This Privacy Policy explains how FriendDiff currently handles information when you use our website, Windows desktop application, and related private-alpha services (collectively, the "Service"). It describes the product as it exists today. Planned features are identified as planned and are not described as current collection.
Information stored by FriendDiff
- FriendDiff account: your email address, unique FriendDiff username, Supabase authentication identifier, account creation time, email-confirmation state, and authentication records maintained by Supabase. FriendDiff does not receive or store your password in readable form.
- League profile: the Riot ID, regional routing choice, Riot PUUID, and last update time associated with a League import. A typed Riot ID and public-data import are stored as unverified and do not prove that the FriendDiff user owns that Riot account.
- Steam and Deadlock profile: when you choose Connect Steam, Steam verifies your sign-in and returns your SteamID64 to FriendDiff. We store that verified identifier, its corresponding Deadlock account ID, public Steam display name, avatar and profile URL, verification time, and update time. FriendDiff never receives your Steam password.
- Match history and sync state: Riot and Deadlock match identifiers, timestamps, queue and mode information, participants and public game identifiers, champions or heroes, teams, results, kills, deaths, assists, damage, roles, final items, and compact match or timeline statistics. A copy is stored locally and, for signed-in users, uploaded to FriendDiff's Supabase database. We also store each game's sync status, local and cloud record counts, recent error text, and sync timestamps so the app can report whether sharing is complete and retry failed uploads.
- Groups: group names, owners, invited users, invitation status, accepted membership, and creation times. FriendDiff usernames and profile creation times are searchable inside the signed-in app so users can send group invitations.
- FriendDiff Plus: subscription entitlement and status, selected recap preferences, early-access enrollment, premium group-presentation presets, and generated recap records containing period dates and summary statistics. If you enable recap email, the generated recap is sent to your confirmed FriendDiff email address.
- Profile and privacy choices: selected profile picture and banner, social game-visibility settings, group-notification preference, optional usage-analytics choice, and FriendDiff accounts you block.
- Support and bug reports: information you choose to send when requesting support, early access, privacy assistance, or account deletion. In-app bug reports can include the selected category, your summary and description, expected behavior, the current FriendDiff page and game filter, app version, operating system, submission time, and your signed-in account identifier and email so we can investigate and respond.
Information stored only on your computer
The desktop app stores a local match-history file, sync settings, per-friend game-tracking choices, appearance preferences, and an encrypted FriendDiff session. It may also store a capped, redacted diagnostic log for crashes and application errors. If an alpha tester enters a Riot development API key, the app stores it using the operating system's encrypted storage. That API-key field is a private-alpha testing mechanism and is not uploaded as part of match history. Overwolf game-detection events are used locally to detect supported games and trigger capture or refresh behavior.
Website and service infrastructure
FriendDiff does not currently run advertising, marketing analytics, behavioral profiling, or payment processing on the public website. Our hosting, authentication, email, and security providers may automatically process request information such as IP address, browser or device details, timestamps, and security signals, and may set cookies needed for security and service delivery. FriendDiff does not currently maintain a separate analytics profile from that infrastructure data.
Planned advertising and subscriptions
FriendDiff includes inactive integration code for future Overwolf advertising and optional FriendDiff Plus subscriptions through Tebex. These services will not process advertising or payment information until they are enabled. Once enabled, Overwolf may process device, cookie, IP address, consent, ad-delivery, and measurement information under its consent system and privacy terms. FriendDiff will provide a link to Overwolf's advertising privacy controls inside the desktop app.
When a user chooses to purchase FriendDiff Plus after billing is enabled, Tebex will handle checkout, payment methods, tax, fraud prevention, renewals, and subscription management. FriendDiff will receive and store the FriendDiff account identifier associated with the checkout, subscription status, plan, renewal or end date, cancellation state, Tebex transaction and recurring-payment references, and a limited webhook record needed to grant or revoke digital benefits. FriendDiff will not receive complete payment-card details. Users who do not start checkout will not have a Tebex subscription record created by FriendDiff.
How we use information
We use stored information to create and authenticate accounts, verify Steam account ownership, import and preserve match history, provide filters and player statistics, operate groups and invitations, calculate comparisons and receipts, generate requested Plus recaps, deliver recap email when enabled, prevent abuse, respond to support requests, and maintain the Service. We do not use a typed Riot ID alone as proof of ownership.
Riot data and account verification
The current alpha retrieves public Riot account and match data through Riot APIs after a user enters a Riot ID. This public lookup is not verified account linking. FriendDiff does not ask for or store your Riot password. Verified Riot Sign On is planned but is not currently active and remains subject to Riot approval.
Steam verification
Steam account linking uses Steam OpenID. Steam authenticates you on Steam's own website and returns a verified SteamID64 to FriendDiff. FriendDiff uses a short-lived, one-time linking request to bind that Steam identity to your signed-in FriendDiff account. You may unlink Steam in the desktop app; previously imported local match history remains until you remove it separately.
How information is shared
Your cloud match records, supported-game connection records, and game sync status can be read by your account and, when your privacy settings permit it, by accepted FriendDiff friends or authenticated users who share an accepted FriendDiff group with you. You can disable all social match sharing or disable it separately for League and Deadlock. Blocking an account prevents social access in either direction. Your Steam ownership-verification record itself is readable only by your FriendDiff account. Pending invitees and unrelated users do not receive access through FriendDiff's database policies.
Current service providers include Supabase for authentication, database hosting, and Steam-link verification; Resend for transactional account email; OpenAI Sites and Cloudflare infrastructure for website hosting and security; Overwolf for local game-event integration and, once enabled, advertising; Tebex for optional checkout and subscription management once enabled; Riot Games for League account and match data; Valve and Steam for Steam identity verification; and the community-run Deadlock API for public Deadlock match and profile data. These providers process information under their own terms and privacy obligations.
We do not sell personal information. We may disclose information when required by law, to protect users or the Service, or as part of a business transfer subject to appropriate safeguards.
Retention and deletion
FriendDiff does not yet apply an automatic age-based deletion schedule to active accounts. You can permanently delete your account from Profile & settings after re-entering your password and typing the displayed confirmation phrase. Deletion removes the authentication account and associated cloud records; an owned group transfers to an accepted member when possible and is otherwise deleted. A Steam connection can be unlinked separately. Local files are cleared by the deletion flow on that computer, but copies on another computer remain until that installation is cleared. Provider backups may take additional time to expire. You may also contact privacy@frienddiff.com for assistance.
Security
FriendDiff uses encrypted network transport, Supabase row-level access policies, protected server-side credentials, one-time expiring Steam-link requests, direct verification of Steam OpenID responses, and operating-system encryption for local sessions and tester-entered API keys. No system is perfectly secure, and private-alpha software may contain defects. Please do not use FriendDiff for sensitive information unrelated to its intended purpose.
Your choices
You may decline group invitations, block FriendDiff accounts, control social match visibility, export your stored data, clear local history, unlink Steam, or permanently delete your FriendDiff account in the desktop app. Depending on where you live, you may have additional access, portability, objection, or restriction rights.
Children
FriendDiff is not directed to children under 13, or the minimum digital-consent age required in their jurisdiction. We do not knowingly collect personal information from children in violation of applicable law.
Changes and contact
We will update this policy when FriendDiff's actual collection or use changes. Questions or requests may be sent to privacy@frienddiff.com.