Coffer Privacy Policy
This is a plain-English policy, not a certificate of legal compliance. Coffer is a small, beta-stage product run by one person. We tell you honestly what we collect, why, and what we do with it. We are not claiming full GDPR or CCPA compliance — see "International data transfers" below.
Coffer is made by PC Industries ("we," "us"), operated by Paul Christopher as its sole operator. Contact: admin@meetcoffer.com (a dedicated support@meetcoffer.com address may replace this later — this document will be updated when it does). This policy is governed by the laws of the Commonwealth of Massachusetts, United States (see the companion Terms of Service, "Governing law").
1. What we collect
Coffer is a RuneLite plugin (client) plus a server at ge-copilot.onrender.com
/ meetcoffer.com. The plugin sends the following to the server over HTTPS:
- Account credentials. A username you choose and your password. We never store your password — only a bcrypt hash of it (a one-way, industry-standard hash; we cannot recover your original password, and even we can't read it back out).
- Email (required for new accounts). New accounts must provide an email address at signup. We use it for account recovery (self-serve password reset) and to contact you about your account. We check that it's a validly-formatted email address, but we do not verify that you actually own/control it (there is no confirmation-email step today) — don't assume it's correct until you've successfully used it (e.g. a real password reset). Accounts created before this requirement took effect are grandfathered and are not required to add an email retroactively. If the email you enter already belongs to another Coffer account, your new account is still created, but that email is silently not attached to it — you won't see an error explaining why, and that account will have no recovery email on file (this is a deliberate anti-enumeration tradeoff so a signup attempt can't be used to probe whether an email is already registered). This matters most if you play multiple OSRS accounts and reuse one email across several Coffer signups: only the first account to register it keeps it. See "Your data, your choices," below, for what to do if this happens to you.
- Your Grand Exchange activity. The offers you place and trades you complete — item, quantity, price, buy/sell side, timestamp, and your in-game account/display name — so Coffer can track your profit & loss and give suggestions. You place every GE offer yourself; Coffer reports what already happened or is happening in-game, it does not place offers for you.
- Derived data. P&L we calculate from the trades above, and aggregated fill-outcome samples (e.g. "did an offer like this fill within X minutes") used to improve suggestion quality across all users. These samples are keyed to items and price buckets, not to your account.
- Discord webhook URL (optional). If you turn on Discord alerts, the webhook URL you provide is stored so we can send alerts to it. Treat that URL as a credential — anyone with it can post to your Discord channel; we send alerts to it and nothing else.
- Preview-page visit counts. If you visit the public landing/preview page without an account, we record a hashed version of your IP address plus the date, only to count unique daily visitors. The hash is one-way; we do not store or use raw IP addresses for this, and it isn't tied to any account.
- Feedback you send us. Bug reports / feature requests submitted via the in-plugin "Send feedback" form, including an optional contact field if you choose to give one.
We do not collect real-money payment details today (Coffer's beta is free — see "Payments," below) and we do not collect your Jagex account credentials — Coffer only reads your locally-running RuneLite client's view of your own GE offers/trades, the same way any RuneLite plugin can.
2. Why we collect it (and the legal-ish basis)
| Data | Why | Basis |
|---|---|---|
| Username + password hash | To authenticate you | Necessary to provide the service (contract) |
| Account recovery (password reset) + contact | Necessary to provide the service (contract) for new accounts, required at signup; your consent if you're a grandfathered account adding one voluntarily | |
| GE offers/trades | P&L tracking, suggestions, coaching | Necessary to provide the service (contract) |
| Aggregated fill samples | Improve suggestion accuracy for all users | Legitimate interest — product improvement |
| Discord webhook | Send the alerts you asked for | Your consent (opt-in) |
| Hashed IP / visit counts | Basic traffic counting | Legitimate interest — minimal, anonymized |
| Feedback | Support and product decisions | Your consent (you submit it) |
If you're in a jurisdiction with a formal legal-basis requirement (e.g. EU/UK GDPR), treat the table above as our good-faith mapping, not a formal legal determination.
3. Where it's stored — sub-processors
We use a small number of third-party services to run Coffer. We don't sell your data, and we don't share it for advertising.
- Render — hosts the Coffer web server.
- Neon — hosts our Postgres database (region: US-East). This is where your account, trades, and offers live.
- Resend — sends transactional email (password resets and other
account-related messages) on our behalf, from
noreply@meetcoffer.com. Used for accounts that have an email on file. This includes an optional monthly recap email summarizing your own account activity (your flips, profit for the month, best flip, win rate) with a link back to your dashboard — see "Your data, your choices," below, for how to turn it off. - Cloudflare — our domain registrar and DNS provider for meetcoffer.com. Cloudflare sees DNS/routing metadata, not your account data.
