Privacy policy
Everything below describes what the site actually stores. No analytics, no advertising, no tracking pixels.
Who is responsible
ExplorersIndex, an independent fan project, decides what is stored here and why: the “controller”, in the words of the GDPR. Reach us on our Discord.
If you never sign in
Reading the site stores nothing about you. The moment you plan an event, sign up for one, or appreciate a screenshot without an account, we set one cookie, az_guest, holding a random identifier for 30 days. It is what lets you come back and change your own sign-up. Clearing it means we can no longer tell that sign-up is yours.
There are no analytics, no advertising networks, no social embeds and no third-party scripts anywhere on the site. Game icons and images are served from our own domain rather than someone else's.
If you sign in with Discord
Discord asks you to approve two scopes, identify and guilds, and we store:
- Your Discord user id, username, display name and avatar reference.
- The servers you are in: their id, name, and whether you own them. This is how the planner can show “your servers” and offer to add the bot. It is refreshed when you sign in.
- Your session: a hash of the cookie value (never the value itself), when it was created, when it was last used, and the browser's user-agent string. A session lasts 30 days and extends while you use it.
- Discord access and refresh tokens, encrypted before they are written down, so the site can refresh your server list without asking you to sign in again.
We never receive your email address, your password or your direct messages. The bot uses no privileged intents: it cannot read your channels' messages, and it never sends direct messages.
Battle.net and Guild Finder
Battle.net can be your only sign-in method, or you can connect it to an account that also uses Discord. We request the wow.profile scope. We store the provider account ID, region, scope, token expiry and an encrypted access token. A keyed identifier keeps your site account recognizable on future sign-ins even after profile caches expire. It is removed when you disconnect or delete your account.
For guild verification we temporarily cache character and realm IDs and guild roster ranks. These are not a public character directory. Guild identity and the date of a successful leadership check accompany published guild pages. Guild introductions, schedules and recruitment choices are written by the owner.
Applications contain the character name, role and message you choose to submit. Only you and the currently verified guild owner can read them through the site. Withdrawal erases the character name, introduction and conversation immediately. Messages and introductions are erased 90 days after closure, retaining minimal application-status history until account deletion. Open conversations remain until closed or your account is deleted. On-site notifications expire after 90 days. Optional Discord alerts contain only a generic private inbox link, never message text. Discord may retain delivered alerts under its own policy.
Battle.net profile caches, connection records and imported guild identity are removed after 30 days without refresh. Guild claim checks are kept for 30 days. Disconnecting removes your connection and private snapshots immediately and pauses your guild management. Token revocation is queued; an encrypted revocation token may remain until delivery or the queue’s 30-day retention limit. Your site account and editorial guild text are separate from this API cache.
What the planner stores
- Characters you add: name, second name, class, spec, role, faction, region, realm type, and which is your main.
- Your sign-ups: the raid, your character, your role and spec, whether you are coming, your note, your place on the roster or bench, and attendance a manager recorded afterwards.
- Raids you organise: title, instance, time, size, role targets, description, ruleset, picture, visibility, and the Discord channel and roles it uses.
- The raid leader named for a raid: their Discord id when a manager picked them from the server, or simply the name that was typed.
- A history of changes to each raid (who changed what, and when), which that raid's managers can read.
- Your private calendar token, the secret in the address of your personal calendar feed.
A raid manager can add someone to a roster by hand, which stores that person's Discord id or the name typed for them. When that person first signs in, the row becomes theirs.
Community gallery: a submitted screenshot is stored privately until it is reviewed, its embedded metadata (including any camera or location data) is stripped, and only the player name and title you chose become public if it is approved.
Talent builds
Talent builds: when you choose Save build, we store the build name, optional notes, talent choices, target level, client snapshot identity and edit timestamps under your account. These stay private and are kept until you delete the build or your account. They are included in your account export. Sharing or exporting a build copies only its talent choices and snapshot identity, not your account, name or notes. Anyone with that shared copy can import it; copies cannot be recalled.
What we do not store
The application keeps no IP addresses and no advertising identifiers. Rate limiting counts requests against your account or session id, not your address. The web server in front of the application keeps ordinary short-lived request logs, as every web server does; those are not used to build a profile of you.
Why we are allowed to keep it
- To do what you asked (performance of a contract): your account, your characters, your sign-ups, the raids you plan and the Discord posts that go with them.
- Legitimate interests: keeping the service secure and working. Session hashes, rate limiting, error alerts, backups, and the raid history that lets a guild see who changed a roster.
- Your choice: submitting a screenshot to the public gallery, and subscribing to a calendar feed. Neither is needed to use the planner.
Recruitment profiles and guild membership
Looking-for-guild profiles are off by default. If enabled, your self-reported character name, class, role, play styles, timezone and availability are visible only to currently verified guild owners. Profiles stop appearing after 30 days without an update. You can hide your profile at any time. Account deletion removes it.
Guild pages may display dated in-game character membership from Blizzard. This does not disclose linked site accounts or Discord identities. Provider roster data expires after 30 days. Leadership changes are recorded so access follows the newly verified owner.
Who else sees it
- Discord, when the site posts your raid, its roster and its reminders to the channel your server chose, and when it signs you in. Their privacy policy applies to everything on their side.
- The people in your raid: a roster is visible to whoever can see the raid, which the raid itself decides: public, unlisted link, or server members only.
- Blizzard, when you choose Battle.net sign-in or guild verification. Their privacy policy applies on their services. Your application message is not sent to Blizzard.
- The verified guild owner, when you submit a private application to their guild.
- We do not sell data, share it for advertising, or use an analytics provider.
The site itself runs on a server we rent and administer; the database, the uploaded pictures and the nightly backups all live there. Public game data is fetched from Blizzard and wago.tools. Account-specific Blizzard requests happen only for the Battle.net connection and verification features described above.
How long we keep it
- Your site account: until you delete it. Battle.net caches and guild applications use the shorter retention periods above.
- Sessions: 30 days after last use, then removed automatically. Expired sign-in states go within the hour.
- Discord tokens: removed 60 days after they expire, and revoked at Discord the moment you delete your account.
- Guest sessions: 7 days after expiry, unless they still hold an event, a sign-up or a gallery submission.
- Rate-limit counters: one hour. Operational records: job runs 14 days, delivered Discord messages 7 days, undeliverable ones 30 days, resolved alerts 90 days.
- Backups: nightly, kept 14 days, then overwritten.
Your rights
- See it: your account page has a one-click export of everything we hold about you, as JSON.
- Correct it: your characters, sign-ups and raids are editable there and then.
- Delete it: deleting your account removes your account, characters, sign-ups, sessions and Discord tokens, and revokes our access at Discord. Raids you organised stay for the people who signed up for them, without your name on them, and the history log keeps the action while losing the link to you.
- You may also object to processing, ask us to restrict it, and complain to your country's data protection authority.
Children
ExplorersIndex is not meant for anyone below Discord's minimum age where they live. If you believe a child has an account here, tell us and we will remove it.
Changes
When this policy changes, the date at the top changes with it and the change is written in the project's changelog. Changes that matter are announced on the site.
