Privacy Policy

What RuneGlass stores, why it is needed, and how you stay in control.

Last updated: September 30, 2026

The short version

Breevoort Design operates RuneGlass and is the controller responsible for the personal data described in this notice.

RuneGlass uses account and character data for your profile, progress history, and timers. RuneLite sync is optional. You choose the character to connect, and additional sync features have separate settings.

The RuneGlass plugin does not upload your Jagex password, launcher credentials, chat messages, screenshots, gameplay input, or other players’ data.

Why we use personal data

We use account and session data to provide the RuneGlass services you request. The legal basis for this processing is performance of our agreement with you. Without the required sign-in information, we cannot provide account-based features.

We rely on your consent for optional app analytics, newsletter subscriptions, and optional RuneLite uploads. Pairing and enabling sync are separate from signing in to RuneGlass. Declining an optional feature does not prevent you from using features that do not need that data.

We use necessary connection and security records to protect accounts, prevent abuse, and investigate service failures. Our legal basis is our legitimate interest in operating a secure, reliable service. We also use support correspondence to respond to requests and resolve problems. Where the law requires us to keep or disclose information, we rely on that legal obligation.

Your RuneGlass account

When you sign in, RuneGlass stores your account identifier, email address, profile name, and authentication records. Signing in with Apple or Google also involves that provider’s identifiers and authentication tokens. These records provide access to RuneGlass, not to your RuneScape account.

We use these records to sign you in, maintain your session, associate saved characters with your account, and send verification and account-deletion emails. Authentication records can include connection information such as your IP address and user agent.

Your account, linked characters, and synced data are stored in our Convex backend. Some preferences and cached information are also stored on your device. Uninstalling the app does not delete your server-side account or synced history.

Optional RuneLite sync

Pairing connects one RuneLite profile to the character you approve in RuneGlass. The plugin receives a revocable, write-only connection credential. The backend stores a one-way hash of that credential, not the credential itself.

Core sync sends your character’s display name, account and profile type, skill levels and XP, observation times, and plugin, RuneLite, and game versions. These snapshots support current stats, progress history, XP gains, and derived estimates such as EHP. Our service also receives your IP address when the plugin connects.

Sync reports what the client observes. It is not a complete record of activity while RuneLite is closed, or tamper-proof evidence.

Bird house and farming timers

Bird house and farming sync are off by default and can be enabled separately in the plugin settings. They send observed states of supported bird houses and plant patches, observation times, and estimated ready times. Compost bins are not included.

RuneGlass stores current observations for your timers and readiness estimates. The plugin does not upload raw game variables, movement paths, or location history.

Character appearance

Where available, appearance sync is a separate, off-by-default option. It sends your local character’s equipped item identifiers, body colours, gender presentation, a bounded low-poly character model, and render attributes. These attributes include face colours, transparency, render priorities, and texture identifiers and presence.

This data provides a private character preview. The plugin does not upload screenshots, animations, game texture assets, or models of other players.

We keep one current appearance snapshot per character profile. New snapshots replace the previous state. Pausing appearance sync stops new uploads but keeps the stored preview. Revoking its connection hides the preview. A newly paired connection must send a fresh snapshot before it appears again. Use the RuneLite-data deletion control to remove the stored snapshot.

Public game data and fallback services

RuneGlass retrieves public player statistics from OSRS Hiscores and uses Wise Old Man where needed for supported fallback estimates or historical data. Player lookups include the RuneScape display name. Item prices and game information also come from public services, including the OSRS Wiki.

Public information already held by Jagex, Wise Old Man, or another service is not removed when you delete your RuneGlass data.

Notifications and widgets

If you enable timer notifications, the app schedules reminders on your device using timer names and estimated completion times. You can disable them in RuneGlass or your device settings.

The farming widget reads timer information shared locally with the app. Depending on your device settings, reminders and widgets can be visible to someone who can see your screen.

