Privacy
QuestRouter is a free, open-source addon for World of Warcraft: Forever. It builds leveling routes from quest data that players choose to share. This page explains exactly what is shared, what the optional character profiles add, and how to export or remove all of it. QuestRouter is run by Moikas LLC.
Sharing is off until you turn it on
The addon's collector does nothing until you agree in its opt-in dialog or type /qr collect on.
/qr collect off stops it at any time, and /qr collect status shows what it is doing.
The route guide works without sharing. Character profiles are a second, separate choice (see
below), off unless you turn them on.
What the collector records
Only quest and world data, with timestamps:
- quest IDs when you accept, progress, abandon or turn in a quest, plus the XP and money a quest awarded;
- quest giver, mob and NPC IDs and names (these are game-world data, not players);
- item IDs you loot, and the creature they came from;
- your map position (map ID plus x/y) at those moments, and a movement trail sampled every 5 seconds while you move;
- your level, and your class, race and faction (used to build routes per faction and class quests);
- the game build, interface version and client locale;
- the list of quest IDs you have completed, once per session.
Each play session gets a random ID that changes every login. The addon stores all of this in its own
SavedVariables file on your computer. The game writes that file only when you log out or /reload.
What is never collected
- your character name, realm or guild;
- your player GUID. With profiles on, only a salted hash of it is sent; the GUID itself never leaves the game;
- your Battle.net or game account, or any login details for them;
- chat, whispers, or other players' names;
- anything from your computer outside the addon's own SavedVariables files.
How it is uploaded
WoW addons cannot use the network, so nothing leaves your computer until you send it from outside the game.
The main way is the upload page: you choose the addon's
QuestRouter.lua file, and your browser reads that one file, on your computer. The page reads
nothing else, and the file itself is never uploaded. It removes every field that is not on the published
allowlist
(submission schema),
shows you what is left, and sends it over HTTPS only when you select Send.
The optional companion app does the same automatically, only if you install it: it reads the addon's file,
applies the same allowlist and sends the rest. qr-upload dry-run shows exactly what would be sent.
Every upload carries a random install ID, created once by the companion or kept in your browser's local storage by the upload page. It is not derived from your computer, account or characters. The first upload asks you to pass a Cloudflare Turnstile check for that ID, to keep bots out. Cloudflare processes browser signals for that check under its Turnstile privacy addendum. QuestRouter only learns pass or fail. To check the result, the API sends Cloudflare the check's token and your IP address, as Turnstile recommends, and keeps neither.
Uploads are rate-limited per install ID and per IP address. For that the API stores a keyed, shortened hash of your IP address (not the address itself), counted per minute and deleted after about two hours.
If you don't use the companion, /qr export gives you a text string with the same data.
The export page decodes it in your browser and shows what it holds. Only when you
select Send does it upload the string's data, cut to the same allowlist the companion uses.
It uses the same install ID as the upload page in that browser, and the first upload from a browser asks
for the same Turnstile check.
Where it is stored and how it is used
Uploads are stored on Cloudflare (R2 object storage and a D1 database) in the project owner's account. A pipeline cleans and combines everyone's data. For example, it finds where quest givers stand and where objectives are done. It scores data quality, sometimes with Cloudflare Workers AI, and turns the result into route data packs. Packs and coverage statistics contain combined, anonymous world data and are published with the addon. Uploads themselves are never sold, licensed or shared for advertising; see publishing and licensing.
Character profiles (a second, separate opt-in)
Profiles let you see your own characters on app.questrouter.app:
level curve, quests, sessions and, if you choose, a public page. They are off by default and only
available while sharing is on. After you agree to share, the addon asks a second, separate question about
profiles; you can also turn them on later with /qr profile on. /qr profile off turns them off and removes the character ID and snapshots from every session not
uploaded yet. /qr profile status shows the current state. Without profiles, uploads are exactly as
described above.
The character ID
With profiles on, each session carries a character ID. The addon computes it in the game as a SHA-256 hash of a random salt and the character's GUID, and keeps the first 32 hex characters. The salt is generated once per WoW account folder on your computer and stays in your SavedVariables file; it is never uploaded. The raw GUID never leaves the game and is never written to disk. Without your salt, the ID cannot be turned back into a character, and the same character played on another computer gets a different ID.
Snapshots
With profiles on, sessions also carry snapshots, recorded at login and when they change:
- gear: the item IDs in your 19 equipment slots and your average item level;
- gold: the amount of money on the character;
- professions: skill line, rank and maximum rank;
- talents: points per talent tree, or the talent loadout string.
Claiming
Until you claim a character, its profile is shown nowhere. Only the companion install that uploaded it can list it (class, race, faction, level and when it was last seen) to offer the claim; the companion labels the list with the character folder names in your WoW directory, shown on your computer only and never sent. You enter a pairing code from app.questrouter.app (valid 10 minutes, single use), and only an install that uploaded a character can claim it.
