1Who is responsible
WoRTool is a free, fan-made planning and community tool for the game War of Rights, operated by one individual in the United States. For the purposes of the GDPR and UK GDPR, that person is the data controller for the personal data described here.
You can reach us about anything in this policy at legal@wortool.com. The operator's name and postal address are not published here, because this is one person's home rather than an office. We will give them to you on request, and to any supervisory authority that asks.
The short version We collect what an account needs to exist and be secure, plus whatever you choose to post. We do not track you across the web, we do not run analytics or advertising, and we do not sell or rent your data to anyone.
2What we collect
Account information
- Your username and email address, and a hash of your password. New passwords are hashed with Argon2id. Accounts carried over from the previous version of this site keep the hash they arrived with until the next time they sign in, at which point it is replaced with an Argon2id one. Either way a password is never stored, logged, or transmitted in readable form, so we cannot see it.
- An avatar image, if you upload one, and a pending email address while a change of address is waiting to be verified.
- Timestamps for account creation, last update, last sign-in, and email verification.
- Whether the account holds site staff or owner rights, whether it is suspended, and whether it has been marked as a memorial.
Linked Discord and Steam accounts
- Discord: your Discord user id, username, avatar URL, and the email address on the Discord account when Discord shares it.
- Steam: your SteamID64, persona name, and avatar URL.
From Discord we ask only to identify you and to read the address on the account. Steam has no scopes: signing in with it proves you hold the account and tells us nothing else. We never receive your Discord or Steam password. Persona names and avatars are display data refreshed on sign-in; they are never treated as authoritative account fields.
If you turn on the Steam widgets, we also ask Steam for your War of Rights achievements, your recorded statistics in that game, and how long you have played it, and we keep a copy so the panel does not have to ask again on every view. Those widgets work only while your Steam profile is public to begin with, and turning them off stops us asking.
Profile information
Anything you choose to add: a biography, a banner image, a timezone, and the visibility switches that decide who can see your profile and whether your linked accounts, communities, and favorites appear on it.
Security and sign-in records
- Sessions: a hash of the session token, the IP address and browser user agent the session was created from, when it was last active, and when it expires. This is what powers the device list in your security settings and lets you sign other devices out. A session the desktop app holds records the app's version and your operating system version in place of a browser.
- Sign-in history: each sign-in attempt, whether it succeeded, the method used, the reason for any failure, and the IP address and user agent. This is how account takeovers get noticed.
- Passkeys: the credential id, public key, signature counter, authenticator model identifier, how the key connects, when it was last used, and any nickname you give it. A passkey's private key never leaves your device.
- Two-factor authentication: your authenticator secret, encrypted at rest, and hashes of your recovery codes. Marking a browser as trusted stores a record of it for 30 days, holding a hash of the token in the cookie, the IP address and user agent it was created from, and when it was last used.
Content you create
Posts, comments, images and video you upload, WoRSketch boards and the drawings on them, community profiles, banners, galleries, events and their attendance, rosters and ranks, catalog contributions and inaccuracy reports, follows, blocks, and favorites. Some of this is public by design; see what other people can see.
Using the site also writes smaller records that are easy to overlook: the reactions you leave, the notifications waiting for you and the text that prompted them, the communities you follow or mute, an application to join a unit including whatever you wrote in it, invitations you create, your answers to operations and events and any assignment or note an officer records against your name, your marker presets and map notes, and your own notification and feed settings.
Two kinds of log sit behind that. A community keeps an audit trail of what its staff did, which names the account and the Discord id that acted, and is readable by anyone that community has given the permission to. We keep a separate one for actions taken by site staff.
Discord server data
Where a community attaches a Discord server, we store the server's id, name, and icon, its channels and their names, its roles with their names, colors, and order, its member count, and for the people on that community's roster their Discord id, username, nickname in that server, avatar, and which roles they hold. This is what lets roles, events, and announcements stay in step between Discord and the site. We also record which account attached the server, and when.
We read that in two ways. The bot reports what it sees as it happens, and the site asks Discord directly when a server is attached or when staff ask for it to be read again. The site's own requests go further than the bot's: they can search the member list, read it in full, look up a Discord account by its id, and create an invite to a channel.
