LEGAL

Privacy Policy

EFFECTIVE AUGUST 2, 2026

This Privacy Policy explains how FriendDiff currently handles information when you use our website, Windows desktop application, and related private-alpha services (collectively, the "Service"). It describes the product as it exists today. Planned features are identified as planned and are not described as current collection.

Information stored by FriendDiff

Information stored only on your computer

The desktop app stores a local match-history file, sync settings, per-friend game-tracking choices, appearance preferences, and an encrypted FriendDiff session. It may also store a capped, redacted diagnostic log for crashes and application errors. If an alpha tester enters a Riot development API key, the app stores it using the operating system's encrypted storage. That API-key field is a private-alpha testing mechanism and is not uploaded as part of match history. Overwolf game-detection events are used locally to detect supported games and trigger capture or refresh behavior.

Website and service infrastructure

FriendDiff does not currently run advertising, marketing analytics, behavioral profiling, or payment processing on the public website. Our hosting, authentication, email, and security providers may automatically process request information such as IP address, browser or device details, timestamps, and security signals, and may set cookies needed for security and service delivery. FriendDiff does not currently maintain a separate analytics profile from that infrastructure data.

Planned advertising and subscriptions

FriendDiff includes inactive integration code for future Overwolf advertising and optional FriendDiff Plus subscriptions through Tebex. These services will not process advertising or payment information until they are enabled. Once enabled, Overwolf may process device, cookie, IP address, consent, ad-delivery, and measurement information under its consent system and privacy terms. FriendDiff will provide a link to Overwolf's advertising privacy controls inside the desktop app.

When a user chooses to purchase FriendDiff Plus after billing is enabled, Tebex will handle checkout, payment methods, tax, fraud prevention, renewals, and subscription management. FriendDiff will receive and store the FriendDiff account identifier associated with the checkout, subscription status, plan, renewal or end date, cancellation state, Tebex transaction and recurring-payment references, and a limited webhook record needed to grant or revoke digital benefits. FriendDiff will not receive complete payment-card details. Users who do not start checkout will not have a Tebex subscription record created by FriendDiff.

How we use information

We use stored information to create and authenticate accounts, verify Steam account ownership, import and preserve match history, provide filters and player statistics, operate groups and invitations, calculate comparisons and receipts, generate requested Plus recaps, deliver recap email when enabled, prevent abuse, respond to support requests, and maintain the Service. We do not use a typed Riot ID alone as proof of ownership.

Riot data and account verification

The current alpha retrieves public Riot account and match data through Riot APIs after a user enters a Riot ID. This public lookup is not verified account linking. FriendDiff does not ask for or store your Riot password. Verified Riot Sign On is planned but is not currently active and remains subject to Riot approval.

Steam verification

Steam account linking uses Steam OpenID. Steam authenticates you on Steam's own website and returns a verified SteamID64 to FriendDiff. FriendDiff uses a short-lived, one-time linking request to bind that Steam identity to your signed-in FriendDiff account. You may unlink Steam in the desktop app; previously imported local match history remains until you remove it separately.

How information is shared

Your cloud match records, supported-game connection records, and game sync status can be read by your account and, when your privacy settings permit it, by accepted FriendDiff friends or authenticated users who share an accepted FriendDiff group with you. You can disable all social match sharing or disable it separately for League and Deadlock. Blocking an account prevents social access in either direction. Your Steam ownership-verification record itself is readable only by your FriendDiff account. Pending invitees and unrelated users do not receive access through FriendDiff's database policies.

Current service providers include Supabase for authentication, database hosting, and Steam-link verification; Resend for transactional account email; OpenAI Sites and Cloudflare infrastructure for website hosting and security; Overwolf for local game-event integration and, once enabled, advertising; Tebex for optional checkout and subscription management once enabled; Riot Games for League account and match data; Valve and Steam for Steam identity verification; and the community-run Deadlock API for public Deadlock match and profile data. These providers process information under their own terms and privacy obligations.

We do not sell personal information. We may disclose information when required by law, to protect users or the Service, or as part of a business transfer subject to appropriate safeguards.

Retention and deletion

FriendDiff does not yet apply an automatic age-based deletion schedule to active accounts. You can permanently delete your account from Profile & settings after re-entering your password and typing the displayed confirmation phrase. Deletion removes the authentication account and associated cloud records; an owned group transfers to an accepted member when possible and is otherwise deleted. A Steam connection can be unlinked separately. Local files are cleared by the deletion flow on that computer, but copies on another computer remain until that installation is cleared. Provider backups may take additional time to expire. You may also contact privacy@frienddiff.com for assistance.

Security

FriendDiff uses encrypted network transport, Supabase row-level access policies, protected server-side credentials, one-time expiring Steam-link requests, direct verification of Steam OpenID responses, and operating-system encryption for local sessions and tester-entered API keys. No system is perfectly secure, and private-alpha software may contain defects. Please do not use FriendDiff for sensitive information unrelated to its intended purpose.

Your choices

You may decline group invitations, block FriendDiff accounts, control social match visibility, export your stored data, clear local history, unlink Steam, or permanently delete your FriendDiff account in the desktop app. Depending on where you live, you may have additional access, portability, objection, or restriction rights.

Children

FriendDiff is not directed to children under 13, or the minimum digital-consent age required in their jurisdiction. We do not knowingly collect personal information from children in violation of applicable law.

Changes and contact

We will update this policy when FriendDiff's actual collection or use changes. Questions or requests may be sent to privacy@frienddiff.com.