Privacy Policy
Effective 4 September 2026 · marketwyrm.com
The short version
MarketWyrm collects the minimum it needs to run: an email address, a username, and the watchlists, price targets, and settings you choose to save. With your separate permission, it may use privacy-limited first-party usage counts, Google Analytics, Yandex Metrica, and a small number of fixed display/native ads on selected pages. MarketWyrm does not sell your account data, and it does not use popup, popunder, interstitial, or notification-style ad formats. Delete your account and your saved account data goes with it.
Who we are
MarketWyrm (marketwyrm.com) is a fan-made Grand Exchange trends tool for RuneScape 3 and Old School RuneScape, run independently from the Netherlands and Canada. For anything in this policy, email MarketWyrm@gmail.com. MarketWyrm is not affiliated with Jagex Ltd.
What we collect
You can browse without an account. Guest requests are rate-limited by IP address, but the address is hashed before it touches our database and the counters are deleted within 24 hours — we do not keep a MarketWyrm database log of raw visitor IP addresses. The app also gives the browser a random visitor ID used for abuse prevention and, only if you accept Analytics, records compact page, item, and successful-search events for aggregate site statistics. It does not attach an email, username, or search text to those events, it excludes the admin account, and the first-party analytics collector honours the browser's Do Not Track setting.
If you accept Analytics, Google Analytics and Yandex Metrica collect standard website-measurement data, including page URLs, referrers, session statistics, approximate location, browser/device information, and aggregate page, link, and click interactions. Their cookies distinguish visitors and sessions. Yandex Session Replay and form analysis are disabled. MarketWyrm does not deliberately send either service your email address, username, account ID, watchlist, targets, notes, or search text. Analytics is disabled on internal search-result URLs and while an authentication callback contains sensitive parameters. MarketWyrm uses Basic Consent Mode for Google and the same prior-opt-in standard for Yandex: neither vendor tag is downloaded before Analytics consent.
If you create an account, we collect and store:
- Your email address and a username. Your password is stored only in hashed form by our authentication provider — we never see or store it in plain text.
- What you save in the app: your watchlist (followed items, buy/sell targets, and any notes you attach), your settings (such as the email-alerts switch and an optional bankroll amount used to size suggestions), and any screeners, strategies, or backtest results you save in the lab.
- Alert delivery details: if you enable notifications on a device, your browser issues a push subscription (a delivery address plus encryption keys) that we store so the server can reach that device.
- Operational records: short-lived rate-limit counters, and minimal delivery logs (did an alert send or fail) kept so we can tell when alerts are broken.
What we don't do
- No selling or renting your MarketWyrm account data.
- No popup, popunder, interstitial, fake-message, or notification-style advertising.
- No third-party ad code in the top-level page. Remote creatives run inside a restricted, opaque-origin frame with no popup or navigation permission.
- No MarketWyrm account profile or saved app data is deliberately sent to Google Analytics or Yandex Metrica. MarketWyrm's separate compact first-party counters go only to its own same-origin endpoint, require Analytics consent, and honour Do Not Track.
- No ad network receives your MarketWyrm email, username, watchlist, targets, or notes.
Storage on your device
MarketWyrm keeps a small amount of data in your browser's local storage: your signed-in
session, a random first-party visitor ID used for rate limiting and optional analytics, which game and theme you
last used, chart preferences, a cache of the item catalogue, and a cache of the latest scan results so the app opens fast.
Signing out removes your session and your account's cached results from the device. The app
also caches its own static files (code, fonts, images — never your data) so it can load
offline. A strictly necessary local-storage record remembers your Analytics and Advertising
choices so the site can respect them. If you accept Analytics, Google Analytics uses first-party cookies such as _ga and
_ga_<container-id>, and Yandex Metrica may use identifiers such as _ym_uid,
to distinguish visitors and retain session state. Adsterra or an
advertiser may also use cookies, pixels, or similar browser storage inside the restricted ad
frame to the extent your browser permits, but only after you accept Advertising.
How we use your information
- To run the service: your watchlist and settings exist so the app can show them back to you and so the server can watch prices for you.
- To send alerts you asked for: when a price crosses a target you set, we notify you by device notification and/or email — each only if you turned it on.
- Account housekeeping: sign-up confirmation and password-reset emails.
- To keep the service fair: rate limiting and abuse prevention.
- To improve the site: aggregate first-party counts, Google Analytics, and Yandex Metrica reports show how visitors use pages and features. MarketWyrm does not deliberately include account details or search text in those analytics events.
- To fund the free service: selected public/content-end placements can request a display or native advertisement after you accept Advertising and after the site's admin policy and audience status resolve.
That's the whole list. MarketWyrm does not use your account data for advertising profiles, marketing, or training. Price predictions are computed from public market data, not from user data.
Emails we send
Two kinds, from two systems:
- Account emails (confirmation, password reset) are sent by our authentication provider, Supabase, and only when you trigger them.