When an officer runs a muster from Discord, the bot reads who is sitting in the voice channel it was told to check, and records those people as having turned out. It reads who is present, not anything said there. We do not read message content in any case.
There are three ways onto a community's roster, and none of them needs an account here. A community may map its ranks to Discord roles, and holding one of those roles places you on the roster at that rank. Staff may import a role's holders as a one-off. And answering a turnout call, or being named in a muster, records you as having served with that unit. Each community chooses how far the role mapping reaches, from treating its roles as the record to switching the behavior off, though names and avatars are refreshed either way.
A roster entry is public Community profiles are open to anyone, including the roster, the staff list, and turnout. If a unit has put you on its roster, your Discord display name, avatar, and rank can be read by anybody, with no account and no membership. Your Discord id is not published as a field, but the avatar address beside it is Discord's own and contains that id, so treat it as public too. Ask the community's staff to remove your entry, or leave the Discord server, and if neither works write to legal@wortool.com and we will remove it for you.
Game server credentials
A community can register its dedicated War of Rights server so its staff can edit the configuration and admin list, read the server log, and go through crash dumps from here. Doing so stores the host, port, username, and password of the FTP account the server's host issued, usually gPortal.
That password is encrypted at rest with AES-256-GCM under a key held only in the server's environment, never in the database beside it. It is not hashed, because unlike a password we only ever check, this one has to be replayed to the hosting provider to reach the server at all. It is never returned by our API, never shown back to the community once saved, and never written to a log. Staff replace it rather than read it.
Inside the community, the credential can be used by its owners, by its moderators, and by any rank it has granted the game server permission. From outside it, only the site owner can, so that a server can be looked at when a community asks us why something is failing. Site administrators cannot: moderating a community and holding the login to its server are separate kinds of trust, and only the second one reaches a machine the community pays for.
Registering, editing, or removing a server, publishing a configuration, and deleting a crash dump are all recorded in that community's audit log; reading a file or a log is not. Removing the server erases the stored password, keeping only what the audit trail needs to say what was removed.
It is a credential to somebody else's service. Use an FTP account scoped to that game server rather than your hosting account's main login, and rotate it as you would any other.
Email delivery records
For each message we send you, we log the recipient address, which template was used, whether it was delivered, the provider's message id, and any error the provider returned. We never log the body of an email, nor any verification or reset link or token it contains.
Support requests
Writing to us through the contact form opens a ticket. It holds your name and email address, the category you chose, your subject and message, any files you attach, the page you were on when you wrote, your browser's user agent, and your IP address. If you were signed in, it also records which account you wrote from.
Replying to a ticket by email adds your reply to it, which means the text of that email and anything attached to it is stored here too. The same is true of mail you send to our support and legal addresses directly. Site administrators can read the whole ticket, including the notes staff add to it, which you do not see. If you wrote without an account, the link we email you is what lets you follow the ticket, and anyone holding that link can read it.
Tickets are kept while they are open and afterwards as a record of what was asked and answered, because a question about an account, a report of abuse, or a legal request is often only understandable next to the one before it. There is no automatic deletion for them. Ask us and we will remove yours, unless it is the record of a ban or a complaint we still need.
Technical logs
Our server and its reverse proxy keep short-lived operational logs containing IP addresses, requested paths, response codes, and user agents. They exist for debugging, abuse prevention, and rate limiting, and are not used to build a profile of you.
Rate limiting keeps its own short-lived counters in memory, keyed by IP address, by network block, and for a few actions such as signing in or asking for a password reset, by the address or username that was submitted. Each counter is discarded when its window closes, which is never longer than a day.
What we do not collect No third-party analytics, no advertising or tracking pixels, no cross-site trackers, no payment or financial data, and no special category data such as health, biometrics, or political opinions. We do not buy data about you from anyone. The only third parties your browser contacts are the ones hosting a picture or a video on the page in front of you, and they are listed under who we share it with. The desktop app also checks GitHub for its own updates; see the desktop app.
3How we use it, and on what basis
We use the information above only for the purposes listed here. For readers in the EU, EEA, or UK, the lawful basis for each is named alongside it.
