Privacy Policy
Summary. CarryForge has no advertising SDK, third-party analytics or CarryForge account system. It does not sell personal data. Linking a Riot ID is optional and is used to show that player their own match history and coaching. Local League credentials stay on the device.
1. Who controls the data
CarryForge is currently operated by Ziya, an independent developer trading as CarryForge. Privacy and deletion questions can be sent to [email protected]. Before commercial launch, this notice will be updated with the final verified individual or legal-entity details used for the Microsoft Store and Riot Developer Portal.
2. Website data
carryforge.net does not set marketing cookies and does not embed a third-party video player; the product walkthrough is served from the same site. The web host and Cloudflare network may process standard connection information such as IP address, date/time, requested URL, response status, user agent and security signals to deliver the site, prevent abuse and troubleshoot faults. Their own infrastructure and legal retention rules also apply.
3. Optional Riot account link
If you enter a Riot ID (GameName#TAG), the app sends it to the CarryForge stats service, which uses Riot’s Web API to resolve and process:
- Riot ID, PUUID and region/platform;
- recent match and timeline data, ranked tier and role;
- champions, items, runes, kills/deaths/assists, farm, gold and objective timing needed for the views you request.
The purpose is to show your own history, role/champion performance and rule-based coaching. CarryForge does not use this information for advertising, public scouting or an alternative ranking system. Personal response caches are held in memory for up to 30 minutes to reduce Riot API requests and are not used to build a permanent server-side profile.
4. Aggregate patch samples
CarryForge may cache a limited sample of Match-V5 records by platform and patch to calculate aggregate champion and build statistics. Before disk storage, direct player identifiers are removed, including PUUID lists, Riot ID names/tags, summoner identifiers/names and profile identifiers. The remaining gameplay sample is capped per platform/patch and expires after 30 days by default (the server permits a 1–90 day operational setting). It is not linked to your local CarryForge account record.
5. Data kept on your device
The app stores preferences locally, which may include language, region, primary role, recommendation weighting, champion pool order, matchup notes, linked Riot ID/PUUID, onboarding state, HUD modules/position, theme and the post-lock loadout-sync choice. This data remains until you remove it in the app, clear app data or uninstall.
If you link a Riot ID, the desktop app also keeps a local match archive: a compact summary of your own past matches, written to %LOCALAPPDATA%\CarryForge\archive on your computer. Each entry holds only your own result — champion, role, patch, queue, K/D/A, CS, gold, final items, runes, summoner spells, and (when available) your item-purchase order, skill order and per-minute CS/gold — plus the champion names of the other nine players. Other players' PUUIDs, Riot IDs and summoner names are deliberately not stored. The archive exists so build and coaching suggestions can learn from your own history without re-downloading it, and it is not uploaded to CarryForge servers. You can export it to a file or delete it at any time in Settings, and uninstalling removes it.
League Client lockfile credentials are read locally only when the desktop integration needs them. They are not uploaded to CarryForge servers. The app does not collect keystrokes, capture the screen, read game/process memory or inspect network packets.
6. League Client actions and Live Client Data
Manual champion hover, ban confirmation and rune/item/spell import require visible player input. A separate Settings opt-in, off by default, may send only one rune page and item set after the player has locked a champion; it does not pick, ban or lock a champion. The in-game HUD reads Riot Live Client Data for on-screen metrics and remains read-only. HUD positions and module choices are stored locally.
7. Store entitlement and external AI
The current public beta does not enable external AI coaching. The server contains a disabled entitlement gate for a possible future Microsoft Store add-on. If that feature is later approved and activated, a Store licence/entitlement token would be processed to verify access and a minimised draft or match summary could be sent to the named AI provider. CarryForge will not enable that flow without an updated notice, appropriate player choice and the required Riot/store review. Raw Riot IDs, PUUIDs, match IDs and raw Riot API payloads are not intended to be sent to the AI provider.
8. Service security and rate limiting
The service uses HTTPS, a server-side Riot API key, origin restrictions, bearer access controls and short-lived per-IP rate-limit state. Riot API keys are never included in the desktop binary. Operational logs may be reviewed only for security, reliability and abuse prevention.
9. Recipients and international processing
Data is processed only as needed by the following categories of recipient: Riot Games for Riot API requests; the cloud host and Cloudflare for delivery/security; and, only if a future paid entitlement is enabled, Microsoft Store. External AI is not an active recipient in the public beta. These providers may process data in other countries under their own terms and safeguards.
10. Retention and deletion
- Local app data: until you unlink, clear app data or uninstall.
- Local match archive: kept on your device until you delete it in Settings, clear app data or uninstall. It is not stored on CarryForge servers.
- Personal API response cache: up to 30 minutes in server memory.
- Sanitised aggregate match samples: 30 days by default, never more than the configured 90-day maximum.
- Per-IP rate-limit state: short-lived in memory and removed after inactivity or a service restart.
- Infrastructure/security logs: according to operational need and hosting-provider controls.
Unlinking removes the account link from your device; it does not call Riot to delete Riot’s own records. For access, correction or deletion questions about data controlled by CarryForge, email [email protected] with enough information to identify the request. Identity may need to be verified before a request is completed.
11. Legal basis and your choices
Where data-protection law applies, optional Riot ID processing is based on your request/consent and providing the feature; security and aggregate service operation rely on legitimate interests in running a safe, useful product. You can choose not to link a Riot ID, turn off HUD modules and post-lock sync, or stop using the service. Depending on your location, you may have rights to access, correct, erase, restrict or object to processing, and to complain to a regulator.
12. Children and changes
CarryForge is not directed to children under 13 and does not knowingly collect personal data from them. This policy will be updated before any materially different processing starts; the date above shows the current version.
13. Riot Games
Riot’s own privacy notice applies to data Riot controls: Riot Games Privacy Notice.
