PRIVACY / PLAYER DATA
Privacy Policy
This policy explains what the public prototype handles today and how player data will be handled when approved account features are activated.
- Last updated
- 25 July 2026
- Product stage
- Production-application prototype
CURRENT STATUS
The public demo contains fixture data.
It does not connect to a Riot account, retrieve a visitor's match history, run advertising, take payment, or make the prototype available through a development or personal Riot API key. The hosting service may still process ordinary security and access logs when the site is visited.
1. Controller and contact
The controller responsible for Untilt is Brilune.
Privacy requests can be sent to privacy@untilt.lol.
2. Information covered by this policy
When the relevant features are activated, Untilt may process:
- Account and authorization data: the Riot account identifier returned through Riot Sign On, Riot ID, region, authorization state, and Untilt account settings.
- Game data: eligible match identifiers, match summaries, timelines, participant mapping for the linked player, patch, queue, rank, role, champion, events, and item timings obtained through documented Riot APIs.
- Coaching data: computed evidence, private reviews, inferred habits, practice focuses, progress history, and feedback the player provides about a review.
- Service and security data: IP address, timestamps, device and browser information, request identifiers, consent choices, authentication events, error records, and abuse-prevention signals.
- Commercial and support data: plan and entitlement state, payment-provider references, invoices required by law, and messages sent to support. Untilt does not need to store complete payment-card details.
3. Sources
Data may come directly from the player, from Riot through approved APIs and Riot Sign On, from the player's use of Untilt, and from service providers operating the website. Untilt does not obtain player data by scraping undocumented sources, reading game memory, or inspecting network packets.
4. Purposes and legal bases
5. Evidence generation and automated analysis
Untilt computes game events and comparisons and may use a language model to turn those computed facts into readable coaching. Reviews can contain bounded inferences and recommendations, but every claim must reference evidence and disclose important limitations.
These reviews do not produce legal or similarly significant effects, are not an official skill ranking, and should not be treated as a complete account of everything that happened in a match.
6. Sharing and processors
Data is shared only as needed with providers that host the application, database, queues, monitoring, email, model inference, customer support, payments, consent management, or approved advertising and analytics. Each provider receives only the data needed for its role and must be bound by appropriate data-protection terms.
Untilt does not sell a player's personal match or coaching history. Personal coaching is not made public by default. Aggregated public statistics are designed not to identify a specific player. The active provider list and relevant transfer safeguards will be published before those providers receive production player data.
7. International transfers
Untilt prefers European hosting and processing where practical. If a provider processes personal data outside the European Economic Area, Untilt will use an applicable adequacy decision or safeguards such as the European Commission's standard contractual clauses, together with supplementary measures where required.
8. Retention and deletion
- Direct account-to-match links, private reviews, habits, and progress history are kept while the account is active and are scheduled for deletion when the player deletes or disconnects the account, subject to a short recovery and backup-expiry period.
- Operational and security logs are retained only for the period needed to investigate reliability, abuse, or security events.
- Billing and transaction records are retained for the period required by tax, accounting, and payment laws.
- Match facts that have been irreversibly separated from the player and included in aggregate statistics may remain in those non-identifying aggregates.
Exact production retention schedules and deletion-job verification will be published before live account linking is activated.
9. Security
Untilt is designed to encrypt provider identifiers at rest, keep API and OAuth credentials in server-side secret storage, remove identifying values from general match records, redact sensitive log fields, restrict access by role, and record source and model provenance. No internet service can guarantee absolute security.
10. Player rights
Depending on applicable law, a player may request access, correction, deletion, restriction, portability, or objection; may withdraw consent for future processing; and may complain to a data protection authority. Identity may need to be verified before a request is completed.
In Finland, the supervisory authority is the Office of the Data Protection Ombudsman. Players may also contact the authority in the EU or EEA country where they live or work.
11. Children
Untilt is not directed to children who cannot lawfully authorize the service under their local law. A user must meet Riot's applicable age requirements and obtain parental or guardian authorization where required.
12. Changes
Material changes will be dated and explained on this page. When required, Untilt will provide additional notice or request renewed consent before the change takes effect.