Privacy
Short version: an account holds your Discord name and id, and you can delete it at any time.
Without an account
Every tool works without signing in. What you make stays in your browser: builds you save, your Legacy checklist, and combat logs you open, which are read on your device and never uploaded.
Signing in with Discord
Guild Golem asks Discord only who you are (the identify permission): your Discord user id, username and display name. It never sees your email or password, your servers or your messages. Discord's access token is used once, to read who you are, and is not kept.
Answering a raid night with the Guild Golem bot's buttons in a guild's Discord server works the same way: Discord tells Guild Golem your user id, username and display name, Guild Golem makes your account if you don't have one, and you join that guild as a member (unless one of its officers removed you; then only an invite link brings you back). The bot reads no messages.
Before a raid night, the bot reminds the people who haven't answered by mentioning them in the channel where the night was posted. It sends you a direct message only if you turn reminder DMs on in your settings.
What an account stores
- Your Discord user id, username and display name, refreshed each time you sign in.
- A random account id and the date you joined.
- For each browser you're signed in on: a one-way fingerprint of its session key, and when the session started, was last renewed and expires. No IP addresses and no device details.
- For each guild you're in: your role and when you joined, your name on its roster (your nickname on its Discord server when the bot first sees you there, which you or its officers can change), the teams you're on, if you're an officer what the guild leader allowed you to do, the characters you list there (name, class and usual role), your answers to its raid nights with their history, and the raid groups you're placed in. The guild's members see the roster and the answers; nobody else does.
- The characters you add to your account: name, class, level, realm, spec and role, the saved build and Legacy plan each uses, and its professions. You see them; members of a guild whose roster has one of them see that one, with its numbers from the logs shared with that guild.
- The Legacy checklist you tick while signed in: which ways of earning Legacy points you've done.
- Whether you want raid reminders by Discord DM (off unless you turn it on).
- Builds and plans you save to your account: the name you give each, the build itself, and the patch it was made on. Only you see the list; a build's link shows the build to anyone you send it to, as it does without an account.
Guilds
A guild stores its name, realm, faction and time zone, its teams, and the invite links its officers make. Leaving a guild takes you off its member list; your name stays on its roster history. When an officer removes someone, the guild notes who and when, so a click in its Discord doesn't add them back. For a month after a raid night, it keeps a record of the reminders sent for it (which channel or which person, and when), so none goes out twice. Deleting a guild removes all of it.
When an officer links a Discord server, the guild also stores the server's Discord id and name and who linked it. Linking adds Guild Golem's bot to that server with permission to post messages in the channels it's given. The bot reads no messages. Linking asks Discord who you are, as signing in does, to check it's your own account.
Recruitment
When officers list a guild in the guild finder, everyone sees its name, realm, faction, member count, recurring raid nights and what the officers write in the listing. Unlisting removes the listing.
Applying to a guild stores the character you name (name, class and role), your message, when you applied and what the guild answered. The guild's leader and the officers allowed to recruit see it with your Discord display name, and a post in the guild's Discord channel can show it there if they set one up. Accepted, you join the guild and the character joins its roster. An application is deleted 90 days after it is answered or withdrawn, or with your account.
Shared reports
Sharing a report sends what its page shows: the fights, the characters in them (names and classes as the log records them), their damage, healing, damage taken and deaths, what they cast, interrupted and dispelled, their buffs, debuffs and consumables, and the log's file name. The log itself never leaves your device. A report stores who shared it, its guild if any, and who may see it: the guild's members, anyone with its link, or only you. You or the guild's officers can delete it at any time; deleting your account deletes your personal reports, while reports you shared with a guild stay with the guild without your name.
Speed measurements
On one page load in four, after the page has finished loading, your browser reports how fast it was: when the main content appeared, how quickly the page answered your clicks, and how much it shifted while loading. The report holds the kind of page (never its address), those numbers, whether your screen is phone-sized, and the country Cloudflare sees the request coming from. No IP address, cookie or account goes with it, and reports are deleted after 30 days.
Cookies
codex-theme: "system", "light" or "dark", for a year, only if you pick a theme. It identifies no one.__Host-session: your signed-in session, while you're signed in. It lasts 30 days from your last visit, and scripts on the page can't read it.__Host-oauth: for ten minutes while you sign in, so Discord's answer can't be forged.codex-scope: which guild or character your personal pages show, for a year, only if you pick one.
How long, and deleting it
A session ends when you sign out, after 30 days without a visit, or when you sign out everywhere in Settings. Your account stays until you delete it there. Deleting is immediate and removes everything listed above; the database's own recovery history can hold it for up to 30 more days, and then it is gone.
No third parties
Every script, font and image comes from this site. Guild Golem loads nothing from other sites, so no one else sees which pages you read; there are no analytics and no advertising. Signing in takes you to Discord and back. Guild Golem runs on Cloudflare, whose network delivers the pages and holds the account database.