Privacy
- 2026-09-20last checked
- 1cookie, set only by you
- 0analytics scripts
- 0third-party requests
- 11browser storage keys
What the site does
- Static pages. No accounts, no sign-in.
- Five things can reach us, and only when you act: a talent build, as an anonymous count; a count of the kind of thing you just did (a button pressed, a tool used, a section opened); a "Wrong number?" report you write yourself, with an optional name on it if you want the fix credited to you; a contact message you write on the home page, which carries your email address so the answer can reach you; and, if you ask to hear when the simulator or the addon opens, your email address. Build counts and reports and Your email address say exactly what each one holds, and what is never kept.
- Page and button counts happen only if you say yes. If this site ever counts which pages get read, it asks first, in a bar at the bottom of the page, and nothing is sent or stored until you answer. Accept and Decline are the same size. Talent builds are tallied anonymously either way, because that count holds a build and nothing about you.
- One cookie,
wf_you, and only if you change a setting: it holds your class, your level and your spoiler settings. It is not used to recognise you or to count you. The one cookie has the details. - No analytics service, no ad scripts, no tracking pixels. The counts above are ours, they are counters and not a record of visits, and "Do Not Track" switches every one of them off.
- No third-party requests: scripts, styles, images, 3D models and the two fonts this site draws with (Golos Text for headings, Cinzel for the spellbook) are served from this site; body text uses the font already on your device.
- We read public community threads and posts to work out what people are asking for, in aggregate and with an AI doing the sorting. We keep the gist, never a post, never a name, never an account. How we listen.
- Search, tooltips, filters and calculators run in the browser on JSON files fetched from this site.
- Talent builds and database filters are kept in the page address (the part after
#or?), which is shared only when the link is shared.
The one cookie
| Cookie | Holds | Set when | Lasts |
|---|---|---|---|
wf_you | The class you picked, the character level you typed, the spoiler level you chose, and the kinds of block you asked to always show. For example c=druid&l=24&s=everything&k=drop-table. 200 bytes at most. | Only when you change one of those under You at the top of a page (or pick a class or a level on a page that offers it). Never on a plain page view. | One year from the last change. Deleted the moment all of them are back to their defaults. |
- First-party: set by this site, for this site (
Path=/; SameSite=Lax; Secure). No other site can read it and it is not shared with anyone. - It holds settings, not an identity. There is no id and no date in it: two people who picked the same class, level and spoiler level have the same cookie.
- The site reads it in your browser, to draw the page in your class colour and to cover what you asked to have covered before the page first paints. Like any cookie, your browser attaches it to the requests it makes to this site; nothing on our side reads it, stores it or writes it to a log.
- It is never used to recognise you, to count you or to join one visit to another.
- If you chose these settings before the cookie existed, they were in browser storage. The first page you open moves them into the cookie once and removes the old keys.
- Clearing cookies for this site, or setting the three back to their defaults, removes it. With cookies blocked the settings still work, for the page you are on.
Browser storage
11Some pages keep state in the browser's localStorage. It stays on the device, is never sent to us or anyone else, and clearing site data in the browser removes it.
| Key | Holds | Written by |
|---|---|---|
wowforever:builds:v1 | Saved talent and Legacy builds: name, class, build code, points per tree, time saved | Saved builds, calculators |
wowforever:rosters:v1 | Saved raid rosters: name, roster code, time saved | Raid roster |
wowforever:roster:current | The roster being edited, as a link code | Raid roster |
wowforever:checklist:v1 | Ids of ticked launch checklist items | Launch checklist |
viewer:dressing | Race and sex chosen in the item model viewer | Item pages |
wowforever:spoiler:note:v1 | That the one-line note about spoiler control has been shown once | What we publish |
wowforever:calc:last:v1:<class> | The last talent build you had open for each class, so the calculator can pick up where you left off | Talent calculator |
wf_seen | One date: the newest entry you have seen in What's new, so the button can count what is new since | What's new |
wowforever:tally:sent:v1 | Session storage, gone when the tab closes: the builds this tab has already counted, so one build is not counted twice. Written only once build counts are switched on | Talent calculator |
wowforever:events:sent:v1 | Session storage, gone when the tab closes: which sections and tools this tab has already counted, so one visit is not counted many times. It holds names of parts of the site ("view:talents"), never a page you looked at and never anything about you. Written only once site counts are switched on | Privacy |
wf_consent | Your answer to the consent banner: analytics yes or no, ads yes or no, and the date of the answer. Written only when there is a banner, which is only in a build that counts pages and buttons or loads a third-party analytics or ads script. This build does none of those, so there is no banner and the key is never written | Privacy |
Build counts and reports
When you finish a build, copy its link, save it, or open a build somebody shared with you, the calculator may tell our server which class it was and which talents were picked, so we can show how often each talent is taken. That message contains the build and nothing else: no cookie, no account, no identifier, and nothing about you or your device. We do not keep IP addresses with the counts; an address is used for a moment to stop one person from counting a thousand times, then forgotten. We publish rates for a class only after 100 builds.
