LEGAL

Privacy Policy

EFFECTIVE JULY 26, 2026

This Privacy Policy explains how FriendDiff currently handles information when you use our website, Windows desktop application, and related private-alpha services (collectively, the "Service"). It describes the product as it exists today. Planned features are identified as planned and are not described as current collection.

Information stored by FriendDiff

Information stored only on your computer

The desktop app stores a local match-history file, sync settings, manually selected friends, and an encrypted FriendDiff session. If an alpha tester enters a Riot development API key, the app stores it using the operating system's encrypted storage. That API-key field is a private-alpha testing mechanism and is not uploaded as part of match history. Overwolf game-detection events are used locally to detect supported games and trigger capture or refresh behavior.

Website and service infrastructure

FriendDiff does not currently run advertising, marketing analytics, behavioral profiling, or payment processing on the public website. Our hosting, authentication, email, and security providers may automatically process request information such as IP address, browser or device details, timestamps, and security signals, and may set cookies needed for security and service delivery. FriendDiff does not currently maintain a separate analytics profile from that infrastructure data.

How we use information

We use stored information to create and authenticate accounts, import and preserve match history, provide filters and player statistics, operate groups and invitations, calculate comparisons and receipts, prevent abuse, respond to support requests, and maintain the Service. We do not use a typed Riot ID alone as proof of ownership.

Riot data and account verification

The current alpha retrieves public Riot account and match data through Riot APIs after a user enters a Riot ID. This public lookup is not verified account linking. FriendDiff does not ask for or store your Riot password. Verified Riot Sign On is planned but is not currently active and remains subject to Riot approval.

How information is shared

Your cloud match records, League connection record, and game sync status can be read by your account and by authenticated FriendDiff users who share an accepted FriendDiff group with you. Pending invitees and unrelated users do not receive that access through FriendDiff's database policies.

Current service providers include Supabase for authentication and database hosting, Resend for transactional account email, OpenAI Sites and Cloudflare infrastructure for website hosting and security, Overwolf for local game-event integration, and Riot Games for League account and match data. These providers process information under their own terms and privacy obligations.

We do not sell personal information. We may disclose information when required by law, to protect users or the Service, or as part of a business transfer subject to appropriate safeguards.

Retention and deletion

The current alpha does not yet provide an automatic deletion schedule or self-service account deletion. Account, group, League connection, and cloud match records remain until deleted as part of an approved request, the account is deleted, or the alpha database is reset. Local files remain on the user's computer until the user removes them or uninstalls and clears FriendDiff's application data. You may request account and cloud-data deletion by emailing privacy@frienddiff.com. Provider backups may take additional time to expire.

Security

FriendDiff uses encrypted network transport, Supabase row-level access policies, protected server-side Riot credentials, and operating-system encryption for local sessions and tester-entered API keys. No system is perfectly secure, and private-alpha software may contain defects. Please do not use FriendDiff for sensitive information unrelated to its intended purpose.

Your choices

You may decline group invitations, stop using the Service, remove local application data, and request correction or deletion of cloud data. The current alpha does not yet provide every choice through self-service controls. Depending on where you live, you may have additional access, portability, objection, or restriction rights.

Children

FriendDiff is not directed to children under 13, or the minimum digital-consent age required in their jurisdiction. We do not knowingly collect personal information from children in violation of applicable law.

Changes and contact

We will update this policy when FriendDiff's actual collection or use changes. Questions or requests may be sent to privacy@frienddiff.com.