Variant Interactive Map: Privacy Policy

variantinteractivemap.org

Last updated: August 27, 2026

Summary: Most personal Variant data starts on your device. The Icarus Prospect Analyzer reads the prospect file you choose directly in your browser and does not upload or edit the original file. Saved analyzer maps stay in local app storage or, when you already approved a Variant PC folder, under the Icarus / Prospect Analyzer subfolder. Prospect share codes are optional and send only the reduced mapped-deposit data needed to recreate that analyzer view. Google Auto Sync and Shared Maps are also optional.

1. Device storage

Variant uses browser local storage for lightweight gameplay progress and preferences. Depending on the features you use, this can include Icarus markers, notes, tool records, calculator plans, custom recipes, saved builds, Valheim progression and checklist state, notes, saved world names and seeds, calculator plans, personal planning records, gallery references, pinned tools, and app settings.

User-added images from galleries and notes, along with saved Prospect Analyzer maps, can be stored separately from normal local storage. On supported desktop browsers, you can choose a parent folder and grant read/write access. Variant can then create or reuse a Variant Interactive Map folder inside that location and organize files into Icarus/Valheim, Gallery, Notes, Companions, and Prospect Analyzer subfolders. On mobile or unsupported browsers, Variant uses browser/app file storage when available, with IndexedDB as a fallback.

Variant cannot browse arbitrary folders on your device. It can access only files or folders you explicitly choose or authorize. You do not need to create a Variant account to use the normal local tools.

2. Local save and data-file analysis

When you choose an Icarus prospect JSON in the Prospect Analyzer, Variant reads that selected file in your browser, decodes supported world records, and displays supported information such as deep mining deposits on the map. The analyzer does not upload the original prospect JSON to Variant's backend and does not edit that file. Variant can save a reduced analyzer map locally so you can reopen it later without selecting the original JSON again.

When app storage is used, saved prospect maps are kept in browser/app storage. When PC Gallery storage is already connected and authorized, Variant can also create Icarus / Prospect Analyzer / Saved Maps and Original Saves subfolders inside the approved Variant folder. The Original Saves copy is a copy of the JSON you selected; Variant does not move or delete the source file from its original location. Variant can rebuild saved analyzer entries from the .vpa files in that approved folder.

Creating a Prospect Analyzer share code is optional. When you choose Copy Share Code, Variant sends a reduced payload containing the selected prospect name, Icarus map, deep-deposit resource types, map coordinates, remaining-ore values when present, and cave/surface flags to a Variant Netlify Function and site-wide Netlify Blobs. The original prospect JSON, unrelated save records, actor paths, and other raw save contents are not sent with the share code. Importing a valid share code downloads that reduced payload. Exporting or importing a .vpa file transfers the same reduced analyzer data as an ordinary local file.

Other file-import features follow the permission shown by the browser or file picker. Selecting a local file does not give Variant general access to the rest of the folder or device.

3. Optional Google Auto Sync

If you connect Google, Variant requests https://www.googleapis.com/auth/drive.appdata. That permission is used only to create, find, read, and update Variant's own synchronization file in Google Drive's hidden application-data area.

Variant does not request permission to browse, read, edit, or share your normal Google Drive files. Google Sync does not request Google profile, email, Contacts, Calendar, or Gmail scopes.

Google OAuth access tokens are short-lived. Variant can keep an unexpired access token temporarily in sessionStorage for the current browser/app session, but it is not stored in localStorage. To avoid asking you to reconnect every time the browser or installed app closes, Variant can use Google's authorization-code flow and store the resulting Google refresh token in Variant's server-side Netlify storage. The refresh token is never written to browser storage or shown to collaborators. Variant does not receive or store your Google password.

If you use Shared Maps, the browser sends the same short-lived Google access token to a Variant Netlify Function so the server can ask Google to verify which Google account is making the request. Shared Maps does not request Google profile or email scopes, and collaborators see the Variant display name you choose rather than your Gmail address. The verified opaque Google account identifier is used server-side only for Shared Maps access control.

When persistent Google authorization is available, Variant can refresh expired access tokens through the server-side refresh token without opening Google sign-in again. Reconnection can still be required if Google expires or revokes the authorization, if it becomes invalid, or if you switch accounts.

