1Who is responsible
WoRTool is a free, fan-made planning and community tool for the game War of Rights, operated by an individual. For the purposes of the GDPR and UK GDPR, we are the data controller for the personal data described here.
You can reach us about anything in this policy at legal@wortool.com.
The short version. We collect what an account needs to exist and be secure, plus whatever you choose to post. We do not track you across the web, we do not run analytics or advertising, and we do not sell or rent your data to anyone.
2What we collect
Account information
- Your username and email address, and a hash of your password. Passwords are hashed with Argon2id and are never stored, logged, or transmitted in readable form, so we cannot see them.
- An avatar image, if you upload one, and a pending email address while a change of address is waiting to be verified.
- Timestamps for account creation, last update, last sign-in, and email verification.
Linked Discord and Steam accounts
- Discord: your Discord user id, username, avatar URL, and the email address on the Discord account when Discord shares it.
- Steam: your SteamID64, persona name, and avatar URL.
We request the narrowest scopes each provider offers for sign-in and, for the bot, for the server management a community has asked it to do. We never receive your Discord or Steam password. Persona names and avatars are display data refreshed on sign-in; they are never treated as authoritative account fields.
Profile information
Anything you choose to add: a biography, a banner image, a timezone, and the visibility switches that decide who can see your profile and whether your linked accounts, communities, and favorites appear on it.
Security and sign-in records
- Sessions: a hash of the session token, the IP address and browser user agent the session was created from, when it was last active, and when it expires. This is what powers the device list in your security settings and lets you sign other devices out.
- Sign-in history: each sign-in attempt, whether it succeeded, the method used, the reason for any failure, and the IP address and user agent. This is how account takeovers get noticed.
- Passkeys: the credential id, public key, signature counter, authenticator model identifier, and any nickname you give the key. A passkey's private key never leaves your device.
- Two-factor authentication: your authenticator secret, encrypted at rest, hashes of your recovery codes, and any devices you have marked as trusted.
Content you create
Posts, comments, images and video you upload, WoRSketch boards and the drawings on them, community profiles, banners, galleries, events and their attendance, rosters and ranks, catalog contributions and inaccuracy reports, follows, blocks, and favorites. Some of this is public by design; see what other people can see.
Discord server data
Where a community invites the WoRTool bot, we store the Discord server id, its channels and roles, its member count, and the Discord identifiers and avatars of roster members, so that roles, events, and announcements stay in step between Discord and the site.
Email delivery records
For each message we send you, we log the recipient address, which template was used, whether it was delivered, and the provider's message id. We never log the body of an email, nor any verification or reset link or token it contains.
Technical logs
Our server and its reverse proxy keep short-lived operational logs containing IP addresses, requested paths, response codes, and user agents. They exist for debugging, abuse prevention, and rate limiting, and are not used to build a profile of you.
What we do not collect. No third-party analytics, no advertising or tracking pixels, no cross-site trackers, no social media widgets that phone home, no payment or financial data, and no special category data such as health, biometrics, or political opinions. We do not buy data about you from anyone.
3How we use it, and on what basis
We use the information above only for the purposes listed here. For readers in the EU, EEA, or UK, the lawful basis for each is named alongside it.
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, showing your profile, and delivering the features you use | Performance of a contract |
| Sending verification, password reset, and account recovery email | Performance of a contract |
| Keeping accounts secure: detecting takeovers, enforcing rate limits, investigating abuse | Legitimate interests, and legal obligation where it applies |
| Moderating content and enforcing the Terms of Service | Legitimate interests |
| Syncing roles, events, and rosters with a community's Discord server | Performance of a contract, and consent for the linked account |
| Linking a Discord or Steam account to yours | Consent, withdrawable at any time by unlinking |
| Diagnosing faults and keeping the service running | Legitimate interests |
| Responding to lawful requests and defending legal claims | Legal obligation, and legitimate interests |
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising.
6What other people can see
Some of what you do here is deliberately visible. Knowing exactly what is visible, and to whom, is part of privacy.