- Price alerts come from alerts@marketwyrm.com via Cloudflare Email Service, our active email delivery provider, and only if you switched email alerts on. Every alert email carries a one-click unsubscribe link that works without signing in.
Device notifications
Push notifications are optional and per-device. If you enable them, delivery goes through your browser vendor's push service (Google, Mozilla, or Apple, depending on your browser); the notification content is encrypted end-to-end so the push service can't read it. Disabling notifications, or revoking permission in your browser, deletes the subscription from our server. Expired subscriptions are cleaned up automatically.
Services we rely on
MarketWyrm runs on a small set of infrastructure providers, which process data on our behalf:
- Supabase — database, authentication, and server functions. All account data listed above lives here.
- Cloudflare — hosts the website, caches chart data, and delivers opted-in price-alert emails. As the network in front of the site, it processes visitor IP addresses at the infrastructure level, under its own privacy terms.
- Google Analytics — after Analytics consent, measures visits, sessions, page use, and device/browser trends. Google describes its data practices in its privacy policy and Analytics data safeguards.
- Yandex Metrica — after Analytics consent, measures visits, SPA page changes, link activity, aggregate click maps, and device/browser trends. Session Replay and form analysis are disabled. Yandex describes its data practices in its privacy policy.
- Resend — retained as a manual rollback provider for price alerts. It processes alert email addresses and content only if we deliberately switch delivery back to Resend.
- Browser push services (Google FCM, Mozilla, or Apple) — deliver encrypted notifications to your device if you enable them.
- Adsterra (AD MARKET LIMITED) — supplies the fixed banner and native creatives on eligible pages after Advertising consent. Its ad requests may include technical data such as IP address, browser/device information, page/referrer details, and ad interactions, and it may use cookies or pixels as described in its privacy policy and cookies policy. MarketWyrm does not send it your account profile or saved app data.
One more honest detail: item icons are loaded directly from the official RuneScape site (Jagex) and the Old School RuneScape Wiki. When your browser fetches those images, those sites see a standard image request from your IP address — the same as viewing any image on the web. No account information is sent to them.
Retention and deletion
Your data is kept for as long as your account exists. When your account is deleted, your watchlist, settings, push subscriptions, and saved lab work are erased with it automatically. A few operational traces (such as internal alert-delivery logs and server error logs) may reference an internal account ID for a while longer; they contain no email address and are not linked back to a person once the account is gone.
Deleting a MarketWyrm account does not automatically delete pseudonymous Google Analytics or Yandex Metrica records because those records are not keyed to the MarketWyrm account. Contact us if your request also concerns analytics data.
There is no self-serve account deletion in the app yet — email MarketWyrm@gmail.com from your account's email address and we'll delete it, normally within a few days.
Your rights
Under the GDPR in Europe, PIPEDA in Canada, and similar laws elsewhere, you can ask us to: tell you what data we hold about you, correct it, delete it, hand it over in a portable format, or stop a particular use of it. Email MarketWyrm@gmail.com and we'll sort it out. You also always have the right to complain to your local data-protection authority.
Children
MarketWyrm is not directed at children under 13, matching the age requirement of the games themselves, and we don't knowingly collect data from them. If you believe a child has created an account, contact us and we'll remove it.
Advertising and analytics
On your first visit, MarketWyrm offers separate Analytics and Advertising choices. Both are off until you opt in. Accept all and Reject all are available at the same level, and Manage lets you choose either purpose independently. Essential security, account, market data, chart, and preference features work without either optional purpose.
MarketWyrm uses only named, fixed banner/native positions: a content-first overview slot, a right rail where a wide screen has room, an in-table slot on long public lists, a contained item-detail rectangle, and a content-end footer. Route rules cap how many can appear and keep account gates, admin tools, errors, this Privacy page, and the Terms page ad-free. Footer and below-content units load only when they approach the viewport.
The admin can disable all ads or exclude signed-in/admin accounts. The loader makes no ad request until Advertising consent, that server-held policy, and the visitor's audience status have all resolved; failure leaves ads off. Refusing advertising does not grant a paid or wider ad-free layout. Google Analytics, Yandex Metrica, and MarketWyrm's compact first-party usage events require Analytics consent. Google advertising consent signals remain denied because MarketWyrm does not use Google Ads or Google ad personalization.
Use Privacy choices in the footer at any time to change or withdraw consent. Withdrawal stops future optional requests; withdrawing Analytics also removes accessible Google Analytics and Yandex Metrica cookies and reloads the page to unload both tags. You can also clear site data in your browser.
Changes to this policy
If we change this policy, the new version appears at this address with an updated effective date. Meaningful changes will be flagged in the app.
Contact
Questions, requests, or complaints: marketwyrm.com/contact.
MarketWyrm · About · Privacy · Terms · Contact — RuneScape and Old School RuneScape are trademarks of Jagex Ltd. MarketWyrm is not affiliated with Jagex.