Privacy policy
This page describes what personal data the mvdanalyzer-api service ("the service") processes, why, and what your options are. The data controller is the operator of this deployment; contact them via the project's issue tracker.
What we collect, and why
When you sign in to this portal
Sign-in uses Discord OAuth2 with the identify scope only. We
receive and store your Discord user id and username —
nothing else: no email address, no server/guild memberships. They are
stored together with your API key record (see below) and are used to
tie your key to your account and to label your API requests in the
access log. Legal basis: performance of the service you request
(issuing and managing your key).
Your API key
We store a SHA-256 hash of your API key, never the key itself (it is shown to you exactly once, at creation), together with the creation time. Regenerating your key revokes the previous one; the revoked record (hash, Discord id/username, timestamps) is retained so revocation stays effective. To have your key records and Discord details deleted entirely, contact the operator.
When you call the API
Requests are recorded in a technical access log: timestamp, method and path, response status and size, latency, a best-effort client IP address, a request id, and a request label (for keyed requests, your key's short identifier / Discord username; for unauthenticated deployments, an optional self-declared label). The log exists for operations, debugging and abuse prevention — including investigating slow-moving abuse patterns (legal basis: legitimate interest). Log entries are kept for up to one year. The operator may derive aggregate usage statistics from these logs (request counts, endpoint popularity, cache hit rates and the like); such statistics are always aggregated and contain no personal data — no IP addresses, no identities. Raw log entries are never shared with anyone, and the logs are not used for profiling.
Cookies
The portal sets strictly necessary cookies only, scoped
to /portal: a short-lived state cookie during the Discord
sign-in handshake and a signed session cookie valid for one hour.
Signing out clears the session. There are no analytics, advertising or
third-party cookies anywhere on the service, and the API endpoints set
no cookies at all.
Demo content (in-game data)
The service analyzes publicly available QuakeWorld demo recordings fetched from hub.quakeworld.nu. Demos contain in-game player nicknames and public in-game chat, which appear in the analytics this API serves. This is a faithful re-presentation of data already published by the QuakeWorld community (legal basis: legitimate interest in community game analysis). If a demo contains something you believe should not be served, contact the operator.
Third parties
Two external services are involved: Discord (the OAuth sign-in — see Discord's own privacy policy) and hub.quakeworld.nu (the public demo source). Nothing is sent to them beyond what those interactions require, and no data is sold or shared with anyone else.
Your rights
Under the GDPR you can request access to, correction of, or deletion of the personal data held about you (your key records, Discord id/username, and any log entries attributable to you), object to processing, and lodge a complaint with your supervisory authority. For any of these, contact the operator via the issue tracker. You can revoke your own key at any time on the key page.