Sharing and permissions
Who sees which parts of an account, and how an owner changes it.
Privacy has two layers:
- The plugin decides what is sent at all, in its own settings.
- The hub decides who sees what arrived. Each account's owner sets that per category.
Categories and defaults
| Category | Covers | Default audience |
|---|---|---|
stats | skills, XP history, gains, levels | guild |
events | loot, level-ups, deaths, collection log, diaries, combat tasks, superiors | guild |
activity | online status, world, sessions and playtime, HP, prayer, spellbook | guild |
location_live | current coordinates | guild |
location_history | the 30-day trail | private |
equipment | current gear and its change log | private |
inventory | current inventory and wealth history | private |
Death and superior locations follow location_live: a member who can't see where you are can't see
where you died either.
Audiences
Each category has one audience:
- Private: only the account's players (its owner and contributors).
- Guild: every active member of the guild. This is also what integration keys see.
- Selected: only the members you grant access to.
Owners and players
Accounts don't belong to Discord users directly; they belong to whoever's RuneLite reports them. Every player whose device reports an account becomes one of its players and always sees everything about it. One of them is the owner, and only the owner changes who sees what.
On the account page's Sharing panel, the owner can:
- set each category's audience, and grant or remove access for selected members;
- block a player: nothing their RuneLite sends for the account is stored any more, and they lose the player's view. Blocking can be undone;
- remove a player: they stop being a player of the account, until their RuneLite reports it again. Block them to keep them out;
- transfer ownership to another player.
An account without an owner, for example after its owner left the guild, can be claimed by one of its players. Until then, nobody can change its sharing.
What admins see
Admins manage members, devices and the hub itself, but admin rights never apply through the API, and
integration keys see only what is shared with the guild. The hub's public /privacy page lists what
is stored, for how long, and what admins can see.