Privacy Policy
Effective date: 2 August 2026
Last updated: 2026-09-28
The short version
teamdiff.gg has no accounts, no sign-in, no analytics and no advertising. We do not collect personal information about visitors browsing the site. You can read every page without telling us anything.
Things are processed when features are used:
- If you search a Riot ID, we fetch that account's public match data from Riot and keep a copy of its recent match history, so the page loads without re-downloading everything on every visit. That copy is held for 60 days from the last time the account was searched, covers the two most recent game patches, and is deleted automatically after that.
- For up to 90 days after an account was last searched, we may refresh that account's match history in the background, so a returning visitor sees their recent games without waiting. This stops automatically if nobody searches the account again, and you can opt out at any time (section 9).
- To stay within Riot's API limits, we enforce a site-wide request budget, and regenerating any one profile or report is limited to once per minute by a short-lived marker keyed to the searched Riot ID. We keep no per-visitor counter of any kind: your IP address is not stored or counted by us.
And one thing is published whether or not anyone asks for it:
- If Riot lists your account in the Challenger tier of a region's Solo/Duo ranked ladder, your Riot ID and your standing appear on our public leaderboard, refreshed once a day, together with your most-played champions and your recent public ranked results. Nobody has to search for you for this to happen — that is what makes it different from the three bullets above. Section 4b says what we keep and for how long; section 9 is how to come off the page.
We also process League of Legends match data from Riot's public API in bulk, aggregated into champion statistics that contain no player identities.
The rest of this page explains that in detail.
1. Who we are
teamdiff.gg is operated by Hyunwook Yim, an individual based in the Republic of Korea.
For any privacy question, including a request to remove data, contact contact@teamdiff.gg (send mail).
2. What this policy covers
This policy covers the website at teamdiff.gg and its subdomains.
It does not cover Riot Games. Your League of Legends account, its match history and its ranked standing are governed by Riot's Privacy Notice. We read match data through Riot's public API; we do not control how Riot collects it.
3. Information we collect from visitors
Nothing, if you are only reading pages.
The site is a set of static pages. It sets no cookies, runs no analytics, embeds no advertising, and has no accounts or sign-in. Browsing the tier list, a champion page or the patch notes records nothing about you.
Your light or dark theme choice is saved in your browser's own storage (localStorage, td.theme) so it is remembered across pages and visits. It is not sent to our servers or synced across browsers or devices. It remains until you change it or clear your browser's site data. If browser storage is unavailable, the choice applies only to the current page.
If you use the search box, your selected region and your last 10 searches (Riot ID and region) are saved in your browser's own storage (localStorage) so the search box can offer them back to you. They are never sent to our servers, are visible only on your device, and clearing your browser's site data removes them.
If you save an Opening Lab practice focus, this browser stores one active practice record under td.opening.practice. The record contains the normalized Riot ID and platform, the starting match's metadata and recorded opening checkpoints, your selected focus, an optional note of up to 500 characters, and its creation and expiry timestamps. Saving this record does not upload it or its note to our servers, and it does not synchronize with other browsers or devices.
The saved focus expires 14 days after it is created. It becomes unavailable after expiry and is removed when Opening Lab next reads it on a visit; a closed browser cannot perform that cleanup. You can remove it earlier with Clear saved practice or by clearing the browser's site data. The profile no longer uses the previous td.review.open setting. Match data fetched to display an opening remains subject to the separate account-data handling described in section 4a.
Two things are recorded when you use the search feature, and neither identifies you:
| What | Why | How long |
|---|---|---|
| A refresh marker keyed to the searched Riot ID — no visitor information | To keep the search feature inside Riot's API limits without counting visitors: any one account's data is regenerated at most once a minute | Expires within 60 seconds |
| A single timestamp meaning "somebody used the site just now", with no address or identifier attached | Our background data collection pauses while a person is using the site, so your search never queues behind it | Expires within 15 minutes |
Searching an account also creates a record about that account — see section 4.
What our host sees
The site is served by Cloudflare Pages. Like any web host, Cloudflare processes connection information — IP address, browser type, requested page — in order to deliver the page and protect against abuse. This is handled under Cloudflare's own privacy policy. We do not receive these logs, do not have access to them, and do not use them.
4. Match data we process
This section is about the bulk collection behind our champion statistics. Two other things we hold are about identified people, and each has a section of its own: data about an account somebody has searched (section 4a), and the public Challenger ladder (section 4b).
