← Back to GuildLog

Privacy Policy

What GuildLog stores about you, why, and what you can do about it.

Last updated 17 August 2026

The short version. GuildLog stores your Discord identity, the characters and guild records you enter, and nothing else. There is no advertising, no tracking pixels, and no analytics cookies. Your ballots in Loot Vote are stored so that not even we can tie them back to you.

Who is responsible

GuildLog (guildlog.app) is operated by Aktero AS, a company registered in Norway, which is the data controller for the personal data described here. For any question about this policy or to exercise the rights below, contact [email protected] or reach us on our Discord server.

What we collect

Your Discord account

You sign in with Discord. We request the identify, guilds and guilds.members.read scopes, and store your Discord user ID, username, display name and avatar hash. We also store the access and refresh tokens Discord issues, because they are how we confirm you are still a member of your guild's Discord server and keep your rank in sync. We never see or store your Discord password.

What you enter

Characters (name, race, class, specialisation, professions), raid attendance, loot history, wishlists, profession recipes, guild bank transactions and loot vote ballots. Officers in your guild can also enter some of this on your behalf.

Cookies

One cookie, gh_session, which identifies your signed-in session and expires after 7 days. It is strictly necessary for the site to work. We set no advertising, analytics or third-party tracking cookies.

How Loot Vote stays anonymous

This is worth stating plainly because it is a deliberate design choice. When you submit a ballot, we record two things in separate tables: that someone with a given hash has voted, and the votes themselves. The hash is SHA-256 of your Discord ID combined with a random salt unique to that voting session, so it cannot be reversed or matched across sessions. The vote rows carry no voter reference and no timestamp. A timestamp would let anyone with database access line votes up against the order people voted in. Officers see totals. Nobody, including us, can see how you voted.

Who can see your data

  • Your guild. Characters, raid attendance, loot history and rankings are always visible to members of guilds you belong to. This cannot be switched off, because guild records exist so that guildmates can see them.
  • Everyone, if you choose. Public character profiles and appearing in the site-wide search are both opt-in, and you can change them at any time in your settings.
  • Officers. Guild Masters and officers can manage members and characters in their own guild, including creating a character on your behalf.

Services we rely on

We use a small number of processors to run the service. We do not sell data to anyone, and there are no advertising partners.

  • Supabase hosts the database where everything above is stored.
  • Cloudflare hosts and serves the application.
  • Discord handles sign-in, rank synchronisation and bot notifications.
  • Blizzard receives a character name and realm when we fetch character portraits.
  • Warcraft Logs provides raid log imports, using credentials your guild supplies. Guild API secrets are encrypted before being stored.

How long we keep it

  • Sessions expire after 7 days.
  • Account and character data is kept until you ask us to delete it.
  • Guild records such as raid logs and loot history belong to the guild and remain after an individual leaves, in the same way a guild's own logs would.

Your rights

If you are in the EU or EEA, the GDPR gives you the right to access your data, correct it, have it deleted, receive a copy in a portable format, object to processing, and withdraw consent you have given. You can change your visibility choices yourself at any time in settings, and remove characters from your profile.

For access, export or deletion of your whole account, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority. In Norway, that is Datatilsynet.

Children

GuildLog is not directed at children under 13, and Discord's own terms require users to meet a minimum age in their country. We do not knowingly collect data from children below that age.

Changes

GuildLog is under active development, so this policy will change as the service does. The date at the top reflects the last revision. Material changes will be announced on our Discord server.