Privacy Policy
This policy explains what information Riftbot handles across accounts, the card market, AI chat, watchlists, and alerts, why it is used, and the choices available to you.
Effective August 20, 2026 · Last updated August 20, 2026
1. Scope and operator
This Privacy Policy applies to the Riftbot website, card market, accounts, chat, watchlists, Telegram alerts, and related support interactions (together, the “Service”). Riftbot is an independently operated fan service. It is not affiliated with, endorsed by, or sponsored by Riot Games or the publishers of Riftbound.
The Riftbot operator is responsible for the information described in this policy. Privacy questions and rights requests can be emailed to contact@riftbot.ai.
2. Information we handle
Information you provide or authorize
- Account information: if you sign in with Google, Google provides the name, email address, email-verification status, profile image, provider account identifier, and authorization scope made available through the sign-in flow.
- Chat content: questions and instructions you submit, plus the answers, citations, and conversation context generated for you.
- Watchlists and alerts: starred card identifiers, requested last-sale notifications, and the settings needed to deliver them.
- Feedback and support: helpful or unhelpful ratings, associated trace identifiers, and information you choose to include in a support request.
Google is the only account sign-in method; Riftbot does not collect a Riftbot password. Riftbot does not currently process payments or ask for collection inventory. Do not place sensitive personal information, confidential information, credentials, or private collection details in a chat prompt.
Information collected automatically
- Account and session records: internal user, account, and session identifiers; sign-in provider; session token and expiration; account and session timestamps; IP address; user agent; and provider tokens or token-expiration records returned as part of the authorized Google sign-in flow.
- Pseudonymous chat identity: a random visitor identifier stored in the signed HTTP-only
riftbot-visitorcookie. It separates visitors’ threads and supports security and request controls. - Network and request data: IP address or hosting-provider network identifier, request time, route, browser language and user agent, response status, and security or rate-limit events. A keyed hash may replace a raw network identifier in the rate-limit store.
- Chat identifiers: thread, run, trace, and feedback identifiers used to route requests, maintain conversation state, and diagnose answers.
- Watchlist storage: starred card identifiers are stored locally and mirrored to a first-party cookie for anonymous visitors. When signed in, watchlist items are also associated with the account so they can sync across sessions.
- Telegram notification data: if you connect Telegram, Riftbot stores numeric Telegram user and private-chat identifiers, optional display information, connection status, alert choices, delivery status, and bounded sale facts needed to explain a notification.
- Optional product analytics: only after you allow analytics, PostHog and Vercel Analytics may receive page views, navigation, clicked links, filter selections, starred card identifiers and names, referring page, browser and device details, and approximate location derived from network information. PostHog uses a pseudonymous analytics identifier and is linked to the internal user identifier after sign-in. Session replay is disabled.
3. How we use information
Riftbot uses the information above to:
- create and authenticate accounts and maintain sessions;
- answer questions and maintain conversation context;
- show, sync, and filter watchlists;
- detect last sales and deliver requested Telegram alerts;
- retrieve requested rules, card, listing, and market information;
- receive answer feedback and diagnose failed or low-quality responses;
- secure the Service, prevent abuse, enforce request limits, and troubleshoot errors;
- operate, maintain, and improve reliability and response quality;
- measure product use when optional analytics are allowed; and
- comply with legal obligations and protect users, the operator, and others.
Where data-protection law requires a lawful basis, processing is based on providing the Service you request, the operator’s legitimate interests in operating and securing the Service, compliance with law, or consent for optional analytics. You may withdraw analytics consent at any time for future processing.
4. AI processing and service providers
Chat content and necessary conversation context are sent to OpenRouter, which routes the request to the model provider configured for Riftbot. Those providers process the content to generate an answer. Their retention, abuse-monitoring, and data-location practices may apply. Avoid submitting information you would not want processed by an external AI provider.
Information may also be processed by providers supporting these functions:
- Google for account authentication and the profile fields you authorize;
- Vercel for website hosting and, only with consent, web analytics;
- Neon-hosted PostgreSQL for account, watchlist, notification, and application data;
- PostgreSQL conversation-checkpoint storage;
- Upstash-compatible Redis for rate limiting and abuse prevention;
- Syncd, eBay, and linked marketplaces for requested card, market, and listing data;
- optional LangSmith diagnostics and feedback. When enabled, Riftbot hides raw trace inputs and outputs and redacts sensitive metadata before transmission; answer ratings and operational trace metadata may still be processed;
- PostHog, only with consent, for pseudonymous traffic, navigation, and interaction measurement; and
- Telegram, when connected, to deliver requested card names, observed sale prices, and source links.
