Faux Bingo is a scoreboard for a community Old School RuneScape event. It is run by one volunteer, not a company. This notice explains what personal data the site holds, why, who can see it, how long it is kept, and what you can do about it.
The short version: no analytics, no advertising, no tracking, and nothing is sold. The site holds your Discord identity, the RuneScape accounts you choose to register through the plugin, the drops the plugin reports, and the images you or the plugin upload. Much of that is public on the site by design, because it is a public scoreboard. You can see and erase all of it yourself at any time from Your data.
1. Who is responsible
The data controller is Daniel Goudie ("we", "us"), who operates Faux Bingo as an individual based in the United States.
- Email: [email protected]
- Discord: message an event admin in the event's Discord server
We have not appointed a data protection officer, because the law does not require one for an operation of this size. Questions about this notice go to the email above.
This notice covers the Faux Bingo website, its plugin API, and its AI-assistant (MCP) connector. It does not cover Discord, Jagex, RuneLite, Wise Old Man, or any other service the event uses; they have their own policies.
Faux Bingo is run by members of the community around the live streamer known as Faux, who knows about and endorses the site. He does not operate it, is not a controller of your data, and is not responsible for how it is handled. Questions and requests about your data go to us, not to him.
2. What we collect
2.1 When you sign in with Discord
Signing in uses Discord OAuth with the identify and guilds.members.read
scopes. We never see your Discord password or email address. We store:
| Data | Why |
|---|---|
| Your Discord user ID | The stable key that identifies you |
| Your Discord display name (server nickname, global name, or username) | Shown as your name on the site. It is updated from Discord when you sign in and on a regular background refresh, so it follows your renames |
| Your Discord avatar reference | Shown beside your name |
| Which team you are on, and whether you are a captain or admin | Worked out from your roles in the event's Discord server |
A player token (a string beginning fbp_) | The credential the game plugin uses. Treat it like a password |
2.2 Your Discord server roles
To check access without calling Discord on every page load, the site keeps your Discord user ID and the IDs of the roles you hold in the event's Discord server, and nothing else. This starts when you sign in. Apart from the event's admins and captains, only people who have signed in have an entry.
About every two minutes the site's bot reads the server's member list from Discord to bring those roles up to date. That read covers every member of the server, because it is also how the site notices a player losing their team role or changing their name, but nothing from it is stored about anyone who does not already have an entry. Your entry is removed when you leave the server or erase your data.
2.3 Security log
We keep a log of sign-ins, sign-outs, and access checks that failed or denied access, each with the Discord user ID and display name involved, a timestamp, and a short note on what happened. It is used to diagnose sign-in problems and misuse, and only admins can read it.
2.4 From the RuneLite plugin, if you install it
The plugin is optional, and none of this is collected unless you install it and enter your player token. It sends:
- Account identifiers: the
accountHashthe game client provides for your RuneScape account, your character name, and account type (for example, Ironman). - Where you were playing: the world number and world type flags.
- Game events: drops, collection log entries, pets, and deaths, including item names, item IDs, quantities, the source (such as the monster), and timestamps.
- The full original event message as sent by the plugin, kept verbatim so events can be re-read later rather than lost.
- Plugin details: the plugin version and how a drop was detected.
- Play sessions: when you started playing and when the plugin last checked in, used to work out playtime.
- Screenshots taken automatically when a drop is detected.
A screenshot is a picture of your whole game client. It may show your character name, your chat box, private messages, other players' names and messages, and anything else on screen at that moment. If you would not want a chat line seen by the event, do not leave it on screen while playing with the plugin active.
2.5 What you add on the site
- Verification images you upload to show your starting state.
- Tile images you or your captain upload as evidence for a tile.
- Emoji reactions you add to drops in the live drop stream, stored with your member record.
- Uploaded images are re-encoded (for example, converted to WebP and resized to at most 2560×1440) to save space. Re-encoding removes most embedded metadata, such as camera or location data, but you should not rely on that.