- Public by default: your username, your avatar, and any posts, comments, catalog contributions, or community content you publish to a public area.
- Controlled by you: your profile page. Set it to public, to signed-in members only, or to private, and choose separately whether your linked Discord and Steam accounts, your communities, and your favorites appear on it. Linked accounts are hidden until you turn them on.
- Visible to a community you join: your membership, rank, roster entry, event attendance, and, where the roster is synced, your Discord identity. Community staff can see and edit these.
- Visible to a board's participants: your display name and cursor on any WoRSketch board you join, including as a guest.
- Never shown to other users: your email address, your password hash, your sessions and IP addresses, your sign-in history, your passkeys, and your two-factor secrets and recovery codes.
Blocking another user hides your content from them and theirs from you within the service. It does not retract content that was already public.
7How long we keep it
We keep personal data only as long as it serves the purpose it was collected for.
| Data | Kept for |
|---|---|
| Account and profile | As long as the account is open |
| Sessions | Until they expire or you revoke them, then cleared |
| Sign-in history | Up to 12 months, for security investigation |
| Verification, password reset, and recovery tokens | Until used or expired, typically within hours |
| Email delivery log | Up to 12 months, for deliverability troubleshooting |
| Technical server logs | Up to 30 days |
| Content you posted | Until you delete it, or the community or board it belongs to is deleted |
| Accepted catalog contributions | Retained as part of the shared catalog after an account closes, with attribution removed on request |
| Backups | Rolling, and overwritten within 30 days |
We may keep specific records longer where we need them to establish, exercise, or defend a legal claim, or to enforce a ban against someone who would otherwise evade it.
8How we protect it
- Passwords are hashed with Argon2id. Session tokens, reset tokens, and recovery codes are stored only as hashes, so a copy of the database does not yield a working credential.
- Two-factor secrets are encrypted at rest with a key held outside the database.
- Traffic to wortool.com is served over HTTPS. Session cookies are HttpOnly, Secure, and same-site restricted.
- Passkeys and two-factor authentication are available on every account, and we recommend turning one of them on.
- Access to production systems is limited to the operator, and secrets are supplied to services at runtime rather than built into any image or committed to source control.
No system is perfectly secure. If a breach affects your personal data and is likely to put you at risk, we will notify you and the relevant supervisory authority without undue delay and, where the GDPR applies, within 72 hours of becoming aware of it.
9Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you.
- Correct anything inaccurate or incomplete.
- Delete your account and personal data. Some records may be retained where the law allows or requires it, as set out under how long we keep it.
- Export a machine-readable copy of the data you gave us.
- Restrict or object to processing we carry out on the basis of legitimate interests.
- Withdraw consent at any time where consent is the basis, including by unlinking Discord or Steam in your settings. Withdrawing does not undo processing already carried out.
Much of this you can do yourself from your account settings: edit your profile and its visibility, change your email or password, review and revoke sessions, and unlink providers. For access, export, or deletion requests, write to legal@wortool.com from the address on your account. We will respond within 30 days and will never charge you for a first request.
If you are in the EU, EEA, or UK and you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first so we can put it right.
10International transfers
Our servers and our providers are located in the United States and in Europe, so using WoRTool involves transferring your data across borders. Where data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable to each provider. You can ask us for details of the safeguards in place for any specific transfer.
11Children
WoRTool is not intended for children. You must be at least 13 years old to hold an account, or 16 in the EU, EEA, or UK. We do not knowingly collect data from anyone below those ages. If you believe a child has created an account, write to legal@wortool.com and we will delete it.
12Changes to this policy
We will update this policy as the service changes. The effective date at the top of the page always reflects the current version. Where a change materially affects how we handle your data, we will give notice on the site, and by email where we hold a verified address for you, before it takes effect.
13Contact
For any privacy question, data request, or complaint, write to legal@wortool.com. Account email such as verification and password resets is sent from accounts@wortool.com; we will never ask you for your password in an email.
See also our Terms of Service. Questions about either document go to legal@wortool.com.