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, showing your profile, and delivering the features you use | Performance of a contract |
| Sending verification, password reset, and account recovery email | Performance of a contract |
| Keeping accounts secure: detecting takeovers, enforcing rate limits, investigating abuse | Legitimate interests, and legal obligation where it applies |
| Moderating content and enforcing the Terms of Service | Legitimate interests |
| Syncing roles, events, and rosters with a community's Discord server | Performance of a contract, and consent for the linked account |
| Linking a Discord or Steam account to yours | Consent, withdrawable at any time by unlinking |
| Holding a roster entry for somebody who has no account here, because a unit mapped its Discord roles | Legitimate interests: a unit's roster is its record of who serves in it, drawn from a server those people joined. Ask and we will remove yours |
| Answering a support request and keeping what was said | Performance of a contract where it concerns your account, and legitimate interests otherwise |
| Diagnosing faults and keeping the service running | Legitimate interests |
| Responding to lawful requests and defending legal claims | Legal obligation, and legitimate interests |
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising.
6What other people can see
Some of what you do here is deliberately visible. Knowing exactly what is visible, and to whom, is part of privacy.
- Public by default: your username, your avatar, any posts, comments, catalog contributions, or community content you publish to a public area, and your place on any community roster, which means your rank there and how often you turned out.
- Controlled by you: your profile page. Set it to public, to signed-in members only, or to private, and choose separately whether it shows your linked Discord and Steam accounts, the communities you belong to and the ones you have fought alongside, your favorites, your Steam statistics, achievements and friends, and your in-game record.
- Shown once you link them: your Discord and Steam accounts. These switches start on, and linking a provider turns its switch back on. While one is on and your profile is public, the profile shows that account's name and its id, and the same details are readable by other sites through our public interface: your username, your Steam ID, when you joined, and the units you belong to with your rank in each. Turn the switch off, or make your profile private, and that stops.
- Visible to a community you join: your membership, rank, roster entry, event attendance, and, where the roster is synced, your Discord identity. Community staff can see and edit these, and a community can grant its own members the right to read its audit trail, which names who did what.
- Visible to a board's participants: your display name and cursor on any WoRSketch board you join, including as a guest.
- Never shown to other members: your email address, your password hash, your sessions and IP addresses, your sign-in history, your passkeys, and your two-factor secrets and recovery codes. Site administrators are the exception: running the service means being able to see account records, including the address on an account, and staff answering a support ticket see what you sent with it.
Blocking another user hides each of you from the other in the feeds: their posts and activity stop reaching you, yours stop reaching them, and your profile closes to them. It is not a wall. It does not hide comments, rosters, turnout boards, events, or operations, it does not stop someone opening a link they already have, and it does not retract content that was already public. If somebody is a problem rather than an annoyance, report them instead.
7Game server credentials
The server editor connects to a game host you name, over the FTP login that host issued you. That login is a credential to a third-party system, so it is worth setting out exactly what happens to it.
A server registered by a community stores the address, the port, the username, and the password, because the whole point is that the tool can reconnect without anybody typing them again. The password is encrypted at rest with a key held outside the database. It is never shown back, never returned by the API, never written to a log, and never sent to your browser: the only thing that ever reads it is the service, at the moment it opens a connection. Somebody who can manage the server can replace the password; nobody can read the stored one.
Who can reach it is decided by the community. Its owners and moderators can by virtue of the job, and any rank granted the permission for managing servers can as well. A member without it cannot see the server, connect to it, or read anything on it. The one account outside the community that can is the site owner, kept for diagnosing a server a community has asked us about; site administrators are not given this, because moderating a community is not the same as holding the login to its machine.
What we record is the fact of each action, not the contents of the credential: who connected, who published a file, who deleted one, and when, in the community's audit log. A copy of each configuration or admin list this tool overwrites is kept, so a bad edit can be undone. Those copies are the game server's files, which is to say they can contain whatever your unit put in them, including a server password or an RCON password if you keep one in the configuration.
The public tool at /tools/server-editor keeps no record of your server. Nothing about it is written to our database: no server, no copies of files, no audit trail. The credentials you type are encrypted and held in short-lived server-side storage for the length of one session, which ends when you disconnect, and otherwise expires half an hour after you last used it, so closing the tab clears it too. Your browser remembers the address and username so the form is not retyped; it never remembers the password.
