osrs-data-hub

Sharing and permissions

Who sees which parts of an account, and how an owner changes it.

Privacy has two layers:

  1. The plugin decides what is sent at all, in its own settings.
  2. The hub decides who sees what arrived. Each account's owner sets that per category.

Categories and defaults

CategoryCoversDefault audience
statsskills, XP history, gains, levelsguild
eventsloot, level-ups, deaths, collection log, diaries, combat tasks, superiorsguild
activityonline status, world, sessions and playtime, HP, prayer, spellbookguild
location_livecurrent coordinatesguild
location_historythe 30-day trailprivate
equipmentcurrent gear and its change logprivate
inventorycurrent inventory and wealth historyprivate

Death and superior locations follow location_live: a member who can't see where you are can't see where you died either.

Audiences

Each category has one audience:

  • Private: only the account's players (its owner and contributors).
  • Guild: every active member of the guild. This is also what integration keys see.
  • Selected: only the members you grant access to.

Owners and players

Accounts don't belong to Discord users directly; they belong to whoever's RuneLite reports them. Every player whose device reports an account becomes one of its players and always sees everything about it. One of them is the owner, and only the owner changes who sees what.

On the account page's Sharing panel, the owner can:

  • set each category's audience, and grant or remove access for selected members;
  • block a player: nothing their RuneLite sends for the account is stored any more, and they lose the player's view. Blocking can be undone;
  • remove a player: they stop being a player of the account, until their RuneLite reports it again. Block them to keep them out;
  • transfer ownership to another player.

An account without an owner, for example after its owner left the guild, can be claimed by one of its players. Until then, nobody can change its sharing.

What admins see

Admins manage members, devices and the hub itself, but admin rights never apply through the API, and integration keys see only what is shared with the guild. The hub's public /privacy page lists what is stored, for how long, and what admins can see.

On this page