Offline services such as Firecrawl collect public Riftbound source material and are not used to collect information from your browser. Providers may process information in countries other than your own. Where required, the operator relies on appropriate contractual or other lawful transfer safeguards.
5. Cookies, local storage, and analytics choices
Riftbot uses necessary cookies and local storage for chat identity, sign-in, watchlists, onboarding, security, and remembering your privacy choice. Optional PostHog and Vercel Analytics remain off unless you allow analytics.
The Cookie Notice lists each technology, purpose, and typical duration. You can at any time. Riftbot does not use advertising cookies, cross-site behavioral advertising, or session replay.
6. When information is disclosed
Information may be disclosed:
- to the service providers described above, only as needed to perform their work;
- when required by law, legal process, or a valid government request;
- to investigate abuse, fraud, security threats, or violations of the Terms;
- to protect the rights, safety, or property of users, the operator, or others; or
- as part of a reorganization, financing, sale, or transfer of the Service, subject to appropriate confidentiality protections.
Riftbot does not sell personal information for money and does not share personal information for cross-context behavioral advertising.
7. Retention
- Account and provider-link records remain while the account is active. Riftbot session cookies normally expire within seven days; server session records expire or are removed when the session ends.
- Signed-in watchlists, Telegram connections, alert settings, and related delivery records remain until you remove them or request account deletion. Telegram connection tokens expire after ten minutes.
- The visitor and anonymous-watchlist cookies expire after no more than one year. Local watchlist, onboarding, import, and privacy-choice records remain until changed or cleared.
- Conversation checkpoints and associated identifiers are retained for thread continuity, security, and failure investigation. Riftbot does not currently provide a fixed automated deletion schedule for this data.
- Rate-limit records are short-lived operational records tied to the request window. Security logs may be kept longer where needed to investigate abuse.
- Optional analytics continue until consent is withdrawn, browser storage is cleared, or the records are no longer needed. Provider copies follow applicable provider settings and terms.
Data may be kept longer when required by law, needed to resolve a dispute, or reasonably necessary to protect the Service. It is deleted or de-identified when no longer needed, subject to backups and technical limitations.
8. Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, information about disclosures, or an appeal of a denied request. You may also have the right to complain to a local data-protection authority. Riftbot will not discriminate against you for exercising an applicable right.
Email contact@riftbot.ai to make a request, close an account, or request deletion. A signed-in user may be asked to verify control of the account email. For anonymous chat records, include the approximate interaction date and enough non-sensitive detail to locate the record; because those records intentionally limit direct identifiers, Riftbot may be unable to connect a record to you without adequate verification.
You can remove cards or alerts in the Service, disconnect Telegram, revoke Google access through your Google account, clear Riftbot browser storage, or stop chat processing by not submitting a message. You can also . Browser “Do Not Track” signals do not otherwise change the Service because Riftbot does not perform cross-site behavioral tracking.
9. International transfers
Riftbot and its providers may process information in the United States and other countries whose privacy laws may differ from those where you live. Where applicable law requires a transfer mechanism, the operator relies on contractual safeguards, adequacy decisions, or another legally recognized mechanism.
10. Security
Riftbot uses measures designed to reduce risk, including OAuth sign-in, signed HTTP-only cookies, access controls, request limits, diagnostic redaction, and omission of image data from stored conversation checkpoints. No internet service is completely secure, and the operator cannot guarantee information will never be accessed, lost, or misused.
11. Children
The Service is not directed to children under 13, and the operator does not knowingly collect personal information from a child under 13. If you believe a child has submitted personal information, contact the operator so it can be reviewed and, where appropriate, deleted. Users under the age of legal majority where they live should use the Service only with permission from a parent or legal guardian.
12. Third-party sites
Riftbot links to official sources, marketplaces, GitHub, and other third-party services. Their privacy practices are governed by their own policies. A link or citation does not make Riftbot responsible for a third party’s content or practices.
13. Changes to this policy
This policy may be updated when the Service, providers, or legal requirements change. The “Last updated” date will change when revisions are posted. Material changes may also be highlighted in the Service when reasonably practical.
Related information appears in the Cookie Notice and Terms and Conditions.