Community data & privacy
Updated 2 October 2026.
Your browser profile
Community participation uses an anonymous profile and a necessary sign-in cookie, wf_session, which expires after 30 days. The server stores a hash of the session key and your recovery key, your chosen display name, a random profile identifier and creation dates. We do not ask for Discord access, an email address or a password.
What is public
Approved build titles, explanations, talent allocations, author names, short profile identifiers, dates and aggregate votes are public. Pending and rejected submissions are visible to their author and moderators. Reports and review notes are private to moderation or the author as appropriate.
Local planning
Character plans, equipment targets, quest history and crafting lists stay in local browser storage. They are not uploaded when you create a community profile. Talent allocations are uploaded only when you submit a community build. Character backup files and recovery keys are private: share them only when you intend to grant access to their contents.
Controls and retention
Issue reports contain the page path, category, message and submission date. They are visible only to the moderator, including content or rights enquiries. Page query strings are discarded. Reports do not require contact details. Resolved reports remain in the database for follow-up.
You can remove your vote, withdraw your build and sign out. Withdrawing hides a build from public listings; moderation and abuse records may remain on the server. Recovery invalidates earlier sessions and rotates your recovery key. Clearing browser storage does not delete server records. Keep your recovery key to retain control of your profile.
Service providers and abuse prevention
Cloudflare hosts the website, API and database. Request limits use a hashed network identifier and time windows; the community application does not store raw IP addresses in its database. Profiles are not proof of a unique person. New publications require review and duplicate votes from the same profile are prevented.
External media and links
YouTube supplies video thumbnails and receives your request when they load. Video links open YouTube. Other source links open the named third-party website. No advertising or analytics tracking scripts are enabled in this release.