Privacy & Data Policy
Last updated: June 9, 2026
What we collect
We collect only what we need to run the product:
- Account & identity — the email you sign up with, your display name, and (when you link them) your Discord and Steam identifiers + public profile data.
- License & subscription — a SHA-256 hash of your license key (plaintext is shown once and never stored), your tier, and your payment processor's customer ID.
- Notes — the text content of player notes you write through the extension, the BattleMetrics player ID they're attached to, and timestamps. Visible only to you.
- Alt-check contributions — when you run an alt check, the queried BMID, the flagged alt's BMID, shared-IP counts, and ban status are added to a shared cache. Every other admin running a lookup on the same player sees aggregate counts from this pool — that's the network effect the alt feature depends on. We don't expose who contributed which row.
- Operational data — an audit log of authenticated actions, technical request metadata (IP via Cloudflare, timestamps) for rate limiting, and a short-lived per-player lookup cache.
- Developer API keys (optional) — if you generate one, we store its SHA-256 hash, your label, and a call log.
We do notstore passwords, your BattleMetrics RCON token, or your Steam Web API key — those live only in your browser's extension storage. We don't use advertising or analytics cookies.
How we use it
To authenticate you, validate your license on every extension call, gate paid features against your subscription state, send transactional emails (login codes, account events), display your notes + alt-check history in the dashboard and extension, and investigate security incidents.
Who we share it with
Nobody, except these service providers acting on our behalf:
- Vercel — hosting + edge.
- Neon — managed Postgres database.
- Cloudflare — CDN + DNS + trusted client IP.
- PayNow — payment processor. When you start a checkout we send PayNow your display name (or email if no name is set), your email, our internal user ID, your Steam ID (if you've linked Steam), and the tier you're purchasing.
- Resend — transactional email. Receives your email address only when we send you a login code or account notification.
- Discord + Steam — identity providers, when you click Link to bind your account.
- When required by valid legal process, or to protect the safety of our users or the public.
No selling. No targeted advertising. No profiling that produces legal or similarly significant effects.
How long we keep it
Account data and linked identities are kept as long as your account is active. Login codes and Steam OAuth state tokens become unusable after 10 minutes; the player lookup cache becomes stale after one hour — expired rows are ignored on read but aren't actively deleted. Audit logs and alt-check contributions accrete and are not currently pruned on a fixed schedule.
We don't offer self-service account deletion yet. If you'd like your account removed, message us via Discord using the email tied to your account; we'll verify and delete your personal data as soon as we can — normally within 30 days, except where retention is required by law.
Your rights
Under the Colorado Privacy Act (and similar laws in California, the EU/UK, and elsewhere) you may request access, correction, deletion, or a portable copy of your personal data, and you may opt out of any sale, targeted advertising, or profiling — note that we do none of these.
To exercise a right, reach out via our Discord and mention the email tied to your account. We'll verify your identity and respond as soon as possible — and always within the 45-day window the Colorado Privacy Act requires. If we deny a request, you may appeal; we'll respond to appeals on the same timeline.
Children
BetterMetrics Plus is intended for server administrators and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we'll delete it.
Security
Session tokens and license keys are stored as SHA-256 hashes — a leaked database backup cannot be replayed as a session or used as a license. Authenticated routes require a valid session or license / API key; all /api/* routes go through per-IP rate limits; authenticated state-changing actions (license rotation, API key creation or revocation, member administration) are audit-logged; database access is restricted to the application backend; all traffic is served over HTTPS. We set one session cookie (bmetrics_session) marked HttpOnly + Secure + SameSite=Lax; we don't use analytics or tracking cookies. No system is perfect — if you spot a security issue, please report it via Discord.
Questions or rights requests? Reach the team on Discord.
We'll update the “Last updated” date above if this policy materially changes.