BABA YAGAS ALLIANCE-CORP REPORT BUILDER
Privacy Policy
Last updated: September 19, 2026
Baba Yagas Alliance-Corp Report Builder (the “Service”) is operated by Baba Yagas to help authorized EVE Online corporation and alliance leadership combine Alliance Auth exports with public EVE-related data, generate activity reports, create player-highlight graphics, and optionally publish generated reports and Player Highlights images to Google Drive.
1. Information the Service processes
The Service may process information contained in reports uploaded by authorized users, including EVE Online character names and IDs, main/alternate character relationships, corporation membership and join dates, fleet activity tracking (“FAT”) information, strategic activity, ISK-generation statistics, SIG membership, director status, and PvP kill/loss activity.
The Service is intended for EVE Online organizational data. Users should not upload real-world personal information that is not necessary for the report-building functionality.
2. Uploaded Alliance Auth reports
Uploaded CSV files are saved temporarily on the application server while a report is being generated. The application deletes those uploaded CSV files after processing finishes, including when a report-generation error occurs. Information derived from the uploads may remain in generated reports, application settings, or local caches as described below.
Users are responsible for uploading only reports they are authorized to access and process.
3. zKillboard, ESI, EveWho, and EVE image data
The Service retrieves public EVE Online-related information from third-party services, including zKillboard, CCP Games’ EVE Swagger Interface (“ESI”), EveWho, and CCP-hosted character-image services.
To improve performance and reduce repeated API traffic, the Service may retain a local archive or cache containing killmail IDs, killmail timestamps and values, character-to-killmail relationships, synchronization metadata, corporation-history data, and downloaded character portraits. These caches may be retained until the operator removes or rebuilds them.
4. Generated reports
Generated Excel workbooks and Player Highlights images are stored on the application server so authorized users can download them. Reports may contain internal corporation information such as member activity, FAT participation, PvP performance, ISK generation, corporation tenure, director status, and SIG membership.
Authorized users are responsible for controlling how downloaded or shared reports are distributed after they leave the Service.
5. Google Drive and Google Sheets data
The Service uses the Google Drive API with the https://www.googleapis.com/auth/drive.file scope. This access is used only to create and manage Google Drive files created by the Service for the report-export feature. The Service does not use this permission to browse or read unrelated files in the connected Google Drive account.
When Google integration is authorized, the Service may receive the connected Google account’s email address and display name to verify that the correct report-owner account is connected. OAuth access and refresh tokens are stored on the application server so the designated account does not need to authorize every report individually.
When a user selects the Google Drive publishing option, the Service uploads the generated Excel report, converts it to a native Google Sheets file, and uploads the generated Player Highlights PNG. Both files are created in a single application-managed Baba Yagas Reports folder in the designated Google Drive account. The Service creates that folder on first use and reuses it for future reports. The Service configures each generated file as Anyone with the link — Viewer. Anyone who receives either sharing link may therefore view that generated file.
Baba Yagas Alliance-Corp Report Builder’s use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
6. Local settings and credentials
The Service may store local configuration and operational information, including director names, Player Highlights exclusion preferences, OAuth client configuration, OAuth tokens, Flask session secrets, archive metadata, and cached API responses. Authentication credentials and OAuth tokens are not included in generated reports.
7. How information is used
Information is processed only as necessary to provide and maintain the Service, including generating corporation activity reports, calculating activity metrics, producing Excel and Google Sheets outputs, creating Player Highlights images, maintaining historical zKillboard data, resolving corporation tenure, reducing repeated API requests, and diagnosing application errors.
The Service does not sell user information or Google user data, does not use it for advertising, and does not use Google Workspace data to train generalized artificial-intelligence or machine-learning models.
8. Sharing and third parties
Information may be transmitted to third-party services when required for the requested functionality, including CCP Games / ESI, zKillboard, EveWho, and Google APIs. Generated Google Sheets and Player Highlights PNG files may also be made accessible to anyone with their sharing links when the Google Drive publishing feature is used.
The operator does not control copies of reports or links after an authorized user downloads, publishes, forwards, or otherwise shares them.
9. Data retention and deletion
Uploaded CSV source files are temporary and are deleted after report processing. Generated report files, zKillboard archives, cached corporation history, portraits, application settings, and OAuth credentials may remain on the application server until they are manually removed, replaced, or expired as part of maintenance.
Requests concerning stored application data may be directed to the contact address below.
10. Security
Reasonable administrative and technical measures are used to protect application data and credentials. No internet-connected service can guarantee absolute security. Authorized users are responsible for safeguarding report links, downloaded files, and any access credentials provided to them.
11. Third-party services
Third-party APIs and services are governed by their own terms and privacy policies. Their availability, behavior, and data may change independently of this Service.
12. Changes to this policy
This Privacy Policy may be updated as the Service changes. The date shown at the top identifies the latest published revision. Material changes to the way Google user data is accessed, used, stored, or shared will be reflected here.
13. Contact
Questions or requests concerning this Privacy Policy may be sent to eve.babayagas@gmail.com.
