Privacy Policy — RiftSeeker

Last updated: 2026-09-03 — Versione italiana più in basso

This Privacy Policy explains what personal data the RiftSeeker mobile application (the "App"), the website riftseeker.lol and the RiftSeeker Discord bot collect, why, for how long, and what your rights are.

RiftSeeker is an unofficial, fan-made companion tool for the Riftbound trading card game. RiftSeeker isn't endorsed by Riot Games and doesn't reflect the views or opinions of Riot Games or anyone officially involved in producing or managing Riot Games properties. Riot Games, and all associated properties are trademarks or registered trademarks of Riot Games, Inc.

If you do not agree with this Privacy Policy, please do not use the App.


1. Who is responsible (data controller)

The data controller is Giovanni Malfa ("Dreidor"), an individual developer based in Italy.

Email: admin@riftseeker.lol

This is the only contact address for privacy matters. We reply within 30 days.


2. At a glance

DataWhen it is collectedWho can see itHow long we keep it
Email, sign-in identity (Google / Facebook / Discord user id)Account creation, account linkingYou; the developerUntil you delete your account
Nickname, friend code, referral code, profile settingsOnboarding, profile editsOther users (nickname, friend code, reputation); the developerUntil you delete your account
Precise device locationOnly while the Radar is switched on (also in the background)Nobody sees the precise position. Other users only see a coarse ~2.8 km grid cell and a distance rounded to 0.5 kmOverwritten every 90–180 s; deleted when you stop the Radar, at the expiry you chose (max 4 h) and in any case by a cleanup job that runs every 10 minutes. Rows not refreshed for 15 minutes are never shown
Chat messagesWhen you send themSender and recipient; the developer (technically, e.g. to handle a report)Until you or the recipient delete them, or until account deletion; deleted messages are purged after 30 days
Collection, decks, lists, match historyWhen you create themPer the visibility you choose (private / friends / public)Until you delete them (purged 30 days after deletion) or delete your account
Trades, trade feedback and reputation scoreWhen you log a trade or leave feedbackThe two parties; the aggregated score is publicUntil account deletion (feedback you gave may be kept anonymised)
Reports you fileWhen you report a user or messageThe developer (moderation)Until account deletion (kept anonymised if needed for moderation)
Push notification tokenSign-in (Android)The developer's serverRemoved at sign-out and account deletion
Purchase data (Google Play purchase token, product id, expiry, state)When you buy PremiumThe developer's server; GoogleUntil account deletion
Advertising ID (free tier only, with consent in the EEA/UK/CH)When ads are shownGoogle AdMob and its partnersPer Google's policies
Crash reports (Firebase Crashlytics)If the App crashesThe developer; GoogleUp to 90 days
Camera frames (card scanner)While scanningProcessed on the device only — never uploadedNot stored

We do not use analytics or marketing trackers, and we do not sell personal data.


3. What we collect and why

3.1 Account and sign-in

To use the social features you need an account. Supabase Auth (our authentication provider, hosted in the EU) stores:

If you link Discord, the RiftSeeker Discord bot can match your Discord user id to your RiftSeeker account when you use its commands (for example /referral).

The App can also be used without an account (guest mode) for the card catalog, collection and deck builder on your device only.

3.2 Profile

Your nickname (chosen by you), an automatically generated friend code and referral code, your collection/deck visibility settings, the timestamp of your acceptance of the Terms of Service, and your Premium status. Nickname, friend code, reliability score and (if you have any) public trade lists are visible to other users; the friend code is searchable so people can add you.

3.3 Location (Radar) — precise, only when you turn it on

The Radar lets you find other players nearby. It is off by default and we ask for the location permission only when you activate it, after showing you a disclosure.

While the Radar is on, the App runs a foreground service (with a persistent notification) that reads your precise device location every 90–180 seconds, also when the App is in the background, and uploads it to our server together with your status, optional announcement, search radius and the session expiry you chose (1, 2 or 4 hours).

Your precise position is stored privately: no other user can read it, not even through the API. Other players only obtain, through a server function, your position snapped to a ~2.8 km grid and your distance rounded to 0.5 km buckets ("< 500 m", "~1 km", …), limited to a radius of at most 25 km, and only while your session is active and refreshed within the last 15 minutes. Users you have blocked (or who blocked you) never see you.

