | Sends account emails and feedback notifications. |
| Ko-fi | Payments, and the payment details above. |
| NCSOFT | When you look up a character, the site asks NCSOFT's character pages for that character's name, faction and server, and caches what comes back. Some game icons load from NCSOFT's servers in your browser. |
| cdnjs (Cloudflare) | Serves the screenshot library, only when you open the feedback box. |
Nothing is sold or shared for advertising.
IP addresses
For rate limits on feedback and developer reports, the site keeps a keyed hash of your IP address, not the address. When you ask for an account email (confirming an address or resetting a password), the request's IP address is recorded with it, to look into abuse. Cloudflare sees your IP address with every request, as any website host does.
How long things are kept
- Account data: as long as the account exists.
- Fight logs, characters, passkeys and linked sign-in methods: until you delete them.
- Revoked meter tokens: kept as revoked, so they can never be used again.
- Developer reports: 30 days. Feedback: until the developer deletes it.
- Payment records: kept, as a record of payments received.
- Sign-in links and codes: they expire (24 hours, 1 hour, 10 minutes); the records of them are kept.
Your choices
- Make any log public or private, set the default for new ones, or delete a log: deleting removes it and its stored slice.
- Delete saved characters, remove passkeys, unlink sign-in methods (one must remain), and revoke connected meters, from your account page.
- Change your display name and avatar.
- To delete your whole account, or to ask what the site holds about you, contact us as below. There is no self-service account deletion yet; it is done on request.
Contact and changes
Ask on Discord (#aion2-dpsmeter), open an issue on GitHub, or use the feedback button on any page. When what the site collects changes, this page changes with it, and the date at the top says when.