OoT: Recompiled OoT: Recompiled, home

The website and the recompilation app

Privacy policy

This policy covers OoT: Recompiled: this website, www.ootrecompiled.com, and the Windows recompilation app it offers. It adds to my master privacy policy, which covers my websites and my web and mobile apps. Where the master policy already covers something, this page points to it rather than repeating it. The master policy does not describe desktop apps, so everything about the recompilation app is set out here, and so is everything this site does that the master policy does not describe. Where the two differ, this page is the one that applies to OoT: Recompiled. The rules for using the site and the recompilation app are in the terms of service.

Last updated

Who is responsible

OoT: Recompiled is developed and operated by Jonathan Barnes, who is responsible for the information described in this policy and decides how and why it is used. Questions and requests about this policy or your information can be sent to [email protected].

In short

  • The recompilation app sends nothing about you. It has no telemetry, no analytics, no crash reporting and no account. The only thing it ever asks the internet is whether a new version exists, and only if you turn update checks on.
  • The website has no analytics, no advertising and no tracking. Nothing measures what you read or where you go next, and nothing is sold, rented or shared for anyone else's use.
  • You can read everything and download the recompilation app without an account. An account exists only so feedback can carry your name, and it is made the first time you send something.
  • Feedback is public; your email address never is. What you send as feedback appears on the site under the display name you choose. Feature requests and bug reports are read first and appear only if I take them up.
  • A log you attach to a bug report is private. Only I can open it.
  • The site stores nothing optional in your browser unless you agree, and it sets no cookies of its own.

The recompilation app

Everything below describes the recompilation app as released, version 0.5.0, and was checked against its source, which anyone can read on GitHub.

What it asks the internet

The recompilation app contains one piece of network code: the update check. It is off until you turn it on. The first time the recompilation app starts, it asks whether it should check for updates, and you can answer "No, stay offline"; the Check for updates row in the settings changes your answer at any time.

When update checks are on, the recompilation app asks releases.jonbarnes.dev for one small file that names the latest version: when it starts, straight away when you turn checks on, and every four hours while it runs until it finds a newer version. The request carries nothing about you, your computer or your copy of the game. There is no identifier, no version number, no system details and nothing from your ROM; the recompilation app names itself only as "OoTRecompiled". As with any request, the releases host, which runs on Cloudflare, sees your IP address.

When a newer version exists, an installed copy downloads its setup file in the background, checks that the file is intact (a SHA-512 digest) and signed by Jonathan Barnes (checked on your computer, with no online lookup), and keeps it in the recompilation app's updates folder. Nothing is installed until you start the recompilation app again, press F5, or click the notice, and even then the setup always opens its own window and waits for you to press Install. A file that fails either check is deleted, and a setup file is cleaned up once the update has happened. A portable copy only tells you that a new version exists; if you press F5, it downloads the setup file into its own updates folder.

Nothing else leaves your computer. There is no telemetry, no analytics, no crash reporting, no account, no advertising, and no Windows Error Reporting: if the recompilation app crashes, the details go only into its own log, on your computer. It opens no web pages and contains no links.

What it keeps on your computer

An installed copy keeps everything in one folder, %LOCALAPPDATA%\OoT Recompiled unless you chose another during setup:

  • the recompilation app itself, in bin;
  • your saves, and your saved moments, each with a small picture of where you were, the place and time in the game, the recompilation app's version and when it was made (the names are made by the recompilation app, never typed by you);
  • your settings, lighting settings and controls, as plain text files;
  • mods and texture packs you add, and the mod settings the recompilation app keeps for them;
  • downloaded updates, while they wait to be installed;
  • its log and the installer's log;
  • the location of your ROM, and, only if you say yes when it asks, a copy of your ROM.

A portable copy keeps the same things in its own folder. Outside that folder, both kinds of copy write:

  • screenshots and recordings to Pictures\OoT-Recomp, in a folder for each day, and videos to Videos\OoT-Recomp;
  • an empty rt64 folder in your local application data, which the renderer the recompilation app is built on creates when it starts.

An installed copy also adds a Start menu shortcut and a desktop shortcut, if you leave them chosen in the setup window, and an entry in Windows' installed apps, recorded under your own Windows account only. It adds no file associations, nothing that starts with Windows, and no scheduled tasks.

