Skip to content

Privacy Policy

Last updated: 1 October 2026

Bankstand is an Old School RuneScape progression tracker. This policy explains what it collects, why, who else sees it, and how to get rid of it.

Who is responsible for your data

Bankstand is operated by Christiaan van Eijnsbergen, based in the Netherlands. We are the controller of the personal data this policy describes, and you can reach us at support@bankstand.gg (section 9).

The short version

  • You don't need an account to use most of Bankstand. Player pages, guides, groups and comparisons are built from data that is already public.
  • Anything the RuneLite plugin reads from your game client is private to you by default. It isn't published, not merged into public pages, and not ranked on.
  • Bankstand never asks for your bank, inventory, worn equipment, chat or location. Not as a setting that defaults to off: those can't be expressed in the format the plugin submits, so they can't be requested at all.

1. Data that is already public

Bankstand reads Old School RuneScape progression from Wise Old Man, which in turn reads Jagex's public hiscores. Skills, experience, boss kill counts, clue completions and account type are public facts about a character, published by Jagex.

Anyone can ask Bankstand to track any character, with no account and no permission from its owner. That is deliberate: the data is public either way, and it is how comparison and group pages work. Tracking a character stores its name and any past names it has had, its Wise Old Man id, its account type, and a history of snapshots, and it produces a public activity log derived from the differences between them.

Being published elsewhere doesn't put this information outside data protection law: the underlying progression data is already publicly accessible from Jagex's hiscores, and Bankstand presents that public information in a different form. We process it under a legitimate-interest basis (section 7), and you can object to it (section 8).

If you don't want a character tracked, contact us (section 9). We will remove it from Bankstand's public tracking as a matter of policy, though this doesn't remove the character from Jagex's hiscores or Wise Old Man, and nothing stops someone else asking us to track it again.

2. Data you give us

You must be at least 16 years old to create a Bankstand account (Terms of Service, section 2). We don't knowingly collect account data from anyone younger.

An email address, if you create an account. Held by our authentication provider (section 6). Used to sign you in and to contact you about the service. Bankstand doesn't send marketing email.

Your saved characters, the characters you have added to your own list.

Your guide progress, the steps you have ticked by hand.

A Discord webhook URL, if you add one in your notification preferences. We store it so it can be used to deliver notifications there; that delivery isn't built yet, so nothing is currently sent to it.

Technical and abuse-prevention data. Bankstand's own database stores only a hash of your IP address, never the address itself, and uses this data only for security and abuse prevention: rate-limiting sign-in attempts, plugin pairing attempts and other actions that could be abused. A pairing code is likewise stored only as its SHA-256 hash, is single-use and expires after 10 minutes. This describes Bankstand's own database; our hosting providers (section 6) may independently log request data under their own privacy policies.

3. Data the RuneLite plugin reads

The Bankstand RuneLite plugin is optional. If you install and pair it, it reads the following from your game client and sends it to us:

WhatWhenNotes
Experience in each of the 24 skillsAlways, while pairedExperience only. Never a level, never a rank: the level is derived and the hiscores own the rank.
An account identifier (accountHash)Always, while pairedRuneLite's own per-account number. It isn't your Jagex account name, email or password, and it can't be used to log in.
Your character's display nameAlways, while pairedTo match the capture to a character on your list.
The plugin version and the time of captureAlways, while paired
Quest stateOnly if you turn it onNot started, in progress or finished, per quest.
Achievement diary stateOnly if you turn it onComplete or incomplete, per region and tier, and how many tasks in a tier you have completed.
Collection log entriesOnly if you turn it onThe item ids you have obtained.
Combat achievement progressOnly if you turn it onHow many tasks you have completed per tier, and per boss or activity for the ones the game tracks separately.
Account typeOnly if you turn it onYour account type (for example Ironman, Hardcore Ironman or Group Ironman), read from the game client.
Notable dropsOnly if you turn it onThe item name, quantity, estimated value and source (an NPC or player name) of a drop worth more than a threshold you set, 1,000,000 coins by default.
Pet dropsOnly if you turn it onThe pet's name.

The account identifier is used only to match a capture to the paired character. We don't use it for advertising or profiling.

