ggez.gg

Privacy Policy

What ggez.gg stores, why, for how long, who else processes it, and how you get it corrected or deleted.

Last updated: 2026-05-17. Version 2.0.

1. Controller

Art. 13 (1) (a) GDPR

Christoph Barton, Vienna, Austria. Full postal address: see Impressum.

Contact for data protection requests: privacy@ggez.gg

A dedicated Data Protection Officer (DPO) has not been appointed — the criteria of Art. 37 GDPR are not met (small operator, no large-scale processing of special categories).

2. Data we collect & legal basis

Art. 13 (1) (c) GDPR

PurposeDataLegal basisRetention
Account (email/password)Email, password hash, verification tokenArt. 6 (1) (b) — contractUntil deletion
Google / Discord OAuth loginProvider sub-ID, email, display nameArt. 6 (1) (b) — contractUntil deletion
Riot RSO linkPUUID, game name, tag line. The OAuth token is used during sign-in to read your account and is not stored.Art. 6 (1) (b)Until unlink/deletion
Login sessionSession ID (httpOnly cookie), user IDArt. 6 (1) (f) — security; § 25 (2) TDDDG30 days rolling
League of Legends match data (you & opponents)Match results, items, KDA, timeline events (Riot API)Art. 6 (1) (f) — legitimate interest in providing stats trackerCache 14 days, aggregates indefinitely
Teamfight Tactics match dataRanked match results of high-elo players (PUUID, placement, units, items) — used only in aggregate for the team-comp tier listArt. 6 (1) (f) — legitimate interestAggregated snapshot only; raw responses not stored
VALORANT match data (your own matches)Match results, scoreboard, and the round positions Riot records at each kill, spike plant and defuse (PUUID, Riot ID, agent, map). Loaded only after you sign in with Riot, and only for matches you played in.Art. 6 (1) (a)/(b) — your Riot Sign-On consentCache 24 h (matches), 5 min (match list)
Drawings on the round mapYour pen, arrow and circle marks, and any markers you move§ 25 (2) TDDDG — strictly necessary for the feature you requestedStored only in your browser (localStorage); never transmitted to us
AI Coach chatYour messages, tool-call results, AI responsesArt. 6 (1) (b) — service delivery; (a) for memory90 days (conversation), 12 months (memory)
AI Coach usage analyticsPer message: the message text, which surface it came from, interface language, country (derived by Cloudflare from the connection, not stored as an IP address), Riot region, PUUID if your account is linked, which data tools ran, whether the answer succeeded, and how long it took. A random browser ID is added only if you consented to analytics; without it the entry cannot be linked to your other visits.Art. 6 (1) (f) — legitimate interest in measuring and fixing the feature90 days
Visit counterEach page load adds 1 to a daily counter for the kind of page you landed on. Nothing about you is stored with it. Only if you consented to analytics, your browser keeps a small record (first and last visit day, number of visit days, in localStorage) so the counter can tell new from returning visitors; that record never leaves your browser, only the resulting "new" or "returning" is counted.Art. 6 (1) (f) — legitimate interest in knowing how the site is used; § 25 (1) TDDDG consent for the browser recordDaily totals indefinitely; browser record until you clear it
Rate-limiting / securityIP address (hashed/short-lived), user agentArt. 6 (1) (f) — securityMax 7 days
Cookie consentChoice + timestamp (localStorage)§ 25 (2) TDDDG12 months

3. Third-party processors

Art. 13 (1) (e), Art. 28 GDPR

We have data processing agreements (DPA / AVV gem. Art. 28 GDPR) with all processors below:

  • Cloudflare, Inc. (USA + global edge) — Hosting (Pages, Workers), CDN, D1 database, KV cache, DDoS protection, Turnstile bot check on login, sign-up and the contact form, Email Routing for our @ggez.gg addresses. Standard Contractual Clauses + EU-US Data Privacy Framework.
  • Resend (Plus Five Five, Inc.) (USA) — sends our emails: account verification, password reset and contact-form messages. SCCs + DPF.
  • Turso (ChiselStrike, Inc.) (EU region) — libSQL user database.
  • OpenAI, L.L.C. (USA) — AI Coach chat completion (model gpt-4o-mini). Your chat messages, match data and selected profile data are transmitted to OpenAI in the USA. Transfer mechanism: SCCs + DPF. OpenAI does not use API data to train models per their data usage policy.
  • Anthropic, PBC (USA) — fallback / experimental AI features. SCCs + DPF.
  • Riot Games, Inc. (USA) — Riot Sign-On (RSO) and the game APIs we use: Account-V1, Match-V5 and Spectator-V5 (League of Legends), TFT-Match-V1 and TFT-League-V1 (Teamfight Tactics), VAL-Match-V1 and VAL-Content-V1 (VALORANT). When you link your Riot account, your PUUID and OAuth tokens are exchanged with Riot. VALORANT match data is requested only for the account you signed in with.
  • valorant-api.com (community project, not a processor) — agent and map artwork plus static map metadata. Images are loaded by your browser from that domain, so it receives your IP address; no account data of yours is sent.
  • Google LLC (USA) — Google OAuth login (if used). SCCs + DPF.
  • Discord, Inc. (USA) — Discord OAuth login (if used). SCCs.

