Privacy Policy
What this site stores, what it does not, and which other companies your browser is sent to.
This website counts its visitors without identifying them, loads images, fonts and a video from other companies’ servers, and publishes information about community members that comes from a separate platform.
Effective date: August 31, 2026
Who runs this site
Briarmont is a roleplay community inside Second Life®, run by a small team. There is no advertising on this website and no email list. The site counts its own traffic with a tool that runs on its own server, described below, and no outside analytics company is involved.
Briarmont charges for some things. Land and homes are rented in Linden Dollars, DJ tip jars at events route a share to Briarmont, and other paid services may follow. All of that happens inside Second Life rather than on this website, so this site never sees a payment, a card number or a bank detail, and holds none.
This policy is about this website and the Munibase community platform behind it. Munibase is Briarmont’s own, run by the same people, so information moving between the two stays inside Briarmont. Second Life and Discord are different: they belong to other companies and have their own privacy policies covering what they hold about you there. Where this page describes something that happens on one of those, it says so.
Questions about anything on this page go to privacy@briarmont-sl.com.
The short version
This site counts its own traffic, without cookies and without keeping your IP address in the counts; the numbers stay on this server, and no advertising code or outside analytics service is involved. It has no email list and it does not accept comments. It does not ask for your name or your email address to read anything. For an ordinary visitor it sets one cookie of its own for each restricted handbook or brand book you unlock, and only if you type the access phrase. Signing in with Discord, if you use it, sets two more. The radio player, when it is switched on, also stores two settings in your browser. The table below lists everything. The small number of people with an account here also get WordPress’s login cookies.
The disclosure that matters most: some images, fonts and one video load from other companies’ servers, including Google, Adobe and Linden Research. Your browser has to contact those companies directly to fetch the files, so they see your IP address, and their own privacy policies apply to what they do with it, not this one. The full list is below.
Separately, the server that runs this website keeps standard webserver logs of every request, including your IP address. That is the largest single record of visitors. The site’s own code neither creates those logs nor reads them, but the volunteers who administer the server can.
What gets stored in your browser
| Name | What it is for | How long | Essential? |
|---|---|---|---|
| briarmont_hbgate_<group> (cookie) | Remembers that you typed the correct access phrase for one restricted handbook or brand book. The group part is one of hcsd, hartwell-general, lore-crafters, staff, briarmont-township, brand-book, oakridge-brand-book or hcsd-brand-book; the last three are the site’s brand books, which unlock the same way. | Until you close your browser, with a signed 12 hour limit. One year, but only if you check the “remember me” box yourself. | Yes for the session version. The one year version is a convenience, not a necessity. |
| briarmont_discord (cookie) | Keeps you signed in after you press the site’s Sign in with Discord button. It holds your Discord account ID, username, display name and avatar reference, signed so it cannot be edited. Unlike the handbook cookie, this one does identify you; that is its job. | One year. A sign-in made without the remember option lasts until you close your browser, with a signed 12 hour limit. Signing out removes it. | Yes, but only if you sign in. Nothing sets it if you never use the Discord sign-in. |
| briarmont_discord_state (cookie) | Protects a Discord sign-in you started against forgery. It holds a random code and nothing else, set when you press the sign-in button and checked when Discord sends you back. | Ten minutes. | Yes, during a sign-in you started. Nothing sets it otherwise. |
| briarmont-radio-playing (local storage) | Remembers whether you had the KBRM radio player switched on. | Until you clear your browser storage. | No. |
| briarmont-radio-volume (local storage) | Remembers the volume you set on the KBRM radio player. | Until you clear your browser storage. | No. |
| WordPress login cookies | Keeps the small number of people with an account on this site signed in. | Set by WordPress, typically two days, or two weeks if you ask to stay signed in. | Yes, for those accounts only. |
The two radio keys are only written if the radio player is switched on. It is switched off in the site’s configuration right now, and no audio player is drawn on the page, so nothing is being written today.
What the handbook cookie contains. Its value is an expiry time followed by a signature. A signature here is a short code generated from that expiry time and a secret key, so the server can tell the cookie was issued by us and has not been edited. It holds no name, no email address, no IP address, and no identifier of any kind. Two people who unlock the same handbook and get the same expiry second hold a byte-for-byte identical cookie, so it cannot single you out. It is marked HttpOnly, so scripts on the page cannot read it. It is marked SameSite=Lax, so another website cannot make your browser send it in the background. It is marked Secure over HTTPS.
