
Account policy
Privacy policy
Margin Warden is designed to collect only the account information needed to provide a private market workspace.
Effective July 18, 2026
Information we handle
We store your email address, authentication identifiers, security and rate-limit records, saved settings, watchlist entries, and the trades you deliberately enter in your journal. We also process ordinary request metadata such as IP-derived rate-limit identifiers, timestamps, and short-lived security logs.
We do not ask for or store RuneScape, Jagex, bank, or payment credentials.
How information is used
Account information provides authentication, owner isolation, recovery, abuse prevention, support, and the features you request. Journal and watchlist information is never used to place trades or take in-game action.
Service providers and public market data
The application is hosted on Vercel and uses Supabase for authentication and PostgreSQL storage. Cloudflare Turnstile may process security signals when you sign in, register, or request recovery. Transactional email is sent through the configured mail provider. These providers process data only to operate and protect the service under their own published terms.
OSRS market information comes from the public OSRS Wiki real-time prices API. Your private settings, watchlist, and journal are not sent to that API.
Retention and deletion
Private account data remains until you delete it, except for short-lived security records and limited records that must be retained to investigate abuse or satisfy legal obligations. Account deletion is available from Account & security and removes the authentication identity and private application records. Shared public market data remains.
Your choices
You can export your settings, watchlist, and journal from Account & security. You can change your password, revoke sessions, or permanently delete your account there as well. Contact the published support address for access or correction questions you cannot complete in the application.
Security and changes
We use encrypted transport, verified sessions, tenant-scoped server access, throttling, bot protection, and least-privilege controls. No system can promise absolute security. Material changes to this policy will be dated and published here before they take effect when practical.