The site also counts four kinds of thing you do here, so we can tell which parts of the site are worth keeping and which buttons nobody finds. Each one is a number going up by one, not a record of your visit:
- A button pressed. Which named button it was ("the What's new pill", "Copy link in the calculator"), and nothing about the page you were on.
- A choice you made. The class you picked, the faction you picked, and the ten-level band your level falls in (60, or 50-59), never the exact level.
- A tool used. That the calculator, the spellbook, the atlas, the search box or the Classic comparison was used at least once while this tab was open.
- A section opened. The name of the part of the site, once per tab: "talents", "guides", "database". Which page you read inside it is not counted, ever.
What is never counted: what you type in the search box, which item, spell, quest or zone you looked at, the address of the page you were on, where you came from, your name, your email, your IP address, your country, your browser, your screen, or the time beyond the date. There is no identifier of any kind, so two counts are never known to be the same person and never known to be two. Nothing is kept that could be joined back together later, because nothing that could be joined is written down. Your answer to a cookie or consent banner is not counted either.
Those four are counted only if you say yes. In a build that counts them, a bar at the bottom of the page asks
before anything is sent: Accept and Decline, the same size and the same weight, and Choose if you
want to answer category by category. Nothing about what you do is sent or stored until you answer, and what you did
before you answered is not kept anywhere to be sent afterwards. Your answer is kept in your browser, in localStorage,
under wf_consent (the table above); it is the only thing that is written for this, and it holds your
answer and the date of it, nothing else. Changing your mind is one click on Privacy choices in the footer.
The talent build count is not behind that question, and here is why: it holds a build code and a class, it writes nothing to your browser except a note to itself not to count the same build twice in this tab, and it carries no identifier, so there is nothing of yours in it to ask about. Builds are tallied anonymously whatever you answer; page and button counts happen only after Accept.
If your browser sends "Do Not Track" or "Global Privacy Control", all of it is off: not the builds, not the buttons, not the tools, not the sections. Nothing is sent, nothing is asked, and nothing is stored in your browser for it.
None of these messages carries the one cookie this site sets. Your browser attaches a first-party cookie to every
request it makes to the site it belongs to, so these counts are sent in the one way that leaves it behind
(credentials: 'omit'): wf_you never reaches a counter.
Every record page and every calculator has a "Wrong number?" form at the foot of it. When you send it we receive
what you typed, the address of the page you were on, which record that page is about ("item 1913"), the game build
it showed, and, if your browser runs scripts, the part of that address after the ? or
#, which is the level, filter or build code you had picked, so the number you are reporting can
be seen the way you saw it. We keep those so the page can be fixed. Nothing about you or your
browser is kept with a report, and its time is kept to the hour only; your IP address is used for a moment to stop one
sender from flooding the form, then forgotten. The text is also delivered to the site team's private Discord channel,
so please do not put personal details in it.
The name you may put in "Credit me as". That form has one optional field and one tick box, and they work like this:
- Optional. Leave it empty and nothing about you is sent at all, exactly as before. The report is as anonymous as it has always been.
- It is a handle, not an email. Up to 32 characters of plain text. An address (anything with an
@and a dot after it) or a web address is refused by the form and by the server: we do not want a way to contact you, only a name to print. - Stored only if you tick the box. "Show this name next to the fix" is off unless you turn it on. With the box off the name is dropped before anything is written down: not stored, not forwarded, not logged.
- What it is used for, and nothing else. One line on the changelog next to the correction you found: "Caught by <your name>". It is never joined to any other report, never used to recognise you on a later visit, and never given to anyone.
- Nothing appears by itself. A name becomes public only when we publish that correction by hand, which is also when the fix goes out. If we never publish the catch, the name is never shown anywhere.
- Taking it back. Send the form again from the same page and say so in the message, and the name comes off the list and out of the store. There is no contact address on this site yet, so the form is the route; when there is one, it will be on this page.
- How long it is kept. With the credited catch, for as long as that correction is on the changelog, because the credit is part of the correction. A name from a report we never publish is deleted with the rest of that report when the store is cleared. Reports are not kept on a timer today; when they are, the rule will be written here.