What the Discord cookies contain. The sign-in cookie holds your Discord account ID, username, display name and avatar reference, with an expiry time and a signature. Unlike the handbook cookie it does single you out, because keeping you signed in is what it is for. It is only ever set when you press the Sign in with Discord button, and signing out removes it. The state cookie holds a random code and nothing else. Both carry the same protections as the handbook cookie: HttpOnly, SameSite=Lax, and Secure over HTTPS.
The “remember me” box is yours to check. It is left empty when the unlock form appears, so by default the cookie lasts only until you close your browser. Check it before you submit and the cookie lasts a year instead, surviving a browser restart. That is the one piece of storage on this site that is a convenience rather than a necessity, which is exactly why it is your decision and not a box we tick for you. Clearing your cookies removes it at any time.
The site does not accept comments. Comments and pingbacks are closed and no comment form is drawn anywhere, so no comment name, email address, website, IP address or comment cookie is collected.
What happens on the server
Two things running on this site read your IP address. The first is the visitor counter described in the next section, which shortens and scrambles the address before storing anything. The second is a guess limiter. When someone types an access phrase for a restricted handbook and gets it wrong, the code joins your IP address to the name of the handbook group. It runs the result through MD5, which turns it into a short fixed-length string. That string is the key for a counter. The counter is held for one hour, is deleted as soon as a correct phrase is entered, and refuses further attempts after eight failures. Its only purpose is to stop someone guessing phrases.
We will not call that anonymous. Running an IP address through MD5 hides it, but it does not destroy it, and someone holding the stored string could work back to the address it came from. It only exists if a wrong phrase was typed, and it is gone within the hour.
The server’s own logs are the bigger store. Like almost every webserver, the one serving this site records each request: the IP address it came from, the browser user agent string, the time, and the full requested address including anything after the question mark. Text you type into a search box on this site ends up in that address, so it ends up in those logs. This happens below the level of the site’s own code: WordPress never sees those logs and nothing on this site reads them. They sit on the server itself, which runs on Google Cloud, and the volunteers who administer that server can reach them. We do not publish a retention period, because we are not going to promise one we cannot hold to, and Google may keep its own operational records of traffic to the server under Google’s terms. The logs are used only to keep the site running and to deal with abuse, they are not used to build any picture of you, and they are not handed to anyone else unless the law requires it.
How visitors are counted
The site runs a counting tool called WP Statistics. It was chosen because it works without cookies and keeps everything it records in this website’s own database. The company that makes it never sees the numbers, and nothing about your visit is sent to anyone else.
For each page view it records the page, the time, the address of the site that sent you here if one did, your browser and its version, your operating system and device type, and a country and city worked out from your IP address. The address itself is not kept in that record. Before anything is stored, the last part of the address is dropped, and what remains is scrambled together with your browser’s user agent string using a key that changes every day. That is how unique visitors are counted: two views on the same day from the same browser produce the same scrambled string, so they count as one visitor, and the next day the key is different and the counter cannot recognize anyone from the day before.
Scrambling is not magic, and we will describe its limit the same way we did for the guess counter above: someone holding a stored string and that day’s key could test a guessed address against it. What the dropped last part and the daily key change do is stop anyone being followed across days, and stop the counts naming anyone.
The counter sets no cookie and writes nothing into your browser storage, which is why it does not appear in the table above. If your browser sends a Do Not Track signal, the counter skips you entirely: your views are not recorded and you appear in no number of ours. It is not connected to the Discord sign-in, so counts are never tied to an account, and it records nothing about where you go on any other website. The server’s own logs, described above, remain the larger and rawer record of visits.
The volunteers who run the site read these numbers to see which pages get read and how many people come by. They are not used to build a picture of any individual visitor, and they are not handed to anyone else unless the law requires it.
If you write to us
The three addresses on this page go to mailboxes the volunteers read. Whatever you put in an email sits in that mailbox, with your address, until it is deleted. There is no ticket system and no database behind it, and we use it to answer you and for nothing else. One thing is worth knowing before you write: if you send a copyright takedown notice, we pass a copy of it to the person who posted the material, including the contact details in it. The Copyright and DMCA page says the same.
Searching
Site search and the search box inside a handbook run against an index stored on this site. Those two searches are not sent to another company, and the words you type are not stored or counted anywhere in the site’s own data. They do appear in the requested address, which means the server access logs described above will contain them.
The citizen directory works differently. It has a find box, and the text you type there is passed to the Munibase community platform’s public interface as a search term so it can return matching people. The site keeps a copy of the answer so the page loads quickly, and a stale copy can be kept for up to seven days. That copy is filed under a key made by running your typed text through MD5, and nothing recording who searched is stored with it.
