Privacy Policy

Last updated: April 12, 2026 · GDPR compliant
Plain English summary We collect the minimum data needed to run RiftRec: your email (encrypted), display name, the videos you upload, and basic usage logs. We don't sell your data, don't use it for advertising, and don't share it with anyone except the friends you choose. You can export or delete everything at any time.

1. Who we are

RiftRec ("we", "us") is the data controller responsible for your personal data when you use our services. We're operated from Finland.

For privacy questions, contact our Data Protection contact at privacy@riftrec.app.

2. What data we collect

Account data (when you register)

DataWhyHow long
Email addressLogin, account recovery, communicationUntil account deletion
PasswordAuthentication (stored as bcrypt hash, never plaintext)Until account deletion
Display nameIdentification within the platformUntil account deletion
Bio (optional)Profile customizationUntil you remove it
Avatar URL (optional)Profile picture (we don't store the image)Until you remove it

Email encryption: We encrypt email addresses at rest using AES-256-GCM, so even if our database were compromised, emails would be unreadable without our encryption key.

Content you upload

DataWhyHow long
Video files (clips)Core service — your gameplay recordingsUntil deleted by you, replaced by quota cleanup, or account deleted
Voice review recordingsCoaching featureUntil deleted by you or sender/recipient
Bookmarks and notesCoaching annotations on clipsUntil deleted
Direct messagesCommunication with friendsCapped at 50 messages per conversation; older messages auto-deleted
Comments on clipsDiscussion featureUntil deleted

Usage data (collected automatically)

DataWhyHow long
IP addressSecurity, rate limiting, abuse prevention30 days in access logs
Browser type and versionCompatibility, security30 days in access logs
Pages visited and timestampsService operation, debugging30 days in access logs
Last login timeAccount securityUntil account deletion
Last seen timeOnline status indicator for friendsUntil account deletion

Optional data (only if you choose)

DataWhy
Riot Games account info (PUUID, game name, tag line)Link your in-game profile to your RiftRec account
Friend connectionsSocial features (sharing clips, voice chat)
Group membershipsTeam-based clip sharing
Ratings you give to other usersCoaching reputation system

3. What we DON'T collect

4. Legal basis for processing (GDPR)

Under the EU General Data Protection Regulation, we process your data on these legal bases:

5. Who we share data with

We share data only with these third parties, and only to the extent necessary:

ServiceWhat we sharePurposeLocation
Hetzner Online GmbHAll hosted data (encrypted in transit and at rest)Server hosting, object storageHelsinki, Finland
Paddle.com Market LimitedEmail, name, billing info (if you subscribe)Payment processingUK / EU
Let's EncryptDomain name onlyFree SSL certificatesUSA

We do not use:

6. Where your data is stored

All data is stored at Hetzner's Helsinki, Finland datacenter. This means:

If we expand to additional regions in the future, we'll update this policy and notify users.

7. Your rights under GDPR

As an EU resident, you have the following rights regarding your personal data:

Right of access (Article 15)

You can request a copy of all data we hold about you. We'll provide it in a machine-readable format (JSON) within 30 days, free of charge.

Right to rectification (Article 16)

You can edit your profile, display name, bio, and other details directly in the app at any time.

Right to erasure / "right to be forgotten" (Article 17)

You can delete your account at any time from the settings page. This permanently removes:

Note: Backup snapshots may retain traces of your data for up to 30 days after deletion. After that period, all backups containing your data have rotated out.

Right to data portability (Article 20)

You can export your data in JSON format from the settings page or by emailing privacy@riftrec.app.

Right to object (Article 21)

You can object to processing based on legitimate interests by emailing us. We'll stop unless we have compelling legitimate grounds to continue.

Right to restrict processing (Article 18)

You can ask us to stop using your data while we resolve a complaint or correction.

Right to lodge a complaint

If you believe we've violated your privacy rights, you can complain to Finland's data protection authority:

Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman)
Lintulahdenkuja 4, 00530 Helsinki, Finland
Website: tietosuoja.fi

8. Cookies

We use a minimal set of cookies and browser storage:

We don't use tracking cookies, ad cookies, or third-party cookies. No cookie consent banner is required because we only use technically essential storage.

9. Children's privacy

RiftRec is not intended for children under 13. We don't knowingly collect data from anyone under 13. If you're a parent and believe your child has registered, contact us and we'll delete the account.

For users 13–17 (or below the age of majority in your country), we recommend parental supervision. Some features (like voice chat with strangers) may not be appropriate for minors.

10. Data security

We take security seriously. Measures include:

11. Data breach notification

If we discover a personal data breach that's likely to result in a high risk to your rights, we'll notify you within 72 hours as required by GDPR Article 34. Notifications will be sent by email and posted prominently on the site.

12. International data transfers

Currently all data stays within the EU. If we add servers in other regions in the future, we'll use Standard Contractual Clauses (SCCs) and other GDPR-compliant transfer mechanisms.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced via email and in-app notice at least 14 days before they take effect.

14. Contact us

For privacy questions, data access requests, or to exercise your GDPR rights:

Email: privacy@riftrec.app
Postal address: Available on request via privacy@riftrec.app
Response time: Within 30 days, usually within 7