Privacy policy
Last updated 1 October 2026
This policy explains what we do with your personal data. The controller is Synaptec, 16 Allée de Jeandey, 33360 Latresne, France. See the legal notice. Privacy requests go to contact@valboard.gg.
1. What we collect
- Account data
- When you sign in with Discord or Google we receive your email address, display name, avatar image URL and the provider's account identifier. We store those and nothing else from the provider. We never receive your password, and because we only use the provider to sign you in, we do not store access or refresh tokens and never call the provider's API on your behalf afterwards.
- Content you create
- Strategies, gameplans, folders, text notes, team names, invitations, and any image you upload.
- Presence data
- While you have a live session or gameplan open, your cursor position, display name and avatar are broadcast to the other people in that room so they can see where you are working. This is transient: it exists for the duration of the connection and is not written to the database.
- Session and technical data
- A record for each signed-in session, holding your browser's user agent, your IP address and when the session was created and last used, plus server logs and error reports used to keep the service working. Section 8 says how long each is kept.
- Beta access requests
- If you request beta access: the optional note you write (up to 500 characters), when you asked, and whether and when we granted or declined it, with an internal note that is never sent to you. If access is granted, we keep a record of the grant: who granted it, when, why, and any end date.
- Feedback
- If you send feedback from the app: its category, your message (up to 2,000 characters), the page you sent it from, and your account.
- Content reports
- If you report content: the address of the page reported, the reason you chose, your explanation, your name and contact email address if you give them, the language of the form, and your good-faith statement. We also keep every message we send you about the report and our internal notes on it. A report is not attached to your account.
- Emails we send
- We send a small number of emails, all from support@valboard.gg: confirmation that we received your report, our decision on it and any reply about it, and the message telling you your beta access is ready. We send no newsletter and no marketing email.
2. Why, and on what basis
- To provide the service: account, content, presence, sessions. Performance of our contract with you.
- To keep it secure and working: logs, error reports, abuse prevention. Our legitimate interest in a service that stays up and is not attacked.
- To take payment: handled by our reseller, see section 4. Performance of the contract and our legal obligations.
- To understand usage: aggregate analytics, see section 3. Our legitimate interest in knowing which parts of the product are used.
- To handle content reports: the report, your contact address if given, and the messages about it. Our legal obligation to run a notice-and-action mechanism under the Digital Services Act (article 16).
- To run the closed beta: your request, our decision and the email telling you access is ready. Steps taken at your request before giving you access, then performance of our contract with you.
- To improve the product: the feedback you choose to send. Our legitimate interest in hearing what does not work.
3. Analytics and error tracking
We use Plausible for analytics and GlitchTip for error tracking. Both are self-hosted on our own server: no data goes to a third-party analytics vendor. Plausible sets no cookies and does not build a profile of you across sites.
Analytics are deliberately not loaded on team invitation links, because the link itself is a credential and recording it would file a secret in an analytics store. A strategy session link is a credential too: analytics and error tracking replace its identifier before anything is sent, so neither ever records it.
4. Paddle
No payment is taken during the closed beta, and nothing is shared with Paddle until subscriptions open. From then, orders and payments are handled by the applicable Paddle entity, identified at checkout, the Merchant of Record for all orders placed on this site. When you buy a subscription, Paddle collects your payment details and billing information directly: we never see or store your card number.
For data protection purposes, we and Paddle act as independent controllers, each responsible for its own processing, under the data sharing terms of our agreement with Paddle. We share with Paddle the data needed to create and manage your subscription: typically your email address, the plan bought and the identifiers linking that subscription to your account. Paddle shares back the transaction, subscription and tax data we need to grant access and keep our books.
Paddle processes data outside the European Economic Area. Those transfers rely on the safeguards set out in Paddle's own privacy notice, which governs everything Paddle does with your data as controller.
5. Where your data is hosted
VALBOARD runs on servers operated by OVH in the European Union (France). Backups are encrypted and stored with the same provider, also in the EU. Apart from the payment path described in section 4 and the two cases below, your data stays in the EU.
Our emails (see section 1) are sent through Resend (Plus Five Five, Inc.), an email provider established in the United States acting as our processor, which receives the recipient's address and the content of each message. That transfer relies on the EU-US Data Privacy Framework, in which Resend participates, and on the European Commission's standard contractual clauses in its data processing agreement.
If your profile picture is the one from your Discord or Google account, it is loaded from that provider's servers whenever it is displayed, including to your teammates, which gives that provider the address of the device viewing it. Uploading your own picture in your settings avoids this.
6. Cookies and local storage
This is the complete list of what VALBOARD reads from or writes to your browser. There is nothing else: no advertising, no cross-site tracking, no third-party tracker, no data sold or shared with anyone.
Cookie. Two, both set by us, both unreadable by scripts. Signing out deletes the first.
- valboard_session
- Keeps you signed in. Set when you sign in, and unreadable by scripts. Kept: 30 days from when you sign in.
- valboard_oauth
- Holds the one-time anti-forgery value that protects a Discord or Google sign-in from being hijacked. Kept: until you close your browser; the one-time value is erased as soon as the sign-in completes.
Local storage. Choices you made in the interface, kept in your browser and never sent to us as personal data.
