DROIDEX

DubTrackr Droidex Privacy Policy

Effective date: August 3, 2026
Last updated: August 31, 2026

Droidex is an Overwolf companion application for the Fortnite Creative experience Droid Tycoon. This Privacy Policy explains what Droidex reads, collects, stores, uses, discloses, retains, and deletes when you use the Droidex Overwolf app, the Droidex website, and related Droidex services.

This Policy is between you and DubTrackr, an independently operated service based in Washington, United States. It is not an agreement between you and Overwolf. Overwolf and Epic Games separately control information they process through their own platforms and services.

1. The most important points

Screen capture may initially include every monitor

Droidex uses Overwolf’s DesktopStreaming capability to obtain a screen-capture frame for local optical character recognition and image matching. Depending on how Windows and the capture system provide the source, one frame may contain every attached monitor stitched together, not only the monitor showing the game. This means anything visible on another monitor may briefly be present in the incoming frame.

Droidex uses Overwolf monitor information to identify the monitor running Fortnite and crops to that monitor before any Droidex screen reader analyzes the frame. Droidex does not intentionally analyze content outside the game monitor.

Droidex normally processes screen images in memory and discards them. If direct or in-memory capture is unavailable, Droidex may use an Overwolf fallback that temporarily writes a full-resolution screenshot file to local storage. Droidex loads that file locally and immediately requests its deletion, including when image decoding fails. Deletion is best effort, so a temporary file may remain if Overwolf or Windows cannot complete the deletion. Droidex does not transmit screen images or send them to an online OCR service. OCR and template matching run locally on your computer using bundled components.

Linking is required before Droidex sends account-linked gameplay data to DubTrackr

An unlinked Droidex installation does not send account-linked player state, collection data, or gameplay observations to the DubTrackr account service. When you link Droidex to your account, the app can synchronize the data described in this Policy.

The Overwolf advertising system is a separate exception. The Overwolf Ads SDK can operate for linked and unlinked users as described in Section 8.

Connected community features depend on sharing

Droidex is designed to bring participating players together through a live shared lobby. After you link Droidex to your account, Share my stats is enabled by default so Droidex can publish the limited in-game statistics described in Section 7 and receive the shared state needed for lobby coordination. This default-on processing is part of the connected community service and is not treated as consent.

You can turn Share my stats off for the current app run. Doing so stops future sharing governed by that control and closes the live lobby connection, so same-lobby statistics, player identification, base ownership, and other connected community features may stop working or become materially limited. Local screen recognition and features that do not require the connected lobby can continue. In the current version, this setting returns to on when the app is restarted or reloaded; if the app is still linked, connected sharing can then resume automatically.

Droidex also publishes a confirmed base-ownership binding as part of the same core shared state so participating players can identify whose base they are visiting. The current version does not present base ownership as a separately optional community feature. Future base publication can be stopped by turning Share my stats off, but this also disables or limits the connected features that depend on shared state.

Account deletion is immediate for active account records, but not every copy disappears immediately

The Delete Account control removes active account-linked records immediately and irreversibly. Some backup copies remain until their retention periods expire. Anonymous observation and calibration records are not removed because they contain no account or device identifier that Droidex can use to locate them.

2. Scope

This Policy applies to:

This Policy does not govern:

Those third parties are responsible for their own privacy practices.

3. Who controls Droidex data

For the information processed by Droidex and the DubTrackr service:

Controller: DubTrackr
Location: Washington, United States
Privacy contact: dubtrackr.support@gmail.com

Questions and privacy requests should be sent to the address above. Do not email passwords, refresh tokens, device-link codes, or other authentication credentials.

4. Information processed locally on your computer

4.1 Screen capture and local screen recognition

Droidex may receive a full desktop capture frame through Overwolf’s DesktopStreaming permission. The frame can include multiple monitors. Droidex identifies and crops to the game monitor before its OCR and template readers run.

Droidex reads the following information from the player’s own Droid Tycoon interface:

Droidex does not read other players’ names from screen pixels. Other-player names used in the same-lobby interface come from Overwolf game events as described below.

The primary capture paths hold the original frame only in memory for processing and then discard it. If direct or in-memory capture is unavailable or fails, Droidex may fall back to Overwolf's screenshot capability. That fallback writes a full-resolution screenshot file to local storage, which Droidex loads only for local processing.