Your ROM

The recompilation app reads your ROM where you keep it. It reads the whole file into memory and checks it against the one version it supports, on your computer; it saves only the file's location, so it can find it next time. Your ROM is never uploaded and never changed. An installed copy offers once to keep a copy of it in the recompilation app's folder; it does so only if you say yes, and uninstalling moves that copy to your Downloads folder rather than deleting it.

The microphone

The microphone is off by default. The recompilation app opens it only while a video is recording, and only when both Video recording and Microphone are turned on; it closes it when the recording stops, and while a recording is paused, what the microphone hears is thrown away. Your voice is mixed into that video's sound track and nowhere else: there is no separate recording, and it never leaves your computer. So that you can choose a microphone, the settings list the names of the microphones on your computer; the recompilation app remembers your choice by its place in that list, and writes the name of the microphone in use to its log.

Screenshots, videos and photo mode

All of these are off by default. They capture only the recompilation app's own picture: the game alone, or the recompilation app's whole window with its menus, as you choose. They never capture your desktop or any other window. Screenshots are saved as PNG files with nothing added to them, and videos as MP4 files, in the folders above, and nothing is uploaded. Photo mode freezes the game and saves nothing by itself. The comparison shots and the frame recorder in the Debugging menu save to the same Pictures folder; the frame recorder also writes down the settings in use, the place in the game and the time of day.

Controllers

The controls file keeps your key and button bindings and, for each controller you have used, its own bindings, dead zone and rumble setting, filed under the identifier SDL gives that kind of controller. The names of connected controllers are written to the log.

The log

The recompilation app writes a log, oot-recompiled.log, in its folder, and replaces it each time it starts. It is never sent anywhere by the recompilation app. It records the recompilation app's version and when it started; the full paths of its folders, which usually include your Windows user name; your ROM's location; the name and driver version of your graphics card; the controllers and microphone it found; the files it saved; and, after a crash, where in the recompilation app the crash happened (never the contents of memory). The log leaves your computer only if you attach it to a bug report yourself.

Uninstalling

The website, without an account

Reading this site and downloading the recompilation app need nothing from you. What happens while you do:

Hosting

The site is served by Cloudflare Pages, on my own Cloudflare account. Like any web host, Cloudflare receives the standard details of each request your browser makes (your IP address, your browser's user agent, the page asked for and the time) in order to deliver the page and protect it from abuse. Cloudflare handles that under its own privacy policy. The master policy names Netlify and Vercel as hosts; this site uses Cloudflare instead, and neither of those.

Release information

The download buttons, file sizes, the current version and the list of past releases are read live from my releases host, releases.jonbarnes.dev, also on Cloudflare. Your browser asks this site for them, and the site fetches them from the releases host on your behalf; nothing about you is added to that request. The downloads themselves come straight from the releases host when you click one, which sees the same standard request details as any download server.

Video and pictures

The video behind the home page is streamed by Cloudflare Stream. The pictures are served from my own media server, mediaserve.dev, which also runs on Cloudflare. Both receive the standard request details when your browser loads them. The fonts are served by this site itself, not by a font service.

Published feedback

The feedback page shows published feedback by reading it straight from Supabase, the backend that holds accounts and messages, so your browser makes that request itself, and Supabase sees the standard request details. The request can only ask for what is public: the display name, the kind of message, the version, the title, the text and the date.

Links to other sites

Cookies and browser storage

This site sets no cookies of its own, and no advertising, analytics or tracking cookies of any kind. What it keeps is in your browser's own storage, on your device, and it comes in two kinds.

Kept because the site needs it, which needs no permission:

  • Your sign-in, only if you sign in: the tokens that keep you signed in, under the name oot-site-session. They stay until you sign out or delete your account.
  • Your answer to the storage question, under the name oot-consent: the word "accepted" or "declined", and nothing else, so the site does not ask on every page.

Kept only if you accept:

  • Which values the settings page shows (Original or Ray traced), under the name oot-settings-columns, so the page remembers your choice. It is written only when you pick one.

The first time you visit, a bar at the foot of the page asks. Accept and Decline carry the same weight, and until you answer, nothing optional is kept. If you decline, nothing optional is kept, and anything kept before is removed. If your browser sends the Global Privacy Control signal, the site treats that as declining and does not ask, unless you choose otherwise yourself. You can change your answer at any time with Cookie settings at the foot of every page, and clearing your browser's site data removes everything.

Accounts

An account is made the first time you send feedback, a feature request or a bug report, so that your display name stays yours. It holds:

  • Your email address, to sign in, to send you the codes and links below, and to reply to what you send.
  • Your password, which is stored only as a one-way hash by Supabase, the backend the master policy describes. Nobody can read it, including me.
  • Your display name, one per email address, which is what appears beside anything of yours that is published.

