Privacy Policy
OSRS Journal ("we", "the service") is operated by Kyle Landon. This policy explains what data the RuneLite plugin and website collect, how it is used, and your choices.
What we collect
From the RuneLite plugin (only while you are logged into Old School RuneScape with sync enabled):
- Character name (RSN)
- Skill levels and XP
- Quest completion states
- Worn equipment (item names and IDs)
- Bank and inventory contents — only if you enable "Sync Bank & Inventory" in plugin settings
We do not read your Jagex password, email, or RuneLite credentials.
From the website when you create an account:
- Email address and authentication data (via Supabase Auth — Google, Discord, or email)
- Your linked character names and privacy preferences
How we use data
- Display your journal dashboard at journal.osrsjournal.com
- Link your in-game character to your website account (pairing code)
- Optionally show skills and quests on a public profile (on by default; you can turn this off)
Bank and worn gear are never shown on public profiles — only to you when signed in.
Where data is stored
Game sync data and accounts are stored in Supabase (hosted PostgreSQL). The website is served via Cloudflare. OAuth sign-in uses Google and/or Discord when you choose those providers.
Sharing
We do not sell your data. We do not share bank or equipment data with other users. Public profiles expose only skills and quest progress for characters you mark public.
Retention & deletion
Data is kept while your account is active. You can delete your account and all synced data from the website under Account → Delete account & data, or by contacting GitHub issues.
Children
The service is not directed at children under 13. We do not knowingly collect data from children.
Changes
We may update this policy. The "Last updated" date at the top will change when we do.
Contact
Questions: GitHub issues