Privacy Policy
Beta — working version
This policy describes the personal data ChallyQ actually collects, why we collect it, who processes it, and how you can have it deleted. We describe only what the product does today.
Data we collect
We collect the following, and only what is needed to run the service:
- Account: your username, display name, region and language. An email address is optional and may be used as a sign-in identifier. ChallyQ does not currently provide an email-based password-reset or account-recovery flow. Passwords are stored only as a salted scrypt hash — never in plain text.
- Riot account: when you link your League account we store your Riot ID (game name and tag) and PUUID, and we read public profile data (summoner level, profile icon, ranked tier) from Riot's API to display on your profile.
- Match data: after you link Riot, ChallyQ may import recent eligible matches to establish your Mastery baseline. For accepted challenges and ongoing validation, we read official Riot match results and store performance data used for settlement, rankings and Mastery.
- Profile content: an optional bio, your chosen in-app avatar or League icon, and — only if you upload one — a custom avatar image.
- Technical/security: session records containing your user-agent and a one-way hash of your IP address (we do not store your raw IP), plus standard server logs.
- Integrity: an anti-fraud risk signal and any fraud flags derived from how the account is used, to protect the competition.
- Referrals: if you use or share a referral code, we record which accounts are linked by it.
- Product analytics: when analytics is enabled, we record in-app usage events (for example sign-ins, challenges accepted, pages viewed) tied to your account identifier, together with your username and Riot ID, to understand how ChallyQ is used and improve it. This is processed by PostHog and is a no-op when analytics is not configured.
Why we use it
To operate your account and sign-in; to link your Riot account and read your public League data; to settle challenges and calculate rankings and prizes fairly; to detect fraud and enforce fair play; to screen uploaded images for unsafe content; and to keep the service secure.
We do not sell your personal data.
Children's privacy
ChallyQ is not directed at children under 13, and you must confirm you are 13 or older to create an account. We do not knowingly collect personal data from anyone under 13. If we learn that we have collected personal data from a child under 13, we will delete it and close the associated account. If you believe a child under 13 has created an account, contact us at challyqcontact@gmail.com and we will investigate and remove it.
Any physical prize, or prize of real monetary value, that ChallyQ may offer in the future is limited to participants 18 years of age or older — see the Terms of Service and Competition & Prize Rules.
Service providers
We share data only with providers that help us run the service:
- Vercel — application hosting.
- Neon — the database where your account and game data are stored.
- Riot Games API — we request your public account and match data from Riot to display your profile and settle challenges.
- Cloudinary and AWS Rekognition — used only if you upload a custom avatar, to store the image and automatically screen it for unsafe content.
- PostHog — product analytics, used only when analytics is enabled, to record in-app usage events and improve the service; it receives your account identifier, username and Riot ID. It is not an advertising network and we do not sell this data.
Advertising
ChallyQ plans to support itself through advertising. No advertising network is active in the product today and we show no third-party ads. The only third-party analytics we use is PostHog, for product usage — and only when it is enabled (see “Data we collect” and “Service providers”); we use no ad-targeting networks. Before we enable advertising, we will update this policy and, where required, ask for your consent. This policy will name any advertising provider we actually use — we will not claim to use one we do not.
Retention
We keep your data while your account exists and as needed to run the competition (for example, to keep leaderboards and prize records consistent) and to meet legal obligations. Session records expire and are pruned automatically.
Deleting your account and data
You can use Account settings to unlink Riot or permanently delete your ChallyQ account. You can also contact us at challyqcontact@gmail.com. Unlinking removes the linked Riot account row and imported per-player performance rows, but keeps your ChallyQ profile, challenge history, Season Points and achievements.
Self-service deletion removes the account and user-owned records, including sessions, Riot link, profile and progression. Shared Match records are not user-owned and remain; their stored raw Riot payload may still contain Riot identifiers and match participant data. ChallyQ does not currently claim that self-service deletion erases those shared payloads. Contact us if you have a privacy request concerning retained match data.
Security
We use reasonable measures to protect your data: passwords are hashed, session tokens are stored only as hashes, IP addresses are hashed, sessions are HTTP-only cookies, and secrets such as API keys are kept server-side and never exposed to the browser. No system is perfectly secure, but we work to keep your data safe.
Contact
Questions about privacy? Contact challyqcontact@gmail.com.