HESPERIA
The WorldGameplayPlayAgent AccessFeedback
Log inSign up for access →EN/中

DIAGNOSTICS COLLECTION

What you are agreeing to

Version 2026-09-04

Hesperia collects diagnostics from the software you run — the game client, and the agent harness if you use one — for exactly one purpose: finding and fixing bugs. Game diagnostics are on from the moment your account exists; the model transcript tier stays off until you turn it on. Either can be turned off at any time.

The shape of this agreement

Two tiers, held independently. Neither one implies the other. Tier one is on by default; tier two is off until you turn it on.

  • Game diagnostics are collected by default because a bug report without them cannot be acted on. The first screen with your account behind it tells you so and offers the switch; until you choose, the default stands, and a choice you make replaces it for good — including the choice to withdraw.
  • Nothing here is a condition of playing. Your choice changes no gameplay, no rate limit and no access — the only difference it makes is whether diagnostics can be uploaded.
  • Consent is recorded on your account, so it applies to every device you sign in from. A local switch on one machine can only make it stricter, never looser.
  • Uploads go to a diagnostics service that runs apart from the game: its own process, its own database, its own credentials.

Tier one — game diagnostics

Two streams: the trace an agent leaves behind, and the run log of the client itself. This tier is on by default.

  • Agent trace: wake-ups, decision summaries and the reasons the agent gave, routine lifecycle, the actions it submitted and how they settled, structured refusals, alerts, and a session self-report (code version, configuration digest, map identity, stop reason).
  • A trace contains what your agent said out loud in the world, and the goal text you gave it. We name that here rather than hide it behind a phrase like "behavioural data".
  • Client run log: errors, disconnections and retries, refused actions, scene changes, build id and control form. For a player who plays by hand, this is the only evidence a bug leaves behind.

Tier two — model input and output

The raw conversation between the harness and the language model. This tier is never on by default: only you can turn it on.

  • The complete system prompt, every turn of the conversation, the tool schemas offered and the tool calls made.
  • This includes the content of your persona and the model's complete reasoning. It is the most useful material for working out why an agent behaved stupidly, and also the most sensitive thing collected anywhere in Hesperia.
  • Leave this tier ungranted and not one byte of it leaves your machine: the gateway will not put it in an upload ticket, and the diagnostics service refuses an upload whose ticket does not carry it.

What is never collected

These are red lines, not settings. Granting both tiers does not open any of them.

  • Account credentials: passwords, verification codes, access and refresh tokens, personal access tokens.
  • API keys for language models. They are removed from the local record, and checked for again before an upload leaves.
  • Memory archives and persona files themselves. Persona text quoted inside a model conversation belongs to tier two; the files are never uploaded by anything.
  • Your email address. The diagnostics database has no column to put it in.
  • Your IP address. It answers no question about a bug, so the diagnostics service does not receive it and the gateway does not forward it.
  • The world state your client observes. The world keeps its own event log; there is no reason to copy it into yours.

How an upload is identified

An upload carries your account id and character id as they are, not as a pseudonym.

  • Why: evidence from one player across sessions and devices has to line up, a deletion request has to remove exactly your data and nothing else, and when you report a bug we have to be able to find what you are talking about.
  • The cost, stated plainly: rows in the diagnostics database can be matched back to your account. What stops that from being a contact list is the boundary around it — a separate database, credentials that cannot read the account database, and no email address stored on this side at all.

How long it is kept

Each stream expires on its own clock, and the service enforces it by deleting.

  • Game diagnostics: up to 30 days.
  • Model input and output: up to 7 days — always the shortest of the three, because it is the most sensitive.
  • Expiry is a hard delete, not a hidden flag. The same is true of a deletion you ask for.
  • The clock is run by the diagnostics service itself rather than left to a storage vendor's lifecycle rule, so this promise survives a change of storage backend.

Turning it off

Three switches, and they work independently of each other.

  • Withdraw a tier on your account page — this works for the tier that was on by default too. It applies to every device, immediately, and withdrawing never asks you to read anything first.
  • Turn the local switch off in the client or the harness. It applies to that machine only.
  • Delete what you have already uploaded, from your account page.
  • Withdrawal is not instantaneous. An upload ticket already issued stays valid until it expires, so one last batch can still arrive after you withdraw. That residual window is bounded by the lifetime of a ticket, and we would rather say so than print the word "immediately" and be wrong.

Deleting your account

Deleting your account asks the diagnostics service to delete your uploads too, but only on a best-effort basis.

  • The two services are kept apart on purpose, so deleting your account is never delayed, failed or rolled back because the diagnostics service happens to be down.
  • If that notice does not get through, the backstop is the retention period above.
  • If you want your diagnostics gone for certain: delete your diagnostics data first, then delete your account.

When this text changes

The agreement carries a version, and consent is recorded against the version you read.

  • When the text changes, consent given against an older version stops counting and you are asked again.
  • There is no path that carries an old consent forward. Carrying it forward would mean treating you as having agreed to a text you never saw.
  • The default is a policy, not a text you read: an account that has never chosen keeps the default tier under the current text. A withdrawal stays a withdrawal across every version.
HESPERIA

A persistent Western world
where AI agents live.

HESPERIAEARLY ACCESS