Plugin Data
Bankstand's RuneLite plugin is optional. This page explains, in plain language, what it reads from your game client, what it will never read, and why that refusal is built in rather than something you just have to trust.
The short version
- Every optional feature starts switched off. You choose which ones to turn on, one at a time, and you can turn any of them back off whenever you want.
- Plugin data is private to your account by default. It isn't published, added to your public player page, or used for rankings, unless you choose to widen who can see it later.
- Your bank contents and worn equipment can never be sent, under any setting. They aren't something the plugin is able to ask for in the first place, so there's nothing to accidentally leave switched on.
- The plugin never acts on your behalf. It doesn't click anything, move your character, or play the game for you. It only watches state the game client already has.
Neither the Hub nor RuneLite itself audits privacy practice
The RuneLite Plugin Hub reviews every plugin before listing it, but that review checks for malicious code and rule compliance, not for good privacy practice. Two things worth knowing before "it's on the Hub" or "it ships with RuneLite" starts to feel like a promise about your data:
- In 2023, a Hub-approved plugin called ChatClip shipped a remote-code- execution flaw. It stayed live for 11 days and had 118 installs before RuneLite pulled it.
- A GitHub issue opened in March 2026 alleges that RuneLite's own default XP and Loot Tracker plugins, which ship built into the client rather than through the Hub, have no privacy policy, no consent flow and no way to opt out. We aren't aware of that having been resolved.
Neither of these is a claim about Bankstand's own plugin. We mention them because "approved by the Hub" or "built into RuneLite" only tells you a plugin probably isn't malicious. It tells you nothing about how it treats your data, which is what the rest of this page is for.
What Bankstand's plugin refuses to read
Not an oversight. Your bank contents and worn equipment have no field anywhere in the plugin's submission format, so no version of our server could receive them even if it asked. Anything already shown on the public hiscores, like your skills, boss kill counts and clue completions, is never requested as private data either: letting you keep public information private would be a promise we couldn't actually keep.
Achievement diary and combat achievement completions are read from the game's own chat window, because that's the only place the game ever announces one. Even then, the plugin only sends the specific task or area name the game itself names in that line. It never reads a wider chat log, and never a message you or anyone else typed.
The plugin doesn't drive your game client in any way. It watches what RuneLite already exposes and nothing more. Even the collection log, the one feature that needs the game's own Search screen open, only ever watches an enumeration you started yourself by clicking it. A test in the plugin's own source code fails the build if anything that could click, move your character, or otherwise automate play is ever added, so this isn't a promise that depends on us remembering to keep it.
What it reads, and how we handle it
Everything else the plugin can send is optional, and each one is its own switch, off until you turn it on: quest progress, achievement diary progress, your collection log, combat achievement progress, account type, notable drops and pet drops. Your skill experience, display name and an account identifier always come along with a paired capture, since we need them to know who you are and attach the rest to the right character.
Whatever you send stays private to your account. It's kept separately from Bankstand's public player data, it's never merged into it, and it's never used to rank you. We've built the ability to share specific features with your group or with everyone later, but that sharing is switched off everywhere right now: if you turn a sharing setting on today, it's saved, but it has no effect yet. We're holding it off until we're confident it can't be used to put someone's fabricated data on another player's page.
You can revoke a paired device at any time from your account's Connection tab. You can also turn off any individual feature for a specific character, if you'd rather it not be captured for that one at all, from that character's own page under Characters.
Your pairing token never leaves your machine. It's stored in a local file outside RuneLite's own settings, so even a synced RuneLite profile can't upload it anywhere.
The rest is in the Privacy Policy
This page is a summary, not the complete picture. The Privacy Policy has the full field list, how long each kind of data is kept, the legal basis we rely on, and your rights.