4. Google data use

Data accessed through Google Sync is used only to provide the backup and synchronization feature you request. It is not used for advertising, profiling, sale of data, or unrelated purposes.

Variant's use and transfer of information received from Google APIs is intended to comply with the Google API Services User Data Policy, including applicable Limited Use requirements.

5. Transmission and Shared Maps

Your private Google sync file is transferred between your browser/app and Google Drive. Variant's backend does not receive or store the contents of that private sync file. The backend can securely store the Google refresh token used to renew short-lived access tokens and a random Variant session identifier used to find that authorization record. The primary session identifier is kept in an HTTP-only cookie; an opaque resume key can also be stored in this device's local site storage so the installed app can restore the same authorization after a restart. The Google refresh token itself is never written to browser storage.

Shared Maps are separate from the private Drive sync file and use site-wide Netlify Blobs for collaboration data. Shared Maps can store the Variant display name you choose, shared-map names, a Valheim world seed when you include one, memberships and invite records, marker coordinates, types, labels, layers, notes, authorship references used for permissions, and timestamps. Collaborators with access to the same shared map can receive its shared marker data and collaborator display names.

Variant does not intentionally expose Google email addresses or the underlying Google account identifier to other collaborators. Shared-map invite codes are reusable for up to 7 days. Creating a new invite code for the same map invalidates the previous active code. Anyone who receives a valid active code can join with the permission attached to it, so share codes only with people you intend to add. Prospect Analyzer share codes are separate from Shared Maps and do not grant collaboration access; they retrieve only the reduced analyzer payload stored for that prospect code.

Screenshot and note-image files, saved Prospect Analyzer maps, and copied original prospect JSON files stored in browser/app storage or a user-selected PC folder are device-local unless you explicitly create a Prospect Analyzer share code. These files are not uploaded by Google Sync or embedded in the normal JSON Backup/Restore file.

If you use Submit Feedback, Variant sends the feedback type, message, optional reply email or name/Discord value, the current Variant version/build, the page and route you were using, viewport size, and whether Variant is running in a browser or installed app to Netlify Forms. Feedback submissions do not automatically include game saves, Google tokens, or other local files. Netlify can store the submission and send a configured form-notification email so the developer can review it.

Variant does not sell Variant data or Google user data. Hosting providers and Google can process ordinary technical information needed to deliver their services under their own policies.

6. Retention and deletion

Local saved records remain on a device until they are cleared, overwritten through restore/sync, or deleted through the relevant feature. Images stored in a selected PC folder remain as ordinary files until deleted through Variant or your operating system. If folder permission is lost, Variant can require you to reconnect that folder before it can view or delete those files.

The Google sync file remains in the Google Drive application-data area until it is removed through Google-account controls or an authorized app action. Revoking Variant's Google access prevents future API access but may not delete previously stored app data by itself.

Shared-map data remains in Variant's Netlify storage until it is deleted through Shared Maps or removed as part of service maintenance. A shared-map owner can remove collaborators or delete the map and its shared markers. A collaborator can leave a map. Markers already contributed can remain after a collaborator leaves or is removed unless the owner deletes them. Prospect Analyzer share-code payloads are stored separately in site-wide Netlify storage so a valid code can retrieve the shared map data; those payloads can remain until service maintenance removes them.

Feedback submissions can remain in Netlify's form-submission storage and any configured notification inbox until they are deleted during normal project or email maintenance.

7. External links and optional support

Variant includes links to official game websites, external wikis, map sites, community tools, and an optional Buy Me a Coffee page. Following an external link leaves Variant and is subject to that site's own privacy practices.

Variant does not process support payments or collect payment-card details. Contributions through Buy Me a Coffee are processed by Buy Me a Coffee under its own terms and privacy practices.

8. Security and policy changes

The deployed site uses HTTPS and Google's OAuth authorization system for Google Sync. No electronic storage or transmission method can be guaranteed completely secure. This policy can be revised when Variant features or data practices change; the date above identifies the current version.

9. Contact

Questions about this policy or Variant's Google-data use can be sent to frenziafun22@gmail.com.

Variant Interactive Map is an unofficial community tool and is not affiliated with or endorsed by RocketWerkz, Iron Gate, Coffee Stain Publishing, or the developers or publishers of Icarus or Valheim.

← Launch Variant Interactive MapHomeTerms of Service