If nobody claims a character, the profile tables built for it are deleted after 180 days without new uploads. The uploads themselves are kept like any other upload, still carrying the character ID and snapshots, until you delete them with Delete my data.
Public pages
Characters are private unless you make one public in the app's settings, or turn on the setting that makes
characters you claim from then on public (off by default). A public page
(app.questrouter.app/p/<name>) shows anyone with the link the character's display name, class,
race, faction, level, level curve, number of quests and zones; never gear, gold, professions, talents or
sessions. The display name is whatever you type, and it does not have to be the character's name. Making the
page private again takes it down within a minute.
Character profiles never feed the routes or the published dataset: the pipeline that builds them ignores character IDs and snapshots completely.
Website accounts and payments
To claim characters you sign in to app.questrouter.app with an email address. There is no password: we send a
one-time sign-in link, valid for 15 minutes and usable once, through our email provider (Resend). We store your
email address, the hashed sign-in link until it expires, and a hashed session token for the
qr_session cookie, which keeps you signed in for up to 30 days. We use your email address only to sign
you in, never for marketing. It is shared only with the email provider, to send the link, and with Stripe if you
subscribe to Pro. Sign-in requests are rate-limited per email address and per IP address; for that the API
stores a keyed, shortened hash of each (never the address itself), deleted after about two hours.
Paid features are not offered yet. There is no Pro subscription to buy, and QuestRouter takes no payments for profiles. The next paragraph describes how Pro payments will work if Pro is offered.
Pro subscriptions are paid through Stripe. Checkout and the billing portal are Stripe pages: your card details go directly to Stripe and never touch QuestRouter's servers. We store only your Stripe customer and subscription IDs, your tier and when it ends, and the IDs of Stripe's billing notifications (to process each one once). Stripe handles payment data under the Stripe privacy policy and keeps the payment records the law requires. Pro changes only what the profile site shows you; uploads, route data and the in-game guide are the same on every tier.
Publishing and licensing the combined data
When you turn sharing on, you agree to this (consent version 2 in the addon and the companion app):
Aggregated, anonymized quest data is published and may be licensed in aggregate (non-commercial use free, commercial use paid).
The combined dataset is free for non-commercial use under CC BY-NC 4.0, and Moikas LLC may license it for commercial use. It holds only combined world data such as quest-giver positions, objective areas, timings and routes. It never contains sessions, trails, install IDs, character IDs, profiles or anything else about one player. See the dataset page. If this wording changes, the addon pauses collection and asks you again; nothing recorded under older terms is uploaded.
Deleting and exporting your data
Uploads
In the companion app, choose Delete my data (or run qr-upload delete-my-data).
For uploads sent from the upload page or the export page,
open either page in the same browser and choose Delete my uploads. Either deletes every upload stored for that install ID, both raw files
and database rows, and removes its registration, including profile data of characters only that install
uploaded and nobody claimed. The app then stops uploading. Routes that were already built and released stay as
they are, because they contain no per-player data.
Characters and accounts
- Delete a character (settings on app.questrouter.app) deletes its profile tables and the character record, and rewrites every stored upload that carried its character ID: the ID is removed and the snapshots are stripped. Your anonymous quest data stays, as if profiles had been off.
- Delete your account does that for every claimed character, cancels any subscription, deletes your customer record at Stripe, and deletes your email address, sign-in links, sessions and pairing codes. Billing notification IDs are kept, unlinked from you, so a late notification cannot recreate anything.
- Export downloads everything stored for a character as JSON, at any time, on any tier.
The database's point-in-time recovery (Cloudflare D1 Time Travel) can still restore deleted rows for up to 30
days; after that they are gone. To stop collecting in game, use /qr collect off (it also turns
profiles off). To clear what is stored locally, delete
WTF/Account/<account>/SavedVariables/QuestRouter.lua; /qr profile off also offers
to forget the profile salt, which gives your characters new IDs if you turn profiles on again.
This website
This site (questrouter.app) sets no cookies and uses no analytics or third-party trackers. It talks to the QuestRouter API to show coverage, to register an install ID and, from the upload and export pages, to send the data you choose to send. The upload page reads only the file you choose, in your browser. The registration, upload and export pages load Cloudflare Turnstile when a check is needed. The upload and export pages keep the install ID in your browser's local storage, and the upload page also keeps the IDs and sizes of the sessions it uploaded, so it does not send them twice; nothing else is stored. Like any web host, Cloudflare Pages may keep standard request logs.
If you sign in to app.questrouter.app, its sign-in cookie is set for questrouter.app and its subdomains, so your browser also sends it to this site, which ignores it.
The support page links to Ko-fi and Patreon, which handle donations under their own privacy policies. The credits list only names people asked us to show. If the dashboard shows a sponsor, it is a plain link labelled "Sponsor": no sponsor scripts, pixels or tracking.
Questions
Open an issue on GitHub. All QuestRouter code is open source, so you can check every claim on this page.