- valboard.theme
- Your light or dark choice, so the page does not flash the wrong one on the next load. Kept: until you change it or clear your browser.
- valboard.locale
- Your English or French choice, so the site opens in it next time. Kept: until you change it or clear your browser.
- valboard.editor-settings
- Which map overlays you keep switched on in the editor (spawn barriers, ult orbs). Kept: until you change it or clear your browser.
- valboard.playbook-sidebar
- Whether you keep the Playbook sidebar collapsed. Kept: until you change it or clear your browser.
- valboard.playbook-location
- The Playbook view you were last in, per workspace, so you come back to it. Kept: until you change it or clear your browser.
- valboard.playbook-save-folder
- The folder you last saved a strategy into, per workspace, so the save dialog preselects it. Kept: until you change it or clear your browser.
- valboard.gameplans-drawer
- Whether you keep the Gameplans drawer collapsed. Kept: until you change it or clear your browser.
- valboard.gameplans-hover-focus
- Whether hover focus is switched on in Gameplans. Kept: until you change it or clear your browser.
- current_session_id
- The id of the strategy session you last had open, so a new tab resumes where you were. Kept: until you open another session or clear your browser.
- last_used_map
- The map you last worked on, so a new strategy opens on it instead of a default. Kept: until you use another map or clear your browser.
Session storage. Two short-lived values, gone as soon as you close the tab.
- valboard.gameplans-drawer-folders
- Which folders you opened in the Gameplans drawer, so they stay open while you work in this tab. Kept: until you close the tab.
- guest_id
- A random value that gives an anonymous editor a stable colour in a shared session. It is not an account, and it is not linked to one. Kept: until you close the tab.
- pending_invite_token
- Parks a team invitation while you sign in, so the invitation still works when you come back. Kept: until the invitation is used, or the tab closes.
Analytics and error tracking store nothing in your browser at all.
- Plausible
- Counts page views so we know which parts of the product are used. Self-hosted on our own server, never loaded on a team invitation link, and never sent the identifier of a strategy session link. No cookie, and nothing in local or session storage.
- GlitchTip
- Receives an error report when something breaks, so it can be fixed. Self-hosted on our own server, and never sent an invitation token or the identifier of a strategy session link. No cookie, and nothing in local or session storage.
You can clear all of it from your browser's settings at any time. Clearing it signs you out and forgets your preferences; nothing else is lost.
Why there is no cookie banner. Article 82 of the French loi Informatique et Libertés requires your consent before anything is read from or written to your device, except where it is strictly necessary to provide a service you have asked for. Everything listed above falls in that exception: the two cookies keep you signed in and stop a sign-in from being hijacked, and the browser-storage entries only remember choices you made in the interface. None of them profiles you, follows you to another site, or is shared with anyone.
Our analytics and error tracking sit outside article 82 altogether, because they write nothing to your device. Both are self-hosted, Plausible sets no cookie, and it measures audience without building a profile, which is also what the CNIL asks of audience measurement that needs no consent.
So a banner is not required here, and asking for consent we do not need would be theatre. If we ever add something that does not fit the exception, whether advertising, cross-site measurement or any third-party tracker, a real consent choice ships with it, not after it.
7. Sharing
Content you put in a team workspace is visible to the members of that team, along with your display name, profile picture and role. Anyone holding a strategy session link can open and edit that session. Beyond that, we do not sell or share your personal data: only the processors named in this policy, OVH and Resend, handle it on our behalf, and once subscriptions open Paddle will receive what section 4 describes, as an independent controller.
8. Retention
Your account data and the content of your personal workspace are kept while your account exists. When you delete your account, we delete them, together with your sessions, your beta access request and your uploaded profile picture. What you created in a team workspace belongs to that team and stays with it, no longer linked to you, and feedback you sent stays, no longer linked to you. An image is deleted within 10 days once nothing in VALBOARD uses it any more: when the strategy, team or account it belonged to is deleted, or when it was pasted into a session that was never saved. An image another strategy still uses, such as a copy made by duplicating, is kept for as long as that strategy exists.
A sign-in session record, with its browser and IP address, is kept until you sign out, sign out your other sessions from your settings, or delete your account; a session unused for 30 days stops working. Feedback is kept for as long as it helps us improve the product. Content reports, the contact address given with them and the messages about them are kept for as long as we need them to handle the report and any dispute about it. Server logs record your account identifier and the requests made, not your IP address, and are deleted on a rolling basis as their storage fills. Error reports are kept for up to 90 days. Analytics keep only aggregate statistics that identify no one. Backups roll over on a 14-day cycle, so deleted data is gone from them within 14 days. Once subscriptions open, records we must keep for accounting or tax purposes will be kept for the period the law requires.
9. Your rights
You can ask for access to your data, correction, erasure, restriction, portability, and you can object to processing based on our legitimate interests. Two of these you can do yourself, in your settings under Data & privacy: Export my data downloads one JSON file with your profile, your personal strategies and folders, your personal Gameplan layout and the list of teams you are in, and Delete account deletes your account as described in section 8. For anything else, including content you created in a team, write to us from the contact page. We answer within one month.
If you are in France you can also complain to the CNIL (cnil.fr), or to the supervisory authority of the EU country you live in.
10. Changes
If this policy changes materially we will say so on this page and, where the change affects you, tell you directly.