Public document · updated 10 August 2026
Privacy policy.
This policy explains how Moon Poro processes data during Riot Sign On verification and normal Discord operation.
1. Controller
The data controller is Jakub Cendalski, the operator of Moon Poro Bot, Polska. For access, deletion or any privacy question, email kontakt@moonporo.pl. Do not disclose private information in a public GitHub issue.
2. Data processed
Depending on the feature, we process:
- Discord user and guild IDs;
- Riot PUUID, Riot ID, League platform and public Solo/Duo rank data;
- verification time and method and the technical audit-message ID;
- short-lived RSO session state and non-sensitive error codes;
- for audited administrator lookups: administrator ID, stated reason, relevant PUUID or Discord ID and timestamp;
- limited operational logs needed for security and incident diagnosis.
We do not receive or retain a Riot password, Riot account email, RSO access token, ID token or refresh token. There is no advertising, analytics or behavioural tracking.
3. Purposes and legal bases
- Service performance: linking accounts, assigning verified, platform and rank roles, and keeping them current.
- User consent: the user deliberately starts RSO and authorises access on Riot's page. They may cancel before completion.
- Legitimate interests: preventing impersonation, protecting the community, auditing moderator actions and resolving failures.
- Legal obligation: responding to a binding request from a competent authority, if one occurs.
4. Recipients and hosting
Discord provides bot and community infrastructure, Riot Games provides authentication and game APIs, and Google Cloud Platform hosts the application and database. Each provider also processes data under its own terms and notices. The operator and authorised server administrators may access links only for moderation or support; their lookups are audited.
We do not sell data or provide it to data brokers.
5. Retention
- Discord–Riot link: until the user runs /usun_weryfikacje, an administrator removes it, or the product ends;
- incomplete RSO session: expires after 10 minutes; session metadata is deleted within 7 days;
- administrator lookup audit: 90 days, unless required for an active investigation;
- application logs: size-rotated with no more than two backups and retained only for operational security and diagnosis.
6. Cookies and security
The dynamic RSO flow sets one strictly necessary cookie named moon_poro_rso. It is HttpOnly, Secure and SameSite=Lax, exists only to display the current result, and expires after 10 minutes.
Controls include HTTPS, high-entropy one-time tokens, OAuth state validation, SHA‑256 session digests, restrictive browser headers, rate limits, a separate RSO service account, and least-privilege processes. No system is absolutely secure; incidents are assessed and reported as required by law.
7. Your rights
Where applicable, you may request access, correction, erasure, restriction, portability, object to processing, or withdraw consent without affecting prior lawful processing. The fastest erasure method is /usun_weryfikacje. We may verify identity through Discord before fulfilling a request.
You may complain to the Polish President of the Personal Data Protection Office (UODO) or your local supervisory authority.
8. Children and changes
The service is not directed at anyone who cannot lawfully use Discord or a Riot account. Material policy changes will be dated and published here; where fresh consent is required, it will be requested before further processing.