Privacy

This site keeps a short operational record of each request so usage, errors, and performance can be understood.

What is recorded

Request time, route and query, response status and size, duration, client IP address, immediate proxy peer, forwarded address/protocol/host values, browser user agent, referring page, and random request and session identifiers.

Anonymous session

A secure, first-party session cookie connects requests made during one browser session. It contains a random identifier, is not an account, and is not used for advertising.

Display preference

When Table or Wrapped rows is selected on a listing page, a secure first-party cookie remembers that one-word preference for up to one year. It contains no identity or gameplay information, and changing the display option updates it.

Journey workbench profile and shared URLs

The travel workbench can store an optional, versioned profile in this browser's local storage. It may contain up to three classes and a level, preferred travel methods, Druid or Wizard travel levels, Ritual access, Gate and bind settings, Origin availability and zone, and selected travel items. It does not contain a character name, account name, live location, or game-client data. The profile is saved only when you use the visible save control and can be cleared from the workbench.

Journey origins, objective identifiers, world scope, and travel settings appear in the page URL so a journey can survive refresh, browser history, and sharing. As described above, the server's operational request log includes route queries; do not put private character or account information into travel fields. Parameterized journeys are excluded from search indexing.

Storage

Logs are stored privately on the application server, automatically rotated and compressed, and used only to operate and improve this site. Arbitrary cookies, passwords, and account data are not written to request logs.

Invite-only accounts

Account records contain a username, email address, display name, roles, password hash, login timestamps, and opaque server-side sessions. Passwords are processed with Argon2id and are never stored or logged in their original form. Authentication cookies are secure, HTTP-only, and separate from the anonymous analytics session.

Retained request analytics can be reviewed only by an authenticated administrator with the dedicated system-administration permission. The private report includes aggregate activity, content and journey signals, performance, errors, bot classification, retained IP addresses, and user agents. It does not display account identities or anonymous session identifiers, is not exposed as JSON, and is not cacheable.

When local GeoIP databases are configured, the server may enrich a retained IP address with an approximate country, region, city, autonomous-system number, and network organization. Addresses are looked up only in files stored on this server and are not sent to an external lookup service. IP geography can be wrong or represent a VPN, proxy, mobile gateway, or network registration location; it is never treated as a household address. The current local evidence is provided by DB-IP under CC BY 4.0. Any access category inferred from an ASN organization is labeled as an inference; it is not a measurement of connection speed or last-mile technology.

Requests for high-confidence secret, credential, source-control, executable-script, traversal, or debug targets can cause an immediate temporary IP-address block. Repeated unknown routes or disallowed methods accumulate short-window strikes before blocking. Active blocks and recent strike totals are stored privately in the account database, shown only to system administrators, and removed under age and count limits. Blocked requests receive a retry time; ordinary missing EQL records are excluded from strike accumulation.

Private character synchronization

If you explicitly link the private companion, the site stores an account-owned device label, a hash of its credential, private character name and server, confirmed inventory snapshots, per-storage-scope freshness, normalized gameplay events, synchronization receipts, and private sale-shortlist notes. A shortlist is planning data and is never a public offer.

Inventory exports are confirmed snapshots. A snapshot replaces only the storage scopes it explicitly covers; unloaded or absent optional storage remains unknown or stale. Log events are shown separately as activity and never silently change confirmed inventory.

What the companion excludes

Raw game logs remain on the player's computer. The current companion discards tells, guild/group/say/auction chat, unknown lines, account details, unrelated player identities, and complete raw lines before they enter its retry database or a request. It sends normalized facts, source fingerprints, and parser/client versions only. It reads client-created files and does not inject input, read game memory, inspect game network traffic, or modify the game.

A future capture tool may let a player choose which channels to preserve on their own computer and for how long. Local capture choices will not broaden what this website accepts: raw chat bodies, private transcripts, unknown lines, and unrelated identities remain excluded from synchronization. Private raw-chat storage will not be offered until protected local storage and complete deletion are implemented.

Character retention, export, and deletion

Current inventory, recent events, devices, receipts, and summaries remain in the private account database. Older normalized events and changed snapshots move to private, indexed monthly archives and are retained until deletion. An account owner can download a JSON export, revoke a device, and delete a character's synchronized history. Deletion hides hot data immediately and queues a verified purge from every cataloged archive.

Administrators can suspend accounts, revoke devices, and inspect aggregate operational counts. Their role does not implicitly grant access to a user's private inventory or gameplay history.