Перейти к содержимому
BlitzInfo

Privacy Policy

Revision of 29 September 2026

What BlitzInfo learns from visitors and account holders, what for, how long it keeps it, whom it passes it to, and how to opt out.

1. Who processes the data

The data is processed by the author of BlitzInfo — blitzinfo.app and its mirrors lesta.blitzinfo.app and wg.blitzinfo.app (the Site). Questions about data go to the contacts at the foot of this page.

2. Visitors without an account

No account is needed to read the Site. Like any server, the Site receives technical details of each request: the IP address, the page's address, the browser type. They are needed for the Site to work and to guard it against abuse — to limit how often requests may come, for instance. Server logs are kept for a limited time and overwritten as they fill.

The chosen language, theme, game and version, recently opened players and similar settings are kept in the browser's local storage and never sent to the server.

The player pages and search show open data the game publishers publish through their API: the name, the statistics, the clan. The Site keeps the values it has read, to show trends and the battle log.

3. Account holders

The username, the email address and the password. The password is kept only as a hash (argon2id): the password itself is not stored and nobody can see it.

When the account was created, when its address was confirmed and when the Terms of Use were accepted; the history of its usernames.

Sign-in sessions: the time, the browser and device type, the IP address. They are needed for “Where the account is signed in” and to protect the account; the owner is shown the IP address in part only.

Linked game accounts: the id, name, realm and open statistics read through the publisher's API. The Site never receives the game account's password.

The profile's appearance and settings; “Strategies” briefings; messages sent through “Bug or idea”.

Where the Mod Manager program is used: the installation's id, the program's version, and installation and update events of the mod.

4. Signing up

What the signup form holds is kept for up to 30 minutes while it waits for the code from the letter. If the code is never entered, it is deleted and no account is made.

Before the form is sent, the browser solves a small computational puzzle — a guard against automated signups. It is solved on the device and collects nothing about it.

The email address is checked against a list of temporary mail services and against the domain's DNS records, to learn whether the domain receives mail at all.

5. What the data is used for

For the account to work: signing in, confirming the address, recovering the password, notices about a password change and about deletion. To show the profile, the statistics and the battle log. To protect the Site and accounts against abuse, and to answer messages.

The Site does not sell data, sends no advertising mail, and does not pass account data on for advertising.

The grounds for processing are the consent given at signup and in the cookie settings, and the performance of the Terms of Use.

6. Letters

The Site sends service letters only: the confirmation code at signup, links to confirm an address, recover a password and confirm an account's deletion, and notices of a password change and of an account's deactivation. They are sent through the mail server of the Site's hosting provider.

7. Cookies and local storage

The Site's own cookies are needed for it to work: bi_refresh — the sign-in session (not readable by scripts on the page, up to 30 days), bi_session — a flag that this browser is signed in, bi_consent — the choice made in the cookie settings (1 year). None of them is used for tracking.

The analytics counters (section 8) and the ad network (section 9) set cookies of their own. With “Necessary only” chosen, the counters are not loaded.

The choice can be changed at any time through “Cookie settings” at the foot of every page.

8. Yandex Metrica and Google Analytics

Two visit counters run on the Site: Yandex Metrica (Yandex LLC) and Google Analytics 4 (Google Ireland Limited / Google LLC) — to show how many people arrive, which sections they use and what on the pages does not work.

The counters collect anonymised technical data: IP address, browser type and language, operating system, screen resolution, device type, referrer, the addresses visited, the time and length of the visit, and actions taken on the page. Session Replay (Webvisor) is on in Metrica: it records cursor movement, scrolling and taps. It does not record what is typed into the sign-in, signup and account settings forms.

The data is processed by those services, under their own rules; the Site sees aggregate statistics only. The Site passes no account data to the counters.

  • Yandex Metrica terms of use
  • Yandex privacy policy
  • How Google uses data from partner sites
  • Google privacy policy

9. Advertising

blitzinfo.app and lesta.blitzinfo.app carry advertising from the Yandex Advertising Network (Yandex LLC); wg.blitzinfo.app has none. The ads are chosen by the network itself: the Site does not decide which ad a visitor sees and receives nothing about an individual visitor.

To choose ads the network sets cookies of its own and collects anonymised technical data; ads may be personalised. Personalisation can be switched off in Yandex's settings.

  • Yandex ad personalisation settings
  • Yandex privacy policy

10. Who receives the data

The hosting provider whose servers run the Site, and the mail server the letters go through. The game publishers — only when a game account is linked, through their own sign-in page. Pictures and models are fetched by the browser from external CDNs (jsDelivr and the game's servers), which see the IP address and browser details.

Beyond that, account data is disclosed only where the law requires it.

11. How long data is kept

Account data is kept for as long as the account exists. Once deleted, the account is deactivated for 30 days and then removed with its sessions, links, settings, briefings and messages. The username stays held for 30 more days: only the name itself is kept, with no tie to any other data.

Sign-in sessions — until they expire and 7 days more. One-time links from letters — until used or expired and a day more. Unfinished signups — up to 30 minutes.

Entries in the moderation log are kept after an account is deleted, but no longer tied to it.

12. Security

The connection to the Site is encrypted (HTTPS). Passwords, session keys and one-time links are stored only as hashes. Sign-in attempts and other sensitive actions are rate-limited, and signups and player lookups through public proxies and Tor are not accepted.

13. Users' rights

The username and the email address are changed under “Security”. The same page ends sessions and deletes the account; deleting the account also withdraws consent to processing its data. Consent to analytics is withdrawn in the cookie settings.

To learn what data is kept, or to ask about how it is processed, write to the contacts below.

14. Changes to this policy

This policy may change. The revision published on this page is the one in force, and its date is given at the top.

15. Contact

Questions about data go to the project's Telegram channel, or through “Bug or idea” in the account menu.

  • @blitzinfo_official

Terms of Use →

© 2026 BlitzInfo

This project is not affiliated or associated with Wargaming or Lesta Games. All trademarks and names belong to their respective owners.

Terms of Use Privacy Policy