MapleStory Quest

Privacy

What MapleStory Quest stores, what it sends, and what it deliberately does not collect.

You can browse and plan without an account. One is only needed to publish a build or keep private drafts. Everything below is what the code in this repository actually does.

No third-party analyticsNo IP address storedNo advertisingOne cookie, only once you sign inNothing sold or shared

Where each thing ends up

Your browser only

Local storage is not a cookie: it is never attached to a request, so none of this leaves your machine on its own.

  • Your working build · so a closed tab does not lose the plan
  • Edit keys · for builds you published
  • Progress ticks · on someone else’s build path
  • Unsaved world-spot notes · drafts in the spot editor

Sent to the server

Ordinary use means requests, and a request has to say what it is asking for. None of these is written down against you.

  • The page you asked for · as with any website
  • A level range or a map id · when the planner or map picker looks something up
  • Autosaved planner drafts · the build state, a short pause after you change it
  • One session cookie · only after you sign in
  • The page and how long you stayed · counted, never tied to you; see below

Readable by anyone

Only ever by pressing Publish. Nothing reaches this column by accident.

  • A published build · its class, level, stats, gear and path
  • Its display name and notes · free text you typed, on a public page
  • View and like counts · kept per build, not per visitor

What the site never does

No third-party analytics

No analytics script, no tag manager, no pixel, no session recording, no fingerprinting, and nothing loaded from anybody else’s server. The site counts its own page views; the panel below says exactly how, and what that count cannot tell anyone.

Browsing needs no sign-in

Accounts only gate publishing and account-owned drafts. Username accounts store a one-way password hash, never the password.

One cookie, and only after sign-in

A random session token. Unavailable to page scripts, expires after 30 days, and gone the moment you log out.

Nothing sold or shared

There is nothing collected to sell, and nothing goes to a data broker, an advertiser or anyone else.

Assets are served from here

Images, fonts, styles and scripts are all local, so an ordinary page load talks to no other host.

Two third parties, both opt-in

Google, if you click Continue with Google, which supplies an account id, a display name and an optional profile image. YouTube, on a published build whose author attached a video, and on the two Nexon clips about the Founder’s Packages. Those two are a picture served from here with a play button on it: nothing is fetched from YouTube unless you press it.

Counting visits, without counting people

This site records that a page was opened and roughly how long it was on screen. It is how anybody here knows whether a page is worth the week it took, and until recently there was no way to know that at all. It is written by this server into this database. No script from anywhere else is loaded, nothing is sent to anybody, and there is no account, product or company on the other end of it.

The design goal was a count that is useless for identifying you, so what it refuses to keep is the substance of it:

No address is stored

A visitor is a one-way hash of an address and a browser name, taken under a secret that is generated fresh every day and deleted two days later. Once that secret is gone the hash cannot be recomputed from an address by anybody, including whoever runs the site.

Nothing links one day to the next

Because the secret changes daily, the same person tomorrow is an unrelated value. There is no profile, no visit history and no way to ask what one person has ever read. Somebody who comes back is counted as a new visitor, and the site accepts that as the price.

No cookie, and nothing stored on your machine

None of this sets a cookie or writes to local storage. Nothing is put in your browser for it to hand back later, which is the usual way a count becomes a tracker.

No query strings, ever

The address of a page is cut at the question mark before it is written down, so a draft link, a search you typed or anything else after the ‘?’ never reaches the record.

No browser fingerprint

The user agent string is read once to decide phone, tablet or desktop and one browser name, and is then discarded. Nothing measures fonts, screen size, canvas, timing or anything else.

Do Not Track is honoured

A browser sending Do Not Track or Global Privacy Control is not counted at all, in the browser and again on the server. Blocking the request works too, and nothing tries to route around a blocker.

What is kept per page view: the path, the referring site’s host name and never the full address, phone or tablet or desktop, a browser name, the seconds the page was visible, and the time. Rows are deleted after 180 days. Only the account running the site can read any of it, and only as totals.

Kept in your browser, and why

StoredWhy
Your working buildSo closing the tab mid-plan does not throw the plan away. Saved on every change and read back when the planner opens.
Edit keys for builds you publishedPublishing returns a key that authorises later edits to that build. It is held in your browser instead of behind a login: clear it and the build stays published but becomes uneditable.
Progress ticks on a build pathThe checkboxes on a published build’s progression path, so your place in someone else’s route survives a reload.
Unsaved world-spot notesDrafts in the world-spot editor, kept locally so an hour of annotation is not lost to a stray refresh.

Clearing site data in your browser removes all of it. Everything except a published build’s edit key can be recreated by planning again.

Worth knowing before you publish

Public means public

A published build is reachable by its short code, listed on the Builds page and readable by anyone. Treat the display name and notes like a forum post: a character name, not your own details.

No self-service delete yet

You can edit a published build from the browser that published it, but removing one means asking the person running the site. Publish accordingly.

Drafts expire after 30 days

Counted from the last change, and editing renews it. Signed-in drafts are linked to the account and appear under My account.

A draft link is its own password

An anonymous draft’s random URL is the edit key, so anyone holding that URL can read and change it. A snapshot link is different: it carries the whole build in the URL and touches no database.

No visitor identifier on a build

Alongside a build the server keeps its publish and edit times, a view count, a like count and the edit key. No IP address and no browser fingerprint.

Lookups are about the snapshot, not you

A level band or a map id gets the same answer for everyone and is cached as such. Nothing about your build travels with one, and none of it is written down.

Hosting, logs and the database

Web hosts keep request logs: a URL, a time, a status code, a user agent, an IP address. That is a property of being on the internet rather than something this site collects on purpose. Nothing in the host’s logs is aggregated, profiled or connected to a build.

The application writes one record of its own about visitors, and only one: the page-view count described above. It holds no address, no user agent and no identifier, and it is not joined to an account, a build or anything else in the database.

The database holds published builds, expiring drafts, reference data, account usernames, password hashes or Google identifiers, and expiring sessions. A build or draft made while signed in is linked to that account.

Children, and changes to this page

Accounts are not intended to collect information from children. Do not use a personally identifying username; Google sign-in is subject to Google’s own account policies.

If the site ever collects more than it does today, this page changes in the same commit as the code that caused it. It describes what the software does, not an intention. The page-view count above is that rule being kept: this page said “no analytics” until the commit that added it, and was rewritten by the same commit rather than afterwards.

© 2026 MapleStory Quest. Fan project, not affiliated with Nexon. See About for where the game data comes from.