Analytics and the website

Optional app analytics use PostHog to help us understand feature use and diagnose problems. Events can include screens visited, feature interactions, and app and device information. When you are signed in, analytics can be associated with your internal RuneGlass account identifier, so they are not anonymous. App session replay is disabled.

Change your app analytics choice in Settings. Turning analytics off stops future optional analytics; it does not erase events already collected. Contact us about deleting existing analytics data.

The website uses Vercel hosting and Web Analytics. Website analytics are separate from the mobile app’s PostHog preference. Hosting and service providers also process connection information needed to deliver their services.

If you subscribe to website updates, your email address is sent to MailerLite to manage that subscription. You can unsubscribe using the link in a newsletter or by contacting us. If you contact support or use our UserJot feedback board, the receiving service processes the information you submit. Feedback posted publicly can be read by other visitors. Do not include passwords or other secrets.

International processing

Our production Convex database uses its EU region, and the mobile app sends analytics to PostHog's EU endpoint. This does not mean every service processes all information only in the European Economic Area. Providers and their subprocessors can process information elsewhere, including in the United States.

For example, Resend's data processing terms describe primary processing in the United States and incorporate the European Commission's standard contractual clauses for applicable transfers. The provider documents linked below explain their processing locations and transfer safeguards. Contact us to request information about the safeguards relevant to your data.

Services that process data

Convex provides backend storage and authentication infrastructure. Resend delivers verification and account emails. Apple and Google process sign-in when you choose those methods. PostHog processes optional app analytics. Vercel hosts the website and provides its analytics, MailerLite handles newsletter subscriptions, and UserJot hosts the feedback board.

Public game-data providers receive the information needed for the requested lookup, such as a character name. These services have their own privacy notices and infrastructure. Contact us for details about a particular provider or how your data is handled.

How long synced data is kept

Detailed XP history is rolled up to limit storage: five-minute records are retained for 48 hours, hourly records for 35 days, and daily records for two years. Monthly history remains until you delete the relevant data. Scheduled cleanup removes expired records in batches, rather than at the exact instant a retention window ends.

Current skill state, timer observations, and the latest appearance snapshot remain until replaced or deleted. Disconnecting a plugin stops its access but is not the same as deleting its stored history.

The plugin’s local skills retry queue is limited to seven days and 5 MiB. Timer and appearance observations are not stored in that disk queue. Account records remain while your account exists, subject to account deletion. Contact us for retention details about support, newsletter, or analytics records.

Your controls and privacy rights

In the RuneGlass plugin settings, pause sync or disable individual optional features. In RuneGlass Settings, revoke a connected client, export a character’s RuneLite data, or request deletion of that character’s stored RuneLite data. This export is not a full export of every account record.

You can request account deletion in the app and complete the email confirmation. Character-data deletion hides affected appearance data while cleanup runs and prevents new uploads during deletion. Deleting the app alone does not perform these server-side actions.

You can withdraw consent for optional processing at any time. Disable the relevant plugin feature, turn off app analytics, or unsubscribe from the newsletter. Withdrawal does not affect the lawfulness of processing before withdrawal. Stopping future collection does not itself erase stored information; use the deletion controls or contact us about removal.

Depending on the circumstances, you can request access, correction, deletion, restriction, or a portable copy of your personal data. You can also object to processing based on legitimate interests. Contact Breevoort Design using the email below. We may need to verify that a request concerns your account before acting on it.

We normally respond within one month. If a request is complex or you make several requests, the law can allow up to two additional months. We will explain any extension within the first month.

You can complain to your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens. You do not have to contact us before making a complaint.

Changes to this notice

We update this notice when our data practices change. The date on this page identifies the latest revision. New optional plugin features describe the additional data they send before you enable them.

Provider information and complaints

Contact Breevoort Design

Send privacy questions or data requests to jeroen@breevoortdesign.com.

RuneGlass is not affiliated with Jagex Ltd. Old School RuneScape is a trademark of Jagex Ltd.