Privacy
What killclog.com collects, what it never sees, and how to change your mind. Last updated October 9, 2026.
The short version
- Collection-log sync is off by default. Turning it on also enables Publish Character Model, but your character is sent only when you press publish character.
- Everything published is game data: your collection log, boss times, or a fixed recipe describing your visible character and active follower. No emails, no passwords, and never your Jagex login.
- Opting out deletes your synced profile and published character, not just hides them. A private record of the opt-out stays, so it keeps working.
What collection-log sync sends
When collection-log sync is on, the plugin publishes the following to your killclog.com profile:
- Your RuneScape name, as your profile's address.
- Your account hash. This is a stable identifier RuneLite reports for your RuneScape account. It links syncs that report the same identifier, and keeps an opt-out in force under any name. It doesn't prove who owns the account: a hiscores check confirms the name and checks its collection log count where available, and name disputes are settled by hand. It is stored privately with your name's history, name disputes and opt-out records, never displayed, and it is not your login, email, or any credential.
- Your collection log: obtained items, quantities, categories and the unlock dates the plugin recorded.
- Your personal best boss times, including per-team-size times, read from RuneLite's records and from your own Adventure Log.
- Your account type (ironman status and similar), your log's obtained/total counters, and the plugin version that sent the sync.
What publishing your character sends
The publish character button, which the Publish Character Model setting adds beside the chalice, is separate from collection-log sync. Nothing is sent until you press it. It sends your RuneScape name and account hash plus a fixed appearance recipe: game build, plugin version, gender, equipment IDs, body-color choices, supported item color/texture overrides, the NPC ID of your active follower (or no follower), and your idle pose animation ID.
The plugin does not upload a screenshot, raw character or follower geometry, raw animation data, arbitrary files, URLs, HTML, or shaders. killclog.com validates the fixed recipe, builds the visible player model from trusted game-cache data, and chooses any follower model and idle loop from its own fixed server catalog.
What the plugin never sends
- Your Jagex or RuneLite login, password, session, or email.
- Your chat, your friends list, or your in-game location.
- Collection-log data while sync is off, or your character until you press publish character.
Lookups
Player lookups are web requests. killclog.com's servers and network providers process connection information, including IP addresses, to serve requests and limit abuse. Routine web access logging is disabled on the production site. Error logs and staging access logs can contain IP addresses and request details for diagnostics and abuse prevention.
Web-server logs rotate daily when non-empty, keeping up to 14 rotated files. This is a rotation limit, not a guarantee that every record is deleted after 14 days; application records, provider logs and backups have separate retention.
Page analytics use GoatCounter, which counts visits without advertising trackers or cross-site cookies. There are no ad networks on this site.
What becomes public
Collection-log sync publishes your collection log and personal bests to your profile page, and your times can appear on leaderboards. Publishing your character makes its validated appearance recipe public and lets the site display server-generated player and follower models on that profile. The generated player model is tied to the published recipe; follower models are shared catalog assets rather than a personal upload.
Boards only rank accounts whose name has passed a verification check. Main-game times flagged by the speed checks are held for review. Times classified as impossible are left out without review.
Changing your mind
- Stop collection-log syncing: untick the setting. No further collection-log or personal-best data is sent. This does not publish, update, or remove your character appearance.
- Stop character updates: turn off Publish Character Model. Your last published appearance remains visible until you remove your data.
- Hide your personal bests: request it through the opt-out page and say "hide" in the reason field. Once approved, your times stop appearing on profiles and leaderboards; they keep updating while you sync, so showing them again needs no fresh sync.
- Remove your profile: an opt-out request, once you're confirmed as the account's owner, deletes your collection log, personal bests, sync record, published appearance, and its profile link to generated models. After approval your profile serves an unavailable page, and new syncs and character publications from your account are refused under any name. If you rename, hiding the new name's page also needs your confirmation. A private record of the opt-out stays, with name-dispute and review records, lookup caches and earlier maintainer alerts. Another account that later takes the name and passes verification can publish under it. Shared follower catalog files can remain because they are not personal uploads and are reused for every player with that follower.
Third parties
Lookups send the name being looked up to TempleOSRS, RuneProfile and Jagex's hiscores; item names come from RuneLite's game cache. Synced data is never forwarded to them or sold.
Maintainer alerts go through Telegram and can include a player's name, synced counts and boss times, and what an opt-out request says, contact and reason included.
Questions
Contact details are in security.txt, or use the contact field on the opt-out page. The plugin's source is public at github.com/420kc/kill-clog-plugin if you would rather read exactly what it sends than take this page's word for it.