Public document · updated 24 August 2026
Privacy policy.
This policy explains the data processed by Moon Poro Bot on Discord, in the current profile-icon verification and in the planned Riot Sign On flow.
1. Controller
The data controller is Ceendi, the operator of Moon Poro Bot, Polska. For access, deletion or any privacy question, email kontakt@moonporo.pl. Do not send passwords or other confidential information.
2. Data and sources
Depending on the feature, we process:
- Discord user and guild IDs and information needed to manage roles;
- moderation data such as user and moderator IDs, the reason, level and status of a warning, timestamps, and audit message IDs;
- Riot PUUID, Riot ID, League platform and public Solo/Duo data: tier, division, LP, wins, losses and inactive status;
- verification time and method; during the current verification we also read the League of Legends profile icon temporarily, but do not retain it in the active link;
- timestamps and operational state needed to schedule, retry and synchronise rank updates;
- after RSO launches: short-lived verification-session state and non-sensitive error codes;
- for logged administrator lookups: administrator ID, stated reason, relevant PUUID or Discord ID and timestamp;
- limited operational logs needed for security and incident diagnosis.
We receive data from the user, Discord and the official Riot API. Discord and Riot identifiers are required to create a link; without them the bot cannot verify an account or manage the corresponding roles.
The /profil command shows the link owner data from the last successful update in a private response. Win rate is calculated when displayed and is not stored separately. Roles are visible according to the Discord server settings, and audit messages are visible to people who can access the relevant channels.
We do not receive a Riot password or Riot account email. We do not persist RSO tokens. After RSO launches, a short-lived access token will be used only in process memory to retrieve the Riot ID and platform, then discarded. We do not request offline access or retain a refresh token. There is no advertising, analytics or behavioural tracking.
3. Purposes and legal bases
- Providing the service requested by the user: linking accounts, displaying the profile, assigning verification, platform and rank roles, and keeping them current.
- Legitimate interests: operating moderation, preventing impersonation, protecting the community, auditing administrator actions, and diagnosing and retrying failed operations.
- Legal obligation: responding to a binding request from a competent authority, if one occurs.
The bot automates data and role updates, but does not make decisions that produce legal or similarly significant effects for the user.
4. Recipients and hosting
Discord provides bot and community infrastructure, Riot Games provides authentication and game APIs, and Google Cloud Platform hosts the application and database. Each provider processes data under its own terms and notices. Providers may process data outside the European Economic Area using the transfer grounds and safeguards they describe.
The operator and authorised server administrators may access data only as needed for moderation or support. Administrator lookups of account links require a stated reason and are logged. We do not sell data or provide it to data brokers.
5. Retention
- active Discord–Riot link, stored rank data and update state: until the user runs /usun_weryfikacje, an administrator removes the link, or the product ends;
- profile icon read during the current verification: only for the time needed to check the one-time challenge;
- after RSO launches: an incomplete session expires after 10 minutes, and completed or expired metadata is normally deleted after 7 days during the next daily cleanup;
- administrator account-link lookup log: 90 days, unless it is needed for an active investigation;
- moderation data and audit messages: for as long as needed to enforce server rules and document moderator decisions;
- daily and pre-deployment database backups: normally 90 days; data deleted from the active database may remain in a backup until the end of that period and is used only for disaster recovery;
- application logs: size-rotated with no more than two backups and retained only for operational security and diagnosis.
6. Cookies and security
The static site does not set cookies. After launch, the dynamic RSO flow will set one strictly necessary cookie named moon_poro_rso. It will be HttpOnly, Secure and SameSite=Lax, will exist only to display the current result, and will expire after 10 minutes.
Controls include HTTPS, high-entropy one-time tokens, OAuth state validation, SHA‑256 session digests, restrictive browser headers, rate limits, separation of the RSO secret from the Discord bot, and least-privilege processes. No system is absolutely secure; incidents are assessed and reported as required by law.
7. Your rights
Where applicable, you may request access, correction, erasure, restriction or portability, or object to processing. The fastest way to remove an account link is /usun_weryfikacje. We may verify identity through Discord before fulfilling a request.
You may complain to the Polish President of the Personal Data Protection Office (UODO) or your local supervisory authority.
8. Children and changes
The service is not directed at anyone who cannot lawfully use Discord or a Riot account. Material policy changes will be dated and published here. If the law requires additional action from the user, we will provide notice before further processing.