Legal

Privacy Policy

Applies to carryforge.net and the CarryForge Windows beta · Controller: Zerkara Technologies Ltd · Last updated: 4 September 2026

1. Who controls the data

CarryForge is operated by Zerkara Technologies Ltd. Privacy and deletion questions can be sent to [email protected].

2. Website data

carryforge.net does not set marketing cookies and does not embed a third-party video player; the product walkthrough is served from the same site. The web host and Cloudflare network may process standard connection information such as IP address, date/time, requested URL, response status, user agent and security signals to deliver the site, prevent abuse and troubleshoot faults. Their own infrastructure and legal retention rules also apply.

3. Optional Riot account link

If you enter a Riot ID (GameName#TAG), the app sends it to the CarryForge stats service, which uses Riot’s Web API to resolve and process:

The purpose is to show your own history, role/champion performance and rule-based coaching. CarryForge does not use this information for advertising, public scouting or an alternative ranking system. Personal response caches are held in memory for up to 30 minutes to reduce Riot API requests and are not used to build a permanent server-side profile.

4. Aggregate patch samples

CarryForge may cache a limited sample of Match-V5 records by platform and patch to calculate aggregate champion and build statistics. Before disk storage, direct player identifiers are removed, including PUUID lists, Riot ID names/tags, summoner identifiers/names and profile identifiers. The remaining gameplay sample is capped per platform/patch and expires after 30 days by default (the server permits a 1–90 day operational setting). It is not linked to your local CarryForge account record.

5. Data kept on your device

The app stores preferences locally, which may include language, region, primary role, recommendation weighting, champion pool order, matchup notes, linked Riot ID/PUUID, onboarding state, HUD modules/position, theme and the post-lock loadout-sync choice. This data remains until you remove it in the app, clear app data or uninstall.

If you link a Riot ID, the desktop app also keeps a local match archive: a compact summary of your own past matches, written to %LOCALAPPDATA%\CarryForge\archive on your computer. Each entry holds your own result — champion, role, patch, queue, K/D/A, CS, gold, final items, runes, summoner spells, and (when available) your item-purchase order, skill order and per-minute CS/gold. Each entry also holds a roster line for every player in that match: champion name, role, whether that side won, the full rune page (both trees, the selected runes and the stat shards) and — when the match timeline is available — the first three completed legendary items, the boots and the skill-max order. Other players' PUUIDs, Riot IDs and summoner names are deliberately not stored; a roster line carries no identifier at all, only a seat number that is meaningful within that single match. Roster lines let build suggestions learn from the whole match rather than from your own seat alone. The archive exists so build and coaching suggestions can learn from your own history without re-downloading it, and it is not uploaded to CarryForge servers. The same folder also holds a small local LP log: timestamped snapshots of your own ranked tier, division and league points, recorded only when the value changes while the app is open. It exists solely to draw the LP progress chart on your Profile page, contains no data about other players and is never uploaded. The same folder also holds a local suggestion log: for each champion-select lobby in which the app showed you a recommendation, one entry with your own PUUID, a lobby session identifier, the timestamp, your role, patch and queue channel, the picks and bans that were suggested (with their scores), the champion you actually locked, the suggested rune keystone and first item, and how much data each suggestion layer had. When the corresponding match later appears in your archive, the entry is completed with that match ID and its result. It exists solely so the app can measure how often its own suggestions were right, contains no data about other players and is never uploaded. If you use “Export” on the desktop app, the exported copy of your archive is written into the same folder as a file you can open or move; it holds the same data as the archive itself. You can export the archive to a file or delete it at any time in Settings — a single delete removes the match archive, the checkpoint, the LP log, the suggestion log and any exported copy left in that folder. Uninstalling does not reliably remove this folder: the Windows uninstaller cleans up its own application-data directory, which is a different path from the archive folder named above. If you want the local data gone, use “Delete archive” in Settings before uninstalling, or delete the folder yourself afterwards.

