Privacy

QuestRouter is a free, open-source addon for World of Warcraft: Forever. It builds leveling routes from quest data that players choose to share. This page explains exactly what is shared, what the optional character profiles add, and how to export or remove all of it. QuestRouter is run by Moikas LLC.

Sharing is off until you turn it on

The addon's collector does nothing until you agree in its opt-in dialog or type /qr collect on. /qr collect off stops it at any time, and /qr collect status shows what it is doing. The route guide works without sharing. Character profiles are a second, separate choice (see below), off unless you turn them on.

What the collector records

Only quest and world data, with timestamps:

Each play session gets a random ID that changes every login. The addon stores all of this in its own SavedVariables file on your computer. The game writes that file only when you log out or /reload.

What is never collected

How it is uploaded

WoW addons cannot use the network, so nothing leaves your computer until you send it from outside the game. The main way is the upload page: you choose the addon's QuestRouter.lua file, and your browser reads that one file, on your computer. The page reads nothing else, and the file itself is never uploaded. It removes every field that is not on the published allowlist (submission schema), shows you what is left, and sends it over HTTPS only when you select Send.

The optional companion app does the same automatically, only if you install it: it reads the addon's file, applies the same allowlist and sends the rest. qr-upload dry-run shows exactly what would be sent.

Every upload carries a random install ID, created once by the companion or kept in your browser's local storage by the upload page. It is not derived from your computer, account or characters. The first upload asks you to pass a Cloudflare Turnstile check for that ID, to keep bots out. Cloudflare processes browser signals for that check under its Turnstile privacy addendum. QuestRouter only learns pass or fail. To check the result, the API sends Cloudflare the check's token and your IP address, as Turnstile recommends, and keeps neither.

Uploads are rate-limited per install ID and per IP address. For that the API stores a keyed, shortened hash of your IP address (not the address itself), counted per minute and deleted after about two hours.

If you don't use the companion, /qr export gives you a text string with the same data. The export page decodes it in your browser and shows what it holds. Only when you select Send does it upload the string's data, cut to the same allowlist the companion uses. It uses the same install ID as the upload page in that browser, and the first upload from a browser asks for the same Turnstile check.

Where it is stored and how it is used

Uploads are stored on Cloudflare (R2 object storage and a D1 database) in the project owner's account. A pipeline cleans and combines everyone's data. For example, it finds where quest givers stand and where objectives are done. It scores data quality, sometimes with Cloudflare Workers AI, and turns the result into route data packs. Packs and coverage statistics contain combined, anonymous world data and are published with the addon. Uploads themselves are never sold, licensed or shared for advertising; see publishing and licensing.

Character profiles (a second, separate opt-in)

Profiles let you see your own characters on app.questrouter.app: level curve, quests, sessions and, if you choose, a public page. They are off by default and only available while sharing is on. After you agree to share, the addon asks a second, separate question about profiles; you can also turn them on later with /qr profile on. /qr profile off turns them off and removes the character ID and snapshots from every session not uploaded yet. /qr profile status shows the current state. Without profiles, uploads are exactly as described above.

The character ID

With profiles on, each session carries a character ID. The addon computes it in the game as a SHA-256 hash of a random salt and the character's GUID, and keeps the first 32 hex characters. The salt is generated once per WoW account folder on your computer and stays in your SavedVariables file; it is never uploaded. The raw GUID never leaves the game and is never written to disk. Without your salt, the ID cannot be turned back into a character, and the same character played on another computer gets a different ID.

Snapshots

With profiles on, sessions also carry snapshots, recorded at login and when they change:

Claiming

Until you claim a character, its profile is shown nowhere. Only the companion install that uploaded it can list it (class, race, faction, level and when it was last seen) to offer the claim; the companion labels the list with the character folder names in your WoW directory, shown on your computer only and never sent. You enter a pairing code from app.questrouter.app (valid 10 minutes, single use), and only an install that uploaded a character can claim it.

If nobody claims a character, the profile tables built for it are deleted after 180 days without new uploads. The uploads themselves are kept like any other upload, still carrying the character ID and snapshots, until you delete them with Delete my data.