You can hide yourself at any time ("Visible on map" off), stop the Radar from the App or from the notification, or revoke the permission in the system settings. Your position row is deleted when you stop, at the session expiry, and in any case by a cleanup job that runs every 10 minutes.

Radar sessions also power trade matching: while both players have the Radar on, the server compares your public trade list and wishlist with those of nearby players and notifies both sides about matching cards.

3.4 Messages (chat)

Chat messages between friends are stored on our server and delivered in real time. They are protected in transit (TLS) and by per-user access rules, but they are not end-to-end encrypted: the developer can technically access them, and does so only to handle a report you or the other party filed, or when required by law. A sender can unsend a message within 2 minutes. Deleted messages are purged 30 days after deletion; all messages are deleted with your account.

New-message push notifications only tell you who wrote (the sender's name): the text of the message is never included in the notification, so it does not appear on the lock screen or pass through the notification service. You can disable message notifications in the system settings.

3.5 Collection, decks, lists, match history (your content)

The cards you own, your decks and card lists (including notes and labels), and your match history (opponent name, result, event, location and notes you type) are stored on your device and synced to our server when you are signed in. Collection and decks are shared only according to the visibility level you set (private, friends or public); trade lists and wishlists can be made visible to nearby players for Radar matching.

3.6 Trades, feedback and reputation

When you log a trade you can record the counterpart (a friend or a free-text name), the cards exchanged, a meeting place and notes. Trade proposals to friends are shared with them. After a completed trade both parties may leave feedback (rating and optional comment); feedback and derived reliability score are shown to other users next to your nickname so that strangers can assess trust before meeting.

3.7 Friends, blocks, reports

Friend requests, friendships, block lists and the reports you submit (with the reason, your details and, for message reports, the quoted message) are stored to run the service and moderate it. Reports are visible to the developer only.

3.8 Referrals

Your referral code, the code that referred you (if any) and the number of reward weeks earned are stored to grant the referral rewards.

3.9 Purchases (Premium)

Premium is sold as an auto-renewing subscription through Google Play Billing. We receive from Google Play the purchase token, the product id and the subscription state/expiry, and we verify them with Google's servers to unlock Premium on your account. We never see your payment method or billing address; Google Play is the merchant of record.

3.10 Push notifications

On Android we store the Firebase Cloud Messaging token of your device to deliver friend requests, messages, trade updates, Radar pings, trade matches and app news. The token is deleted when you sign out and when you delete your account.

3.11 Advertising

If you are not a Premium subscriber the App shows ads served by Google AdMob. AdMob may collect a resettable advertising ID, coarse IP-based location and app/device signals to serve, measure and (with consent) personalise ads. In the EEA, the UK and Switzerland ads are shown only after you make a choice in the Google User Messaging Platform consent dialog; you can change or withdraw your choice at any time from Settings → Ad privacy options in the App.

3.12 Crash reports

The App uses Firebase Crashlytics to receive crash reports (stack trace, device model, OS version, app version, a Crashlytics installation id and basic device state). Crash reports do not include your email, messages or location. We use them only to fix bugs.

3.13 Card scanner (camera)

The scanner uses the camera to recognise cards. Frames are processed on the device and are never uploaded or stored.

3.14 App settings

Preferences such as language, theme, grid size and Radar notification options are synced to your account so they follow you across devices.

3.15 Technical logs

Our hosting provider keeps standard server logs (IP address, request time, endpoint) for security and debugging, rotated within 30 days.



5. Who we share data with

We do not sell personal data and we do not share it for third-party marketing.


6. International transfers

Our database and authentication run in the European Union. Google, Meta and Discord may process data in the United States and elsewhere; they rely on the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.


7. Retention

See the table in section 2. In short: account data lives as long as your account; Radar positions are deleted within minutes of stopping; deleted content (cards, decks, lists, messages, friendships, notifications) is kept as a "deleted" marker for 30 days so that your other devices can sync the deletion, then purged; crash reports are kept by Google for up to 90 days; server backups are rotated within 30 days. When you delete your account everything linked to it is removed immediately (see section 9); feedback you left for other users and reports may be kept in anonymised form, unlinked from you.