Each of the optional capabilities is a separate switch and each is off until you turn it on. The Connection tab in your account shows which are active, and lets you view and revoke any device you have paired.

Some of the above is also captured as a specific moment, not just a count. When the game itself announces something in your chat, the plugin reads that broadcast line in addition to the running counts above:

  • A completed combat achievement task, a collection log unlock or a pet drop sends the specific task, item or pet name.
  • Finishing an entire combat achievement tier sends which tier, as its own moment separate from the running count.
  • A completed achievement diary task sends the region and tier it belongs to. The game's own broadcast for this doesn't name the specific task, so Bankstand can't send what it is never told.

This still only reads the game's own output; it never reads a message you or anyone else typed, whether public, private or clan chat.

The plugin doesn't automate anything. It doesn't click, move your character, or interact with the game. It reads state the client already has. A test in the plugin's source fails the build if a call that could drive the game is ever added.

What it will never read

Your bank, your inventory, your worn equipment, your chat and your location are not capturable by design. The plugin's submission format has no field for any of them, so they can't be sent even by a version of our server that asked. This is a structural refusal, not a preference we could quietly change.

4. What we do with plugin data

Plugin data is private to your Bankstand account by default. We don't publish it, merge it into the public player record, or use it for rankings or leaderboards. Public game data and private plugin data are kept as separate datasets on our side, and a plugin capture never overwrites, enriches or otherwise contributes to the public player record.

Sharing plugin data with anyone else is currently switched off entirely, at the point where it is read, so a sharing setting can't take effect even if one were stored. When sharing does become available it will be per capability, off by default, and only ever attributed to the account that submitted it rather than presented as the character's own state.

5. How long we keep it

We keep different data for different reasons, and for different lengths of time:

  • Account, saved characters, guide progress and plugin captures. Kept while your account exists, and for a short period afterwards where needed to resolve a dispute, meet a legal obligation, or recover from an accidental deletion. Deleting your account starts that clock.
  • Raw plugin submissions. Kept for 7 days, then their contents are discarded. We keep the submission's identifier, its timestamps and whether it was accepted for longer than that, because that is what stops a resent submission being processed twice. Those longer-lived records contain no game data.
  • Your account activity history, the changes you (or your paired plugin) make to your own account, such as who can see what. Kept for 90 days, then deleted outright. You can see this list yourself under Account, Your data.
  • Public tracking data (section 1). Not tied to an account, so it isn't deleted when one is. We keep it for as long as our legitimate interest in providing the tracking service continues, and remove a specific character on request (section 8), though nothing stops someone else asking us to track it again.

6. Who else is involved

WhoWhat they holdWhy
Wise Old ManPublic character dataOur source for hiscores progression. We send them character names.
SupabaseThe database and your email addressStorage and authentication.
VercelHosting, and cookieless page-view and performance countsServes the site, runs the scheduled refresh, and counts page views and page-load performance (see below).
SentryError reports (what broke, not what you typed)Tells us when something is broken so we can fix it (see below).
PostHogProduct analytics, only if you consentHow you use the site, so we know what to improve. Off by default (see below).
CookiebotYour consent choice itselfRuns the consent banner and remembers your answer.

RuneLite is deliberately not in the table above: nothing about your Bankstand account is sent to it.

Your pairing token stays on your machine. The plugin stores its pairing token in a local file, deliberately outside RuneLite's own configuration, so it is never uploaded to RuneLite's servers even if your RuneLite profile has sync enabled. It grants the ability to submit captures for your account, and nothing else: it can't read your Bankstand account or your email. You can view and revoke any paired device at any time from your account's Connection tab.

Cookies and local storage. Signing in sets a session cookie through our authentication provider so you stay signed in between visits. Your theme preference (light or dark) is stored in your browser's local storage, not a cookie, and never leaves your device. A cookie banner (Cookiebot) remembers your answer to the question below in its own cookie, which is what makes your choice stick across visits rather than asking every time. None of this, and nothing below, is used for advertising or tracking you across other sites.

Page-view counting. We use Vercel Analytics to see which pages get used. It counts page views and the page you came from, doesn't set a cookie or any other persistent identifier, and can't follow you to another site. We don't sell data, and we don't use it, or anything else on Bankstand, for advertising or cross-site tracking. This one runs regardless of your cookie choice below, since it sets nothing on your device to consent to.