Other companies your browser contacts
Several parts of this site are files that live on other companies’ servers, so your browser fetches them directly from those companies. Each one learns your IP address, the address of the page you were on, and your browser user agent string, and each applies its own privacy policy. This is the part of the site that affects your privacy most, and here is the full list as of the effective date above. Your browser also contacts the server itself, which runs on Google Cloud, for every page and file that comes from this site, and that is what produces the server logs described above.
This site shows no cookie banner and does not ask you first. The home page video contacts Google as the page loads, so by the time you could answer a question, the request has already gone. We would rather tell you that than put a box on the screen that does not change what happens.
- YouTube, which is Google. The home page contains a video player served from www.youtube-nocookie.com, Google’s reduced-tracking address for embedded video. It is muted, and it starts loading and playing on its own, without you clicking anything, so your browser contacts Google as soon as the home page opens. The player itself sets no cookies unless something is played. The page also loads Google’s player control script, which is what keeps captions off and makes the clip loop where we want it to. That script exists only at www.youtube.com, and fetching it does set YouTube’s cookies, so on the home page you get those cookies whether or not you watch anything. The preview image comes from Google’s i.ytimg.com, which sets none. Videos elsewhere on the site load only after you click them, and use the same reduced-tracking address.
- Google Fonts (fonts.googleapis.com). Four typefaces, Libre Caslon Text, Public Sans, JetBrains Mono and Caveat, are loaded from Google by the stylesheet that comes with the Munibase components. The site’s own five typefaces are served from this site. These four are not.
- Adobe Typekit (use.typekit.net). One stylesheet, also brought in by the Munibase components.
- Google Cloud Storage. Citizen portraits and group crests are held in the object storage Munibase uses, which is Google Cloud, so those image files are fetched from Google’s servers even though Munibase itself is Briarmont’s.
- Linden Research, which runs Second Life. The rentals page shows roughly 63 photographs of parcels, and those pictures are served from Second Life’s own servers.
- The community’s own servers. The wiki at wiki.briarmont.muniba.se and the Munibase platform at briarmont.muniba.se supply some images and a stylesheet straight to your browser. Pages also carry preconnect hints for those two addresses, which tell your browser to open a connection to them early, before any image has been requested.
- Gravatar. An address at secure.gravatar.com appears inside the machine-readable data in the page source, built from a hashed form of the site administrator’s email address. It is published as text and the page does not request the picture, so your browser does not normally contact Gravatar. The address is there, and we would rather say so.
If you block third-party requests, most of the site still works. The home page video, the rental photographs, the citizen portraits, the group crests and some wiki images will not appear, and some text will fall back to a different typeface.
What the site fetches for you
Some pages are built from content held elsewhere, and the server goes and gets it before sending you the page. That happens server to server, and your browser is not involved. The sources are:
- The BookStack wiki, for lore pages, guides and handbook text.
- The Munibase platform, for almost everything the site says about people and organizations: names, character names and biographies, portraits, group membership and roles, faculty and course listings, rentals, events and honors.
- raw.githubusercontent.com, for the six community governance documents.
- GitHub’s releases interface, which is how the site checks for its own updates.
With one exception, none of those requests carry anything about you. No header from your request is copied onto an outgoing request, so your IP address, your user agent string and your cookies are not passed along to any of these services. The exception is the citizen directory find box described above: what you type in it goes to Munibase as a search term, because that is how the page finds a match. Nothing identifying you goes with it.
What we publish about members
This site publishes information about people in the community, in public, where search engines index it. That is what the site is for, and it deserves a plain description.
- The citizen directory at /township/citizens/ lists about 200 people across ten directory pages. For each person it shows the display name, the full character name, a portrait photograph, a verified badge, the month the character was filed, and a roll number written as № NNN-NN-NNNN. Character pages and organization pages carry more: written biographies, group membership and the roles a character holds, employment, where they study or teach, and the courses they take or give. These pages are open to search engines and are listed in the site’s sitemap.
- The team page at /help/team/ names 13 real people who help run the community, using their Second Life avatar names, with their roles and short biographies.
- Group registers publish each group’s leadership: name, portrait, role and how long they have held it.
- Faculty pages publish credentials and the courses a person teaches.
- The honors page at /oakridge/honors/ is built to publish named academic rankings. It is empty at the moment.
A Second Life avatar name is not your legal name, but it still points at one particular person, so we treat it as personal information. European data protection law treats it that way too.
Where it comes from and how to change it. All of it is pulled from the Munibase community platform. Munibase is Briarmont’s own platform, run by the same people who run this website, so a correction or a removal does not depend on anyone outside the community. Entries are created and edited there rather than here. Write to privacy@briarmont-sl.com and we will make the change at the source.
