Privacy
ePOE is a full companion for Path of Exile 2 — pricing, crafting, leveling, build planning, and more — made by exiles, for exiles. We built it to help you play, not to harvest you. This page explains, in plain language, exactly what we do and don’t do with your information.
Our pledge
We collect the minimum needed to give you an account, sync your shop, and run the features you turn on. We keep it to ourselves, we secure it, and we let you take it back or delete it whenever you like. That really is the whole story — the sections below just spell it out.
Only what a feature actually needs:
Your Path of Exile session stays on your PC. If you connect your Path of Exile session in the ePOE app, the session token (POESESSID) is stored only on your own computer, encrypted with your operating system’s keychain. It is never sent to or stored on ePOE’s servers. Every request the app makes to Path of Exile with it (price checks, shop and stash reads, undercut checks) goes straight from your computer to Path of Exile. Our servers only receive the results you choose to sync to your ePOE account, such as your shop listings and prices.
We don’t ask for anything we don’t need, and we don’t collect data in the background “just in case.”
Telemetry is on by default, and easy to turn off. The desktop app sends coarse, anonymous usage data so we can see what breaks and what’s slow. The first time you launch it, a one-time notice — “Thanks for helping us build a better ePOE!” — explains this and the Sharing Perks it unlocks, with links to exactly what is collected and to an in-app guide on turning telemetry and Sharing Perks off. To turn it off, at any time, use the Product Telemetry switch in Settings → Privacy. That stops telemetry and crash reports immediately and discards anything still queued on your PC — nothing more is sent.
What an event contains. Each event carries only these fields:
event_id — a random id so an event is never counted twiceclient_id — an anonymous random UUID for this installsession_id — a random UUID per app launchkind and name — what happenedapp_version and platformleague — the trade league you price inoccurred_at — when it happenedprops — a few coarse details, listed belowThe kinds of event. Price checks (how long a check took, how many trade searches it needed, whether it ended with a price, and the item’s class and rarity — never the item itself), feature use (which tool you opened and what opened it), performance timings (start-up, attaching to the game, each price-check stage), errors (where in the app it failed and the first lines of the message and stack, redacted as below), and onboarding milestones sent once per install (first run, first price check, first time opening the dashboard, first custom hotkey, first sign-in).
The coarse details (props). Durations in milliseconds, probe counts, how a check ended, item class and rarity, the trigger (what started the check, such as a hotkey), the error source, per-stage timings (parse, deduce, fetch, render), whether the game window was attached, and your OS family and major version.
Never sent: your POESESSID or any other credential, your Path of Exile account or character names, item text, modifier values, file paths, or your IP address. Before anything leaves your PC, your home folder in any path is replaced with ~ (so your operating-system username never travels), anything shaped like a session token is replaced with [redacted], and error messages and stacks are cut to their first lines.
Never linked to your account. Telemetry is sent without cookies or any account login, so it stays anonymous even when you’re signed in to ePOE in the app. The only account-related detail is a yes / no flag for whether the app was signed in at the time — never which account, and no account id is stored with it.
Retention. Raw events are deleted after 90 days. Daily rollups — counts and timing percentiles per day, with no client ids — are kept indefinitely so we can see long-term trends.
Crash reports. Under the same switch, the app reports crashes and errors to Sentry, our error-tracking provider, so we can fix them. Every report is scrubbed on your PC before it’s sent: the same home-folder and token redaction as above, web addresses cut to the site and page (no query strings, and nothing after a /profile/ segment, where account names live), the app’s own log lines dropped entirely, no local-variable values, and no user details at all — crash reports aren’t linked to your ePOE account either. Turning Product Telemetry off in Settings → Privacy stops crash reports too — it’s one switch.
ePOE is designed so your machine does the work. Whether you’re pricing an item, planning a craft, following a leveling route, importing a build, or browsing the item database, most of it runs right on your computer. When the overlay needs live trade prices, it talks to Path of Exile’s service directly from your own connection — the same way your browser would. We store only what’s needed to power your account and the features you turn on. Beyond the coarse, anonymous telemetry described in section 03 (which you can turn off), nothing about your moment-to-moment activity leaves your machine unless you choose to sync it.
Running a service means trusting a small number of infrastructure providers. We keep this list short, we send them only the minimum required, and they’re contractually bound to use it only to provide that service to us — never to sell it or use it for their own purposes:
These are service providers, not partners we “share” your data with. None of them get your data to keep or resell.
ePOE uses Grinding Gear Games’ official APIs to read your account’s data and to look up live trade prices, always acting on your behalf and within their rules. Your PoE session is used solely to fetch your own game data. ePOE is an independent, unofficial companion — it is not affiliated with, endorsed by, or sponsored by Grinding Gear Games.
We use essential cookies — the kind that keep you logged in and your session secure — and, only if you accept our cookie banner, Google Analytics 4 for aggregate, IP-anonymised usage statistics. Analytics runs under Google Consent Mode and is off by default: decline the banner (or browse with Global Privacy Control / Do Not Track enabled) and no analytics cookie is set. You can change or withdraw your choice any time via Cookie settings in the footer. There are no advertising cookies and no cross-site ad profiling; Google processes analytics data as our processor (see Google’s Privacy Policy). The desktop app’s separate product telemetry and crash reporting (on by default, anonymous) are covered in section 03; the Product Telemetry switch under Settings → Privacy controls both.
You’re always in charge of your data:
Depending on where you live, you may have additional legal rights (such as under GDPR or CCPA). We honor them for everyone, everywhere — reach out and we’ll take care of it.
Traffic is encrypted with HTTPS. Sensitive tokens are encrypted at rest. Your PoE session token exists only on your own computer, secured by your operating system’s keychain and never written to disk in plain text. Passwords are stored only as strong one-way hashes. We limit access on a need-to-know basis and keep only what we still need.
If we ever change how we handle your data, we’ll update this page and move the “last updated” date below. We’ll never quietly weaken these promises — and if a change is significant, we’ll do our best to tell you directly.
Questions, requests, or just want to check something? Email support@epoe.io or reach us through the in-app Support page. We read every message.
Last updated October 7, 2026 · ePOE is a free companion for Path of Exile 2, not affiliated with Grinding Gear Games.