If your installed version offers Local match recording and you separately enable it, the Windows app captures video of only the strictly process-verified League of Legends.exe game window and audio rendered by that verified game process tree through process-scoped Windows loopback. That audio can include in-game voice chat and anything else rendered by League. CarryForge never captures your microphone or audio from other desktop applications and never falls back to the default desktop audio endpoint. If verified process-scoped audio is unsupported or cannot start, recording fails closed; there is no video-only fallback. Media and local status metadata are written to %LOCALAPPDATA%\CarryForge\media. Recording is off by default and requires explicit, separate consent in the app. The accepted consent revision and time are stored locally; a material disclosure change requires consent again, and disabling recording withdraws that local capture consent. This disclosure uses consent revision 4, so an earlier recording consent is not carried forward. While capture is active, Windows keeps its capture border visible and the tray menu provides a stop action. Captured pixels can include anything League itself displays in that window, including chat and visible player names. Recordings are never uploaded automatically to CarryForge, Discord or an AI service. You can stop recording, delete recordings, open the folder and choose a disk budget. Starred recordings are never removed by automatic budget cleanup; if no eligible unstarred recording can be removed, a new recording is not started. Where automatic highlights are offered, you may independently keep each full match, selected automatic clips, or both. Clip-only mode temporarily records the full source, then removes it after every selected clip is finalized or explicitly fails; if no selected event occurs, no match-length recording is retained. Successfully finalized clips consume additional space, remain after their source is removed and are not automatically evicted. A master switch and event checkboxes choose which verified moments become physical clips; the policy is frozen in the local manifest when each recording starts. Supported granular events are your death, kill, assist and double/triple/quadra/pentakill; an ace by your team; dragon/herald/baron killed by your team or explicitly stolen by you or your team; and turret/inhibitor destruction by your team. CarryForge labels an objective as stolen only when Riot's local event explicitly supplies that value. Void Grub killed/stolen choices remain unavailable until an equally explicit local event contract is verified; a generic observed Void Grub timeline marker may still appear. Player display names are used only transiently in memory to verify the local event actor and are not written into event or clip metadata, although captured video pixels can still show names or chat. A clip is independent only after the app reports successful finalization. If creation cannot finish, the marker remains but no failed or unfinished file is represented as playable saved media.

Post-game death-review notes — your verdict, tags, note, next-match rule and links to CarryForge guide tactics — are stored locally. They are your own assessment; CarryForge does not infer unseen camera attention, wards, cooldowns or intent from the recording. These notes are not uploaded automatically.

Local achievements (milestones from your own archive and successful click-only rune/item imports) are stored only on your device. Three optional sharing features — anonymous community build tallies, a cloud backup of app preferences and anonymous usage statistics — are described in section 6. Cloud preference backup and usage statistics are off by default. Anonymous community build tallies are on by default because the recommendation pool is mutual, and can be turned off at any time in Settings; the records contain no identifier of any kind.

League Client lockfile credentials are read locally only when the desktop integration needs them. They are not uploaded to CarryForge servers. While the signed-in local League client is open, the Home page may read its pending mission titles, objectives, rewards and event-pass progress. That response is held in memory only, is not added to the local match archive and is never sent to CarryForge servers. The app does not collect keystrokes, read game/process memory or inspect network packets. Screen capture occurs only through the optional local recording feature described above.

5b. Optional CarryForge account

The account is optional. Every feature described above works without one: local custom sets, the local match archive, coaching from your own archive and the server-wide curated sets are all available to signed-out users. An account adds one thing: a cloud backup of data you choose to store.

What an account itself stores. A username you choose, a display name, and a password that is never stored in readable form — only a salted scrypt digest. Session tokens are stored as SHA-256 digests, not in the clear, and expire after 30 days or when you sign out. We do not ask for or store an email address, so account recovery by email is not available.

Nothing personal is stored until you say yes, separately. Creating an account is not consent to store your data. The app shows a separate permission screen listing exactly what would be stored, with an unchecked box you must tick yourself. Until that permission is recorded on the server, every personal endpoint refuses the request and writes nothing.

What is stored once you give permission:

What is never stored under your account: your local match archive, your League Client credentials, an email address, an IP-based profile, or any advertising identifier. Community statistics remain anonymous and are not linked to your account; the server rejects any anonymous row that carries a PUUID or other identifier.

Permission is versioned and withdrawable. If this text changes materially the permission version changes and you are asked again, because you cannot be said to have agreed to text you never saw. Withdrawing permission in the app (Account → “Withdraw permission and delete my data”) deletes your custom sets, linked Riot accounts and skin collection from the server immediately. Records on your own device are not touched by that action; deleting those is a separate button in Settings.

Roles. Ordinary accounts can read and write only their own data. An elevated “developer” role, used to publish the server-wide curated sets, cannot be requested or granted through the app or any network endpoint; it is set directly on the server by the operator.