Public pages

Characters are private unless you make one public in the app's settings, or turn on the setting that makes characters you claim from then on public (off by default). A public page (app.questrouter.app/p/<name>) shows anyone with the link the character's display name, class, race, faction, level, level curve, number of quests and zones; never gear, gold, professions, talents or sessions. The display name is whatever you type, and it does not have to be the character's name. Making the page private again takes it down within a minute.

Character profiles never feed the routes or the published dataset: the pipeline that builds them ignores character IDs and snapshots completely.

Website accounts and payments

To claim characters you sign in to app.questrouter.app with an email address. There is no password: we send a one-time sign-in link, valid for 15 minutes and usable once, through our email provider (Resend). We store your email address, the hashed sign-in link until it expires, and a hashed session token for the qr_session cookie, which keeps you signed in for up to 30 days. We use your email address only to sign you in, never for marketing. It is shared only with the email provider, to send the link, and with Stripe if you subscribe to Pro. Sign-in requests are rate-limited per email address and per IP address; for that the API stores a keyed, shortened hash of each (never the address itself), deleted after about two hours.

Paid features are not offered yet. There is no Pro subscription to buy, and QuestRouter takes no payments for profiles. The next paragraph describes how Pro payments will work if Pro is offered.

Pro subscriptions are paid through Stripe. Checkout and the billing portal are Stripe pages: your card details go directly to Stripe and never touch QuestRouter's servers. We store only your Stripe customer and subscription IDs, your tier and when it ends, and the IDs of Stripe's billing notifications (to process each one once). Stripe handles payment data under the Stripe privacy policy and keeps the payment records the law requires. Pro changes only what the profile site shows you; uploads, route data and the in-game guide are the same on every tier.

Publishing and licensing the combined data

When you turn sharing on, you agree to this (consent version 2 in the addon and the companion app):

The combined dataset is free for non-commercial use under CC BY-NC 4.0, and Moikas LLC may license it for commercial use. It holds only combined world data such as quest-giver positions, objective areas, timings and routes. It never contains sessions, trails, install IDs, character IDs, profiles or anything else about one player. See the dataset page. If this wording changes, the addon pauses collection and asks you again; nothing recorded under older terms is uploaded.

Deleting and exporting your data

Uploads

In the companion app, choose Delete my data (or run qr-upload delete-my-data). For uploads sent from the upload page or the export page, open either page in the same browser and choose Delete my uploads. Either deletes every upload stored for that install ID, both raw files and database rows, and removes its registration, including profile data of characters only that install uploaded and nobody claimed. The app then stops uploading. Routes that were already built and released stay as they are, because they contain no per-player data.

Characters and accounts

The database's point-in-time recovery (Cloudflare D1 Time Travel) can still restore deleted rows for up to 30 days; after that they are gone. To stop collecting in game, use /qr collect off (it also turns profiles off). To clear what is stored locally, delete WTF/Account/<account>/SavedVariables/QuestRouter.lua; /qr profile off also offers to forget the profile salt, which gives your characters new IDs if you turn profiles on again.

This website

This site (questrouter.app) sets no cookies and uses no analytics or third-party trackers. It talks to the QuestRouter API to show coverage, to register an install ID and, from the upload and export pages, to send the data you choose to send. The upload page reads only the file you choose, in your browser. The registration, upload and export pages load Cloudflare Turnstile when a check is needed. The upload and export pages keep the install ID in your browser's local storage, and the upload page also keeps the IDs and sizes of the sessions it uploaded, so it does not send them twice; nothing else is stored. Like any web host, Cloudflare Pages may keep standard request logs.

If you sign in to app.questrouter.app, its sign-in cookie is set for questrouter.app and its subdomains, so your browser also sends it to this site, which ignores it.

The support page links to Ko-fi and Patreon, which handle donations under their own privacy policies. The credits list only names people asked us to show. If the dashboard shows a sponsor, it is a plain link labelled "Sponsor": no sponsor scripts, pixels or tracking.

Questions

Open an issue on GitHub. All QuestRouter code is open source, so you can check every claim on this page.