8. Your rights

Under the GDPR you can ask us to access, rectify, erase, restrict or port your data, object to processing based on legitimate interest, and withdraw consent at any time. You can also lodge a complaint with your supervisory authority — in Italy the Garante per la protezione dei dati personali.

Most of it you can do yourself in the App:

For access or portability requests write to admin@riftseeker.lol from the email linked to your account; we provide a machine-readable export (JSON) within 30 days.


9. Deleting your account

You can permanently delete your account and all associated data directly in the App: Profile → Account → Delete account, then confirm. Deletion is immediate and cannot be undone; it removes your profile, collection, decks, lists, match history, trades, messages, friendships, blocks, notifications, Radar position, push token, referral data, purchase records and your sign-in identity.

If you can no longer open the App, request deletion at riftseeker.lol/delete-account or by email; we will verify that you control the account's email before deleting.

An active Google Play subscription is not cancelled by deleting the account: cancel it in Google Play → Payments & subscriptions → Subscriptions.


10. Children

RiftSeeker is for adults only: you must be 18 or older to create an account. The App is published on Google Play with an 18+ target audience because it includes chat between users, a Radar that shares an approximate position with nearby players and advertising. We do not knowingly collect personal data from minors; if you believe a minor has created an account, contact us and we will delete it.


11. Security

All traffic uses TLS. Access to data on the server is enforced per user with row-level security rules; sensitive operations (purchase verification, account deletion, moderation) run server-side with the user's identity verified. Precise Radar positions are never readable by other users. No system is perfectly secure: report any issue to the contact address above.


12. Changes

We may update this policy. The current version is always available at riftseeker.lol/privacy and inside the App (Settings → About). Material changes will be announced in the App.


13. Contact

Giovanni Malfaadmin@riftseeker.lol



Informativa sulla privacy — RiftSeeker

Ultimo aggiornamento: 03/09/2026 — In caso di discrepanze fa fede la versione inglese.

Questa informativa spiega quali dati personali raccolgono l'app RiftSeeker (l'"App"), il sito riftseeker.lol e il bot Discord di RiftSeeker, perché, per quanto tempo e quali sono i tuoi diritti.

RiftSeeker è uno strumento amatoriale non ufficiale per il gioco di carte Riftbound. RiftSeeker non è approvato da Riot Games e non riflette le opinioni di Riot Games o di chiunque sia ufficialmente coinvolto nella produzione o gestione delle proprietà di Riot Games. Riot Games e tutte le proprietà associate sono marchi o marchi registrati di Riot Games, Inc.

Se non accetti questa informativa, non utilizzare l'App.

1. Titolare del trattamento

Il titolare è Giovanni Malfa ("Dreidor"), sviluppatore indipendente con sede in Italia.

Email: admin@riftseeker.lol

È l'unico recapito per le questioni privacy. Rispondiamo entro 30 giorni.

2. In sintesi

DatoQuando viene raccoltoChi può vederloConservazione
Email, identità di accesso (id utente Google / Facebook / Discord)Creazione account, collegamento accountTu; lo sviluppatoreFino alla cancellazione dell'account
Nickname, friend code, codice referral, impostazioni profiloOnboarding, modifiche al profiloAltri utenti (nickname, friend code, reputazione); lo sviluppatoreFino alla cancellazione dell'account
Posizione precisa del dispositivoSolo con il Radar attivo (anche in background)Nessuno vede la posizione precisa. Gli altri vedono solo una cella di ~2,8 km e una distanza arrotondata a 0,5 kmSovrascritta ogni 90–180 s; eliminata quando fermi il Radar, alla scadenza scelta (max 4 h) e comunque da una pulizia automatica ogni 10 minuti. Le righe non aggiornate da 15 minuti non vengono mai mostrate
Messaggi di chatAll'invioMittente e destinatario; lo sviluppatore (tecnicamente, es. per gestire una segnalazione)Finché tu o il destinatario li eliminate o fino alla cancellazione dell'account; i messaggi eliminati vengono rimossi dopo 30 giorni
Collezione, mazzi, liste, storico partiteAlla creazioneSecondo la visibilità che scegli (privato / amici / pubblico)Finché li elimini (rimossi 30 giorni dopo) o cancelli l'account
Scambi, feedback e punteggio di affidabilitàQuando registri uno scambio o lasci un feedbackLe due parti; il punteggio aggregato è pubblicoFino alla cancellazione dell'account (i feedback che hai lasciato possono restare in forma anonima)
Segnalazioni che inviiQuando segnali un utente o un messaggioLo sviluppatore (moderazione)Fino alla cancellazione dell'account (in forma anonima se necessarie alla moderazione)
Token per le notifiche pushAccesso (Android)Il server dello sviluppatoreRimosso al logout e alla cancellazione dell'account
Dati di acquisto (purchase token Google Play, id prodotto, scadenza, stato)Acquisto di PremiumIl server dello sviluppatore; GoogleFino alla cancellazione dell'account
ID pubblicitario (solo versione gratuita, con consenso in SEE/UK/CH)Quando vengono mostrati annunciGoogle AdMob e partnerSecondo le policy di Google
Segnalazioni di crash (Firebase Crashlytics)In caso di crashLo sviluppatore; GoogleFino a 90 giorni
Fotogrammi della fotocamera (scanner)Durante la scansioneElaborati solo sul dispositivo — mai caricatiNon conservati

