Privacy
This site keeps a short operational record of each request so usage, errors, and performance can be understood.
What is recorded
Request time, route and query, response status and size, duration, client IP address, immediate proxy peer, forwarded address/protocol/host values, browser user agent, referring page, and random request and session identifiers.
Anonymous session
A secure, first-party session cookie connects requests made during one browser session. It contains a random identifier, is not an account, and is not used for advertising.
Canonical website origin
The application origin is https://eql.gamertan.com. The former eql.colespeelman.com hostname permanently redirects to the same path and query on that origin. Cookies and local storage are scoped by browsers to their original host and are not copied by the redirect; old-host state cannot be read by the canonical application and may be cleared through browser site-data controls.
Display preference
When Table or Wrapped rows is selected for mixed search results, a secure first-party cookie remembers that one-word preference for up to one year. It contains no identity or gameplay information, and changing the display option updates it. Typed collection pages use the table view consistently and do not change this preference.
Journey workbench profile and shared URLs
The travel workbench can store an optional, versioned profile in this browser's local storage. It may contain up to three classes and a level, preferred travel methods, Druid or Wizard travel levels, Ritual access, Gate and bind settings, Origin availability and zone, and selected travel items. It does not contain a character name, account name, live location, or game-client data. The profile is saved only when you use the visible save control and can be cleared from the workbench.
Journey origins, objective identifiers, world scope, and travel settings appear in the page URL so a journey can survive refresh, browser history, and sharing. As described above, the server's operational request log includes route queries; do not put private character or account information into travel fields. Parameterized journeys are excluded from search indexing.
Storage
Logs are stored privately on the application server, automatically rotated by size and compressed, and used only to operate, secure, investigate, and improve this site. During the current private security-evidence period, rotated request logs are retained indefinitely while private checksum-verified off-site archival and a reviewed retention schedule are prepared. Arbitrary cookies, passwords, and account data are not written to request logs.
Accounts and API keys
Account records contain a username, email address, display name, roles, password hash, login timestamps, and opaque server-side sessions. Passwords are processed with Argon2id and are never stored or logged in their original form. Authentication cookies are secure, HTTP-only, and separate from the anonymous analytics session.
Public registration, when enabled, stores a syntactically valid but initially unverified email address. Registration and API-key security events retain trusted IP address, bounded user agent, request ID, outcome, and UTC time for up to one year. They do not use browser hardware fingerprinting. Read-only API keys are displayed once, retained only as hashes, and may be revoked or expire. Per-key hourly usage includes endpoint, response class, bytes, aggregate latency, cache-validation outcomes, and throttling so maintainers can offer optimization guidance.
Community partner submissions
Partner and external-reference proposals are private until reviewed. They may contain project identity, exact approved hostnames, licensing/provenance notes, and contact/reference notes for reviewers. Public catalog records disclose only approved references belonging to approved partners; suspending a partner hides links without deleting review history.
Optional Discord identity foundation
The disabled Discord-bot foundation can store a stable Discord user ID, link status, verification time, and a recovery-enabled choice. Challenges are hashed, expire, and can be consumed once. It does not store Discord messages or channel history. No bot is currently deployed, Discord membership grants no role, and any future recovery completes privately and revokes sessions, API keys, sync devices, and outstanding recovery challenges.
Retained request analytics can be reviewed only by an authenticated administrator. Raw live security evidence additionally requires the dedicated sensitive-analytics permission on every page and data request. The private reports include aggregate activity, content and journey signals, performance, errors, bot classification, retained IP addresses, and user agents. Sensitive feeds are same-origin, non-cacheable, and never public.
When local GeoIP databases are configured, the server may enrich a retained IP address with an approximate country, region, city, autonomous-system number, and network organization. Addresses are looked up only in files stored on this server and are not sent to an external lookup service. IP geography can be wrong or represent a VPN, proxy, mobile gateway, or network registration location; it is never treated as a household address. The current local evidence is provided by DB-IP under CC BY 4.0. Any access category inferred from an ASN organization is labeled as an inference; it is not a measurement of connection speed or last-mile technology.
Requests for high-confidence secret, credential, source-control, executable-script, traversal, or debug targets cause an immediate permanent block of the exact IP address. Repeated unknown routes or disallowed methods accumulate short-window strikes before a temporary block. Permanent-ban evidence—including the address, normalized reason, request identifier when available, timestamps, counts, administrative notes, and every later outcome—is retained indefinitely for security, appeal, and accountability. A pardon restores access but does not erase that history. Only administrators with the dedicated abuse-management permission may review or change it. Temporary blocks receive a retry time; permanent blocks receive a forbidden response. Ordinary missing EQL records are excluded from strike accumulation, and address decisions never claim to identify a person or ban an entire subnet.
Private character synchronization
If you explicitly link the private companion, the site stores an account-owned device label, a hash of its credential, private character name and server, confirmed inventory snapshots, per-storage-scope freshness, normalized gameplay events, synchronization receipts, and private sale-shortlist notes. A shortlist is planning data and is never a public offer.
Inventory exports are confirmed snapshots. A snapshot replaces only the storage scopes it explicitly covers; unloaded or absent optional storage remains unknown or stale. Log events are shown separately as activity and never silently change confirmed inventory.
What the companion excludes
Raw game logs remain on the player's computer. The current companion discards tells, guild/group/say/auction chat, unknown lines, account details, unrelated player identities, and complete raw lines before they enter its retry database or a request. It sends normalized facts, source fingerprints, and parser/client versions only. It reads client-created files and does not inject input, read game memory, inspect game network traffic, or modify the game.
A future capture tool may let a player choose which channels to preserve on their own computer and for how long. Local capture choices will not broaden what this website accepts: raw chat bodies, private transcripts, unknown lines, and unrelated identities remain excluded from synchronization. Private raw-chat storage will not be offered until protected local storage and complete deletion are implemented.
Character retention, export, and deletion
Current inventory, recent events, devices, receipts, and summaries remain in the private account database. Older normalized events and changed snapshots move to private, indexed monthly archives and are retained until deletion. An account owner can download a JSON export, revoke a device, and delete a character's synchronized history. Deletion hides hot data immediately and queues a verified purge from every cataloged archive.
Administrators can suspend accounts, revoke devices, and inspect aggregate operational counts. Their role does not implicitly grant access to a user's private inventory or gameplay history.