2.6 Cookies and browser storage
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
faux-bingo-jwt | Cookie | Keeps you signed in. HTTP-only, so page scripts cannot read it | 7 days |
discord_oauth_state | Cookie | Protects sign-in against forged requests | 10 minutes |
mcp_oauth_pending | Cookie | Only set while you connect an AI assistant | 10 minutes |
| Sidebar display mode | Browser local storage | Remembers a display choice you made | Until you clear it |
| Recently used emoji | Browser local storage | Remembers emoji you picked | Until you clear it |
Browser storage never leaves your device. Our hosting security provider,
Cloudflare, may also set short-lived security cookies (such as __cf_bm) to
tell people from bots.
All of these are strictly necessary for a service you asked for or remember a choice you made yourself, so the site does not show a consent banner. There are no analytics, advertising, social media, or tracking cookies, and no third-party scripts.
2.7 Connection data
All traffic reaches the site through Cloudflare, which handles your IP address and ordinary request details (such as browser type and the page requested) to deliver the site and protect it from attacks. The site's own code does not record your IP address.
2.8 What we do not want
We do not ask for special category data (such as health, religion, or ethnicity), and please do not include any in an upload. We do not collect payment details; nothing on the site costs money.
3. Do you have to provide it?
- Discord sign-in is required to take part as a player, captain, or admin. Without it you can still view the public pages.
- The plugin is optional. Without it, your drops will not be tracked automatically, and evidence has to be uploaded by hand.
- Images and reactions are optional.
4. Why we use it, and our legal basis
This table gives the legal basis under the UK and EU GDPR for each purpose.
| Purpose | Legal basis |
|---|---|
| Signing you in, working out your team and role, issuing and checking your player token | Contract: needed to provide the site under the Terms of Use you accept by taking part |
| Recording plugin data, scoring drops against tiles, totalling points, working out playtime | Contract: this is the service you ask for by installing the plugin and entering your token |
| Storing and showing images and reactions you add | Contract, as above |
| Showing names, teams, drops, and evidence publicly on the scoreboard | Legitimate interests: a community competition needs results that participants and spectators can check |
| Keeping your Discord server roles, and reading the server's member list to update them | Legitimate interests: controlling access reliably without depending on Discord's rate limits |
| The security log, and protecting the site from misuse (including via Cloudflare) | Legitimate interests: keeping the site and people's accounts secure |
| Keeping evidence after a drop is scored, so disputes can be settled | Legitimate interests: a fair competition needs checkable evidence |
| Responding to legal claims or lawful requests | Legal obligation or legitimate interests in establishing or defending legal claims |
We have weighed these interests against yours. The data involved is limited to what an ordinary game event needs, it is already visible within the clan or the game, and you can object at any time (see section 9).
We do not use your data for marketing, profiling, or training AI models.
5. Automated decisions
The site automatically matches drops against tile rules and, when there is only one possible tile, adds the drop to that tile. This decides game points only. It has no legal or similarly significant effect on you, and captains and admins can review, move, or reject any scored drop.
6. Who can see it
Anyone, without signing in
The site is a public scoreboard. Anyone who visits can see:
- your display name, your team, and your role as a captain (where shown);
- drops reported for you (item names and values, and the tile they counted toward);
- screenshots attached to drops that were shown in the drop stream or counted toward a tile, whether you uploaded them or the plugin captured them;
- verification images and tile images;
- your emoji reactions and your name beside them.
Public pages can be copied or saved by visitors, and search engines may index them. Removing something from the site cannot recall copies others have made.
Your character names are not shown on public pages, and playtime is not shown publicly.
Other participants using the plugin
The plugin API gives every signed-in participant the event roster, including each player's registered character names, so the plugin can show team badges in clan chat.
Captains and admins
Captains can manage evidence for their own team. Admins can see everything the site stores, including the full drop log, character names, and the security log.
AI assistants you connect
Signed-in users can connect an AI assistant to the site through its MCP connector. The assistant can read teams, active member display names, tiles, and scores. Anything it reads is then handled by that assistant's provider under their own terms. It has no access to images, tokens, character names, or the security log.
Service providers
- Cloudflare, Inc. provides the network and security layer every request passes through. It processes connection data for us under its data processing terms and is certified under the EU–US Data Privacy Framework.
