TroubleByte

Privacy

TroubleByte is intentionally privacy-light: the application ships no advertising SDK, tracking pixel or third-party web font. Cloudflare sits in front of the site for DNS, proxying and Tunnel delivery. If Cloudflare Web Analytics/RUM is enabled at the zone level, Cloudflare can inject its own performance beacon at the edge; that setting is controlled in Cloudflare rather than by the TroubleByte application.

Cookies used by the application

TroubleByte uses a random first-party visitor identifier cookie tb_vid for interactive security features and pseudonymous browser identity. It is used when issuing short-lived anti-forgery tokens and, for Community Outcome, lets one browser update its vote rather than creating unlimited duplicate votes. Application tables use an HMAC-derived visitor hash where this identity is needed rather than storing the raw tb_vid value.

When you sign in, TroubleByte also uses the first-party tb_session cookie containing a random opaque session token. The database stores only an HMAC-derived hash of that token. The raw session token remains in the browser cookie and is not stored in the database.

Community Outcome environment data

When you submit a Community Outcome vote, TroubleByte automatically sends only coarse operating-system family, browser family and device class with that vote, for example Windows, Edge and desktop. This context is used only to produce aggregate troubleshooting outcome statistics. The outcome payload does not include the raw user-agent string, IP address, hostname, timezone, screen dimensions or the Browser & System Info report. Environment-segment statistics remain hidden until the configured minimum sample is reached.

IP addresses

TroubleByte application data used for outcomes, accounts, sessions, community discussions, reports and the moderation audit trail does not store raw IP addresses. IP addresses may still be processed temporarily for abuse prevention and rate limiting, and may appear in normal web-server, Cloudflare or infrastructure logs according to the server operator’s retention settings.

Search

Search queries are processed by the TroubleByte server. The current schema does not create a permanent search-history table.

Troubleshooting tools

The Windows Error Decoder, BSOD / Stop Code Decoder, HTTP & Browser Error Decoder and Browser & System Info tool run locally in the browser against static TroubleByte data and do not automatically upload the entered code or generated report. The Public DNS Inspector is the exception: it sends only the hostname you submit to the TroubleByte backend, which then queries the fixed Cloudflare 1.1.1.1 DNS-over-HTTPS resolver to obtain public DNS records. The DNS tool does not fetch the target website or scan target ports, and requests are rate-limited for abuse prevention.

Analytics and consent

TroubleByte uses Google Analytics 4 only after you explicitly accept optional analytics. Before a choice is made, and after a rejection, the Google Analytics tag is not loaded by the TroubleByte application and analytics cookies are not created by that tag. If you accept, Google Analytics can set first-party analytics identifiers such as _ga and receive measurement data including page views, engagement, device/browser information and approximate location derived from network information. Advertising storage, advertising user data and ad personalization consent remain denied in this implementation.

When analytics is accepted, TroubleByte also sends a small set of aggregate product-use events so we can improve search, tools and troubleshooting flows. These custom events can record actions such as a search submission, which tool was run, whether a published solution was marked as worked or did not work, and whether a diagnostic report or troubleshooting summary was copied. TroubleByte custom analytics events do not send raw search terms, hostnames entered in the DNS Inspector, error-code input, pasted logs, or the contents of a generated diagnostic report.

Your analytics choice is stored locally in your browser under tb_analytics_consent_v1 so the site can remember it. You can change or withdraw the choice at any time with the Privacy choices control in the footer. TroubleByte currently disables Google Signals and ad-personalization signals in its GA4 configuration.

Current browser choice

Advertising

No advertising is currently enabled. Before Google AdSense or another advertising provider is activated, this policy and the consent implementation must be updated to describe the actual data processing and regional consent requirements.

Community accounts

Account registration and sign-in are available for the TroubleByte community. Registered users can post discussions and replies using their account display name. The account email address is not shown publicly. Guest participation remains available using a pseudonymous browser-specific identity, and existing Guest posts are not automatically claimed by a later account.

Community discussions and reports

Community discussions are public user-submitted content attached to a canonical troubleshooting problem. Guest posts use a pseudonymous browser-specific identifier derived with a server-side HMAC; the raw visitor cookie is not published. When a guest starts a discussion, TroubleByte may attach only coarse operating-system family, browser family and device class. The raw user-agent string, hostname, timezone, screen dimensions and Browser & System Info report are not automatically uploaded with a community post.

Users can report community posts for spam, abuse, unsafe advice, off-topic content or another reason. TroubleByte stores the report reason, an optional note and a pseudonymous reporter identifier for moderation. Raw IP addresses are not stored in the community discussion or report tables. Rate limiting uses derived server-side identifiers to reduce abuse.

Do not post passwords, authentication tokens, API keys, recovery codes, private personal information or other secrets in a community discussion.

Accounts and sessions

When you create a TroubleByte account, TroubleByte stores the username, email address, display name, password hash, account role, trust score and account timestamps needed to operate the account. Passwords are not stored in plaintext.

Signed-in sessions use a random opaque browser token. TroubleByte stores only a server-side HMAC-derived hash of that session token together with the account ID, a pseudonymous visitor hash, session timestamps and revocation state. The raw session token remains in the browser cookie and is not stored in the database.

Account and session tables do not store raw IP addresses or raw user-agent strings. IP addresses may be processed transiently to derive server-side rate-limit identifiers used to reduce automated abuse.

Your display name may appear publicly next to community discussions and replies. Your account email address is not displayed publicly. Existing Guest posts are not automatically transferred to a newly created account.

The account page can show active session creation, last-active and expiry timestamps without exposing raw session tokens, IP addresses or user-agent strings. You can sign out other active sessions. Changing your password revokes existing sessions and rotates the browser performing the password change to a fresh session.

Moderation and security audit trail

Reported community content can be reviewed by authorized moderator, editor and administrator accounts. Moderation actions can hide or restore posts, lock, unlock or hide threads, and clear resolved reports. Account-state changes such as suspension or disabling are restricted to administrators and revoke active sessions when applied.

State-changing account-security and moderation actions are recorded in a minimal audit trail. Depending on the action, the audit record can contain the acting account ID, target account, post or thread ID, an action name, a bounded moderation note and a timestamp. The audit trail does not store raw IP addresses, raw user-agent strings, raw session tokens, visitor cookies, CSRF tokens, passwords or password hashes.