After loading or attempting to load a fallback screenshot, Droidex immediately asks Overwolf to delete the file, including when image decoding fails. This deletion is best effort. If Overwolf or Windows does not complete the deletion, the temporary screenshot may remain in local Overwolf application storage until it is removed by the user, Overwolf, Windows, or another cleanup process. Droidex does not intentionally retain fallback screenshots and does not transmit screen images to DubTrackr or an online OCR service.

4.2 Overwolf game-event information

Droidex subscribes to Overwolf game events. Privacy-relevant information can include:

Game-world coordinates are not GPS coordinates and are not your real-world location.

Names of other players are held temporarily in memory to display the lobby interface. Droidex does not read those names from the screen and does not transmit those other players’ names to the DubTrackr service.

4.3 Monitor and display information

Droidex receives monitor topology information from Overwolf, including display position, width, height, DPI, primary-display status, and an operating-system monitor handle. Droidex uses this information to identify the monitor running the game, crop a multi-monitor capture, and place the companion window on the correct display.

Monitor topology information is held in memory and is not transmitted to DubTrackr. A screen resolution can be transmitted as part of an anonymous calibration profile, as described in Section 6.3.

4.4 Fortnite log file

Droidex scans limited parts of Fortnite’s FortniteGame.log file for droid-card pickup and drop events. Droidex does not transmit the log file or its contents.

4.5 Local app storage

Droidex uses local storage on your computer for app operation and preferences. Local data can include:

Local information remains on the computer unless the app removes it or you clear the app’s local data. Server-side account deletion does not guarantee that every local file or local-storage value on your computer is erased.

4.6 Local diagnostic files

The developer-only Event Lab can write game-event payloads to local application storage. It is restricted through the authenticated owner account. Event payloads are sanitized before writing and are not automatically uploaded.

Development builds that used Event Lab before sanitizer version 1.1 on August 1, 2026 may have stored the player’s Epic display name and squadmate display names in local diagnostic files because earlier redaction rules did not cover every event shape. Those files were never transmitted by Droidex. Anyone who used an affected development build should delete the older Event Lab session files.

Droidex can also create two reader logs when the user deliberately presses the corresponding capture control:

These logs contain reader decisions, reader state, and screen-region coordinates. They do not contain screenshots, account details, or player names. Droidex does not automatically upload them. You may choose to attach a log to a support request.

5. Information collected when you use a Droidex account or online feature

5.1 Epic account identity and authentication

When you sign in with Epic, Droidex receives the Epic account information authorized for the sign-in flow, including a unique Epic account identifier and public display name. Droidex uses this information for account identity and does not receive your Epic password.

Droidex also processes authentication and security information such as:

5.2 Account-linked player state

After you link Droidex, the app may synchronize:

5.3 Collection and progress data

Droidex may store:

When the competitive system is enabled for a linked account, Droidex may also store a no-score baseline; app-verified craft and Droidsmith-level events; server-derived resource-balance increase events; daily positive-growth totals and amount-tier progress for Credits, Upgrade Chips, and Nova Crystals; immutable event identifiers; observation and receipt times; canonical droid, variant, and resource values; reader authority, confidence, and consistent-read evidence; the linked device; acceptance, quarantine, anomaly, and invalidation state; season score-ledger entries and reversals; final season results; achievements; player-profile visibility; and the released Droidex droid portrait selected for the profile. The baseline prevents existing progress from being scored retroactively. Manual website collection, Flawless, or resource edits do not create Season XP.

5.4 Community content

When you use community features, Droidex may process information you choose to submit or generate, including:

Announcement comments and replies are public. Do not submit sensitive personal information in comments, messages, listings, profile names, or other free-text fields.

5.5 Network and operational logs

Droidex infrastructure and hosting providers may process network and operational metadata such as IP address, request time, route, response status, and similar technical information for security, reliability, abuse prevention, and troubleshooting.

Droidex request logs do not record request bodies, refresh tokens, account UUIDs, or Epic identity values.

5.6 Support communications

If you contact DubTrackr, Droidex processes your email address, message, and any screenshots, logs, or other files you choose to provide. Droidex reader logs are not uploaded unless you attach or send them yourself.

