PRIVACY POLICY

Last updated: July 18, 2026

StackUp ("we", "the Service") is a multi-game LFG / stack-finder with a web app, optional Discord bot, and desktop client. This Privacy Policy explains what we collect, why, and your choices. It applies when you use our hosted Service. If you self-host StackUp, you are the operator for that instance and should publish your own policy.

Information we collect

  • Account (OAuth) — Discord and/or Google: provider user ID, username / display name, avatar, and email when the provider grants it (Google requires a verified email). We do not store Discord or Google OAuth access or refresh tokens for your login. Bot tokens live only in server environment config for the StackUp bot.
  • Profile — StackUp username, game prefs (rank, roles, region, language, vibe), optional bio / Riot ID-style fields, and Discord visibility (including Hide Discord).
  • Looking / In Match — status you set, session start/expiry, and filter preferences used for discovery and Discord live boards.
  • LFG rooms — rooms you host or join (mode, game, server, language, roles needed, team code). When a room or Looking session is created from a Discord community bot, we store source guild attribution: Discord guild ID, display name, and icon hash/URL snapshot so other players can see which server the post came from.
  • Discord guild settings — for servers that add the bot: guild ID, name, icon, optional feature flags, channel IDs for boards/logs, installer Discord user ID, and enabled state. Used to run boards and LFG sync for that community.
  • Chat — LFG room chat and match DMs are stored in plaintext so the Service can deliver them and moderators can review reports. Friend DMs use end-to-end encryption: we store ciphertext and public keys only; private keys stay on your device.
  • Safety — friend requests, friendships, blocks, user reports (reason and optional notes — not encrypted friend-DM plaintext), ban records, and ban appeals you submit.
  • Match activity — when you express interest in another player (for matching and optional Discord notifications).
  • Technical — IP address and basic request metadata for rate limiting, abuse prevention, and security (e.g. failed sign-in lockouts). We do not use advertising trackers for this product.

Discord bot — what we process

When the bot is in a server, Discord provides guild and channel metadata needed to create or update Looking / In Match / Idle boards and to post moderation embeds (reports/appeals) to configured channels or webhooks. Board embeds show player display names and status derived from StackUp sessions — not a full archive of every Discord message in your server.

We do not use the bot to scrape unrelated chat history. Commands and interactions you run with the bot are processed to fulfill the request. Desktop Rich Presence (Looking / In Match / LFG) is set by the StackUp client on your machine via Discord's local RPC; we do not receive a separate copy of your presence payload beyond the status already stored for LFG.

How we use information

  • Authenticate you and operate discovery, rooms, and chat
  • Show public profile / Looking fields to other signed-in users (respecting Hide Discord)
  • Attribute community LFG to the Discord server it came from
  • Run Discord boards, optional notifications, and Rich Presence status
  • Moderate the Service (reports, bans, appeals, ops tools). Friend E2EE DMs are not readable by moderators; they act on reports, blocks, and account actions instead
  • Keep the Service secure and rate-limited

Sharing

We do not sell your personal data. Other signed-in users see the profile and LFG fields you make available. Hide Discord keeps your Discord identity off cards and Connect links; Google account IDs are never shared with other players. Source guild name/icon may appear on LFG posts that originated from that server.

Trusted operators with admin access may view account fields, LFG room chat, match DMs, reports, and appeals for safety. Infrastructure providers (hosting, Supabase, Discord, Google) process data solely to run the Service under their agreements with us.

Retention & deletion

Looking sessions auto-expire (about 45 minutes for free accounts). Account, profile, room, chat, guild settings, and moderation records are kept while needed to operate the Service and handle abuse. You may request account deletion by contacting us (below). We may retain limited ban / appeal records as needed to prevent evasion and meet legal obligations.

Children

StackUp is intended for users who meet Discord's (and, if applicable, Google's) minimum age. We do not knowingly collect data from children below those ages. If you believe a child has used the Service, contact us so we can delete the account.

Your choices

  • Edit or clear profile fields in the app
  • Use Hide Discord to limit Discord visibility to others
  • Leave Looking / close rooms / remove the bot from a server
  • Block users and submit reports or ban appeals
  • Request account deletion via the contact methods below

Contact

Privacy or deletion requests: open a private report via GitHub Security Advisories or contact the maintainer on GitHub. See also Terms and Community Guidelines.