Community data & privacy
Updated 2 October 2026.
Your browser profile
Community participation uses an anonymous profile and a necessary sign-in cookie, wf_session, which expires after 30 days. The server stores a hash of the session key and your recovery key, your chosen display name, a random profile identifier and creation dates. We do not ask for Discord access, an email address or a password.
What is public
Build titles, explanations, talent allocations, author names, short profile identifiers, dates and aggregate votes become public immediately when you choose to publish. Withdrawn and hidden builds are excluded from public listings. Reports and review notes are private to moderation or the author as appropriate.
If you also choose “Publish equipment with this build”, the selected character's active equipment, race, form and additional stat bonuses are published with those talents. Other milestones, notes, wishlists and quest progress are excluded. Edit your build and turn this option off to remove its public equipment. Withdrawing the build also hides its character page. Visitors may retain copies they previously saved.
Local planning
Character plans, equipment targets, quest history and crafting lists stay in local browser storage. They are not uploaded when you create a community profile. Talent allocations are uploaded only when you submit a community build. Character backup files and recovery keys are private: share them only when you intend to grant access to their contents.
Controls and retention
Issue reports contain the page path, category, message and submission date. They are visible only to the moderator, including content or rights enquiries. Page query strings are discarded. Reports do not require contact details. Resolved reports remain in the database for follow-up.
You can remove your vote, withdraw your build and sign out. Withdrawing hides a build from public listings; moderation and abuse records may remain on the server. Recovery invalidates earlier sessions and rotates your recovery key. Clearing browser storage does not delete server records. Keep your recovery key to retain control of your profile.
Service providers and abuse prevention
Cloudflare hosts the website, API and database. Request limits use a hashed network identifier and time windows; the community application does not store raw IP addresses in its database. Profiles are not proof of a unique person. Publication is immediate; visitors can report content for moderation. Duplicate votes from the same profile are prevented.
External media and links
YouTube supplies video thumbnails and receives your request when they load. Video links open YouTube. Other source links open the named third-party website. No advertising or analytics tracking scripts are enabled in this release.