The support form at droidex.dubtrackr.win/support/ collects your reply email address, support category, summary, message, and an optional name. The form does not accept file attachments. The Droidex API forwards the ticket over the private OVH server network to the DubTrackr bot operating on that server. The bot posts the ticket to a private Droidex support channel on Discord so DubTrackr can review it and reply from dubtrackr.support@gmail.com. Discord may process the ticket content and related technical metadata under its own privacy policy. Do not include passwords, tokens, device-link codes, private keys, payment information, or other sensitive information in a support ticket.

When you uninstall the Droidex Overwolf app, the background uninstall task may open the optional survey at droidex.dubtrackr.win/uninstall-survey/ in your browser. The survey collects the reason you selected, any optional comments you enter, the Droidex app version, and the fixed source label overwolf-uninstall. It does not ask for or include your Droidex account, player name, or email address. The API sends the response through the same private bot relay and the bot posts it in the existing private Droidex support channel with the label Uninstall Survey. After a successful relay, the API also adds one to a daily aggregate grouped only by the selected reason and app version. That aggregate does not store the comment, support ticket ID, account or device identifier, or IP address. The website, API, hosting providers, and Discord may also process the network and technical metadata described in Section 5.5.

5.7 Content and reference requests

The protected droid-card artwork displayed inside Droidex is rendered from droidex.dubtrackr.win. That request contains the droid keys and tiers being displayed and a short-lived authorization ticket.

Droidex also downloads reference information such as calibration consensus and rebirth-plan data. Those downloads do not submit account data.

Droidex checks a public file at game-events-status.overwolf.com to determine whether Overwolf’s Fortnite game-event provider is degraded. Droidex does not include user data in that request.

6. Anonymous and unlinked service-improvement data

6.1 Droid observation records

Droidex readers can identify droids on the conveyor belt, in the player’s hand, in the craft banner, in a rare-spawn line, or as a companion. After account linking, Droidex may send an observation event containing:

The request is authenticated to prevent unauthorized submissions, but the account identity is discarded before the observation is stored. The observation table contains no account identifier or device identifier. The per-launch session key is not derived from your account, computer, or device, is not saved to disk, and is replaced when the app restarts.

A short-lived network log may separately contain ordinary network metadata, but the stored observation record is designed not to identify the player.

Droidex uses these records to measure in-game spawn and pickup patterns, evaluate reader quality, distinguish app-reader changes from game changes, and prevent duplicate retries from being counted twice.

6.2 Why observations survive account deletion

Observation records cannot be selectively removed through account deletion because they do not contain the identifier needed to find which rows came from a particular account. They remain in the aggregate observation dataset after account deletion.

6.3 Calibration profiles

When you save a screen-region calibration profile, Droidex may submit:

The free-text profile name and local profile identifier are not transmitted. The Droidex API rejects a calibration submission that contains the profile name rather than silently accepting it. Calibration records contain no account identifier or device identifier.

Droidex uses pooled calibration profiles to improve default capture regions for different resolutions and interface configurations.

6.4 Why calibration profiles survive account deletion

Calibration profiles cannot be located by account because they do not contain an account or device identifier. They therefore remain in the calibration dataset after account deletion.

6.5 Website audience and guide-action counters

The Droidex website creates a random browser identifier in local storage. The server stores a one-way hash of that identifier to count total views and approximate unique browsers. It does not attach a page path, account identifier, or Epic identity to that counter.

When someone views any public page, follows a guide link, opens a calculator, starts using the Rebirth Tracker, changes collection progress, visits an update page, or uses a site search, Droidex adds one to a daily aggregate containing the public page, destination path, and action type. Search events do not contain the search text, selected result, or droid name. Collection events do not contain the affected droid or variant.

On the first page load, Droidex may also count the referring website's normalized hostname, such as google.com. Droidex does not store the full referrer URL, path, query string, or fragment. Same-site referrals are not recorded.

These measurement totals contain no browser identifier, account identifier, Epic identity, or individual browsing history. Ordinary short-lived network logs may still contain the technical metadata described in Section 5.5.

