Privacy Policy

Last Updated: January 2026

At RuneSpin, we value your privacy and aim to be 100% transparent about how we handle your data. We are a tool built for players, and your trust is our highest priority. We do not sell your data, and we do not use tracking or marketing cookies.

1. Information We Collect

We process data based on Contractual Necessity (to provide the service you signed up for) and Legitimate Interest (to keep our site secure). We collect:

  • Email Address: When you log in via our One-Time Password (OTP) system, we store your email address to identify your account and save your progress.
  • Game Data: We collect public hiscore data (levels, boss kills, quest counts) from the official RuneScape hiscores and RuneMetrics to track your challenge progress.
  • Technical Logs: Our server logs your IP address and browser type for security purposes and to prevent brute-force attacks. These logs are purged periodically.

2. Cookie Disclosure

We use exactly one "strictly necessary" cookie to function:

  • PHPSESSID: This is a first-party functional cookie used to keep you logged in and secure your session. If you select "Stay Logged In" during the login process, this cookie persists for 30 days to save you from re-verifying your email. Otherwise, it expires when you close your browser.

3. Third-Party Sharing

We do not share, sell, or rent your information with any third-party advertisers, data brokers, or external entities. Your data is stored on our secure private database and is used solely for the functionality of this application.

4. Your Rights & Data Deletion

You have the right to access, export, or delete your personal data at any time. If you wish to close your account and have your email address and all associated character profiles permanently removed from our database, please contact us:

Requests are typically processed within 48-72 hours. Once deleted, your data cannot be recovered.

5. Age Restriction

RuneSpin is intended for users aged 13 and older. We do not knowingly collect or maintain personal information from children under the age of 13. If we learn that a user under 13 has provided us with personal information, we will take steps to delete that information as quickly as possible.