Privacy

What killclog.com collects, what it never sees, and how to change your mind. Last updated October 9, 2026.

The short version

What collection-log sync sends

When collection-log sync is on, the plugin publishes the following to your killclog.com profile:

What publishing your character sends

The publish character button, which the Publish Character Model setting adds beside the chalice, is separate from collection-log sync. Nothing is sent until you press it. It sends your RuneScape name and account hash plus a fixed appearance recipe: game build, plugin version, gender, equipment IDs, body-color choices, supported item color/texture overrides, the NPC ID of your active follower (or no follower), and your idle pose animation ID.

The plugin does not upload a screenshot, raw character or follower geometry, raw animation data, arbitrary files, URLs, HTML, or shaders. killclog.com validates the fixed recipe, builds the visible player model from trusted game-cache data, and chooses any follower model and idle loop from its own fixed server catalog.

What the plugin never sends

Lookups

Player lookups are web requests. killclog.com's servers and network providers process connection information, including IP addresses, to serve requests and limit abuse. Routine web access logging is disabled on the production site. Error logs and staging access logs can contain IP addresses and request details for diagnostics and abuse prevention.

Web-server logs rotate daily when non-empty, keeping up to 14 rotated files. This is a rotation limit, not a guarantee that every record is deleted after 14 days; application records, provider logs and backups have separate retention.

Page analytics use GoatCounter, which counts visits without advertising trackers or cross-site cookies. There are no ad networks on this site.

What becomes public

Collection-log sync publishes your collection log and personal bests to your profile page, and your times can appear on leaderboards. Publishing your character makes its validated appearance recipe public and lets the site display server-generated player and follower models on that profile. The generated player model is tied to the published recipe; follower models are shared catalog assets rather than a personal upload.

Boards only rank accounts whose name has passed a verification check. Main-game times flagged by the speed checks are held for review. Times classified as impossible are left out without review.

Changing your mind

Third parties

Lookups send the name being looked up to TempleOSRS, RuneProfile and Jagex's hiscores; item names come from RuneLite's game cache. Synced data is never forwarded to them or sold.

Maintainer alerts go through Telegram and can include a player's name, synced counts and boss times, and what an opt-out request says, contact and reason included.

Questions

Contact details are in security.txt, or use the contact field on the opt-out page. The plugin's source is public at github.com/420kc/kill-clog-plugin if you would rather read exactly what it sends than take this page's word for it.