7. Information shared with other players

7.1 Share my stats

After you link Droidex to your account, Share my stats is enabled by default because Droidex's live lobby and coordination features depend on participating players exchanging a limited set of current in-game information. Droidex may share the following with participating players in the same lobby:

Turning this control off stops future sharing governed by the control for the current app run and closes Droidex's live lobby connection. Features that depend on reciprocal lobby state, including same-lobby statistics, player identification, and base ownership, may stop working or become materially limited. In the current version, the control returns to on when the app is restarted or reloaded; if the app remains linked, connected sharing can then resume automatically. Turning the control off does not by itself delete account-linked records already held by DubTrackr; those records remain subject to the retention and deletion rules in Sections 11 and 12.

Because the feature is enabled by default after account linking, DubTrackr does not treat the default state as consent. The shared fields are limited to in-game identity and gameplay state, are shared only for the participating-player community experience, and are not supplied to advertising networks by DubTrackr.

7.2 Base ownership sharing

Droidex can publish a confirmed base-ownership binding so another participating player's app can identify whose base the player is standing in. The binding associates the player's in-game identity with the confirmed base identifier. Publication occurs as part of the default-on connected community service when the app is linked, Share my stats is on, and a base has been confirmed.

Base ownership is a core input to Droidex's same-lobby coordination and is not presented as a separate optional community feature in the current version. Turning Share my stats off stops future base publication but also closes the live lobby connection and disables or materially limits connected features that depend on shared state. Account deletion removes the active account-linked base record as described in Section 12; turning sharing off does not itself delete records already retained under Section 11.

7.3 Other players’ names

Other players’ names reach Droidex through Overwolf’s me and team events for players in the same lobby or squad. Droidex holds those names in memory to draw the lobby list. Droidex does not transmit those other players’ names to its service.

7.4 Public player profiles and season rankings

A Droidex player profile is private by default. If you deliberately make it public, its display name, selected Droidex droid portrait, collection and Flawless totals, app-observed Droidsmith level, unique verified droid/variant craft record and totals, current Season XP and rank, season history, and achievements can be visible to anyone. Public profile visibility is also the opt-in for the public competitive leaderboards and final season placement.

Private profiles are excluded from public competitive rankings and final placement. Droidex may still retain account-linked verified activity and score records while the profile is private so that linked synchronization, integrity review, and a later choice to participate can work. Changing a profile back to private removes it from public rankings and prevents public access to the profile; it does not delete the retained account records. Account deletion removes the active profile and account-linked competitive records as described in Section 12.

Public leaderboards never expose Epic account identifiers, email addresses, Discord identities, device identifiers, authentication material, or screen images.

8. Advertising and Overwolf

Droidex displays an advertisement unit through the Overwolf Ads SDK. The SDK is loaded and operated by Overwolf and can run for every Droidex user, including users who have not linked a Droidex account. It is not controlled by the Share my stats setting.

Droidex does not provide the Overwolf Ads SDK with:

Overwolf controls ad selection, ad delivery, advertising partners, and the information processed by its advertising system. Overwolf states that its advertising systems may process advertising or online identifiers, device and technical information, active application, process, or window information, privacy-consent strings, ad-call information, approximate location derived from network information, and advertising interactions. Actual processing depends on Overwolf’s systems, the user’s region, privacy choices, and the applicable advertising partners.

Overwolf provides its own consent-management and privacy controls. Users should review and manage those choices through Overwolf. Overwolf’s processing is governed by the Overwolf Platform Privacy Policy, not this Policy.

Droidex does not include a separate general-purpose analytics SDK such as Google Analytics, Sentry, Amplitude, Mixpanel, or Segment in the shipped Overwolf app.

9. Other disclosures and service providers

Droidex may disclose or make information available to the following categories of recipients only for the purposes described in this Policy:

Overwolf

Overwolf provides the app platform, game-event APIs, screen-capture capability, and advertising SDK. Overwolf independently processes platform and advertising information under its own policies.

Epic Games

Epic Account Services provides the sign-in flow and authorized Epic account identity information. Epic independently processes Epic account information under the Epic Games Privacy Policy.

Cloudflare

Cloudflare provides website delivery, network protection, and Cloudflare Tunnel services. Cloudflare may process network and request metadata needed to provide those services.

OVHcloud

OVHcloud provides infrastructure on which the Droidex API and PostgreSQL database operate.

