Privacy Policy
Last updated
MetaRoK (meta-rok.com) is a fan-made Rise of Kingdoms companion site run by Cortex. It is not affiliated with or endorsed by Lilith Games. This page explains, in plain language, what the site stores about you, why, who can see it, and how to get it removed. It describes what the site's code actually does today.
Browsing without an account
The tier lists, commander pages, marches and makers work without logging in. Nothing you do there is tied to you. The site sets no analytics or advertising cookies and loads no tracking scripts. The tier list maker and talent tree maker keep their state in the page URL and, for a couple of display preferences, in your browser's local storage; that data never leaves your browser.
Like any website, requests pass through the hosting provider's infrastructure (see third parties). The site's API uses your IP address to rate limit requests. Those counters live for one to ten minutes and are then discarded; the site does not keep an access log of its own.
Logging in
You can log in with Discord or with Google. There are no passwords on MetaRoK; the site never sees your Discord or Google password.
- Discord. The site asks Discord for the
identifyscope only. It stores your Discord user ID, your username, your display name and the URL of your Discord avatar. It does not ask for or receive your Discord email address, your servers or your friends. The username and avatar URL are refreshed each time you log in. - Google. The site asks for
openid,emailandprofile. It stores your Google account ID (thesubclaim), your verified email address and, on first login, your Google name as the initial display name. The email is refreshed on each login. It is shown only to you, in the Accounts section of your profile, so you can see which Google account is linked; the site does not send you email and does not show the address to anyone else.
The first sign-in with a Discord or Google account creates one profile record with a random ID. That ID, not your Discord or Google ID, is what everything else on the site is keyed to.
Linking logins. One profile can be opened by both a Discord login and a Google login. From the Accounts section of your profile you can link the other kind of login: the site sends you through that provider's normal sign-in and, once it completes, records that identity on the profile you were signed in to. Nothing is linked on the strength of a matching email address or name; only a completed sign-in with the other account links it. You can unlink either login again as long as one remains. Unlinking Discord also ends Discord-verified kingdom leadership on that profile until it is linked again, and removes any manual king or officer promotion the profile held.
Merging two profiles. If the login you are linking already has its own profile on MetaRoK (you signed in with Discord once and with Google another time), the site does not merge them on its own. It shows you both profiles and asks which one stays your main profile; that offer expires after ten minutes if you do nothing. When you confirm, both logins are placed on the profile you kept and the other profile becomes a secondary profile under it, exactly like a farm account: nothing on it is deleted, and its Governor ID, sets, pairings, comments, forum posts and likes stay where they are. Its own secondary profiles and saved tier lists move under the kept profile, and any kingdom leadership tied to the Discord account follows the Discord account. Records that name the Discord account behind an older comment, note or post keep the name they were written with. Link, merge and unlink actions are logged on the server with the profile IDs involved.
Your profile
Everything on your profile is entered by you, and you can change or clear it at any time on the profile page. It can include: a display name, your in-game Governor ID, alliance name, kingdom number, VIP level, power, kill points, dead troops, highest acclaim, the commanders you own with their skill levels and sculptures, equipment and armament sets, march pairings, filter presets, and your activity times (see below).
Visibility. New profiles are public by default. You can set your profile to one of four levels:
- Public: anyone with the link can see it, and it appears in the Players directory.
- Kingdom: only approved members and leaders of your kingdom.
- Leadership: only verified leaders of your kingdom.
- Private: only you.
Site admins can view every profile regardless of this setting. Profile pages ask search engines not to index them, but a public profile shared as a link is visible to anyone who has the link.
Multiple profiles. One login can hold up to 20 profiles (for farm or alt accounts). Secondary profiles have no login of their own and are stored under your primary profile. The Governor ID on a secondary profile is required and must be unique across the site; the one exception is a profile that became secondary through a merge, which keeps whatever Governor ID it had, possibly none, until you set one.
