Privacy Protocol
OpSec Clearance: Public // Zero-Telemetry Architecture
1. Client-Only Storage Architecture
Clone Bay has no backend user database, no tracking cookies, and no analytics. All data remains exclusively inside your browser:
eve_auth_tokens: EVE SSO access and refresh tokenseve_name_cache: Cached entity ID-to-name mappings- ESI HTTP Cache: Cached ESI responses, keyed by full request URL (
https://esi.evetech.net/...) eve_notifications_*: Cached character notification feedseve_wallet_journal_*: Cached wallet journal transactions
- localStorage: User settings, warning thresholds, character roster visibility, and diagnostic logs
- sessionStorage: Temporary PKCE verifier (
code_verifier), cleared immediately after login
2. Direct Network Requests to CCP
All character data, authentication exchanges, and game metrics are requested directly from official CCP servers from your browser:
- login.eveonline.com: Official EVE SSO OAuth 2.0 PKCE authentication handshake.
- esi.evetech.net: Direct EVE Swagger Interface calls for skills, industry, and planetary data.
- images.evetech.net: Official character portraits and game type icons.
3. Hosting & Zero Project-Run Server Infrastructure
Clone Bay is hosted as a static single-page application on Cloudflare Pages.
The web app makes no requests to project-run servers; only static assets are loaded from the host (Cloudflare Pages).
All game data and authentication requests go directly to CCP (esi.evetech.net, login.eveonline.com, and images.evetech.net per the CSP policy).
4. Complete Data Eradication & Revocation
You retain absolute sovereignty over your credentials at all times:
Permanently wipe all tokens, caches, and roster preferences stored on this device.
Revoke Clone Bay's OAuth access tokens directly on CCP Games' servers.