Discord

Discord hosts the private Droidex support channel used to receive tickets submitted through the Droidex support form. The DubTrackr bot running on OVHcloud posts the reply email, optional name, support category, summary, message, submission source, and ticket identifier to that channel. Discord independently processes that information under the Discord Privacy Policy.

Other participating players and public profile visitors

Droidex shares the lobby statistics and base information described in Section 7 as part of the connected community service and subject to the Share my stats control. If you opt into a public player profile, public profile visitors can also see the limited profile, ranking, season, and achievement fields described in Section 7.4.

Legal, safety, and security recipients

DubTrackr may preserve or disclose information when reasonably necessary to comply with law, respond to valid legal process, protect users, investigate fraud or abuse, enforce applicable terms, or protect the security and integrity of Droidex.

Business transfer

If ownership or operation of Droidex is transferred, relevant information may be transferred as part of that transaction, subject to this Policy and applicable law. Users will receive notice of a material change where required.

DubTrackr does not sell personal information for money. DubTrackr does not provide Epic identity or account-linked gameplay data to advertising networks for cross-context behavioral advertising. Overwolf’s separate advertising processing is described in Section 8.

10. Purposes and legal bases

Where data-protection law requires a legal basis, DubTrackr uses the following:

PurposeInformation involvedLegal basis
Provide local OCR, overlays, tracking, account linking, synchronization, collection, and requested community featuresScreen-derived values, Epic identity, authentication records, player state, collection and community dataPerformance of the service requested by you and performance of a contract
Operate the default-on connected lobby, including Share my statsSelected lobby statistics and display namePerformance of the connected community service requested by the user and legitimate interests in providing reciprocal, limited same-lobby coordination; users can object by turning the control off, although dependent connected features will stop or become limited
Provide base-ownership identification as a core part of the connected lobbyDisplay name or player identity associated with a confirmed basePerformance of the connected community service requested by the user and legitimate interests in providing limited same-lobby identification and coordination; future publication stops when Share my stats is turned off, although dependent connected features will stop or become limited
Operate verified player profiles, season scoring, integrity review, rankings, final results, and badgesPublic display name, selected droid portrait, and profile choice; baseline; verified event and evidence records; score ledger; season results; achievementsPerformance of the requested linked and competitive services and legitimate interests in fair, auditable rankings and abuse prevention; public display is opt-in through the public-profile control
Secure accounts and infrastructure, prevent abuse, troubleshoot failures, and enforce rulesAuthentication records, device links, IP and network metadata, operational logsLegitimate interests and, where applicable, legal obligations
Improve reader accuracy, spawn measurement, and calibration defaultsUnlinked observation and calibration recordsLegitimate interests in improving Droidex and measuring game events using minimized, non-account-linked data
Respond to support and privacy requestsContact information and information you submitPerformance of requested support, legitimate interests, and legal obligations
Retain or disclose records required by lawRelevant account, transaction, security, or request recordsLegal obligation

Overwolf determines the legal bases for its separate platform and advertising processing.

11. Retention

Droidex uses the following retention rules and criteria:

Data or copyRetention
Active account, player-state, collection, competitive, profile, sharing, announcement-comment, and other community recordsRetained while the account remains active or until the user deletes the account, unless a longer period is required for legal, security, integrity-review, moderation, or dispute purposes
Device links, app tokens, authorizations, browser sessions, and related authentication recordsRetained until expiration, revocation, replacement, or account deletion, as applicable
Local app storage and user-created local logsRetained on the computer until removed by the app or user
Temporary local fallback screenshotsNormally deleted immediately after Droidex loads or attempts to load them; deletion is best effort, and a file may remain in local Overwolf application storage if Overwolf or Windows cannot complete the deletion
Support communications and uninstall surveys, including copies in the private Discord support channelRetained for as long as reasonably necessary to address the request, improve Droidex, protect the service, and meet legal obligations
Anonymous or unlinked observation recordsRetained while useful for longitudinal spawn measurement, reader-quality analysis, and integrity checks; not selectively deletable by account
Anonymous or unlinked calibration profilesRetained while useful for calibration consensus and reader compatibility; not selectively deletable by account
Website audience hashes, aggregate first-party measurement totals, and anonymous uninstall reason/version totalsRetained while useful for audience and product-performance measurement; not linked to a Droidex account or Epic identity
Active PostgreSQL account rows after confirmed deletionRemoved before the deletion response is returned
Local database or rollback backupsUp to 30 days; currently not encrypted at rest
Off-site backupsUp to 183 days under daily, weekly, and monthly rotation; encrypted at rest
Host journalsUp to 7 days
Container logsRotating files, limited to 7 files of up to 10 MB each