Uploaded images
You can upload a profile avatar and a showcase background; kingdom leaders can upload a kingdom avatar
and rally / garrison backgrounds; forum posts can carry up to four images; a Governor ID report
requires a screenshot. Uploads are limited to raster images (PNG, JPEG, WebP, GIF), are resized in your
browser before upload where needed, and are stored in Cloudflare R2 object storage. They are served
from /img/ URLs on this site with a one-year cache lifetime, so a replaced or deleted
image can remain in browser and edge caches for some time after it is gone from storage. Anyone who
can see the page an image is on can see the image.
Activity times
You can optionally record the hours you are usually online and a preferred four-hour window for events, both in UTC. One setting controls who sees both:
- Leadership only (the default): verified leaders of your kingdom, and you.
- Public: anyone who can see your profile.
- Public + Showcase: the same, and the times are also printed on your exported showcase image.
The server removes these fields from the profile before sending it to anyone who is not allowed to see them. Kingdom pages can show an aggregate of members' activity (the most active window and peak hour across the kingdom). That aggregate is computed from members' windows without naming anyone, and kingdom leaders choose whether it is visible to the public, to kingdom members, or to leadership only.
Kingdoms and leadership
Setting a kingdom number on your profile and applying to that kingdom records a membership status (pending or approved). Approved members appear on the kingdom's member list, can be assigned as rally or garrison captains, and can receive invitations, march pairing suggestions and notes from kingdom leaders. Notes a leader leaves on your profile are visible to you and to that kingdom's leaders.
Leadership verification. To know who is a king or officer, the site fetches a roster of kingdom leaders from codexhelper.com (the TKC leadership list), which is keyed on Discord user IDs. The roster is fetched server-side, cached for five minutes, and compared against the Discord ID of the logged-in user. Nothing about you is sent to codexhelper.com; the site only reads their list. Because the roster is Discord-based, kingdom leadership cannot be verified for a profile with no Discord login; linking a Discord account to it (see Logging in) is what enables it. A verified king can also manually promote members to king or officer; those promotions are stored on this site.
Kingdom leaders can see the profiles of their kingdom's members that are set to kingdom or leadership visibility, including activity times set to leadership only.
Speedup tracker. The Codex Helper bot in the TKC Discord server lets players post screenshots of their speedups, action points, gems and equipment or armament materials, and to claim a Governor ID for each bot profile. When you open your profile editor, and when a leader opens their kingdom's dashboard, the site asks codexhelper.com for the scans that match a profile: by the Governor ID set on it and, for a main profile, by its Discord user ID; on a kingdom dashboard that is done for every approved member, whether or not they have ever used the bot (for those who have not, the answer is simply empty). A Governor ID claim in the bot is used only when it was made from the Discord account linked to your main profile, so typing someone else's Governor ID into meta-rok shows nothing of theirs; a login with no Discord linked is not looked up by Governor ID at all. Nothing is sent to codexhelper.com except those IDs. The site also reads the scan history the bot holds for the matched bot profiles, and keeps one copy of each scan per day so it can draw how the numbers change over time; copies older than about 400 days are dropped the next time that record is refreshed. Everything the bot scanned is shown to you on your profile editor. The leaders of a kingdom you are an approved member of, and site admins, see only your speedups and action points on the kingdom dashboard (alongside every other linked member's, because that is who the tracker bot serves); your gems, VIP points and material stacks are never included in that view. A profile with neither a Governor ID nor a Discord login is never looked up. Leaving the kingdom removes you from its dashboard. The stored scans are keyed on the Governor ID or Discord ID the bot reported rather than on the profile, so deleting a secondary profile does not touch them; an account deletion request (see Retention and deletion) removes them with everything else.
Forum and comments
Forum posts, comments, votes and follows are stored with your profile ID and shown with your display name and avatar. Posts and comments are public: anyone can read them, including search engines. Votes are not shown to other users. Deleting a post or comment blanks its text but keeps a placeholder row so replies underneath it still make sense. Admins can ban a profile from writing on the forum for a fixed period or permanently; the ban, its reason and who issued it are shown to you in your notifications.
Profile comments and likes follow the visibility of the profile they are left on. Profile owners can delete comments on their profile and block individual commenters. Comments on a kingdom page follow that kingdom's visibility.
