Gielinor Gains Privacy Policy
1. Introduction
This Privacy Policy explains how Gielinor Gains collects, uses, stores, and shares information when you use the site. By using Gielinor Gains, you agree to this policy. If you do not agree, do not use the service.
2. Information We Collect
- RuneLite connection: your browser reads the local files or folder you choose. Raw RuneLite files, game account names, and historical trade records are processed on your device, not uploaded through the trading-session sync. If you allow analytics, connection diagnostics linked to your signed-in account help us investigate setup problems. They include failure codes, profile counts and selection number, connection status, and approximate ages of saves and updates. They exclude character names, filenames, paths, raw errors, log contents and trade details. You can also choose to copy this limited summary into a support reply.
- Saved trading state: your plan and a limited snapshot of current offers and holdings can be stored with your Gielinor Gains account for use on another device. The snapshot includes item IDs, quantities, prices, purchase costs, offer states, and observation times. It excludes RuneLite profile IDs, account names, raw files, and historical trades.
- Trading results: session results stay on your device unless you choose to save Progress. If you allow analytics, we measure completed trade counts, wins and losses, and broad profit ranges using a random session identifier. With analytics allowed, we also connect a displayed Trader suggestion to subsequently observed offers and a matched outcome. These events include the public item ID, suggested quantity and prices, public market-activity estimates, entry-margin and quote-age ranges, fill and timing ranges, repricing counts, and broad profit or loss ranges. We also record the guidance shown, including loss reviews and unavailable prices, and whether a later observed sell offer matches the suggested price. We do not send separate fields for actual purchase costs or actual sale prices. Game profile IDs, account names, raw files and complete trade histories are excluded. Ambiguous records stay out of completed outcomes. Exact saved Progress records are not sent to PostHog.
- Saved Progress: if you choose to save Progress, available records from your selected game profile are stored privately with your Gielinor Gains account. These include whether a trade was a buy or sale, item IDs, quantities, prices, timestamps, session times, and your progress goal. A coded profile identifier keeps different game profiles separate without uploading their names. This is separate from the current-offer snapshot. If you also allow analytics, we save the Trader instruction shown before a buy, its selection source and version, and a link to the observed offer and completed trade. We use these links with saved records to calculate aggregate Trader outcomes, including losses. Unrelated GE history is excluded from Trader performance metrics. Saving Progress does not publish your results or upload raw RuneLite files or game account names.
- Shared sessions: publishing a session link is a separate, optional action. Anyone with the link can view its recorded result, completed trade counts, elapsed time, excluded-record counts, and any caption you choose to add. We do not add your email address, RuneScape name, individual items, or offer prices to the page. You can revoke the link; copies other people have already made cannot be recalled.
- Account data: your email address for sign-in, session handling, entitlement lookups, and user preferences.
- Optional password sign-in: if you add a password, we store a salted, one-way password hash, not the password itself. We use short-lived verification links, sign-in rate limits, and session security records to protect account access.
- Optional Google sign-in: if you choose to sign in with or connect Google, we receive your name, email address, email verification status, and Google account identifier. We store the identity needed to sign you in and connect it to your Gielinor Gains account. We do not request access to your Gmail, Drive, or Calendar, and we do not store Google API access tokens or refresh tokens.
- Payment and subscription data: Stripe session identifiers, subscription status, billing state, and timestamps needed to provide Planner and Dump Alerts access.
- Notification preferences: whether Dump Alerts are enabled and any quiet-hours settings you configure.
- Contact form submissions: your name, email, message type, message content, and basic anti-abuse metadata.
- Security and anti-abuse data: IP address data, hashed email identifiers for sign-in throttling, and rate-limit records for protected actions.
- Analytics and diagnostics data: usage, performance, and error events collected through PostHog only after you explicitly allow analytics. When you are signed in and allow analytics, we share your sign-in email with PostHog to associate these events with your account for product diagnostics.
3. How We Use Information
- Provide sign-in, Planner access, Dump Alerts, and account settings.
- Process payments, trials, subscription changes, and billing portal actions.
- Send authentication emails, billing-related messages, support replies, and user-enabled Dump Alerts.
- Prevent fraud, spam, abuse, and unauthorized access.
- Measure performance and improve the product when analytics consent exists.
4. Cookies and Local Storage
- Essential cookies: NextAuth session cookies required for sign-in and secure account access.
- Local storage for product UI: preferences and interface state that support core site behavior.
- Analytics storage: PostHog identifiers and related storage only after you explicitly choose Allow Analytics.
You can reopen cookie preferences from the legal menu. Declining analytics does not affect core product functionality.
5. Email and Notifications
We use Resend to deliver email-based sign-in links, contact-form messages, and Dump Alert emails. Dump Alerts are product communications you enable from your account settings and may be delivered using Resend audience or broadcast tooling so alerts can be sent at scale.
You can turn Dump Alert emails off in your preferences at any time. Qualifying alerts detected during your quiet-hours window are skipped rather than delayed, because a later email may describe a stale market opportunity. We do not use your email address for unrelated marketing campaigns under the current product model.
6. Storage, Sharing, and Vendors
We use third-party providers to operate the service:
- Upstash Redis for sessions, preferences, entitlements, and application data.
- Stripe for payment processing, checkout, subscriptions, taxes, and billing portal actions.
- Resend for transactional and product email delivery.
- PostHog for analytics and client-side diagnostics when consent exists.
- NextAuth.js for authentication flows.
- Google for optional Google sign-in and account verification.
We do not sell personal information. We may disclose information when required by law, to protect the service, or as needed for payment disputes, fraud prevention, or security incidents.
7. Data Retention
- Authentication sessions last up to 30 days unless you sign out sooner.
- The saved trading-session snapshot expires 30 days after its last server update. When analytics is allowed, a bounded recommendation-matching journal stays on your device. Entries older than seven days are removed the next time Trader processes observations. Declining analytics clears it when Trader is open. A separate matching journal for saved Progress also stays on the device for up to seven days, with the same consent requirement. New attribution collection stops when analytics is declined or Progress saving is paused. Existing saved attribution follows Progress retention and is removed when you delete Progress.
- Saved Progress remains with your account until you delete it. Pausing Progress stops new uploads and keeps your existing history. Deleting it removes saved history and makes its shared session links unavailable.
- Sign-in throttling records are short-lived and expire automatically.
- Payment and subscription records are retained as needed for entitlements, accounting, and dispute handling.
- Preferences remain until you request deletion or remove them.
- Analytics data retention follows our PostHog configuration and only applies when you opted in.
8. Security
We use reasonable technical and organizational safeguards, including validated inputs, signed Stripe webhooks, authentication controls, rate limiting, and vendor-managed infrastructure. No system is perfect, and no transmission or storage method can be guaranteed 100% secure.
9. Your Choices
- Manage product preferences while signed in.
- Turn Dump Alert emails on or off from the user preferences menu.
- Reopen cookie preferences from the legal menu to change analytics consent.
- Save, pause, or delete Progress separately from the current-offer snapshot. Publishing a session is optional, and each published link can be revoked.
- Request account or data deletion through the contact form below.
10. International Processing
Our vendors may process information in the United States or other jurisdictions where they operate. By using the service, you understand that information may be transferred to and processed in those locations.
11. Policy Changes and Contact
We may update this policy as the product, vendors, or legal requirements change. When we do, we will update the date on this page. For privacy requests or questions, use the contact form below.