Privacy Policy
Beta — working version
This policy describes the personal data ChallyQ actually collects, why we collect it, who processes it, and how you can have it deleted. We describe only what the product does today.
Data we collect
We collect the following, and only what is needed to run the service:
- Account: your username, display name, region and language. An email address is optional; if you set one it is used for sign-in and account recovery. Passwords are stored only as a salted scrypt hash — never in plain text.
- Riot account: when you link your League account we store your Riot ID (game name and tag) and PUUID, and we read public profile data (summoner level, profile icon, ranked tier) from Riot's API to verify ownership.
- Match data: for challenges you accept, we read the official result of your relevant League games from Riot's Match API and store the performance stats needed to settle those challenges and compute rankings.
- Profile content: an optional bio, your chosen in-app avatar or League icon, and — only if you upload one — a custom avatar image.
- Technical/security: session records containing your user-agent and a one-way hash of your IP address (we do not store your raw IP), plus standard server logs.
- Integrity: an anti-fraud risk signal and any fraud flags derived from how the account is used, to protect the competition.
- Referrals: if you use or share a referral code, we record which accounts are linked by it.
Why we use it
To operate your account and sign-in; to verify you own the Riot account you link; to settle challenges and calculate rankings and prizes fairly; to detect fraud and enforce fair play; to screen uploaded images for unsafe content; and to keep the service secure.
We do not sell your personal data.
Service providers
We share data only with providers that help us run the service:
- Vercel — application hosting.
- Neon — the database where your account and game data are stored.
- Riot Games API — we request your public account and match data from Riot to verify identity and settle challenges.
- Cloudinary and AWS Rekognition — used only if you upload a custom avatar, to store the image and automatically screen it for unsafe content.
Advertising
ChallyQ plans to support itself through advertising. No advertising or third-party ad or analytics network is active in the product today. Before we enable advertising, we will update this policy and, where required, ask for your consent. This policy will name any advertising provider we actually use — we will not claim to use one we do not.
Retention
We keep your data while your account exists and as needed to run the competition (for example, to keep leaderboards and prize records consistent) and to meet legal obligations. Session records expire and are pruned automatically.
Deleting your account and data
You can request deletion of your account and personal data at any time by contacting us at support@challyq.com. On request we will delete or anonymise your personal data — including your email, password, Riot ID/PUUID and profile content — retaining only the minimum needed for competition integrity (for example anonymised standings) or where the law requires.
Note: a self-service “delete my account” and “unlink Riot account” control in the app is planned but not yet built. Until then, deletion is handled on request.
Security
We use reasonable measures to protect your data: passwords are hashed, session tokens are stored only as hashes, IP addresses are hashed, sessions are HTTP-only cookies, and secrets such as API keys are kept server-side and never exposed to the browser. No system is perfectly secure, but we work to keep your data safe.
Contact
Questions about privacy? Contact support@challyq.com.