Privacy
Effective 31 August 2026 · plain English on purpose
The short version
We never ask for your Jagex login. We hold the minimum needed to run the service, encrypt the sensitive parts, never sell anything, and you can delete everything yourself with one button.
What we collect
- Sign-in identity: your Google account's email, name, and avatar — used only to identify your Account Audit account. We never see a password.
- Linked characters: display names and a salted SHA-256 of the RuneLite account identity (the raw value never leaves your machine).
- Synced game data (via the plugin, with your consent): quest states, quest points, skill levels, worn equipment, achievement diary tiers, personal-best times.
- Bank contents — only if you enable the separate opt-in toggle. Stored encrypted (AES-256-GCM); never shown on any public page; deleted when you unlink.
- Advisor chats: your goal-advisor threads and the distilled memory built from them, private to your account.
- AI usage records: token counts per AI call, for credits and abuse prevention.
- Your own OpenAI key, if you add one: validated once, stored encrypted, used server-side only for your calls, never logged, deletable in one click.
- Payments: handled entirely by Stripe. We store only your Stripe customer id and subscription status — never card details.
- Cookies: a session cookie to keep you signed in. No advertising or tracking cookies.
What we share, and with whom
- OpenAI (AI features only): gameplay context — levels, quest states, kill counts, gear/bank item names, playstyle signals, and your chat messages. Never your email, name, or account identifiers. If the advisor searches the web, your question shapes the search.
- Stripe: payment processing, if you subscribe.
- Public data sources we read (hiscores, OSRS Wiki, GE prices) receive nothing about you.
- We do not sell or rent data. Ever.
Public vs. private
Anyone can look up a display name and see what the official hiscores already publish. Everything synced by the plugin — quests, diaries, gear, bank, records, chats — is visible only to the signed-in account that owns the character.
Retention & deletion
- Unlinking a character immediately deletes its synced data, bank included.
- Sync history is pruned automatically (we keep roughly the last 60 snapshots per character).
- Delete account (on your dashboard) permanently removes everything: identity, characters, synced data, chats, memory, keys, usage records.
Security
Bank data and API keys are encrypted at rest; plugin tokens are stored only as hashes; private queries are always scoped to your session. Full details live in our public repository's security documentation.
Age & changes
The service is for users 13 and older. If this policy changes materially, the effective date above changes and significant changes will be noted on the site.
Contact
Questions or data requests: open an issue on our GitHub repository (github.com/aTrapDeer/osrs-player-audit).