Privacy Policy
Last updated: 2026-09-15
This policy explains how FPS Tournament App processes personal data.
1. Data We Collect
- Twitch identity data needed for authentication and account linking (for example Twitch user ID, username, display name, profile image URL).
- Discord account-linking data when you link Discord (for example Discord user ID, username, discriminator, avatar).
- Tournament and team data you submit (teams, members, scores, registrations, chat messages, overlay settings).
- Optional first-party analytics data (only when analytics consent is accepted): analytics session identifier, visited page/path, timestamps, browser user agent, request IP for visit tracking, and minimized event metadata.
- Operational telemetry and security logs (timestamps, technical diagnostics, moderation/security events).
- Clip/highlight metadata and related references required by feature workflows.
2. Optional Analytics and Consent
- Non-essential analytics is optional and remains disabled until you choose Accept analytics.
- If you choose Necessary only, optional analytics requests remain disabled.
- Analytics events use minimized metadata after A2.1C payload minimization.
- Analytics event user linkage is limited to authenticated Twitch ID only where supported by current code paths.
- Chat message content is not stored in analytics payloads.
3. Legal Basis and Purpose
- Contract/performance: to provide tournament, overlay, and account functionality.
- Legitimate interest: service security, abuse prevention, diagnostics, and moderation.
- Consent/authorization where required by Twitch OAuth scopes and user settings.
4. Browser Storage, Cookies, and Session Data
- We use cookies, localStorage, and sessionStorage for different purposes.
- See the dedicated Cookie / Storage page for item-level classification and purposes:
- Cookie / Storage Policy
5. Third-Party Services Used by Current Implementation
- Twitch login and Twitch API features use official Twitch OAuth and APIs.
- Discord OAuth is used for account linking features.
- OpenAI is used in OCR-enabled flows to extract data from submitted screenshots/KD images (for example result verification OCR and registration KD image OCR).
- Cloudinary is used for media storage/delivery in clip and highlight workflows.
- MongoDB (Atlas) is used as the application data store.
- Vercel (frontend hosting) and Render (backend hosting) are used in deployment configuration and may process request metadata as infrastructure providers.
- Twitch content and API usage are additionally subject to Twitch Terms/Developer policies.
6. Data Sharing
- We do not sell personal data.
- Data is shared only when needed for service operation, legal compliance, or trusted processors under contract.
- When OCR-enabled submission paths are used, submitted image references can be processed by OpenAI for OCR extraction.
7. Retention
- Analytics visits are retained for 180 days (automatic TTL deletion).
- Analytics events are retained for 90 days (automatic TTL deletion).
- OCR-related pending/approved/review records (including stored image references and extracted OCR fields) are kept according to operational needs; no fixed time-based TTL is currently defined for these records in audited runtime schemas.
- Data is retained only as long as required for active service operation, legal duties, dispute handling, and security records.
- You can request deletion through in-app GDPR controls or support contact.
8. OCR Decision Boundary
- OCR output is used as extraction/verification support, not as a standalone final moderation decision.
- Tournament result approval/rejection is human-reviewed through moderator/creator/admin review flow.
- For submissions based on OCR extraction alone, low-confidence or invalid extraction is rejected and the user is directed to submit the result manually.
- When a submitted result is compared with screenshots for moderation, extracted values and confidence may be retained for human review instead of being rejected solely for low confidence.
- For registration KD images, extracted values and confidence are stored with the registration when available. Registration can continue if extraction fails; this workflow does not require manual resubmission solely because confidence is low.
- /manualsubmit does not run OCR, but evidence screenshots are still required for moderator review.
9. Security
- We use HTTPS, access controls, and operational monitoring.
- No method is 100% secure, but reasonable safeguards are maintained.
10. Your Rights
- Access, correction, deletion, and objection rights where applicable by law (including GDPR rights for EU users).
- You can revoke Twitch authorization from Twitch account settings.
11. Contact
For privacy requests, use the Support & Contact page in the app. If this service is operated commercially, publish your legal entity details and privacy contact email here.
12. Third-Party Policy Links (Twitch)