Legal

Privacy policy

Last updated 26 July 2026

RaidPlan.io is a free tool for creating and sharing raid encounter plans. This policy explains what personal data we collect, how we use it, and your rights. We collect as little as possible and never sell it. You can use the site, including creating an account, without giving us your real identity.

What we collect and why

Account data (only if you sign up)

An account requires only a username and password. Passwords are stored as a salted hash, so we never see them in plain text. An email address is optional; if you add one, we use it solely for password resets and essential messages about your account. We do not send marketing email.

Linked accounts (optional)

You can link third-party accounts such as Warcraft Logs, FFLogs, or Patreon. We store the linked account's identifier and display name so we can recognise the connection, together with the access token the platform issues us so we can act on your behalf. You can unlink at any time from your settings, which deletes the stored token.

For Warcraft Logs and FFLogs, linking lets our tools read log data through your account at your direction. That includes reports that are private or limited to your guild, which we could not otherwise see. We read only what you ask for: the reports and pulls you open, your list of recent reports, and your guild list so you can choose between them. We never read a linked account unless you request it, we never post or change anything on the platform, and log data is fetched live when you use the tool rather than copied to our servers.

Content you create

Plans, drawings, and notes you create are stored so we can provide the service. Anyone with a plan's link can view it, so don't put personal information in a plan you intend to share.

Technical and security data

When you use the site, our servers and our security provider process technical data about the request, including your IP address, browser user-agent, and request metadata. We use it only to protect the service against abuse, fraud, and attacks, and delete it once it is no longer needed for that purpose.

Usage analytics

We use a privacy-focused analytics tool to measure aggregate usage (page views, referrers, browser types). It sets no cookies, stores no IP address, does not track you across other sites, and builds no profiles.

Legal bases (GDPR): account data, linked accounts, and your content are processed to perform our contract with you (Art. 6(1)(b)); technical, security, and analytics data rest on our legitimate interest in keeping the service secure and improving it (Art. 6(1)(f)).

Cookies

The only cookie we set is a session cookie created when you sign in, which keeps you signed in. This is a strictly necessary cookie that needs no consent. We use no tracking or advertising cookies. If you never sign in, we set none at all.

Who we share data with

We never sell your data. We share it only with the service providers that help us run the site, and only as far as needed:

  • Cloudflare: security, content delivery, and abuse prevention. Traffic to the site, including your IP address, passes through Cloudflare's network.
  • Email provider: delivers transactional email such as password resets, only if you provided an email address.
  • Cloud hosting providers: run our application, database, and analytics.
  • Connected platforms: only if you choose to link an external account. When you use a feature that reads your logs, we contact that platform on your behalf, under its own privacy policy.

International transfers

Some of our providers (including Cloudflare) are based in the United States. Where personal data is transferred outside the European Economic Area, we rely on safeguards recognised under the GDPR, such as the EU–U.S. Data Privacy Framework or Standard Contractual Clauses.

How long we keep data

  • Account data and your content: kept while your account exists, and deleted on request.
  • Security and technical logs: kept briefly, then deleted once no longer needed for abuse prevention and troubleshooting.
  • Analytics: stored only in aggregate, anonymous form.

Security

All traffic to RaidPlan.io is encrypted with TLS, passwords are stored only as salted hashes, and access to production systems is restricted. Cloudflare filters malicious traffic before it reaches our servers. No method of transmission or storage is ever completely secure, but we take reasonable measures to protect your data.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased, including your whole account;
  • receive your data in a portable format;
  • restrict or object to processing based on our legitimate interests;
  • lodge a complaint with your local data protection authority.

Residents of the UK, California, and other regions have similar rights; in every case, we do not sell personal data. To exercise any right, including deleting your account and all associated data, email [email protected]. Because an account may hold no identifying information beyond a username, we may ask you to prove control of it (for example, by signing in) before acting on a request.

Children

We do not knowingly solicit data from children under 18. By using RaidPlan.io, you confirm that you are at least 18, or that you are the parent or guardian of a minor and consent to their use of the site. If we learn that we have collected personal information from a user under 18, we will deactivate the account and take reasonable steps to delete that data from our records.

Changes to this policy

We may update this policy as the service evolves. The "last updated" date above reflects the current version, and we will announce material changes on the site.

Questions? Contact [email protected]