To build the statistics, we collect completed ranked match records through the Riot Games API.
What each record contains: the match identifier, the game patch, and for each of the ten participants — champion played, assigned role, win or loss, kills, deaths, assists, creep score, gold earned, damage dealt, final items, summoner spells and rune selections. For a sample of matches we additionally collect the timeline: the order items were purchased and abilities were levelled.
What each record does not contain: no summoner name, no Riot ID, no PUUID, no account identifier of any kind. These records are anonymous at the point of collection — we never store who played the match. The challenger matches behind section 4b are written to a separate file and never enter this one; our release check fails the build if a single byte of the anonymous file changes while the ladder is running.
One exception, and we want to be clear about it. To find matches to collect, we read lists of ranked players from Riot's league endpoints and keep a record of which player identifiers (PUUIDs) we have already visited, purely so we do not crawl the same account twice. This list contains no names, no match data and no statistics — only identifiers, used for deduplication. It is deleted when a crawl finishes. The ladder in section 4b keeps its own, separate record of the accounts Riot lists as Challenger; that one is described there, and it is not this list.
What we publish, and there are three kinds:
- Anonymous aggregates. A figure such as "Kai'Sa, bottom lane, 51.3% win rate over 24,118 games" describes thousands of matches collected as above, with no identity attached to any of them. The tier lists, builds and matchups are all of this kind.
- Public data about identified players. A player report describes the searched account's own recent public matches — the same data visible in the game client and on comparable statistics sites — and is generated only when someone searches that Riot ID. The public Challenger leaderboard describes the accounts Riot itself lists at the top of each region's ranked ladder, and it is not generated on request: it is published daily whether or not anyone asked. Section 4b covers it in full. If you want your Riot ID excluded from search, write to us (section 9) and we will block it; if you want to come off the leaderboard, section 9 is the route for that too.
- Nothing about visitors. We publish nothing about the people who read the site, because we collect nothing about them (section 3).
4a. Data we keep about a searched account
This section covers accounts that someone has looked up. If your Riot ID has never been searched on teamdiff.gg, none of this applies to you.
Why any of it is kept. Riot's API is rate limited. Re-downloading an account's entire match history on every page view would be slow for you and would exhaust the limits for everyone else. So when an account is searched, we keep a working copy.
| What we keep | Contents | How long |
|---|---|---|
| Match history copy | The account's recent ranked games — for each game, the ten participants' in-game display names, champions, roles, results and scoreboard figures, each team's objective counts, and, where it could be measured exactly, the LP the searched account gained or lost in that game. Held for the two most recent game patches, up to 500 games. | 60 days from the last search of that account, then deleted automatically |
| Rank history | One entry per calendar day: date, tier, division, LP, and the identifier of the newest ranked game seen at that moment. Up to 400 entries, none older than 400 days — so the record can carry across a season boundary. Collected when the account is searched, and then re-read at most once a day for as long as the "has been searched" record lasts — 90 days from the last search. The two numbers are different things: 90 days is how long we keep updating the record, 400 days is how long we keep it. | Points over 400 days old are dropped whenever the record is next updated, and the whole record is deleted 400 days after the last time the account was searched — sooner if it is deleted on request |
| A record that the account has been searched | An account identifier and a timestamp. No name, no statistics. | 90 days from the last search, then deleted automatically |
| A cached copy of the finished page | The rendered report | Up to 42 days, or until the game patch changes |
| The Riot ID last seen for an account | The account's current Name#Tag, stored against its identifier. No statistics. | 42 days, the same life as the cached page it exists to remove |
These records are stored under an account identifier, but the records themselves do not contain it. Nothing we send to a browser contains a PUUID.
Background refresh. For as long as the "has been searched" record exists — 90 days from the last search — our collector may fetch that account's newly completed ranked games and add them to the stored match history, and re-read its current ranked standing. A returning visitor then sees their recent games immediately instead of waiting for a download, and the rank graph can gain a point for a day on which nobody looked. Both are background best-effort and always yield to live use of the site, so neither is a promise about any particular day — "at most once a day" above is a ceiling on what we do, not a guarantee that we did it. This is the only processing we do about an identified account without a request in that moment, and it is why the 90-day record exists at all. It ends by itself if the account is not searched again, and you can switch it off or have everything deleted at any time (section 9).
What we do not do with it. We do not sell it, share it for advertising, build advertising profiles, combine it with data from anywhere other than Riot's API, or use it to identify anyone off the Service.