The desktop app can save a login on your computer. The password is encrypted there with your operating system's key store, while the address, port, and username are kept as they are. Saving it spares you typing it again and nothing more: connecting with it sends the password to us for the session in exactly the way typing it does. See the desktop app.
Connecting reaches out to a host you chose, which is neither ours nor operated by us. Our server makes that connection, encrypting it with TLS when the host offers it and in plain FTP when the host does not. What that host does with the connection, and what it logs about it, is between you and them.
8The desktop app
The WoRTool app for Windows, macOS, and Linux shows the same service as the website, so everything above applies to it. This section covers what is different: what it keeps on your computer, what it reads from your keyboard, and what it connects to on its own.
Signing in
The app never asks for your password. It opens wortool.com in your browser, where you sign in however you normally do. Your browser then hands the app a one-time code through a connection to the app on your own computer, on the address 127.0.0.1 and a port chosen at random. The code works once and for a minute, and only together with a secret the app generated and kept to itself, so a code seen by anything else is useless.
The app receives a session of its own, the same as a browser's: it lasts up to 90 days and ends after 30 days without use. We record it with the IP address it came from and the app's version and your operating system version, such as wortool-desktop/0.1.2 (Windows 10.0.26200), and it appears in your sessions on the website, where you can end it. The sign-in is written to your sign-in history like any other.
Signing out in the app forgets the session on your computer and asks us to end it. If the computer is offline at that moment, our side of the session stays valid until it expires or you end it from your sessions. Signing out of the app does not sign your browser out, nor the other way around.
What it keeps on your computer
None of this is sent to us except where this section says so. We cannot see it, and we cannot delete it for you.
| What | Holds | Protection |
|---|---|---|
| Your session (credentials.json) | The token that keeps the app signed in, and beside it your account id, username, and avatar address so the app can show who is signed in before it reaches us. | The token is encrypted with your operating system's own key store: DPAPI on Windows, the Keychain on macOS, the Secret Service or KWallet on Linux. Where no key store is available the token is held only in memory and you sign in each time the app starts. The id, username, and avatar address are not encrypted. |
| Server logins you chose to save (server-logins.json) | For each one, the host, port, username, file paths, when you last used it, and the password. Written only when you tick the box to save a password, up to 50 of them. | The password is encrypted with the same key store; the rest is not. The feature is not offered where no key store is available. On macOS and Linux the file can be read only by your own user account. |
| Remembered server connections | The host, port, username, and file paths of servers you connected to, so the form is not retyped. On unless you untick it, as on the website. Never the password. | Kept in the app's own storage on your computer, not encrypted. |
| The game catalog (catalog folder) | Maps, units, weapons, campaigns, and their facts: the same public data for everybody, refreshed when the app starts and every 30 minutes. | Not about you, so nothing to protect. |
| A picture cache (art folder) | Up to 256 megabytes of pictures the app has shown, which includes map and weapon art and also avatars and pictures other people uploaded. | The pictures as they were published. Oldest are removed first. |
| Settings and layout | Your settings, including the overlay's keys; where the window was left; the last plan shown over the game, and the overlay's opacity and ruler choice; panel sizes; the last eight things you opened; colors you mixed; and questions you asked not to be asked again. | Kept on your computer, not encrypted. |
| Update identifier (.updaterId) | A random identifier the updater creates the first time it runs. It is not linked to your account. See what the app connects to, below. | Not encrypted. |
| The browser engine's own files | Caches that the Chromium engine inside the app keeps for pages, code, and graphics. | Kept on your computer, as any browser keeps them. |
Anybody who can sign in to your account on the computer can use the saved session and the saved logins, because the key store opens them for whoever is signed in. On a computer you share, sign out and forget saved logins when you finish.
The keyboard
The plan overlay answers keys pressed while a game has the keyboard. On Windows the app does this by checking, about thirty times a second, whether particular keys are held down: Ctrl, Alt, Shift, and the Windows keys, and the keys you have assigned to the overlay, which it only looks at while one of those is held unless you gave one a key that stands alone. It checks for as long as the app is running, including from the tray, because the keys that show and focus the overlay work even when no overlay is open.