We may periodically back up the database (compressed dumps) for disaster recovery. These backups contain the same personal data as the live database (including your email, if you have one on file, and your trade history) and are access-controlled to the developer, not public, and rotated/aged out over time rather than kept indefinitely.
If we add or change a sub-processor in a way that changes what happens to your data, we'll update this policy (see "Changes to this policy," below).
4. Security
- Passwords are hashed with bcrypt — never stored or logged in plaintext.
- All plugin↔server traffic is over HTTPS/TLS.
- Sessions use signed tokens; changing your password invalidates old sessions (a "session-kill" mechanism), so a stolen old token stops working once you reset.
- Password-reset tokens are single-use, expire in 30 minutes, and are stored as a one-way hash, never in plaintext.
- No system is perfectly secure. If we ever have reason to believe your data was exposed in a breach, we will notify affected users. This policy is not itself a breach-notification procedure.
5. The third-party-server disclosure (why this matters)
Coffer is a third-party plugin, not made or verified by Jagex or the RuneLite developers. Installing it and creating an account means your GE offers and trades are sent to our server (see above) — this is disclosed up front in the RuneLite Plugin Hub listing, the plugin panel, and the landing page, and stays true regardless of what else changes in this policy. If what we collect changes, that disclosure gets updated too, not just this document.
6. Your data, your choices
- Access: email us (admin@meetcoffer.com) and we'll tell you what we have on your account.
- Delete your account: email us and we'll delete your account. Deleting an account removes your user record, trades, watchlist, open offers, email address, and any pending password-reset tokens from the live database. There is currently no self-serve in-app delete button — it's a request to us. Aggregated fill-outcome samples used for suggestion quality aren't tied to your account and can't be traced back to you, so they aren't removed by an account deletion. Feedback you've submitted (bug reports, etc.) is also removed when your account is deleted. Caveat: deletion removes data from the live database; it does not retroactively scrub already-taken database backups, which age out and rotate over time (see "Sub-processors," above).
- Correction: email us if something's wrong (e.g. a bad email on file) and we'll fix or remove it.
- Opt out of optional data: Discord alerts are off by default and never required. Email is required at signup for new accounts (see "What we collect," above); if your account predates that requirement, you're not required to add one.
- Opt out of the monthly recap: every recap email has a one-click unsubscribe link that turns it off immediately. This only affects the recap — it does not unsubscribe you from essential account email like password resets or security notices, which we send regardless.
- No recovery email attached (email collision at signup): if you registered with an email that turned out to already belong to another Coffer account (see "What we collect," above), self-serve password reset won't work for your account — there's no email on file for it to send to. Email us and we'll help verify you own the account manually, but we can't promise the same self-serve recovery guarantee we can for accounts with a working email on file.
7. Children / age
Old School RuneScape's playerbase skews young, and we have no reliable way to verify age. Coffer is not directed at children, and we ask that anyone under the age of majority in their jurisdiction not use it without a parent/guardian's awareness. We intentionally collect the minimum data needed to run the product (no real name, address, phone number, or payment details today) and never ask for more than an in-game trading history, a username/password, and (for new accounts) an email address. If you're a parent/guardian and believe your child has given us data you'd like removed, email us and we'll delete the account (see "Your data, your choices," above).
8. Cookies / local storage
The Coffer web dashboard uses your browser's localStorage (not cookies) to keep you signed in and remember dashboard preferences on your own device. We don't use advertising cookies, tracking pixels, or third-party analytics scripts on the dashboard. Clearing your browser's site data for meetcoffer.com signs you out.
9. International data transfers
Our database (Neon) is hosted in the US. If you access Coffer from outside the US, your data is transferred to and stored in the US. We are not making a jurisdiction-specific representation (e.g. EU Standard Contractual Clauses) about that transfer today. If this matters to you — e.g. you're an EU/UK/other-regulated user and need a specific transfer mechanism — contact us before relying on Coffer for that use case.
Coffer does not sell your data and does not implement CCPA/CPRA-specific mechanics (like recognizing browser-level opt-out signals such as Global Privacy Control) today.
10. Payments (future)
Coffer's beta is currently free. If/when paid tiers launch, payment processing will be handled by Stripe, and Stripe (not Coffer) will hold your card details — we don't plan to see or store full card numbers ourselves. This policy will be updated with the specifics (what billing metadata we do retain, e.g. subscription status) before any paid tier goes live; see the companion Terms of Service for planned billing/refund language.
11. Changes to this policy
We'll update this document as Coffer's data collection changes (e.g. when payments launch) and update the "Effective date" above. We won't expand what we collect about existing users without updating this policy and the in-product disclosure first.
12. Contact
Questions, access/deletion requests, or concerns: admin@meetcoffer.com.