Non usiamo strumenti di analytics o tracker di marketing e non vendiamo dati personali.

3. Cosa raccogliamo e perché

3.1 Account e accesso. Per le funzioni social serve un account. Supabase Auth (il nostro provider di autenticazione, ospitato nell'UE) conserva l'email (per la registrazione con email/password) e/o l'identità fornita da Google, Facebook (Meta) o Discord quando accedi o colleghi questi provider (id utente del provider, email, nome visualizzato — mai la password), oltre ai token di sessione. Se colleghi Discord, il bot Discord di RiftSeeker può associare il tuo id Discord al tuo account quando usi i suoi comandi (es. /referral). L'App può essere usata anche senza account (modalità ospite) per catalogo, collezione e mazzi, solo sul dispositivo.

3.2 Profilo. Nickname (scelto da te), friend code e codice referral generati automaticamente, impostazioni di visibilità di collezione e mazzi, data di accettazione dei Termini di servizio, stato Premium. Nickname, friend code, punteggio di affidabilità ed eventuali liste di scambio pubbliche sono visibili agli altri utenti; il friend code è ricercabile.

3.3 Posizione (Radar) — precisa, solo quando lo attivi. Il Radar è disattivato per impostazione predefinita; il permesso di localizzazione viene richiesto solo quando lo attivi, dopo un'informativa. Con il Radar attivo l'App esegue un servizio in primo piano (con notifica persistente) che legge la posizione precisa ogni 90–180 secondi, anche in background, e la invia al nostro server insieme a stato, annuncio facoltativo, raggio di ricerca e scadenza scelta (1, 2 o 4 ore). La posizione precisa è conservata in modo privato: nessun altro utente può leggerla, nemmeno tramite API. Gli altri giocatori ottengono, tramite una funzione del server, solo la posizione arrotondata a una griglia di ~2,8 km e la distanza arrotondata a scatti di 0,5 km ("< 500 m", "~1 km", …), entro un raggio massimo di 25 km e solo mentre la sessione è attiva e aggiornata negli ultimi 15 minuti. Gli utenti bloccati (in entrambe le direzioni) non ti vedono mai. Puoi nasconderti in qualsiasi momento ("Visibile sulla mappa" off), fermare il Radar dall'App o dalla notifica, o revocare il permesso nelle impostazioni di sistema. La riga con la tua posizione viene eliminata quando fermi il Radar, alla scadenza e comunque da una pulizia automatica ogni 10 minuti. Le sessioni Radar alimentano anche la corrispondenza scambi: mentre entrambi i giocatori hanno il Radar attivo, il server confronta lista scambi e wishlist pubbliche con quelle dei giocatori vicini e notifica entrambi.

