Privacy Policy
Last updated: August 10, 2026
ArmoryLink is a product of Six87 Labs LLC, an Iowa limited liability
company doing business as ArmoryLink (“Six87 Labs,” “we,” “us,” or “our”).
This Privacy Policy explains how we collect, use, disclose, and protect information when you use armorylink.com, our APIs, the ArmoryLink game addon export workflow, and related services (collectively, the “Service”). By using the Service, you agree to this Policy. If you do not agree, do not use the Service.
1. Controller / operator
The data controller (or equivalent operator) for the Service is:
Six87 Labs LLC d/b/a ArmoryLink
An Iowa limited liability company
Email: hello@six87.com
2. Information we collect
We collect information in the following categories:
- Account information. Email address used to sign in (magic link), optional display name derived from email, account identifiers, and timestamps for account creation and updates.
- Authentication data. One-time sign-in tokens (stored as irreversible hashes), session identifiers, and session expiry times. We do not use account passwords.
- Character and export content you upload. Player-exported World of Warcraft character snapshots and related fields you choose to import (for example equipment, bags, bank, keyring, gold, reputations, skills/professions, talents, and completeness metadata). You control what you export and when you publish a shareable armory link.
- Service usage data. Draft and listing identifiers, publish/unpublish status, credit balances and ledger entries, share-related metadata, and similar operational records needed to run the Service.
- Payment-related data. If you purchase credits, payment processors (such as Stripe) collect and process payment card and billing details. We receive limited payment references (for example transaction or session IDs, amount, and status) to apply credits. We do not store full card numbers on our servers.
- Technical and log data. Standard server and edge logs, which may include IP address, approximate location derived from IP, user agent, request path, timestamps, and error diagnostics. This data is used for security, abuse prevention, reliability, and debugging.
-
Cookies and similar technologies. We use a session cookie
(
al_sessionor similar) after you complete magic-link sign-in to keep you logged in. We do not use third-party advertising cookies on the Service as of the date above.
3. How we use information
We use information to:
- Provide, operate, and improve the Service (including drafts, listings, and armory pages)
- Authenticate you and protect accounts from unauthorized access
- Send transactional emails such as sign-in links
- Track and apply publish credits; process purchases when payments are enabled
- Enrich display of game data (icons, tooltips, models) using cached or third-party sources
- Monitor security, prevent abuse, and comply with law
- Respond to support and privacy requests
We do not sell your personal information, and we do not share personal information for cross-context behavioral advertising as those terms are commonly defined under US state privacy laws.
4. Legal bases (EEA/UK users)
If you are in the EEA or UK, we process personal data where:
- Contract — to provide the Service you request
- Legitimate interests — security, fraud prevention, product improvement (balanced against your rights)
- Legal obligation — where required by law
- Consent — where we ask for it and you provide it
5. Shared armories and identity
Default share links use identity-redacted listing mode: character name, realm, and guild are withheld on the public page. Residual re-identification risk can remain from unique gear, inventory, or other content in an export. You choose what to export and whether to publish. Shared listing pages are intended for link-based sharing and are served with noindex guidance to reduce search indexing.
6. How we share information
We share information only as needed to operate the Service, including with:
- Infrastructure providers — currently Cloudflare (Workers, D1, R2, DNS/CDN, and email delivery where configured)
- Payment processors — Stripe or similar, when you buy credits
- Game-data enrichment sources — public community sources (for example item/talent icons and tooltip data) used to render displays
- Professional advisors and authorities — where reasonably necessary for legal compliance, safety, or enforcement of our Terms
If we are involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction, subject to ongoing confidentiality and notice where required.
7. International transfers
We and our providers may process data in the United States and other countries. Where required, we rely on appropriate transfer mechanisms (such as standard contractual clauses) provided by our vendors.
8. Retention
We retain account, draft, listing, and credit records while your account is active and as needed to provide the Service, including any listing time-to-live or expiry settings. Authentication tokens expire quickly. Logs are kept for a limited operational period. When you request deletion, we delete or anonymize personal data we control, except where we must retain records for legal, security, or accounting reasons.
9. Your choices and rights
Depending on your location, you may have rights to:
- Access, correct, or delete personal information
- Export a copy of certain data
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Appeal a denial of a privacy request (where applicable under state law)
To exercise rights, email hello@six87.com from the email address on your account. You may also unpublish or delete listings from the dashboard where available, and sign out to clear the session cookie on that browser.
We will not discriminate against you for exercising privacy rights. Authorized agents may submit requests where required by law; we may need to verify identity and authority.
10. Security
We use reasonable administrative, technical, and organizational measures appropriate to the nature of the Service (HTTPS, access-scoped storage, hashed tokens, session cookies). No method of transmission or storage is completely secure.
11. Children
The Service is not directed to children under 13 (or the higher age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will take appropriate steps.
12. Do Not Track
There is no consistent industry standard for Do Not Track browser signals. The Service does not respond to DNT signals at this time.
13. Changes
We may update this Policy from time to time. We will post the revised Policy on this page and update the “Last updated” date. Material changes may be communicated by additional notice when appropriate. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
14. Contact
Privacy questions and requests:
Six87 Labs LLC d/b/a ArmoryLink
hello@six87.com ·
Contact ·
Terms of Service