4b. The public Challenger ladder
Riot publishes, through its own API, the accounts currently in the Challenger tier of each region's Solo/Duo ranked ladder — the same list the game client shows. Once a day, when the date turns in that region's own time zone, we take a copy of it and publish it as our leaderboard. It is the one thing on the Service that names players without anyone having asked for them, which is why it has a section to itself.
Who this applies to. Accounts Riot currently lists in Challenger, in Solo/Duo ranked, in the fifteen regions we cover. It applies to nobody else: we do not publish Grandmaster, Master or any other tier, and we do not publish Flex ladders.
What the page shows, for each listed account: the Riot ID, the position on the ladder, League Points, wins and losses, how those figures moved since the previous day's copy, up to three most-played champions with a game count for each, and the results of recent ranked games as wins and losses. All of it is drawn from what Riot publishes about that account.
What we store to build it:
| What we keep | Contents | How long |
|---|---|---|
| The daily standings | Per region: an account identifier, League Points, wins and losses, and how each moved since the previous copy | The most recent copy per region — each day's copy replaces the one before it |
| A Riot ID for each listed account | An account identifier and the Riot ID it belongs to, so the page can print a name rather than an identifier | For as long as we publish the ladder. An entry is not dropped when an account leaves Challenger, so an account that returns does not have to be looked up again |
| Recent ranked games of listed accounts | One row per game per listed account: the match identifier, the champion played, win or loss, kills, deaths, assists, position, game patch and time. Not the other nine players in the game | The two most recent game patches, then deleted — the same rule, and the same trigger, as the anonymous records in section 4 |
Three things this store is not. It is not mixed into the anonymous records of section 4: challenger games go to a file of their own, and our release check fails the build if the anonymous file changes by a single byte while the ladder runs. It puts no account identifier into anything a browser can read: the page, and the data files behind it, carry Riot IDs and no PUUIDs, and the same release check looks for identifiers in every file we publish. And it holds nothing about an account Riot does not list in Challenger.
Coming off it. Write to us (section 9). We take the account off the published page, delete the rows we hold for it, and keep it out of every later copy — deleting alone would not hold, because the next day's copy of Riot's list would put the account straight back. The exclusion stays in force until you tell us otherwise, and it does not stop you being searched for or using the site. Honouring the request means keeping one thing: the account identifier itself, on a list used for nothing except keeping the account off the page. It carries no name, no standing and no match data, and we hold it for as long as the exclusion stands.
5. Why we process it, and our legal basis
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Publish champion tier lists, builds and matchup statistics | Anonymous match records | Legitimate interest |
| Avoid collecting the same account twice | Player identifiers, for deduplication only | Legitimate interest |
| Show a searched account its own match history and report | That account's public match and rank data | Legitimate interest — the person searching has asked for exactly this, and the data is already public in the game client |
| Keep a searched account's history up to date in the background | That account's identifier and public match data | Legitimate interest, and you may object at any time (section 9) — it exists only to make a returning visit fast, ends after 90 days of no searches, and is switched off on request |
| Keep the search feature inside Riot's rate limits | A site-wide request budget and 60-second refresh markers keyed to the searched account — no visitor data | Legitimate interest |
| Publish the public Challenger ladder | Riot ID, ladder standing, public match results | Legitimate interest — Riot publishes the same standings itself and the data is public in the game client, and you may object at any time (section 9) |
Where we rely on legitimate interest, we have weighed it against individual rights. The match data we read is already available through Riot's own systems and through every comparable statistics site. For the bulk collection behind our champion statistics we strip identities at the point of collection, and what we publish from it describes champions rather than people. Where we do publish data about identified players — a report someone searched for, or the Challenger ladder Riot itself publishes — we publish only what is already public in the game client, we keep it no longer than the page needs it, and anyone who would rather not appear can say so and be removed (section 9).
6. Automated processing
Champion statistics are calculated by our own software using ordinary statistical methods — averages, proportions, and a shrinkage estimator that pulls small samples toward the mean so that a champion with few games cannot top the list on a lucky streak.
Written match reviews. The Service can produce a written review of a player's recent games. Every number and every judgement in it is computed by our own software from the match data, using fixed rules and comparisons against same-role averages from our Emerald–Diamond crawl.
Where a language model is used, it is used only to rewrite already-computed findings into readable sentences. It never calculates anything, never decides anything, and is never given an account identifier, a summoner name or a raw match record — only the finished figures. Turning that rewriting off changes the wording of a review and none of its content.