3.4 Messaggi (chat). I messaggi tra amici sono conservati sul nostro server e consegnati in tempo reale. Sono protetti in transito (TLS) e da regole di accesso per utente, ma non sono cifrati end-to-end: lo sviluppatore può tecnicamente accedervi, e lo fa solo per gestire una segnalazione o quando la legge lo richiede. Il mittente può annullare l'invio entro 2 minuti. I messaggi eliminati vengono rimossi dopo 30 giorni; tutti i messaggi vengono eliminati con l'account. Le notifiche push dei nuovi messaggi indicano solo chi ti ha scritto (il nome del mittente): il testo del messaggio non è mai incluso nella notifica, quindi non compare sulla schermata di blocco e non transita dal servizio di notifica. Puoi disattivare le notifiche dei messaggi nelle impostazioni di sistema.

3.5 Collezione, mazzi, liste, storico partite. Le carte che possiedi, i mazzi e le liste (con note ed etichette) e lo storico partite (nome avversario, risultato, evento, luogo e note che inserisci) sono salvati sul dispositivo e sincronizzati sul server quando hai effettuato l'accesso. Collezione e mazzi sono condivisi solo secondo il livello di visibilità che imposti; liste di scambio e wishlist possono essere rese visibili ai giocatori vicini per la corrispondenza Radar.

3.6 Scambi, feedback e reputazione. Registrando uno scambio puoi indicare la controparte (un amico o un nome libero), le carte scambiate, il luogo d'incontro e note. Le proposte di scambio agli amici sono condivise con loro. Dopo uno scambio completato entrambe le parti possono lasciare un feedback (valutazione e commento facoltativo); feedback e punteggio di affidabilità derivato sono mostrati agli altri utenti accanto al nickname.

3.7 Amici, blocchi, segnalazioni. Richieste di amicizia, amicizie, liste di blocco e segnalazioni (con motivo, dettagli e, per i messaggi, il testo citato) sono conservati per far funzionare e moderare il servizio. Le segnalazioni sono visibili solo allo sviluppatore.

3.8 Referral. Il tuo codice referral, il codice di chi ti ha invitato e le settimane di ricompensa ottenute.

3.9 Acquisti (Premium). Premium è un abbonamento con rinnovo automatico venduto tramite Google Play Billing. Riceviamo da Google Play il purchase token, l'id prodotto e stato/scadenza dell'abbonamento e li verifichiamo con i server di Google per attivare Premium. Non vediamo mai il metodo di pagamento né l'indirizzo di fatturazione; il venditore è Google Play.

3.10 Notifiche push. Su Android conserviamo il token Firebase Cloud Messaging del dispositivo per recapitare richieste di amicizia, messaggi, aggiornamenti scambi, ping Radar, corrispondenze e novità. Il token viene eliminato al logout e alla cancellazione dell'account.

3.11 Pubblicità. Senza abbonamento Premium l'App mostra annunci di Google AdMob, che può raccogliere un ID pubblicitario reimpostabile, posizione approssimativa basata sull'IP e segnali app/dispositivo per mostrare, misurare e (con consenso) personalizzare gli annunci. In SEE, Regno Unito e Svizzera gli annunci compaiono solo dopo la tua scelta nella finestra di consenso Google User Messaging Platform; puoi modificarla in qualsiasi momento da Impostazioni → Opzioni privacy annunci.

3.12 Segnalazioni di crash. L'App usa Firebase Crashlytics per ricevere i crash (stack trace, modello del dispositivo, versione OS e app, un id di installazione Crashlytics, stato base del dispositivo). Non includono email, messaggi o posizione. Servono solo a correggere i bug.

3.13 Scanner (fotocamera). I fotogrammi sono elaborati sul dispositivo e mai caricati o conservati.

3.14 Impostazioni. Lingua, tema, dimensione griglia e opzioni di notifica Radar sono sincronizzate sull'account per seguirti su più dispositivi.

3.15 Log tecnici. Il provider di hosting conserva log server standard (indirizzo IP, ora, endpoint) per sicurezza e debug, ruotati entro 30 giorni.

4. Basi giuridiche (GDPR)

Contratto (art. 6.1.b): account, sincronizzazione, funzioni social, chat, scambi, Radar, Premium. Consenso (art. 6.1.a): posizione (permesso di sistema + attivazione Radar), pubblicità personalizzata (consenso UMP), notifiche; revocabile in ogni momento senza pregiudicare i trattamenti precedenti. Legittimo interesse (art. 6.1.f): sicurezza, prevenzione abusi, moderazione, crash report, sistema di reputazione. Obbligo di legge (art. 6.1.c).

