Privacy policy

Last updated 7 October 2026

A2 Tools (a2tools.app) is a community project: guides, a lookbook, and the website side of the A2Tools DPS Meter. It is not affiliated with NCSOFT or AION 2. This page says what the site collects when you use it, why, who else handles it, what other people can see, and what you can change or delete. It covers the website and the parts of the DPS meter that talk to it. What the meter does on your own computer is described in the meter's own privacy notes.

The short version: you can browse without an account. An account holds what you need to sign in and the things you choose to save. Fight logs show your character name and mask everyone else's. There are no ads, no analytics or tracking cookies, and nothing is sold.

Signing in

You can sign in four ways. Each gives the site only what is listed.

MethodWhat the site receives and keeps
DiscordYour Discord user id, username, display name and avatar. The site asks only for the identify permission, so it does not receive your email address, servers or messages. Discord's access token is used once to read your profile and is not stored.
GoogleYour Google account id, email address and whether Google has verified it, your name and profile picture (permissions openid email profile). If the address is verified and matches a verified address already on an A2 Tools account, Google is linked to that account.
Email and passwordYour email address and a hash of your password (PBKDF2-HMAC-SHA256, 600,000 iterations, a random salt per password). The password itself is never stored. You confirm the address through a link that works once and expires after 24 hours.
PasskeyThe passkey's public key and id, a name you choose, the time it was added and last used, and a use counter. The private key never leaves your device, and the site asks for no attestation, so it learns nothing about the device itself.

You can link several methods to one account and remove any of them, as long as one is left.

Your account

An account holds:

Email is used only for the account messages you trigger: confirming an address, and resetting a password (a link that works once and expires after an hour). There is no newsletter or marketing email.

Cookies and browser storage

NameWhat it is forHow long
a2sKeeps you signed in. It is signed by the server so it cannot be forged, and holds your account id, names, avatar and role. It is not encrypted: anyone with your browser can read what is in it. HttpOnly, Secure, SameSite=Lax.7 days, or until you sign out
a2stProtects a Discord or Google sign-in from being forged while you are away at the provider (a random value the provider must hand back).10 minutes
langThe language you picked.1 year

The fight-log viewer remembers some display settings and your language in your browser's local storage; they stay on your device. There are no analytics, advertising or tracking cookies.

A session cannot be cut short from the server once issued: signing out removes the cookie from your browser, and a session left on another device ends when its 7 days run out. A banned account gets no session at all.

The DPS meter and your account

To connect the meter, it shows a short code and opens a2tools.app/link; you approve it while signed in. The meter then holds a token for your account. The site keeps only a hash of that token, the device name the meter gave, what it may do, and when it was created and last used. Tokens do not expire on their own: you can revoke one any time from your account page, and it stops working at once.

A connected meter can read your basic profile and supporter status, keep your saved characters in sync, store its own settings and history on the site (up to 200 items of 256 KB each), and upload fight logs.

Fight logs

When you upload a fight, the meter sends an evidence slice: the game packets of that one fight that the parser reads, with every character name replaced by a code before it leaves your computer, plus the names the meter showed you. The server works out every number from the slice itself, checks that no name was left in it, and refuses the upload if one was.

Feedback and logs sent to the developer

The feedback button sends your message, an optional reply address, the page you were on, your language, screen size and browser (user agent), your account id if you are signed in, and, if you leave the box ticked, a screenshot of the page taken in your browser. All of it is stored and emailed to the developer, with your reply address as the reply-to. It is kept until the developer deletes it.

"Send logs to dev" in the meter uploads up to three of your packet logs for a bug report. These are raw game traffic and include character names. Only site admins can open them, and they are deleted after 30 days. No account is needed; if you are signed in, your account id is attached.

Supporters and payments

Payments go through Ko-fi; the site never sees card or bank details. Ko-fi tells the site about each payment: the name and email you gave Ko-fi, your message, the amount and currency, and the tier or subscription. The site keeps those details and Ko-fi's full notification. A payment is matched to your account by the claim code from your account page in the message, or by a verified email address that is on your account. Supporter status is shown publicly: a gold name on your logs and the leaderboards, and a badge on guide bylines.

What other people can see

Who else handles your data

ServiceWhat for
CloudflareRuns the site and stores its database and files (Workers, D1, R2). Cloudflare also keeps request logs for operating and securing the service.
Discord, GoogleSign-in, if you use them. Your browser loads Discord and Google profile pictures from them.
ResendSends account emails and feedback notifications.
Ko-fiPayments, and the payment details above.
NCSOFTWhen you look up a character, the site asks NCSOFT's character pages for that character's name, faction and server, and caches what comes back. Some game icons load from NCSOFT's servers in your browser.
cdnjs (Cloudflare)Serves the screenshot library, only when you open the feedback box.

Nothing is sold or shared for advertising.

IP addresses

For rate limits on feedback and developer reports, the site keeps a keyed hash of your IP address, not the address. When you ask for an account email (confirming an address or resetting a password), the request's IP address is recorded with it, to look into abuse. Cloudflare sees your IP address with every request, as any website host does.

How long things are kept

Your choices

Contact and changes

Ask on Discord (#aion2-dpsmeter), open an issue on GitHub, or use the feedback button on any page. When what the site collects changes, this page changes with it, and the date at the top says when.