Once a change is made in Munibase, this website picks it up on its next sync, so there is a delay between the change and the page updating. Search engines then take their own time to drop or refresh a copy they have cached, and that part is outside anyone’s control here. We will not promise a deadline we cannot hold to.
Roleplay written about your character is a different thing. Bulletins, event write-ups and in-fiction records naming a character are stories other members wrote, not data about you that we hold, so they are not corrected or deleted as a privacy request.
Getting something taken down
Which route to use depends on what it is.
- Your directory entry, your portrait, or other details about you. Write to privacy@briarmont-sl.com. That is this page.
- Roleplay another member wrote about your character. Not a privacy request, because it is a story rather than a record about you. Where a character is already part of published canon, the Terms of Use explains what Briarmont keeps and what it will take down.
- Your own writing or art that you contributed. The permission you gave when you contributed does not expire, so published work generally stays up. The Terms of Use sets out exactly what that covers.
- Someone else’s copyrighted work published here. Write to copyright@briarmont-sl.com and follow Copyright and DMCA.
- Something being used to harass you. That is a conduct matter, and the Community Covenant is the route.
Your choices
- See what is held. Ask, and we will tell you what this website shows about you and where each piece of it came from.
- Correct it. Tell us what is wrong and we will fix it at the source, which is usually Munibase.
- Have it removed. Ask, and we will take it off the pages we control. Your directory entry and your portrait live in Munibase rather than here, so the removal has to be made there, and this website drops it at the next sync. Where the record sits somewhere we do not control, we put the request to the person who does. This covers information about you. It does not reach roleplay other members wrote about your character.
- Object. If you are unhappy that something about you is published, say so and we will talk it through rather than pointing you at a form.
- Complain. If you think we handled something badly, write to the same address and say so. If you live somewhere with a data protection authority, you can complain to them as well, and you do not have to come to us first.
Volunteers do this work in their own time, so we are not going to put a turnaround time in writing that we cannot keep. We will get to it as quickly as we can.
Age
Briarmont is 18+. The regions are Moderate rated, and Linden Lab does not admit accounts under 18 to a Moderate region, so that check sits with the platform before it reaches us. The Terms of Use sets out our rule alongside the separate Second Life and Discord ones, which are lower and do not override ours.
Reading this website is a different thing from taking part, and anyone can read it. The site is not aimed at children, does not knowingly collect personal information from a child under 13, and has nothing for a child to sign up to. If we learn that a member is under 18, they are removed from the community, and if we learn we are holding information about a child under 13 we delete it.
There is no parental consent process here, and we do not ask anyone for a date of birth. Collecting birth dates to check ages would mean holding more personal information than the site holds now.
Tracking across other websites
This site does not follow visitors around other websites, and nothing here builds a picture of where you go elsewhere. The visitor counter described above runs only on this site and cannot recognize you from one day to the next, let alone across sites. It honors the Do Not Track signal anyway: send one and the counter skips you entirely, as described under “How visitors are counted”. Nothing else on this site tracks, so there is nothing else for the signal to reach.
The other companies listed under “Other companies your browser contacts” may track across sites, and each decides for itself how to handle Do Not Track. Their policies cover what they do. This one does not.
Security
Restricted handbooks are protected by an access phrase, with the guess limit described above, and gated pages are kept out of the site’s search, its sitemap and its public listings. The site holds no payment data, no identity documents and no financial information, so there is nothing of that kind here to lose.
The site is served through a full-page cache, which keeps finished pages on disk so they load quickly. Pages behind an access phrase are kept out of that cache by a rule that watches for the unlock cookie. The site can check that the rule is in place but cannot enforce it, so we will not tell you it is impossible for a gated page to reach someone who has not unlocked it.
We are not claiming more than the site actually does. There is no certification behind any of this.
Changes to this policy
If this policy changes, the effective date at the top changes with it, and we post a notice in the community Discord. If a change affects what is collected or who receives it, the notice will say so plainly rather than telling you to compare versions.
Contact
Privacy questions, corrections and removal requests: privacy@briarmont-sl.com. Copyright complaints go to copyright@briarmont-sl.com, and anything else legal goes to legal@briarmont-sl.com.
Related pages: Terms of Use, Copyright and DMCA, and Disclaimers and Site Notices. The Community Covenant and the Stream Governance document cover reporting and appeals inside the community.
Second Life, SL, and inSL are trademarks of Linden Research, Inc. Briarmont SL is not affiliated with or sponsored by Linden Research.
This page describes the real website, not the fiction. The other legal pages are linked at the foot of every page.
