Privacy Policy

How Ages of Norrath collects, uses and retains personal data.

Last updated: [DATE].

Ages of Norrath is run by volunteers. We collect as little as we can get away with, and we do not sell anything to anyone.

What we collect

Account data

  • Email address (sign-in, password resets, account recovery)
  • Display name
  • Password, stored as an Argon2id hash — never in plaintext, and never logged
  • Two-factor secret, encrypted at rest, if you enable 2FA

Game account data

  • Game account names you create and their password hashes
  • Login timestamps and the IP address used

Technical data

  • IP addresses in web server logs and in our audit log
  • Browser user agent

Content you submit

  • News comments, forum posts, and any evidence files you upload to the wiki

We do not use advertising trackers or third-party analytics.

Why we collect it

  • To operate your account and authenticate you in-game
  • To enforce the Terms of Service and investigate abuse
  • To keep an audit trail of administrative actions
  • To publish aggregate, non-identifying server population statistics

Donor names

Donations are handled by Open Collective, not by us directly.

Your name is only ever displayed publicly if you explicitly consent to it. The default is "Anonymous". If you consented and change your mind, contact us and we will remove your name — the donation amount remains in the public ledger without attribution, so the running balance stays accurate.

Retention

  • Account data: for as long as your account exists
  • Server population history: 90 days at full resolution
  • Audit logs: retained indefinitely, as they are a security record
  • Wiki evidence files: retained indefinitely, as corrections must remain verifiable
  • Backups: rotated on a short cycle

Your rights

Depending on where you live, you may have the right to access, correct, export, or erase your personal data, and to object to or restrict processing. If you are in the EU or UK this is under the GDPR; if you are in California, under the CCPA/CPRA.

To exercise any of these, email [CONTACT EMAIL]. We will respond within 30 days.

How we handle erasure

Accounts are permanent, but your personal data is not.

We do not delete accounts. An account id is attached to forum posts, game accounts, moderation records and the audit log, and removing the row would orphan all of it. What we do instead is anonymise: your name, email address, avatar, signature and login history are erased, and the account is left in place as an anonymous shell so that nothing else in the system breaks.

In practice this means everything that identifies you is gone. What remains is content you posted publicly, no longer attributed to you.

Two further limits, stated plainly:

  • We cannot remove entries from the audit log, which exists precisely so that administrative actions cannot be quietly erased. Anonymising your account disassociates them from you.
  • Wiki corrections you submitted, and the evidence supporting them, remain part of the project's factual record. We will remove your name from attribution on request.

If you believe anonymisation does not satisfy a legal right you hold, say so when you write to us and we will deal with it individually rather than pointing at this page.

Security

Passwords are hashed with Argon2id. Two-factor secrets are encrypted with AES-256-GCM. Sessions use httpOnly, secure, SameSite cookies. Failed logins are rate limited with exponential backoff. Two-factor authentication is mandatory for all staff accounts.

No system is perfectly secure. If you find a vulnerability, please report it to [SECURITY EMAIL] rather than disclosing it publicly, and we will credit you.

Children

This service is not directed at children under 13 and we do not knowingly collect their data. If you believe a child under 13 has created an account, contact us and we will remove it.

Changes

Material changes will be announced on the news page.

Contact

[CONTACT EMAIL]

Last updated Aug 9, 2026.