There is no automated decision-making that produces legal or similarly significant effects. These are statistics about a video game.
7. Who we share with
We do not sell data, and we do not share it for advertising or marketing.
| Recipient | What they handle | Why |
|---|---|---|
| Cloudflare | Serving the website | Hosting and content delivery |
| Vultr | The server that collects and aggregates match data | Infrastructure |
| A language-model provider | Rewrites already-computed findings into sentences (section 6). Receives figures only — no identifiers, names or raw match records | Readability of written reviews |
Published aggregate statistics contain no personal information and may be shared freely. The public Challenger leaderboard is different: it carries Riot IDs and is published openly on the site, which is what it is for. It is not handed to any of the recipients above — section 4b says what it holds and how to come off it.
8. How long we keep things
| Data | Retention |
|---|---|
| Aggregate statistics published on the site | Indefinitely — they contain no personal information |
| Anonymous match records used to build them | The three most recent game patches; older records are deleted |
| Player identifiers used for crawl deduplication | Deleted when the collection cycle finishes |
| The daily Challenger standings behind the public leaderboard | The most recent copy per region; each day's copy replaces the one before it |
| Riot IDs of the accounts on the Challenger ladder | For as long as we publish the ladder |
| Challenger accounts' recent ranked game rows | The two most recent game patches, then deleted |
| A request to stay off the public leaderboard | Kept until you withdraw it — it is what keeps the account off the page |
| A searched account's match history copy | 60 days from the last search, then deleted automatically |
| A searched account's rank history | 400 days from the last search, then deleted automatically; points over 400 days old are dropped on each update; sooner if deletion is requested |
| The record that an account has been searched (enables background refresh) | 90 days from the last search, then deleted automatically |
| Cached rendered reports | Up to 42 days, or until the game patch changes |
| The Riot ID last seen for an account (so a changed name cannot serve the previous holder's page) | Up to 42 days |
| Refresh-cooldown markers (keyed to the searched account, never the visitor) | Within 60 seconds |
| The "site is in use" timestamp | Within 15 minutes |
| Visitor browsing data | Not collected, so nothing to retain |
9. Your rights
Under the Korean Personal Information Protection Act (PIPA), the GDPR, and comparable laws elsewhere, you may request access to, correction of, or deletion of personal information we hold about you, object to processing, and complain to your data protection authority.
We store no visitor data at all, and the bulk collection behind our champion statistics strips player identities at the point of collection. What we hold about identified people is in two places, and only two: what section 4a describes about accounts somebody has searched, and what section 4b describes about accounts Riot lists in Challenger.
If you believe your data appears on the Service and want it removed, or want your account excluded from future collection, write to contact@teamdiff.gg (send mail). We will respond within 30 days.
You can ask us, for your Riot ID, to:
- delete the stored match history, rank history and search record;
- switch off background refresh while still allowing manual searches;
- block the account from search entirely, so it cannot be looked up on the Service at all;
- come off the public Challenger leaderboard — we delete the rows we hold for the account and keep it out of every later copy of Riot's list, so it does not reappear the next day (section 4b).
None of these require an account, and we will not ask you for anything beyond the Riot ID in question and enough to show it is yours.
If everything expires on its own first, that is also fine — the match history copy is deleted 60 days after the last search and the search record after 90 days, with no action from anyone. The leaderboard is the exception: while Riot lists an account in Challenger it stays on the page until somebody asks for it to come off.
10. International transfers
We operate from the Republic of Korea. Our hosting providers operate globally, and match data is processed on a server located in Seoul. Where data is handled outside your region by those providers, it is covered by their own transfer mechanisms — see the Cloudflare privacy policy linked in section 3.
11. Security
The site is served over HTTPS. The collection server accepts no inbound connections except administrative access over SSH with key-based authentication, has a default-deny firewall, and stores API credentials in files readable only by the account that runs the collector.
No system is perfectly secure. If a breach affects personal information we will notify affected people and the relevant authority without undue delay.
12. Children
teamdiff.gg is a statistics site with no accounts and collects nothing from visitors of any age. It is not directed at children under 14. If you believe we hold a child's personal information, contact contact@teamdiff.gg (send mail) and we will delete it.
13. Changes
We will post any changes here and update the date at the top. If a change is material — in particular if we ever begin collecting visitor data — we will give clear notice on the site before it takes effect.
14. Contact
contact@teamdiff.gg (send mail)
Hyunwook Yim, Republic of Korea