6. Optional sharing and cloud backup

Anonymous community build tallies (on by default; switch off any time). This feature is enabled by default because the recommendation quality every user receives depends on the size of a shared, mutual pool. You can disable it at any moment with “Contribute anonymous community data” in Settings, and disabling it stops all future contributions immediately. While it is enabled, the app sends identity-free build records derived from your local match archive: champion name, role, game patch, queue type, the full rune page (trees, selected runes, stat shards), the first three completed legendary items, the boots, the skill-max order, and whether the game was won. A record is sent for every player in the match, not only for you — this is what makes the aggregate large enough to be useful, and it is exactly the same identity-free shape in both cases. The same setting also contributes one team-composition record per match — the champion names of the winning five and the losing five, each with the lane that champion played (top, jungle, mid, bot or support), plus patch and queue — which is what duo-synergy ratings and lane-matchup win rates are computed from. The lane is a property of the match, not of a person: it is what makes it possible to tell which two of the ten champions actually faced each other, and without it a “lane matchup” figure would be guesswork. It contains no player identifier of any kind and no match id; the pairs themselves are derived on the server. No PUUID, Riot ID, summoner name, match ID or any other identifier is included, and the server additionally rejects any record that carries an identity field. These records are merged into aggregate build statistics served to all users; champions with fewer than 20 contributed games are not served at all. Because records are anonymous by construction, they cannot be attributed back to you afterwards and therefore cannot be individually retrieved or deleted; turning the toggle off stops all future contributions immediately.

Cloud backup of app preferences (opt-in). If you enable “Cloud sync” in Settings, the app can back up your application preferences (region, recommendation profile and weighting, HUD and overlay settings) and your starred champion pool to CarryForge servers, and restore them on demand. The backup is keyed to a random installation identifier generated on first run — not to your Riot account. It never contains your PUUID, linked Riot accounts, match archive, learned build history or any match data, and the server rejects payloads carrying such fields. Backups are kept until overwritten by a newer backup; you can request deletion at [email protected] (include the wish to delete cloud preferences; no account details are needed because none are stored).

Anonymous usage statistics (opt-in). If you enable “Send anonymous usage data” in Settings, the app reports which of its screens you open and for how long, plus error category codes from a fixed list (for example “stats service unavailable”). Screen names come from a fixed allowlist; free-form text, error messages, champion names and identifiers are never sent, and the server drops anything outside the allowlist. Events are merged into day-level totals that are not stored per user or per installation, so they cannot be attributed to you. Turning the toggle off stops reporting and discards any queued events.

7. League Client actions and Live Client Data

Manual champion hover, ban confirmation and rune/item/spell import require visible player input. A separate Settings opt-in, off by default, may send only one rune page and item set after the player has locked a champion; it does not pick, ban or lock a champion. The in-game HUD reads Riot Live Client Data for on-screen metrics and remains read-only. HUD positions and module choices are stored locally.

8. Service security and rate limiting

The service uses HTTPS, a server-side Riot API key, origin restrictions, bearer access controls and short-lived per-IP rate-limit state. Riot API keys are never included in the desktop binary. Operational logs may be reviewed only for security, reliability and abuse prevention.

9. Recipients and international processing

Data is processed only as needed by the following categories of recipient: Riot Games for Riot API requests, and the cloud host and Cloudflare for delivery and security. These providers may process data in other countries under their own terms and safeguards.

10. Retention and deletion

Server-side account data is kept until you withdraw permission or ask for the account to be removed; withdrawing permission in the app deletes your stored custom sets, linked Riot accounts and skin collection right away. Unlinking removes the account link from your device; it does not call Riot to delete Riot’s own records. For access, correction or deletion questions about data controlled by CarryForge, email [email protected] with enough information to identify the request. Identity may need to be verified before a request is completed.

11. Legal basis and your choices

Where data-protection law applies, optional Riot ID processing is based on your request/consent and providing the feature; security and aggregate service operation rely on legitimate interests in running a safe, useful product. You can choose not to link a Riot ID, keep local recording disabled, delete recordings and clips, turn off HUD modules and post-lock sync, turn off any of the three optional sharing features in section 6 (cloud preference backup and usage statistics are off by default; anonymous community build tallies are on by default and can be switched off at any time in Settings), or stop using the service. Depending on your location, you may have rights to access, correct, erase, restrict or object to processing, and to complain to a regulator.

12. Children and changes

CarryForge is not directed to children under 13 and does not knowingly collect personal data from them. This policy will be updated before any materially different processing starts; the date above shows the current version.

13. Riot Games

Riot’s own privacy notice applies to data Riot controls: Riot Games Privacy Notice.