A plain-language summary of what Mboxer accesses, stores, and does with your data. No legalese — just the facts so you can make an informed decision.
Last updated: April 2026When you sign in, Mboxer requests zero ESI scopes. We receive only your character name and character ID from EVE SSO — nothing else. This is the minimum required to identify your account.
esi-skills.read_skills.v1When you link a character for skill tracking, we request read-only access to that character's trained skills. This scope cannot modify anything in-game. You grant this per-character and can revoke it at any time.
login.eveonline.com OAuth authentication with EVE Onlineesi.evetech.net EVE Swagger Interface — character search and skill dataimages.evetech.net Character portrait imagesError tracking service Application error monitoring — sensitive data is scrubbed before transmissionAll data is stored in a database on the server. Nothing is shared with third parties. Here is exactly what we keep:
Mboxer has no ability to read or modify any of the following. These ESI scopes are never requested:
This application undergoes regular penetration testing using source-code-aware tooling that validates real, reproducible exploits across OWASP Top 10 categories including injection, cross-site scripting, server-side request forgery, and authentication bypass.
EVE OAuth tokens are scoped to the minimum required permissions and are stored server-side only — they are never exposed to client-side code or sent to your browser.
Open your Roster, select a character, and click Disconnect. This revokes access with CCP's servers and clears all cached skill data for that character.
Delete a character from your Roster to permanently remove their record, portrait file, group memberships, tags, ship certifications, and any EVE data.
Logging out invalidates your session immediately. Session records are automatically cleaned up.
Permanently delete your account and all associated data from the Account page (accessible via the shield icon in the sidebar after signing in). This removes your account, all characters, portraits, activity groups, tags, sticky notes, ship certifications, industry favorites, and all active sessions. EVE OAuth tokens are revoked with CCP during deletion. This action is irreversible.
Signed-in users can export a complete copy of their data from the Account page.