TourneyEngineLogin with Discord

Privacy Policy

Last updated 20 August 2026

TourneyEngine runs tournaments inside Discord servers and publishes their brackets on this site. This page explains what we collect, why, and what you can do about it.

The short version

  • We use your Discord account to know who you are. We never see your password.
  • Brackets are public. If you enter a tournament, your display name and any in-game name you give are shown on a public web page that anyone can open.
  • We do not sell your data, and we run no advertising or analytics trackers.
  • Two cookies, both strictly functional. No tracking cookies.

Who we are

TourneyEngine (“we”, “us”) is an independently run project. You can reach us at phobvoid@proton.me about anything on this page.

What we collect, and why

When you sign in to this website

Signing in uses Discord’s OAuth. You approve it on Discord’s own screen and we receive:

  • Your Discord user ID, username and avatar — to show who is signed in and to check whether you may edit a tournament.
  • Your email address — stored on your session so that, if paid features launch, we can send a receipt without asking you to sign in again. Nothing currently sends you email.
  • The list of Discord servers you are in, and your permissions in each — to show you the servers you can manage.
  • Your roles in one specific server — checked only when deciding whether you are staff of a tournament you are trying to edit.

This is held in a signed cookie in your browser, not in our database. We keep no table of sessions. Signing out, or letting the session expire, removes it.

When you take part in a tournament

Through the Discord bot we store, for each tournament you enter:

  • your Discord user ID and the display name you had when you signed up;
  • an in-game name, if the organizer asks for one;
  • your seed, check-in state, team membership, match results and placement;
  • if a staff member disqualifies you: that it happened, when, who did it, and any reason they typed.

A server’s staff can also add you to a block list for their own server, which stores your Discord user ID and an optional reason.

What organizers write

Tournament names, descriptions, rules, round headers and banner images are written and uploaded by organizers. Banner images are stored by us so they keep working after Discord’s own image links expire.

What we do not collect

We do not read your Discord messages, we do not use analytics or advertising trackers, we do not build profiles across servers, and we do not take payment information — there is nothing to pay for yet.

What is public

A tournament’s bracket page is public and needs no login. Anyone with the link — and search engines — can see the tournament, the entrants’ display names, any in-game names, seeds, scores and final placements. Archived tournaments keep their bracket page so results stay linkable.

If you would rather your name were not on a public page, do not enter, or ask the organizer to remove your entry before the bracket is published.

Cookies

Two, both necessary for the site to work:

  • Session cookie — keeps you signed in. Expires when your Discord authorisation does, or sooner.
  • Sign-in cookie — a short-lived value used to verify a sign-in you started is the one that finished. It lasts ten minutes and is cleared as soon as the sign-in ends.

We set no advertising, analytics or third-party cookies.

Who else sees this data

We do not sell or rent personal data. It is handled by:

  • Discord — the platform the bot runs on. Their handling of your data is governed by Discord’s own privacy policy.
  • Our hosting and database providers, who store and serve the data on our behalf and may not use it for anything else.
  • Your server’s staff — organizers can see the entrant list for their own tournaments, including in-game names.

We may also disclose data where the law requires it, or to investigate abuse of the service.

How long we keep it

Tournament records last until the organizer deletes them; deleting a tournament removes its entrants, teams, matches and results. Archived tournaments are kept so their result pages stay available. Removing the bot from a server does not delete that server’s tournament history, so it survives the bot being added back.

Your choices

  • Sign out at any time — that removes the session cookie and everything in it.
  • Revoke our access in Discord under User Settings → Authorised Apps.
  • Ask an organizer to remove you from a tournament.
  • Ask us at phobvoid@proton.me for a copy of what we hold about you, or for it to be deleted. Depending on where you live you may have a legal right to this; we will honour the request either way. We may keep what we must to resolve a dispute or meet a legal obligation.

Children

Discord requires its users to be at least 13, or older where local law says so. TourneyEngine is not intended for anyone below that age. If you believe a child has given us personal data, contact us and we will remove it.

Security

Sign-in is handled by Discord and we never see your password. Session cookies are signed, marked Secure and HttpOnly, and cannot be read by scripts. Data is stored with reputable hosting providers. No service can promise perfect security, and we do not.

Changes

We will update this page when what we collect changes, and move the date at the top. If a change matters to you, we will say so more loudly than a date.

TourneyEngine
Terms of ServicePrivacy Policy