Information the controller tester handles
The tester reads gamepad information made available by your browser, which can include a device name or identifier, mapping label, button states, axis values, timestamps, and whether a browser haptics interface is available. The live test processes those values in your browser. Our standard site code does not transmit or store the live stream on our server.
When you save a report to My Lab, the report is placed in local browser storage on your device. Clearing site data can remove it. A signed-in member may deliberately import a completed report into the cloud account. That snapshot can contain the report title, controller name, test summary, captured result data, and test date. We do not continuously synchronize live button, stick, or trigger input.
When you intentionally create a share link, the selected report is encoded in the URL fragment. URL fragments are normally not sent to the web server, but anyone who receives the complete link can read the embedded report. Review a report before sharing it.
Account and security information
If you create an account, we process a username, email address, display name, password hash, account role and status, profile details you choose to add, account timestamps, and security records such as password-reset tokens, failed-login counters, API-key metadata, and audit events. We never store your account password in readable form. API secrets are shown once when created; only a one-way hash and identifying prefix are stored afterward.
A secure session cookie keeps a signed-in member authenticated and protects account forms. Account and administrative routes are excluded from the site’s first-party page-view analytics. Members should use a unique password, protect API keys as credentials, and revoke any key that may have been exposed.
First-party aggregate analytics
We use limited first-party measurement to understand page demand and site performance. It records aggregate daily counts for page views, approximate unique visitors, requested paths, referring hostnames, broad device category, and whether a view came from a signed-in or signed-out session. It does not store a visitor’s raw IP address or full user-agent string in the analytics tables.
For daily uniqueness counting, the server briefly combines the request IP address and user-agent string and transforms them with a keyed HMAC that also includes the calendar day. Only the resulting hash is stored. The day-specific input makes the value rotate daily, so it is not designed to follow a person over time. We honor the browser’s Do Not Track signal for this measurement, exclude known bots, and do not collect it on account, administrative, authentication, installer, or API routes.
Information collected by normal web hosting
Like most websites, our web host, network, or security provider may create server logs containing an IP address, request time, requested page, referring page, user-agent string, and security or error information. These operational logs are separate from our aggregate analytics and support delivery, reliability, fraud prevention, and troubleshooting. Their handling can also be governed by the provider’s terms and documented retention schedule.
Contact messages
If you contact us, we receive the information you choose to provide, such as your name, email address, message, and technical details. We use it to reply, investigate an issue, protect the service, and maintain a record of corrections or requests. Do not send passwords, payment-card data, serial numbers, or other sensitive information.
Retention
Account information and cloud reports are kept while the account remains active or until the member deletes the report or account. Local My Lab reports remain on the member’s device until deleted or until browser storage is cleared. Contact messages and related correspondence may be kept for up to 24 months after the last interaction unless a longer period is needed for security, a correction record, a legal obligation, or a dispute.
The default installation retains daily uniqueness hashes for up to 35 days and security audit records for up to 365 days; an operator may select a documented period within the limits available in Admin. Aggregate counts that no longer identify a daily browser may be retained longer for historical comparison. Where we control hosting-log settings, routine logs should be kept for no longer than 90 days, although a hosting or security provider may retain limited records under its own schedule.
When a member completes the in-account deletion process, cloud controller reports are deleted, active API keys are revoked, and account identity fields are anonymized. Limited audit, security, correction, transaction, or backup records may remain for their applicable retention period when needed to protect the service, comply with law, or document the request.
Cookies, advertising, and measurement
The base tester uses local storage for reports and interface preferences, a session cookie for authentication and form security, and a consent-choice cookie. Optional integrations can include Google Analytics or Tag Manager and Cloudflare Web Analytics for audience measurement, plus Google AdSense, Meta Pixel, or Microsoft Advertising UET for advertising or marketing measurement. Search Console, Bing Webmaster Tools, and IndexNow verification do not by themselves activate behavioral advertising.
Optional analytics and marketing integrations are disabled until an administrator enters a valid identifier and enables them. The site’s integration layer loads analytics only after the analytics category is allowed and loads advertising or marketing tags only after the marketing category is allowed. In regions where a certified consent platform is required—such as for certain Google advertising uses—this site notice must be supplemented with the required compliant platform before those services are enabled.
Third-party providers process information under their own terms and privacy documentation. Enabling an integration does not guarantee approval by an advertising network, eligibility for monetization, or any search ranking.
Purposes and legal bases
- Provide the requested website and controller diagnostic features
- Create and secure an optional account and member-requested cloud reports
- Protect the service against abuse, fraud, and security incidents
- Respond to messages and exercise legal rights
- Understand aggregate demand and improve content and performance
- Display advertising with consent or another valid basis where applicable
Sharing and sales
JSAN Media may use hosting, security, email, analytics, and advertising providers to operate the site. They receive information needed for their function and are governed by their terms and data-protection obligations. We may also disclose information when required by law, needed to protect rights or safety, or connected with a legitimate business reorganization subject to appropriate safeguards.
We do not sell live controller readings, and we do not exchange personal information for money. Some U.S. state privacy laws define disclosures for targeted or cross-context behavioral advertising as a “sale” or “sharing.” If we activate processing covered by those definitions, we will provide the applicable notice and opt-out method.
Your choices and rights
A signed-in member can edit profile information, download a JSON export of account details and completed cloud report snapshots, delete individual cloud reports, and permanently delete the account through Privacy & Data. Account deletion also revokes API keys associated with that member. An administrator can separately revoke an issued key. Local My Lab reports must be deleted in that browser or by clearing site storage because we cannot retrieve local-only records.
You can decline optional analytics or marketing categories through the consent controls, adjust browser settings, enable Do Not Track for first-party page-view measurement, or use provider-specific advertising controls. Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. You may also have a right to appeal or complain to a regulator.
Send a request through the contact page or to privacy@gamecontrollertest.com. We may need to verify the request and may deny or limit it where an applicable exception permits. An authorized agent should explain their authority to act for the individual.
Children, security, and international use
The service is a general-audience controller utility and is not directed to children under 13. We do not knowingly request personal information from children. If we learn that we collected it contrary to applicable law, we will take appropriate steps to remove it.
We use safeguards such as password hashing, secure sessions, request-forgery protection, rate limits, scoped API keys, access controls, and audit records. No internet system is risk-free. Visitors outside the United States should understand that JSAN Media and service providers may process information in the United States or other countries, subject to applicable safeguards.
Policy changes and contact
JSAN Media may update this policy when the service, providers, or legal requirements change. The effective date identifies the current version. Material changes will be presented appropriately. Privacy questions can be sent through the contact page or to privacy@gamecontrollertest.com.
Questions about this page?
Contact JSAN Media and include the relevant page address. We review privacy, accessibility, correction, and technical requests.
Contact us