Every sign-in asks for a code sent to your email as well as your password, for every account, administrators included, and it cannot be turned off. The code works for ten minutes and is stored only as a one-way hash; once it is used, that sign-in is recorded as verified, and nothing that reads or sends anything works for a sign-in that has not been. A password can be changed only after the code, or from a link or code sent to your email.

Sign-in attempts are recorded: the account, whether it was a password or a code, whether it succeeded, and when. This is what limits guessing (five wrong attempts within thirty minutes stop that account's sign-in until the thirty minutes have passed) and what lets me see an attack on an account.

Feedback, feature requests and bug reports

What you send

The form takes the kind of message (feedback, a feature request or a bug report), your display name, your email address, the version of the recompilation app you are running, a title for requests and reports, and what you write, up to 4,000 characters. A bug report may also carry the recompilation app's log file, which is optional and up to 2 MB.

The bot check

Before anything is accepted, the form asks Cloudflare Turnstile whether you are a person, loading its script from challenges.cloudflare.com. Turnstile runs a check in your browser and gives the form a token; the site sends that token, with your IP address, to Cloudflare to verify it. Cloudflare handles that under its own privacy policy. The site keeps nothing from the check.

The rate limit

To stop a script from flooding the form, the site counts how often each visitor sends, allowing five in an hour. It does not keep your IP address for this: it keeps a one-way fingerprint of it (a SHA-256 hash) with the time of each attempt, which is enough to count with and cannot be read back into an address.

What becomes public

  • Feedback is published on the feedback page as soon as its confirmation email reaches your inbox, which is how the site knows the address is real. If the email bounces, or you mark it as spam, nothing you sent is published.
  • Feature requests and bug reports are never published automatically. I read each one first, and the ones I take up appear beside the roadmap.
  • What is shown is your display name, the kind of message, the recompilation app's version, its title, what you wrote, and the date. Your email address is never shown, anywhere. Neither is a log file.

I may also decline to publish something, or take it down later; what is not published stays private.

Log files

A log attached to a bug report is stored in a private area of my own Cloudflare R2 storage. It cannot be reached by any public address. When I open one, the site makes a link that works for five minutes and only after I have signed in with both my password and an emailed code. Logs exist to find the bug you reported and are not used for anything else. A log holds what the recompilation app writes about your computer (see "The log" above), including folder paths that usually contain your Windows user name and the name of your graphics card, so open it before you attach it, and remove anything you would rather not send.

Email

How long things are kept

  • Your account and your display name: until you delete the account, or ask me to.
  • What you send: until you ask for it to be removed, or I remove it. Published feedback stays published until then. Deleting your account does not remove it; it stays under "Deleted user", as below.
  • Log files: until I delete them, which I do once the bug is dealt with, sooner if you ask, and always when the account that sent them is deleted.
  • Sign-in codes stop working after ten minutes; the hashed code record is kept with the account.
  • Sign-in attempt records and the rate limit's fingerprints are kept as security records and are not yet removed automatically.

Your choices

  • Deleting your account. Sign in and use Delete my account on your account page, then type the account's address to confirm. It happens at once, signs you out, and an email confirms it. You can also email [email protected] from the address on the account and ask, and I do the same within 30 days.
    • Deleted: your sign-in and password, your email address from everywhere the site kept it, your display name (which becomes free for someone else), any log files you attached, and your sign-in codes, sessions and sign-in attempt records.
    • Stays: the feedback, feature requests and bug reports you sent stay on the site, published or not, with any private note I made on them, but your name, email address and account are no longer associated with them. They show "Deleted user", and can never be tied to you or to another account, including one that later takes your old display name. To have any of them taken down as well, email the same address.
    • Also stays, out of my reach or not tied to you: the rate limit's one-way fingerprints of IP addresses, which were never linked to an account; the request records Cloudflare, Supabase and Resend keep for their own set periods; emails already sent, in your inbox and mine; and anything the recompilation app keeps on your own computer.
  • Removing one thing you sent, or correcting a display name: email the same address.
  • A copy of what is held about you, and your other rights, as the master policy describes: email the same address. I answer within 30 days.

Changes to this policy

If what this site or the recompilation app does with your information changes, this page changes first, with a new date at the top. A change that matters to people with an account may also be sent to them by email.