Skip to content

Privacy Policy

ZugZugDB is a fan-run World of Warcraft Forever database with no ads, no analytics and no trackers. This page says what we do keep, and why. Effective 3 October 2026.

Who we are

ZugZugDB is a fan site offered at no charge; there is no company behind it. It is not affiliated with or endorsed by Blizzard Entertainment. Questions about this policy go to the contact page or by email to pixelportllc@pm.me.

Reading the site

You can read everything without an account. For a plain visit we keep no record of your address: the visitor counter on the homepage and the rate limits that keep scrapers out work on a salted hash of your network (IPv4 address or IPv6 /64), computed with a secret key, and the hash is what is stored. Rate-limit rows are deleted when their window ends. The site writes no access log of its own; the network layer in front of it (Cloudflare) sees your address to deliver the page and to stop attacks, under its own terms.

Cookies

We set only strictly necessary and functional cookies, so no consent banner is shown. There are no analytics, advertising or third-party tracking cookies.

CookieSet whenLastsPurpose
__Host-zz_sessionyou log in30 days, or 14 days unusedEssential. A random token that names your session; the server stores only its hash.
zz_prefsyou save Site Preferences1 yearFunctional. Rows per page, comment view, tooltips on or off. Not set while every setting is at its default.
zz_oauthyou start a Discord or Battle.net log-in10 minutesEssential. Ties the log-in you started to the answer the provider sends back.
Cloudflare Turnstilea page shows a comment or suggestion formset by CloudflareEssential anti-spam check. Cloudflare's widget may set its own cookie from challenges.cloudflare.com.

If you make an account

An account is only needed to comment, vote, report or post a Theorycraft thread. You log in with Google (through Firebase Authentication), Discord or Battle.net; we never see or store a password. From the provider we keep:

  • the account id the provider gives us, so you can log in again;
  • your email address where the provider supplies one (Google, Discord), and whether the provider has verified it. It is used to check whether you are on the moderator list and for nothing else: never shown, never mailed to;
  • your Discord name or BattleTag, shown to you on your account page;
  • the display name you choose here, which signs everything you post.

Each session also records the first 200 characters of your browser's user-agent string.

What you post

  • Comments, Theorycraft threads and votes are public under your display name. Comments are checked automatically before they appear: the text of the comment and the name of the page it is on are sent to OpenAI's moderation service (see below). No name, email, address or account id goes with it. The verdict and its one-line reason are stored with the comment and shown only to moderators. Reports you file, and the reason you give, are seen by moderators.
  • Suggestions (the form) need an email address so a moderator can answer. It is shown to moderators and nowhere else; it is never sent to a third party.
  • Poll votes are stored per account so you can change your vote; only the totals are shown.

Services that process data for us

Firebase Authentication (Google)
Runs the Google log-in. Google sees that you logged in to this site; its script loads on the log-in page only.
Discord, Battle.net
Their log-in pages, under their own terms; we receive your id, name and (Discord) email.
Cloudflare
Sits in front of the site and runs the Turnstile anti-spam check, which also receives your address when a form is checked.
OpenAI
Automated comment moderation: comment text and the page name, nothing about you.
Google Safe Browsing
Any web address found in a comment is looked up to catch malicious links. Only the address in the comment is sent.
Discord webhook
Each new suggestion pings the moderators' Discord with its category, the first 200 characters and the page it is about. Never your email.
Our asset host
Your browser fetches icons, maps and 3D models from it, as it would any image.
Blizzard's image servers
Pictures in mirrored official news posts are loaded by your browser straight from Blizzard's servers; Blizzard sees that request.
Ko-fi
An outbound link on the tip page only. Nothing is loaded from it here.

Search and the database run on our own server; no search query leaves it.

How long we keep things

  • Sessions: 30 days, or 14 days after you last use them; logging out ends one at once.
  • Comments and threads: until you or a moderator delete them. Moderation verdicts live and die with the comment.
  • Suggestions: as long as needed to act on them; ask and we delete yours.
  • Rate-limit and anti-scrape records: deleted when their window ends (hours to two days).
  • Periodic backups are kept for a limited time and then overwritten.

Your rights

Wherever you live, you can see what we hold about you and have it corrected or deleted. Under the GDPR and the UK GDPR you also have the right to a copy of your data, to object to processing, and to complain to your supervisory authority; under the CCPA, to know what is collected and to have it deleted. We sell nothing to anyone.

  • Delete your account yourself at your account page. Your comments stay in their threads as "[deleted]" with no name and no text, your votes are withdrawn, and your log-in methods and sessions are removed. Theorycraft threads you started keep their text and the display name they were posted under; ask us if you want one removed. For a Google log-in the record at Google's sign-in service is deleted too.
  • Export or anything else: write to us from the contact page with your display name and we answer within a month.

Children

The site is not directed at children under 13, or under 16 in the European Union, and we do not knowingly open accounts for them. If one was opened, tell us and it is deleted.

Changes

If this page changes, the date at the top changes with it. Material changes are announced under News.

See also the Terms of Use.