Navigation menu expanded

Data Privacy & Security

PoeHow connects to Grinding Gear Games (GGG) services to deliver value tracking, strategy insights, and community tools. This page explains what we collect, how we use it, and the controls you have over your information.

Last updated: November 2025


At a glance

  • Minimal account data

    We store your Path of Exile UUID, display name, placeholder email, linked OAuth tokens, and timestamp of your last login. Strategy submissions and moderation actions you perform are tied to this record so you retain control over them.

  • On-demand gameplay data

    We call GGG APIs only when you explicitly request a feature (e.g., importing stash tabs). Raw responses stay on the server and are dropped after the computation completes.

  • No third-party tracking scripts

    Outside of OAuth handshakes with GGG and optional Patreon linking, PoeHow does not embed advertising, analytics beacons, or social pixels.

  • Self-service controls

    Visit your profile's “Data Privacy Controls” card to export your data, anonymize past strategy submissions, unlink providers, or delete your account entirely.

Data we collect when you sign in

Signing in with Path of Exile creates a PoeHow user in our database. The following fields are stored:

  • Path of Exile account identifiers

    Your UUID and display name let us distinguish your submissions and personalize the interface. GGG never shares an email address, so we generate a placeholder in the format <uuid>@pathofexile.com that only satisfies our unique constraint and is not used for contact.

  • Session and login metadata

    We track when you last authenticated so we can expire stale sessions and keep audit trails meaningful.

  • OAuth credentials

    Access, and expiry details from GGG (and Patreon if linked) are stored encrypted server-side.

  • Roles and permissions

    Administrative reviewers, moderators, and Patreon supporters receive roles that gate additional features. These can be revoked at any time.

If you optionally connect Patreon, we retrieve only the membership details required to confirm your tier and unlock supporter features.

How gameplay data is used

We fetch Path of Exile data on-demand to drive specific tools:

  • Stash imports and valuations

    Tab and item information is requested when you kick off an import. The server matches those items against our economy database to generate totals and then discards the source payload.

  • Strategy submissions

    Player-entered results, notes, and loot tallies are saved so moderators can vet them and the community can reference them later. You can anonymize or delete these records from your profile.

  • Beta features

    We are currently testing out including character equipment and atlas passive choices with data submissions.

We do not resell or share gameplay data with third parties. Aggregated statistics may be published in guides or dashboards, but they are anonymized and cannot be linked back to an individual account.

OAuth scopes requested from GGG

GGG requires scopes to be declared during the OAuth handshake. The scope descriptions below are excerpted from the official developer documentation and paired with our usage notes.

account:profile

Provides access to your basic Path of Exile profile information.

How PoeHow uses it

  • Create and maintain your PoeHow user record (display name, realm, guild) and prevent duplicate accounts.

  • Verify ownership before we allow actions that touch your Path of Exile data, such as initiating stash imports or linking Patreon.

account:stashes

Allows viewing the account’s stash tabs and the items inside them.

How PoeHow uses it

  • Stash import and valuation tools. We fetch only the tabs you ask us to process, compute the totals server-side, and discard the raw response after the request finishes.

account:characters

Allows viewing the account’s characters and their inventories.

How PoeHow uses it

  • Support upcoming character analytics (loadout snapshots, farming templates). The scope must be granted up front, but we only call the character endpoints when you opt into those tools. We do not persist your full character roster today.

account:league_accounts

Allows viewing the account’s allocated Atlas passive skills.

How PoeHow uses it

  • Prepare atlas-aware recommendations and benchmarking features that tailor strategies to your passive tree. As with characters, we only read this data on demand and do not store your atlas layout verbatim.

We do not request any service:* scopes on behalf of regular users, nor do we gain the ability to change your account settings within Path of Exile.

Storage, retention, and security

  • Database protections

    Our PostgreSQL database is accessible only from service infrastructure. OAuth tokens never leave the server and are blocked from the client API responses. The tokens are encrypted at rest.

  • Session cookies

    NextAuth issues HTTP-only cookies so your browser can stay signed in. They do not contain gameplay data and are cleared when you sign out or delete your account.

  • Audit logging

    Administrative actions (moderation, price edits, anonymization) are written to an internal audit log to keep a trace of who changed what.

Data tied to community contributions (strategy results, pricing edits) is retained while it remains useful to the community. If you anonymize or delete your account we scrub player identifiers from those records as part of the process.

Your rights and how to reach us

You can manage most requests instantly from your profile. For anything else, including regulatory inquiries, reach out to [email protected].

You can always revoke PoeHow's access from the official Path of Exile applications dashboard at pathofexile.com/my-account/applications.

  • Export

    Download a JSON snapshot of the data we hold about your account.

  • Anonymize

    Replace your player identifiers on past strategy submissions while keeping the aggregated data live for the community.

  • Delete

    Remove your PoeHow account and linked credentials. We also clear reviewer assignments and anonymize any submissions tied to you.

We may update this page as new tooling or regulations arrive. When that happens we will update the timestamp above and highlight meaningful changes in-app.

This product isn't affiliated with or endorsed by Grinding Gear Games in any way.