UPDATED 05 OCTOBER 2026
Your data.
Clear boundaries.
Founder & owner: WioraleighT. This independent prototype's site membership is separate from your Riot account. No Riot Sign On or live Riot API connection is available.
Google and Discord membership
When activated and you choose to sign in, the provider shares your stable provider identifier, display name and verified email. These are stored with join and last-sign-in dates in a private Cloudflare D1 database for membership and request handling. You and the owner can view your profile; other members cannot access it. No public member directory is provided.
We do not receive your provider password. Provider access and refresh tokens are not retained or sent to browser code. Google and Discord memberships remain separate; matching emails are not automatically linked.
Sign-in network and bot protection
On successful sign-in we store only your latest sign-in IP, approximate country supplied by Cloudflare and capture time in private D1 storage. Only the owner can retrieve this network record. VPNs, proxies and mobile networks can change it; it is not your exact or verified physical location. Records older than 30 days are never returned by the owner API and are deleted on subsequent sign-in, request-submission or owner-list activity. There is no scheduled deletion job, so expired records may remain in inactive storage until that activity occurs. Account deletion also deletes your network record.
Sign-in attempts and request submissions use per-network rate limits with SHA-256 network/window identifiers stored until their short windows expire. Expired counters are cleaned during subsequent protected activity. Turnstile, when configured, loads a Cloudflare security widget on account and request pages and validates each single-use token on the server. Cloudflare processes network/browser signals for that security check. No blanket VPN block or guarantee to stop all bots or DDoS attacks is provided.
Session cookies
A Secure, HttpOnly cookie keeps you signed in for up to seven days. Only a hash of its random token is stored in D1. A five-minute cookie binds sign-in to your browser. Expired states and sessions are cleaned up during subsequent sign-in activity. Signing out removes the current session.
Support and access requests
Submitted requests store type, subject, message, submission date and member identifier. You and authorized Owner/Staff reviewers can retrieve request contents. The owner can see your name and verified email alongside requests. Never send passwords or API keys. Submission does not guarantee a response, access or an approved release. When the private bot bridge is configured, new request contents, display name, provider, type, reference and status are sent to the configured Discord review channel. Emails and IPs are excluded. Discord stores these messages separately; website account deletion cannot retract Discord messages or reviewer copies. Do not submit sensitive personal information. Authorized Discord Owner/Staff roles can accept or reject; acceptance changes request status only, not installer or game access. No automated email is sent.
Preparing, copying or downloading a draft does not submit its contents. Drafts remain on the current page unless you explicitly copy or download them.
Staff authorization
Only the configured site owner can grant manual Staff access or remove members. Staff can view and decide requests, but cannot retrieve the member IP directory, export member data or delete memberships. Discord Owner/Staff role synchronization grants request-review access to linked Discord memberships for short renewable two-minute leases; role removal or bot outages expire that access. Manual grants expire after one year or owner revocation. Membership does not automatically join the Discord server.
Retention and deletion
The owner may remove a membership and its active requests, sessions and network record. Removal is not a ban and the person may sign up again. Profiles and requests otherwise remain until you delete your membership; no automatic profile/request expiry is implemented. Sign in, open Account and type DELETE in the deletion section to remove your active profile, requests and sessions. This does not delete your provider account, Cloudflare-managed backups or hosting logs. Their retention is controlled by Cloudflare. Signing in again creates a new membership.
Owner CSV exports contain private information and must be kept private. Deleting active data does not retract previously exported copies. For privacy assistance, submit a request before deleting your account.
Browser demo and desktop records
The demo uses fictional records, with no real-rank lookup or game connection. Focus notes, warm-up checklist and appearance preferences may be stored locally in your browser. Sample match notes are temporary. Clearing this site's browser data removes local preferences. The separate desktop prototype stores up to 30 personal summaries locally; live event behavior still requires validation.
Journal exports
Client-side CSV and JSON journal downloads exclude player names, player IDs, match IDs and personal notes. Sample exports are labelled DEMO. They do not upload summaries to a server.
Website requests
Cloudflare may process normal request data such as IP addresses, URLs and browser details to operate and protect the service. Public pages and the embedded tracker use system fonts; this build does not request external fonts. No application analytics, ads or desktop-use telemetry are implemented. Last sign-in is not proof of tracker usage.
Approvals and future integration
Riot and Overwolf product approvals are not obtained. No endorsement or ban-safety guarantee is claimed. VALORANT trademarks belong to Riot Games, Inc. Future Riot account integration would require a separate reviewed consent flow and updated notice.
Manage membership