- Discord receives your sign-in on its own systems, under Discord's privacy policy. We use Discord to identify you and read server roles; we do not send Discord any other data about you.
Nobody else
We do not sell, rent, or share personal data for advertising. We would only disclose data to a court, authority, or other party if the law requires it, or if it is necessary to establish, exercise, or defend a legal claim.
7. Where it is stored
The database and images are stored on a server the operator owns, located in the United States. Cloudflare may process connection data in data centres worldwide, including near you.
If you are in the UK or EEA, you provide your data directly to us in the United States, and the UK and EU GDPR apply to that processing. The United States does not have the same data protection laws as the UK or EU, but this notice and the protections described in it apply to your data wherever you are. Cloudflare's processing is covered by the EU–US Data Privacy Framework (and its UK extension) and its data processing terms.
8. How long we keep it
| Data | How long |
|---|---|
| Screenshots of drops that were neither shown in the drop stream nor counted toward a tile | Deleted automatically about 24 hours after upload (the check runs when new drops arrive, so on a quiet site it can take a little longer) |
| Your member record, registered accounts, drop events, play sessions, other images, reactions | For the event, then for as long as the results site stays online so results remain checkable, until you erase it yourself from Your data, ask us to (section 9), or the site is retired |
| Security log | Same as above |
| Discord server roles | From when you sign in; updated about every 2 minutes, and removed at the first refresh after you leave the server, or when you erase your data |
| Sign-in cookie | 7 days |
| Cloudflare connection logs | Under Cloudflare's own retention periods |
When the site is retired, its database is deleted.
9. Your rights
If you are in the UK or EEA, the GDPR gives you the right to:
- access the personal data we hold about you and get a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict how we use it;
- receive data you gave us in a portable, machine-readable format;
- object to processing based on legitimate interests (see below);
- complain to a data protection authority.
Your right to object. Where we rely on legitimate interests (section 4), you can object at any time, on grounds relating to your situation. We will stop unless we have compelling legitimate grounds that override your interests, or need the data for legal claims.
We give these rights to everyone, wherever they live.
Do it yourself. Sign in and open Your data. It lists everything stored against your Discord account and erases all of it immediately, with no request and no wait.
Or ask us. Email [email protected] or message an event admin on Discord. Your identity here is your Discord account, so we may ask you to confirm the request from that account. There is no charge. We will respond within one month, which we may extend by up to two more months for complex requests, in which case we will tell you why.
What erasure removes. Whether you erase your data yourself or an admin does it for you, it deletes the member record and player token, every registered RuneScape account, every play session, every drop event reported for those accounts (including the stored original messages), every screenshot and image uploaded by or captured for that person, their emoji reactions, their stored Discord server roles, and their entries in the security log. Team scores and tile results that drops already earned are kept, so erasing one person does not change the scoreboard for everyone else; they no longer identify you.
If you are erased but still hold a team role in the event's Discord server, signing in again creates a new record. To leave for good, leave the server or ask an admin to remove your team role first.
Complaints. Please contact us first so we can try to fix it. You can also complain to your data protection authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the authority in the country where you live or work (list of EU authorities).
10. Security
We protect data with measures proportionate to a small volunteer site: encrypted HTTPS connections through Cloudflare, HTTP-only session cookies, access checks on every write, admin-only access to the security log and drop log, and public pages that receive only the fields they display, never tokens or Discord role details. No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will notify the relevant authority where the law requires it, and tell affected people without undue delay where the risk is high.
If you find a security problem, please email [email protected] rather than testing it against other people's data.
11. Children
The site is only for people aged 18 or over (see the Terms of Use). We do not knowingly collect data from anyone under 18. If you believe someone under 18 is taking part, email [email protected] and we will remove their data.
12. US residents
We do not sell or "share" personal information for cross-context behavioural advertising, and we do not use sensitive personal information to infer characteristics about you. Whichever US state you live in, you can ask to access, correct, or delete your data using the contact details in section 9, and we will not treat you differently for doing so.
13. Changes to this notice
This notice is kept in the site's public source repository, so every change has a date and a readable history. The date at the top shows the latest revision. We will announce material changes in the event's Discord server before they take effect, and if a change needs your consent we will ask for it.