4. International transfers

Art. 13 (1) (f), Art. 44-49 GDPR

Transfers to the USA (Cloudflare, OpenAI, Anthropic, Riot, Google, Discord) take place on the basis of Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and, where available, the EU-US Data Privacy Framework (Art. 45 adequacy decision, 10 July 2023).

5. AI Coach — automated processing

Art. 22, Art. 13 (2) (f) GDPR

The AI Coach analyses your match data and generates recommendations using a large language model (OpenAI gpt-4o-mini). This is not an automated decision with legal effect within the meaning of Art. 22 GDPR — recommendations are advisory and do not affect any contract, ranking or legal status. Inputs to the AI are processed in the USA; do not enter sensitive personal data into the chat.

6. Match data of other players

Art. 6 (1) (f), Art. 14 GDPR

To deliver tier lists, opponent stats, OTP (one-trick) detection and matchup analysis, we process publicly available match data from the Riot API which contains other players' game names and PUUIDs. Legal basis: legitimate interest in operating a community stats tracker (Art. 6 (1) (f)). The interest is balanced by: (i) data is provided by Riot via a public API that players consent to under Riot's ToS; (ii) we store no contact data; (iii) any player may request erasure of their data from our caches by emailing privacy@ggez.gg.

6a. Pro players and streamers

Art. 6 (1) (f), Art. 14, Art. 21 GDPR

On leaderboards and profiles we show when a Riot account belongs to a professional player or a streamer: their esports handle, current team and stream channel (Twitch, SOOP, CHZZK). We store only the Riot ID, the handle and the channel name — no real names, no contact data. The link between account and person comes from public community sources: lolpros.gg, Leaguepedia (CC BY-SA 3.0), onetricks.gg, trackingthepros.com, deeplol.gg and the players' own channel pages; teams and lineups come live from the official LoL Esports API. Legal basis: legitimate interest in showing who is who on a public ranked ladder, as other stats sites do (Art. 6 (1) (f)); the data is already public and concerns people in their public role as players or streamers.

Objection: if this is you and you don't want the link shown, press "That's you? Remove" on your profile while signed in with that Riot account — all your known accounts are unlinked at once and stay unlinked on future imports. Without a Riot sign-in, email privacy@ggez.gg and we remove it within 30 days (Art. 21, Art. 12 (3)).

6b. Contact form

Art. 6 (1) (b), (f) GDPR

When you use the contact form, your email address, the optional name and Riot ID and your message are sent to us as an email through our mail provider Resend and are not stored on ggez.gg. We use them only to answer you and delete the mail when the matter is closed. Cloudflare Turnstile checks that the form is sent by a person; it processes technical data such as your IP address and browser characteristics and sets no advertising cookies.

8. Cookies & local storage

§ 25 TDDDG

Strictly necessary (no consent): session cookie (login), cookie-consent record (localStorage), Cloudflare security cookies (__cf_bm).

Functional / Analytics / Marketing (consent required): see cookie banner. You can revoke consent at any time via the banner — open it by clearing the ggez-consent-v2 localStorage entry or by clicking the link in the page footer (coming soon).

9. Your rights

Art. 15-22, 77 GDPR

  • Access (Art. 15) — request a copy of your stored data
  • Rectification (Art. 16) — correct inaccurate data
  • Erasure / "right to be forgotten" (Art. 17) — delete your account & data via Profile → Delete Account, or by email
  • Restriction (Art. 18) — limit processing
  • Data portability (Art. 20) — export your data via Profile → Export My Data (JSON)
  • Objection (Art. 21) — object to processing based on legitimate interest
  • Withdraw consent (Art. 7 (3)) — without affecting prior lawfulness
  • Lodge a complaint with the supervisory authority (Art. 77) — Austrian Datenschutzbehörde (DSB), or in Germany the BfDI / your state authority

To exercise any right, contact privacy@ggez.gg. We respond within 30 days (Art. 12 (3)).

10. Minors

Art. 8 GDPR

Our service is not directed at children under 16. If you are under 16, please use the platform only with verifiable consent of a parent/guardian. We do not knowingly collect data from children under 16 without such consent — contact us if you believe we hold such data.

11. Security

Art. 32 GDPR

TLS encryption in transit, password hashing (Argon2id), database access tokens, principle of least privilege. No system is perfectly secure — please report vulnerabilities responsibly to privacy@ggez.gg.