Everykill · Install · Monsters

Privacy Policy

Last updated 25 August 2026

The short version.

  • The plugin works fully with upload switched off. Uploading is opt-in and adds ranking, nothing else.
  • Uploading kills never sends your RuneScape username. Not hashed, not encrypted — it is not part of what upload sends.
  • No email address, no IP address in our logs, no device fingerprint.
  • Your account is a random number your own client generated.
  • You can export or erase everything from inside the plugin, without asking us and without waiting.

Who we are

Everykill is a RuneLite plugin and companion website that records how many of each monster you have killed in Old School RuneScape. It is an independent, non-commercial project run by one person in California, United States, who is the data controller.

Everything below is handled by that person directly. Write to contact@everykill.com for anything at all, including their name, which is given on request to any user or data protection authority who asks for it.

We are not affiliated with Jagex Ltd or the RuneLite project.

What the plugin records locally

With upload off, everything stays in .runelite/everykill-plugin/ on your machine and none of it reaches us: kill counts per monster, XP measured per monster, drops attached to the kill they came from, session totals, and goals you set.

What we receive when upload is on

Per kill: the monster's game id, name and combat level; the region id where the fight happened; how the kill was detected and how confident we are in it; damage you dealt, damage others dealt, attack and hit counts, your biggest hit; fight length in game ticks; a timestamp from your client; any items dropped, with quantities; and a client-generated event id used to avoid storing the same kill twice.

Per account: a salted hash of the random 128-bit identifier your client generated on first run, a salted hash of each access token, a random public profile identifier, and timestamps for account creation and last activity.

For rate limiting: the time of each request, and nothing else about it.

What we deliberately do not collect

Why the identifier is hashed on our side, not yours

Your client generates a random 128-bit id and sends it once, to register. We store only a salted hash of it. The salt is a server-side secret and never leaves our infrastructure.

The plugin is open source. Had the client done the hashing, the salt would ship inside a public jar — and a salt everyone can read is not a salt. Since RuneScape usernames are public and finite, anyone could hash the lot and reverse our database in an afternoon. Doing it server-side is what makes the promise real rather than decorative.

Pseudonymous data is still personal data under GDPR Recital 26. We are not claiming this puts us outside the regulation; it reduces what a breach would expose.

Why we process it

To count your kills, rank them against other players, and calculate how lucky or dry you have been. That is the entire purpose. Ranking requires comparing your data with other players', which is the only reason we hold it centrally.

Legal basis

Consent (GDPR Article 6(1)(a)). Upload is off by default and you switch it on. You can withdraw consent at any time by switching it off, which stops all further transmission immediately, and separately by erasing what we already hold.

We do not rely on legitimate interests. Consent is the honest description of a feature you have to deliberately enable.

How long we keep it

Your kills are kept while your account is in use. A lifetime kill count you can't keep isn't a kill count, so there is no fixed expiry date on your history while you're playing.

Accounts that go silent are erased. If an account has not uploaded anything for three years, it and all its kills are deleted automatically. Data about someone who stopped playing years ago serves no purpose, and keeping it would mean claiming a need we don't have.

Rate-limiting timestamps are deleted automatically after a few minutes.

Your rights, and how to actually use them

Under GDPR you have the right to access, rectify, erase, restrict, port and object. Two of those are built into the product, so you don't have to email anyone or wait a month:

For anything else, email contact@everykill.com. We respond within one month, as Article 12(3) requires.

One consequence worth stating plainly: because we hold no username or email, your token and recovery code are the only proof that an account is yours. Lose both and we cannot restore your history or verify a request about it — there is nothing to check you against. That is the price of collecting so little, and we would rather say so than quietly benefit from it.

Public leaderboards

This does not exist yet. No leaderboard is live, and nothing you upload today is published anywhere. When it does exist, it will work like this, and we are describing it now rather than surprising you with it later.

Ranking you against other players needs a name people recognise, so there will be a second, separate opt-in to publish one. It is not bundled with upload:

Even then, what becomes public is deliberately narrow: your name, kill counts, ranks, completion totals and luck position. Not per-kill timestamps, regions or session times. A scoreboard is a scoreboard; a timestamped log of when a named person was online is something else, and we are not building it.

Turning publish off deletes the name from our servers rather than hiding it. Your ranks remain as unnamed entries, because the kills still count for everyone else's position.

Because this is a material change to what we collect, it will ask for your consent when it ships. It cannot be switched on for you.

Who else sees it

Nobody. We do not sell, rent or share your data. There are no analytics, no advertising, no trackers, and no third-party scripts on everykill.com beyond a webfont request to Google Fonts.

Data you choose to make public — a profile page, a leaderboard entry — is public by your action, and shows a random profile identifier rather than your RuneScape name.

If you are in the EU, UK or EEA

Everykill is operated from the United States by an individual. If you use it from the EU, UK or EEA, the data described above is transferred to and stored in the United States.

We have not appointed a representative in the EU under GDPR Article 27. Everykill is a non-commercial hobby project with no revenue, and the cost of appointing one would exceed the entire cost of running the service. We consider the processing here low-risk: it is opt-in, involves no special-category data, no name, no email address and no IP address, and you can export or erase everything yourself at any time without contacting us.

If you are an EU or UK supervisory authority and disagree with that assessment, contact contact@everykill.com and we will engage with you directly.

California and other US states

Everykill is operated from California, so the CCPA is the closest US law to it. It does not currently apply. The CCPA reaches for-profit entities meeting at least one of three thresholds: $26,625,000 in annual gross revenue, personal information of 100,000 or more consumers or households, or 50% or more of revenue from selling or sharing personal information. Everykill has no revenue at all and is not operated for profit, so none are met.

We do not sell or share personal information as those terms are defined in the CCPA, and have no plans to.

Children

Not directed at children under 13, and we knowingly collect nothing from them. We hold no age or date of birth, so we cannot verify this beyond saying it.

Changes

If we change this policy we will update the date above and say what changed in the plugin's release notes. Material changes to what we collect will require your consent again.

Complaints

If you are in the EEA or UK and believe we have handled your data wrongly, you can complain to your national data protection authority. We'd rather you emailed us first.