It is not a keylogger The app asks only about those keys, never reads what you type, installs no keyboard hook, keeps no record of any key, and sends nothing about the keyboard anywhere. A matching combination runs the overlay action and nothing else.
On macOS and Linux the same combinations are registered with the system as shortcuts instead, which means that while the app holds them, those combinations go to the app rather than to the program in front.
Focusing the overlay moves the focus away from the game. To do that, and to give the focus back afterwards, the app notes which window was in front by the handle the system gives it, never by its title or contents, and briefly joins that window's input so Windows lets the focus move. Resting the pointer on the overlay tells the app only that the pointer is over it.
What it connects to
- wortool.com, for everything the service does: pages and data, live boards, notifications, the catalog, and pictures. Your session token goes only with requests to our API, not with the catalog or pictures. Every request names the app, its version, and your operating system version as above.
- GitHub, where the app is published, to check for updates when it starts, every 30 minutes, and when the computer wakes or you bring the app back to the front, and to download them. GitHub receives your IP address and the update identifier described above, which lets GitHub tell one installation's checks from another's. Updates download and install automatically, when the app quits or when you choose to restart it, and cannot be turned off.
- Discord and Steam, only to fetch the avatars they host. Each request reveals your IP address and which avatar was asked for.
Nothing else. The app sends no telemetry, analytics, crash reports, or error logs, and writes no log files. Links out of the app open in your browser.
Notifications and running in the background
While you are signed in, the app keeps a connection open to wortool.com to hear about new activity, and checks for it every two and a half minutes as well. Turning notifications off in the app's settings stops the pop-ups, not the checks, so the unread count on the icon stays current. The pop-ups are shown by your operating system, which may keep them in its own notification history.
Closing the window leaves the app running in the tray unless you turn that off in its settings, and while it runs there it keeps its keys, its notification checks, its catalog refresh, and its update checks. Starting with your computer is off unless you turn it on.
Live boards
Opening a board in the app joins its room exactly as the website does, and shows the others what the website shows them: your name, avatar, cursor, which slide you are on, and what you draw, point at, or say in chat. The plan overlay is different. It signs in as you so it can read the board, but it only watches: the others are not shown it, and it sends nothing into the room.
The server editor in the app
The app's server editor works through wortool.com exactly as the website's does, including when you connect with a saved login: the password is sent to us for the length of the session, as described under game server credentials. Saving it only spares you typing it again; it does not keep it from us.
Removing it
- Signing out removes the session and the account details kept beside it. It leaves saved logins, remembered connections, the catalog, the picture cache, and your settings.
- Forget on a saved login removes that login.
- Reset to defaults in the app's settings restores the settings, the overlay's keys, the window, and the layout. It keeps the session, saved logins, remembered connections, the things you opened recently, your mixed colors, the catalog, and the picture cache.
- Uninstalling leaves the app's data folder in place. To remove everything, uninstall and then delete that folder:
%APPDATA%\WoRToolon Windows, along with%LOCALAPPDATA%\wortool-desktop-updaterwhere updates are downloaded;~/Library/Application Support/WoRToolon macOS; and~/.config/WoRToolon Linux.
None of that ends the session on our side if the app could not reach us when it signed out; end it from your sessions on the website. Anything the app showed you from your account, such as your posts, lives with us and is covered by the rest of this policy and the Terms of Service.
9How long we keep it
We keep personal data only as long as it serves the purpose it was collected for.
