← back
Privacy Policy
Effective: April 1, 2026 · Last updated: September 13, 2026
Rigour Hero ("the Game", "we", "us") is a free, non-commercial fan game inspired by Old School RuneScape. This policy explains what data we collect, why, how we store it, and your rights regarding that data.
1. Data We Collect
1.1 Account Data
- RuneScape Name (RSN):used as your in-game identity. Verified against the official OSRS Hiscores API.
- Account password:optional, set by the player. Sent over an encrypted connection for authentication and stored as a one-way cryptographic hash. Use a password that is different from your Jagex password.
- Account type:Ironman, Hardcore Ironman, Ultimate Ironman, or regular. Retrieved from OSRS Hiscores.
1.2 Gameplay Data
- Scores, combos, and game statistics:submitted when you complete a game session.
- Collection log items and pets:earned through gameplay, stored per-RSN.
- Inventory, consumables, and GP balance:virtual in-game currency and items with no real-world value.
- Game mode and boss selections.
- Star ratings:optional boss/mode ratings you submit.
1.3 Social Data
- Friends list, follow list, and ignore list:managed by you through in-game commands.
- Chat messages:public chat messages sent in-game are broadcast to other connected players but are not stored on our server.
- Private messages:stored server-side with a rolling cap of 50 messages per player to provide message history when you reconnect. Older messages are automatically deleted as new ones arrive.
- Channel/clan membership:which channels you have joined.
- PM privacy settings:your preference for who can send you private messages.
1.4 Discord Linking (Optional)
- If you use the
/link command in our Discord server, we store your Discord user ID and tag alongside your RSN. This is voluntary and can be unlinked.
1.5 Technical Data
- Connection and security data:IP addresses are used in memory for rate limiting. Submission and authentication audit records use a keyed IP hash; abuse bans can retain an IP address on disk. Web error logs and staging access logs can also contain IP addresses and request details.
- WebSocket connection state:used to track online status and deliver real-time updates. Security events may be recorded for abuse investigation.
1.6 Client-Side Storage (Your Browser)
We use your browser's localStorage to remember your preferences locally on your device:
- RSN, selected boss and mode, quick prayer choice
- Sound/music volume and mute preferences
- HUD element positions (if you've moved them)
- UI preferences (timestamps, keyboard mode, activity feed, etc.)
- Session authentication token
- Cached collection log data
These local copies keep your settings between visits. Your RSN and session token are also sent when needed for game and account requests. Clearing browser storage removes the local copies, not your server-side account.
2. What We Do NOT Collect
- Email addresses
- Real names or physical addresses
- Payment or financial information (the Game is entirely free)
- Advertising cookies or cross-site advertising trackers
- Data for advertising. Page-visit analytics are described below.
- Your actual RuneScape account credentials
3. How We Use Your Data
| Data | Purpose |
| RSN | Identify you on the leaderboard and in-game |
| Password hash | Authenticate you when you log in |
| Scores & stats | Populate the leaderboard and your profile |
| Friends/follows | Show online status and enable social features |
| Private messages | Deliver PMs and provide recent history on reconnect |
| IP address and keyed IP hash | Rate limiting, abuse prevention and operational diagnostics |
| Discord link | Connect your Discord identity to your in-game RSN |
We do not sell your data or use it for advertising. Service providers process information needed to host, protect and operate the Game; feature-specific services are listed below.
4. Data Retention
- Account and gameplay data:retained for as long as you have an account. Deletion requests remove your account data from the active service. Backup copies are handled separately as described below.
- Private messages:rolling cap of 50 per player. Older messages are automatically overwritten.
- Security records:memory-only rate limits clear as their entries expire or the process restarts. IP-based bans and audit records can persist. Some security logs rotate by size; this does not give every record a fixed expiry date.
- Discord links:retained until you unlink or request deletion.
Backups are kept for recovery and can retain earlier copies of game data. Backup retention is separate from the active service and from log rotation.
5. Data Security
- All connections to rigourhero.com use HTTPS/TLS encryption.
- WebSocket connections use WSS (encrypted WebSocket).
- Passwords are stored as one-way cryptographic hashes. The stored hash is used to check your password rather than retaining it in plaintext.
- Server access is restricted and protected by SSH key authentication and firewall rules.
- Rate limiting and lockout mechanisms protect against brute-force attacks.
6. Your Rights
Regardless of where you live, you have the right to:
- Access:request a copy of all data we hold about you.
- Correction:request correction of inaccurate data.
- Deletion:request permanent deletion of all data associated with your RSN. This includes scores, stats, inventory, friends, messages, and any other stored data.
- Data portability:request your data in a machine-readable format.
To exercise any of these rights, reach out to the site operator directly.
We will process deletion requests within 30 days. Your leaderboard entries, stats, pets, inventory, and social data will be removed from the active service. Backup copies can remain until their retention period expires.
7. Children's Privacy
Rigour Hero is not intended for children under the age of 13. We do not knowingly collect personal data from anyone under 13. If you are a parent or guardian and believe your child has provided data to us, please contact us and we will promptly delete it.
8. Third-Party Services
We interact with the following third-party services:
- OSRS Hiscores API (Jagex): to verify RSN existence and account type. We send only the RSN. Jagex's own privacy policy governs their handling of that request.
- TempleOSRS API:to retrieve boss kill counts for profile display. We send only the RSN.
- Discord:if you use our Discord bot, Discord's privacy policy applies to data processed by Discord.
- GoatCounter:counts page visits without advertising cookies. See its privacy documentation.
- Telegram:receives game and operator notifications, which can include RSNs, scores, rewards and security-event details such as keyed IP hashes.
- Hosting and network protection:process requests and operational data needed to serve and protect the site.
9. Changes to This Policy
We may update this policy as features change. The "last updated" date at the top will reflect the most recent revision. Continued use of the Game after changes constitutes acceptance of the updated policy.
10. Contact
For any privacy-related questions or requests, reach out to the site operator directly.
Created using intellectual property belonging to Jagex Limited under the terms of Jagex's
Fan Content Policy. Not endorsed by or affiliated with Jagex.