Backup copies that contain deleted account data remain until the applicable retention period expires. DubTrackr will not represent that every backup copy disappears immediately when the active account is deleted.

12. Account deletion and other controls

12.1 Delete Account

You can use the Delete Account control in your Droidex website account settings. Deletion requires the exact typed confirmation:

DELETE MY DROIDEX ACCOUNT

Deletion is immediate, irreversible, and cannot be cancelled by signing in again. A later Epic sign-in creates a new account and does not restore deleted account data.

Confirmed deletion removes active records for:

Deletion does not immediately remove:

12.2 Actions that do not delete the account

Signing out, unlinking a device, rotating a token, or linking another computer does not delete account progress. The confirmed Delete Account process is the destructive action.

12.3 Sharing controls

You can:

12.4 Data export

Droidex does not currently provide a complete self-service account-data export. Where applicable law gives you a right to access or receive a copy of personal data, contact dubtrackr.support@gmail.com. DubTrackr will respond as required by applicable law.

13. Your privacy rights

Depending on where you live, you may have the right to:

DubTrackr does not discriminate against users for exercising applicable privacy rights.

To submit a request, email dubtrackr.support@gmail.com. DubTrackr may ask you to authenticate through your Droidex account or provide information reasonably necessary to verify the request and protect the account. To appeal a decision, reply to the decision with the subject Privacy Appeal.

Rights generally do not apply to information that is genuinely anonymous and cannot reasonably be linked to an individual. Requests concerning Overwolf platform or advertising information must be directed to Overwolf under its privacy policy. Requests concerning Epic account information must be directed to Epic.

14. International processing

DubTrackr is based in the United States. Droidex service providers may process information in the United States and other countries in which they or their subprocessors operate. Those countries may have privacy laws that differ from the laws where you live.

Where applicable law requires a recognized transfer safeguard, DubTrackr will use an available lawful transfer mechanism or require the relevant service provider to do so.

15. Security

DubTrackr uses administrative, technical, and organizational measures intended to protect Droidex information. Measures include local screen processing, data minimization, authenticated account and device links, access controls, encrypted network transport, restricted diagnostics, short-lived session credentials where appropriate, request-body log exclusions, and encrypted off-site backups.

A known limitation is that local database and rollback backups may remain unencrypted at rest for up to 30 days. No storage or transmission method is completely secure, and DubTrackr cannot guarantee absolute security.

If a breach affects information for which notice is legally required, DubTrackr will provide notice to affected users and authorities as required by applicable law.

16. Children and eligibility

Droidex is intended only for users who are at least 18 years old and otherwise eligible to use the Overwolf platform. Droidex is not directed to children, and DubTrackr does not knowingly collect personal information from children.

If DubTrackr learns that it collected account-linked personal information from a child under 13, or under the applicable age of digital consent in the child’s jurisdiction, DubTrackr will take reasonable steps to delete that information. A parent or guardian who believes a child provided information should contact dubtrackr.support@gmail.com.

Overwolf and Epic apply their own age, account, and parental-consent rules to their services.

17. Automated processing

Droidex uses OCR, template matching, confidence scoring, event matching, and deduplication to read game information and operate app features. Droidex does not use automated decision-making that produces legal effects or similarly significant real-world effects about a person.

18. Changes to this Policy

DubTrackr may update this Policy when Droidex features, data practices, service providers, or legal requirements change. The updated version will show a new effective or last-updated date.

For a material change, DubTrackr will provide additional notice in the app, on the website, or through another appropriate channel where required. If applicable law requires consent for a new use, DubTrackr will request it before beginning that use.

19. Contact

For privacy questions, requests, or concerns:

DubTrackr
Washington, United States
Email: dubtrackr.support@gmail.com