Your email address
Two places on this site ask for an email address. One is the form on the simulator page, which is there so you can be told when the simulator or the recording addon opens; everything about it is below. The other is the contact form (the home page's Contact card, and "Write to us" on About), described under Contact. An address is the only personal data this site stores, you type it yourself, and everything about the simulator form is below.
- What is stored: your address, which of the two boxes you ticked ("the simulator", "the addon"), and the date you sent it. That is the whole row. No name, no IP address, no country, no browser, no page you were on, no identifier, and no time of day.
- Why: to send you one message when the thing you ticked opens. Not a newsletter, not a digest, not an offer. If you ticked both, that is two messages, ever.
- Who else sees it: nobody. It is never shared, never sold, never handed to an advertiser or an analytics service, and it is not put into a mailing service today. It sits in this site's own small database on this site's own server.
- How to be removed: the same form. Tick Remove my address instead, type the address and send it, and the row is deleted. You do not need to write to anyone and you do not need an account.
- How long it is kept: until the announcement has been sent, and at the latest 12 months from the day you sent it. After that it is deleted whether the announcement went out or not.
- No confirmation email is sent today. Nothing arrives to say "you are on the list". The page says it on the page instead. The first message you get from us will be the announcement itself.
- The answer is always the same. The form answers the same way whether the address was stored, was already there, was removed, or was rejected. That is deliberate: an answer that differed would let anybody test whether a given address is on the list.
The form is only there in a build that was given an address to send to; today it may be absent entirely, and then nothing on this site asks for an email address at all. As with everything else on this page, this was written before the feature was switched on.
Visit statistics
We would like to know the boring things: how many people came, which pages they read, whether the talent calculator is actually being used. For that we use PostHog, a product analytics company in the United States. It is the only outside service this site loads, and it loads only if you say yes.
- It only runs if you accept. The bar at the bottom of the page asks first. Nothing is loaded and nothing is sent until you press Accept, and if your browser says "Do Not Track" or "Global Privacy Control" we do not even ask.
- It uses cookies. Your browser gets a random id so two page views can be seen as one visit. That id is not a name and we never attach one to it: we do not run accounts and we never tell PostHog who anybody is.
- What it sees: the pages you open, the buttons you press, the site that linked you here, your device and browser, and roughly where in the world you are, worked out from your IP address as the request arrives.
- What it never sees: what you type into the search box, what you write in a "Wrong number?" form, your email address, or the talent build code in the address bar. Those fields are marked so the tool skips them, and page addresses are rebuilt from a short list of allowed parts before anything is sent.
- How long. PostHog keeps events for as long as our plan says, which today is seven years for events and one month for any session recording. If you want yours gone sooner, ask us and we will have it deleted.
- Changed your mind? Privacy choices in the footer, any time. Decline and we stop it and clear its cookies from your browser.
This is for us, not for you: nothing it collects is shown on the site or sold to anyone. The numbers the site does show you, like which talents people take, come from our own counting described above, which uses no outside service at all.
Links to other sites
Source links lead to Blizzard's own posts, and the Contribute card on the home page leads to this site's ko-fi page. Nothing is loaded from them until you follow one; after that, their own policies apply.
One other outside service has a part on this site, and it waits for you too: Cloudflare Turnstile, the bot check on the contact form. Its script is loaded only when you open that form, never on a plain page view, and from that point Cloudflare's own policies apply to what its check does.
Hosting and server logs
Coming soon Hosting provider. Not chosen yet; this section will name it and say what its access logs keep.
Contact
The home page has a contact form (the Contact card at the foot of it; "Write to us" on About opens the same form). It asks for your email address and your message, lets you say which of four things it is about, and sends them with the address of the page you were on. Your address is used to answer you, and for nothing else: no list, no newsletter, no sharing. We read everything and reply within 24 hours. The message is delivered to the site team, so put in it only what the answer needs.
- The bot check. The form is protected by Cloudflare Turnstile so one program cannot flood it. The answer to the check is verified on our own server before your message is accepted, the proof is single-use, and it is never stored with your message. Your IP address is not sent to Cloudflare by us and is not written down here.
- What is kept: your address, your message, which of the four subjects you picked (or none), the page's address, the site build it was made from, and the day and the hour. No name unless you write one, no browser fingerprint of ours, no identifier, and nothing about your device.
- How long: 12 months at the outside, and sooner when the conversation is done. There is no account to look it up with, so ask in any later message and it comes off early.
The form is only there in a build that was given an address to send to; today it may be dormant, with a "Coming soon" mark where Send will be. As with everything else on this page, this was written before the feature was switched on.
Share
Share this page
Post it to
Nothing is sent anywhere until you press one of these. WoW Forever has no share counters.