RoKdle
RoKdle is the daily commander guessing game. Playing signed out stores nothing on the server: your guesses, today's board and your streak live only in your browser's local storage, and every guess is sent to the server to be checked without being kept. Playing signed in stores, against your login's main profile, the commanders you guessed for each day and mode, whether you solved it, the points earned, your streak and your totals. Those totals put you on the public weekly, monthly and all-time leaderboards, which show your display name, avatar, score and number of solves to everyone, including signed-out visitors and search engines. Your Governor ID and Discord ID are used to link your name to your profile page unless your profile is set to private, in which case the row shows only the name and avatar. Playing signed in is how you opt in to that; playing signed out keeps you off the boards entirely. Linking two logins merges their RoKdle history into the kept profile; deleting a profile deletes its RoKdle rows with it. One automated check runs on the stored plays: when a week ends, a login that solved five or more Classic puzzles that week, each on the first guess with no miss, has its points for that week set to zero. Nothing else is changed or removed.
Governor ID reports
If someone else's profile holds your in-game Governor ID, you can file a report. The report stores your profile ID, the profile currently holding the ID, a required in-game screenshot and an optional message. Reports are reviewed by site admins, who can release the ID or reassign it. Reports are kept so that repeat disputes can be understood; they are removed when the reporting profile is deleted.
Feedback
The Feedback button sends your message together with the page you were on, your display name and (for Discord logins) your Discord username, so the site owner can follow up. Feedback is visible only to admins.
Cookies and browser storage
-
rok_session: set when you log in. A signed token that identifies your active profile. It lasts 30 days, is not readable by page scripts, and is only sent over HTTPS. Logging out clears it. -
rok_oauth_stateandrok_oauth_next: set for ten minutes while a login is in progress, to protect the login against forgery and to return you to the page you came from. They are cleared as soon as the login completes. -
rok_oauth_link: set for ten minutes while you are linking a second login. It holds a signed note of which profile started the link, so the sign-in that comes back can only be attached to that profile from that browser. It is cleared when the link completes.
There are no analytics, advertising or third-party cookies. The site also uses your browser's local storage for display preferences (for example the height of the tier list maker's unranked pool), session storage to carry an unsaved tier list across a login, and a service worker that caches pages and images for offline use. All of that stays on your device.
Third parties
- Cloudflare hosts the site. Pages, the API, the database (D1), the cache (KV) and uploaded images (R2) all run on Cloudflare's infrastructure, and requests are subject to Cloudflare's privacy policy.
- Discord and Google handle the login itself. Their own policies apply to what they record about that sign-in. If you use a Discord avatar, your browser loads it from Discord's image servers when it is displayed.
- codexhelper.com provides the kingdom leadership roster and the speedup tracker scans, as described above. The site reads from it; the only thing it sends is the Discord user ID of the player whose scans it is asking for.
- Ko-fi, YouTube and Discord are linked from the footer. Following a link takes you to their site under their terms.
The site does not sell or share your data with anyone else.
Moderation and admins
A small number of admin accounts, identified by Discord ID, can view every profile and kingdom regardless of visibility, read feedback and Governor ID reports, manage forum categories, delete or pin forum posts, ban users from the forum, and resolve Governor ID disputes. Admin access exists to run the site and handle abuse, not to browse private data for its own sake.
Retention and deletion
Your data is kept for as long as your profile exists. You can edit or clear any profile field yourself, delete your own forum posts and comments, and delete comments on your profile.
- Secondary profiles can be deleted from the profile switcher in the avatar menu. Deletion removes the profile and everything attached to it (comments, likes, notes, invites, suggestions, feedback, reports, kingdom assignments, RoKdle history) and its uploaded images. Live forum posts and comments must be deleted first.
- Primary profiles (the one carrying your Discord or Google login) cannot yet be deleted from the site itself. To have your account and all of its data removed, ask in the MetaRoK Discord server and it will be deleted by hand. The same applies if you want a copy of the data held about you.
Cached copies of images may persist at the edge and in browsers for up to a year after deletion. Rate limit counters expire on their own within minutes.
Contact
Questions about this policy, and deletion or access requests, go to the MetaRoK Discord server. Changes to this policy are posted on this page with a new "last updated" date, and notable changes are also listed in the changelog.