5. Destinatari

Altri utenti (solo come descritto sopra e secondo le tue scelte di visibilità); responsabili del trattamento: Supabase (database, autenticazione, storage, funzioni — UE, regione Parigi), Google (Firebase Cloud Messaging, Crashlytics, AdMob + UMP, Play Billing, Google Sign-In), Meta (Facebook Login), Discord (login, bot della community); fornitori di dati sulle carte (TCGGO, Cardmarket, TCGplayer, Riftcodex) da cui scarichiamo dati pubblici — nessun tuo dato personale viene inviato loro; autorità, se obbligati per legge. Non vendiamo dati personali.

6. Trasferimenti extra-UE

Database e autenticazione sono nell'Unione Europea. Google, Meta e Discord possono trattare dati negli Stati Uniti in base al Data Privacy Framework UE-USA e/o alle Clausole Contrattuali Standard.

7. Conservazione

Vedi tabella al punto 2. I dati dell'account durano quanto l'account; le posizioni Radar vengono eliminate entro pochi minuti dallo stop; i contenuti eliminati restano come marcatore per 30 giorni (per sincronizzare la cancellazione sugli altri dispositivi) e poi vengono rimossi; i crash report restano su Google fino a 90 giorni; i backup del server vengono ruotati entro 30 giorni. Con la cancellazione dell'account tutto ciò che è collegato viene rimosso subito (punto 9); feedback lasciati ad altri utenti e segnalazioni possono restare in forma anonima.

8. I tuoi diritti

Puoi chiedere accesso, rettifica, cancellazione, limitazione, portabilità, opporti ai trattamenti basati sul legittimo interesse e revocare il consenso in ogni momento; puoi presentare reclamo al Garante per la protezione dei dati personali. Nell'App puoi: modificare nickname, visibilità e impostazioni (Profilo → Account / Impostazioni); spegnere il Radar, nasconderti o revocare il permesso; cambiare il consenso pubblicitario (Impostazioni → Opzioni privacy annunci); eliminare singoli contenuti; cancellare l'intero account (punto 9). Per accesso o portabilità scrivi a admin@riftseeker.lol dall'email collegata all'account: forniamo un export leggibile da macchina (JSON) entro 30 giorni.

9. Cancellazione dell'account

Puoi cancellare definitivamente l'account e tutti i dati associati direttamente nell'App: Profilo → Account → Elimina account, poi conferma. La cancellazione è immediata e irreversibile: rimuove profilo, collezione, mazzi, liste, storico partite, scambi, messaggi, amicizie, blocchi, notifiche, posizione Radar, token push, dati referral, record di acquisto e identità di accesso. Se non riesci più ad aprire l'App, richiedi la cancellazione su riftseeker.lol/delete-account o via email; verificheremo che controlli l'email dell'account prima di procedere. Un abbonamento Google Play attivo non viene annullato dalla cancellazione dell'account: annullalo da Google Play → Pagamenti e abbonamenti → Abbonamenti.

10. Minori

RiftSeeker è riservato ai maggiorenni: per creare un account devi avere almeno 18 anni. L'App è pubblicata su Google Play con pubblico di destinazione 18+ perché include chat tra utenti, un Radar che condivide una posizione approssimativa con i giocatori vicini e pubblicità. Non raccogliamo consapevolmente dati di minori; se ritieni che un minore abbia creato un account, contattaci e lo elimineremo.

11. Sicurezza

Tutto il traffico usa TLS. L'accesso ai dati sul server è vincolato per utente con regole di sicurezza a livello di riga; le operazioni sensibili (verifica acquisti, cancellazione account, moderazione) avvengono lato server con identità verificata. Le posizioni Radar precise non sono mai leggibili da altri utenti. Nessun sistema è perfettamente sicuro: segnala qualsiasi problema al recapito indicato.

12. Modifiche

Possiamo aggiornare questa informativa. La versione corrente è sempre disponibile su riftseeker.lol/privacy e nell'App (Impostazioni → Info). Le modifiche rilevanti saranno annunciate nell'App.

13. Contatti

Giovanni Malfaadmin@riftseeker.lol