Performance monitoring. We use Vercel Speed Insights to see how fast pages actually load for real visitors. Like page-view counting above, it is cookieless, sets no persistent identifier, and can't follow you to another site, so it also runs regardless of your cookie choice below.

Error tracking. We use Sentry to know when something on the site is broken. It receives a technical error report (what failed, the page you were on, a stack trace) but no session cookie of its own and none of what you typed. This runs regardless of your cookie choice below too, for the same reason as page-view counting: it doesn't set anything on your device.

Product analytics, only with your consent. We use PostHog to see how the site gets used beyond a raw page count: which features get clicked, where people get stuck. Unlike the two above, this one does set a real cookie and local storage entry to recognise you across visits, so it only runs if you say yes to "Statistics" in the cookie banner. Until you answer, or if you decline, nothing is captured and nothing is stored. You can change your answer at any time (the banner has its own way to reopen); declining later clears whatever PostHog had already stored for you.

7. Legal basis

Where the GDPR applies, we rely on:

  • Contract for your account, your saved characters, your guide progress, and the minimum plugin data needed to run the pairing itself: your skill experience, account identifier, display name, and the plugin version and capture time, all sent automatically while paired rather than as a separate choice. Without these the paired service can't function.
  • Consent for each optional plugin capability beyond that minimum, which you give by switching it on and withdraw by switching it off; and separately, for product analytics (PostHog), which you give or withhold through the cookie banner and can change at any time (section 6).
  • Legitimate interest for tracking public character data, for the technical and abuse-prevention data described in section 2 (hashed IP addresses, pairing-code hashes) that keeps sign-in, pairing and rate-limiting working, and for error tracking (Sentry): keeping the site working is a narrower, less invasive use than behavioral analytics, and it processes no session cookie and none of what you typed. For public tracking we weigh this against your interests: the underlying data is already published by Jagex with no login required to see it, and you can object to a specific character being tracked (section 8).

8. Your rights

Where the GDPR applies, you have the right to:

  • access a copy of your personal data;
  • rectification of data that is wrong;
  • erasure of your data, subject to the distinction below;
  • restriction of how we process it, in some circumstances;
  • object to processing based on legitimate interest, including public tracking (section 7);
  • portability, where the GDPR gives you that right, in a commonly used machine-readable format;
  • withdraw consent for any plugin capability at any time by switching it off, which stops further capture from that point on and doesn't affect the lawfulness of capture that already happened. What was already captured stays, stored as part of your account under the contract basis above, the same as your saved characters or guide progress; ask under "erasure" above if you want it gone too.

We aim to respond within one month. Bankstand doesn't use automated decision-making that produces legal or similarly significant effects.

"Delete my data" can mean different things here, and we treat them separately:

  • Delete my Bankstand account. Self-service: a typed confirmation in your account's Danger Zone deletes your account immediately. This removes your email, saved characters, guide progress and plugin captures, and any character you claimed loses that claim. If you own a group, deleting your account deletes that group for everyone in it, not just you; there is no transfer or archive step today. If you had made a character's page public, its address becomes available for someone else to claim once your account is gone.
  • Remove a character from Bankstand's public tracking, or object to it. As a matter of policy, we honour this the same way either way: we stop tracking that character going forward. This doesn't remove the character's data from Jagex's hiscores or from Wise Old Man, and it does not stop someone else asking us to track it again, since the underlying data stays public regardless.

Export. Download a copy of your account data (your email, saved characters, capability and sharing settings, notification preferences, paired plugin devices, and a recent history of account actions) as a single file, at any time, from your account's Data page. You can still email us (section 9) if you would rather we action either of these by hand.

If you are in the EU or UK you also have the right to complain to your data protection authority; in the Netherlands, that is the Autoriteit Persoonsgegevens.

9. Contact

Email support@bankstand.gg. Sections 1, 5 and 8 all point here.

10. Changes

If this policy changes materially we will say so on the site. Bankstand is in early access and the product is changing quickly, so this is likely.

11. Not affiliated

Bankstand is an independent project. It isn't affiliated with, endorsed by or sponsored by Jagex Ltd or the RuneLite project. Old School RuneScape is a trademark of Jagex Ltd.