| Data | Kept for |
|---|---|
| Account and profile | As long as the account is open. An open account is never deleted for being dormant, however long it has been since you last signed in. |
| A new account that is never confirmed | Deleted 72 hours after it was created. The trigger is the address never being confirmed, by the emailed link or by connecting Discord or Steam, never inactivity. |
| Sessions | Until they expire or you revoke them. A daily sweep deletes them once they have, and a revoked one 30 days later |
| Sign-in history | 12 months, for security investigation, then deleted by that same daily sweep |
| Trusted devices | 30 days from when you marked the browser as trusted, and using it again does not extend that |
| Verification and password reset tokens | A password reset link lasts an hour and a verification link a day. Both are deleted once used or expired |
| Email delivery log | 12 months, for deliverability troubleshooting, then deleted |
| Support tickets | No fixed period. Kept as the record of what was asked and answered, and removed on request unless we still need it |
| Technical server logs | Rotated by size rather than by date, so each service keeps only its most recent 30 megabytes. In practice that is days rather than months, and it is never an archive |
| Rate limiting counters | The length of the window they enforce, never over a day |
| Content you posted | Until you delete it, or the community or board it belongs to is deleted |
| Accepted catalog contributions | Retained as part of the shared catalog after an account closes, with attribution removed on request |
| A community's stored FTP login for a game server | Until the server is removed from the community or the community is deleted, then deleted with it |
| Copies of game server files this tool overwrote | The most recent 20 per file, per server; older ones are discarded as new ones are taken |
| A public server editor session | Until you disconnect, and otherwise half an hour after you last used it |
| Backups | Taken nightly and deleted after 30 days, except the most recent, which is always kept so there is something to restore from |
| A copy of the data someone asked us to export | Deleted 30 days after it was made |
| What the desktop app keeps on your computer | Until you remove it there. We hold none of it; see the desktop app |
We may keep specific records longer where we need them to establish, exercise, or defend a legal claim, or to enforce a ban against someone who would otherwise evade it.
10How we protect it
- Passwords are hashed with Argon2id, and an account carried over from the old site keeps its original hash only until its next sign-in. Session tokens, reset tokens, and recovery codes are stored only as hashes, so a copy of the database does not yield a working credential.
- Two-factor secrets are encrypted at rest with a key held outside the database.
- Traffic to wortool.com is served over HTTPS. Session cookies are HttpOnly, Secure, and same-site restricted.
- Passkeys and two-factor authentication are available on every account, and we recommend turning one of them on.
- The desktop app keeps its session and any password you save encrypted with your operating system's key store, never hands its session token to the pages it shows, and runs those pages sandboxed, cut off from your computer except through the few actions the app offers them.
- Access to production systems is limited to the operator, and secrets are supplied to services at runtime rather than built into any image or committed to source control.
No system is perfectly secure. If a breach affects your personal data and is likely to put you at risk, we will notify you and the relevant supervisory authority without undue delay and, where the GDPR applies, within 72 hours of becoming aware of it.
11Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you.
- Correct anything inaccurate or incomplete.
- Delete your account and personal data. Write to us and we will close the account, which signs out every session and releases the Discord and Steam links so they can be used again. Tell us you want it erased and we will go further and remove the record itself, along with what you posted, except where we have to keep something, which is set out under how long we keep it. There is no button for this yet; a person does it, which is also why we would rather you asked than wondered.
- Export a machine-readable copy of the data you gave us. We assemble this by hand, so allow us the 30 days rather than expecting it by return.
- Restrict or object to processing we carry out on the basis of legitimate interests.
- Withdraw consent at any time where consent is the basis, including by unlinking Discord or Steam in your settings. Withdrawing does not undo processing already carried out.
Much of this you can do yourself from your account settings: edit your profile and its visibility, change your email or password, review and revoke sessions, including the desktop app's, and unlink providers. What the desktop app keeps on your computer is yours to remove, as set out under the desktop app. For access, export, or deletion requests, write to legal@wortool.com from the address on your account. We will respond within 30 days and will never charge you for a first request.
If you are in the EU, EEA, or UK and you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first so we can put it right.
12International transfers
Our servers and our providers are located in the United States and in Europe, so using WoRTool involves transferring your data across borders. Where data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable to each provider. You can ask us for details of the safeguards in place for any specific transfer.
13Children
WoRTool is not intended for children. You must be at least 13 years old to hold an account, or 16 in the EU, EEA, or UK. We do not knowingly collect data from anyone below those ages. If you believe a child has created an account, write to legal@wortool.com and we will delete it.
14Changes to this policy
We will update this policy as the service changes. The effective date at the top of the page always reflects the current version. Where a change materially affects how we handle your data, we will give notice on the site, and by email where we hold a verified address for you, before it takes effect.
15Contact
For any privacy question, data request, or complaint, write to legal@wortool.com. Account email such as verification and password resets is sent from accounts@wortool.com; we will never ask you for your password in an email.
See also our Terms of Service. Questions about either document go to legal@wortool.com.