Privacy Policy
Last updated 2026-08-10
This policy explains what personal data Hexa collects, why it is collected, where it is stored, how long it is kept, who else processes it, and how you can have it removed. It covers https://hexa.tools and applies to everyone who uses the service, as well as to players whose public game data appears in it without them ever having used Hexa.
Who we are
Hexa is operated by Igor Omote, an individual developer, who is the data controller responsible for the personal data described in this policy. Hexa is an independent tool for analysing Teamfight Tactics matches and is not a Riot Games product.
For any question about this policy, or to exercise any of the rights described below, contact:
What data we collect
We collect the following categories of personal data. Most of it is game data obtained from Riot Games’ public API; the rest you provide when you sign in or make a purchase.
- Account data — when you sign in with Discord: your Discord account identifier, email address, display name, and avatar image.
- Riot account data — when you link a Riot ID: the game name and tag line you supply, plus the Riot account identifier (PUUID) and platform we resolve from them.
- Game data — matches fetched from Riot’s API, including placements, units, items, traits, board state, and the identifiers of every participant in those matches.
- Derived analysis — scores computed from your games across six axes, comp identifications, and per-unit item records.
- Coach usage — one record per AI coach request, used to meter your weekly allowance for your plan.
- Plan data — your current plan, its expiry date, and any adjustment we have made to your coach allowance.
- Payment data — when you buy a paid plan: the amount, the payment status, the payment provider’s reference identifiers, and the CPF you enter at checkout. We never receive or store your card number.
- Administrative records — when we change a plan, issue a refund, or take a similar action on an account, we record what changed, who changed it, and when. Where a refund dispute requires it, we may retain the CPF involved in order to decline future purchases from it.
- Waitlist data — if you join a waitlist: your email address and the plan you expressed interest in.
- Technical data — the IP address and request metadata your browser sends when loading the site, handled by our hosting provider.
Legal basis for processing
Where the GDPR or the LGPD applies to you, we rely on the following bases:
- Performance of a contract — running your account, delivering the analysis and coaching you asked for, and processing a purchase you made.
- Legitimate interests — operating and securing the service, preventing abuse of paid features, and measuring the ranked ladder so that scores can be calibrated against real player performance. We have weighed these interests against your rights and use only data Riot already publishes.
- Legal obligation — retaining financial records for the period the law requires.
- Consent — sending your match summary to our AI provider for coaching analysis, which happens only when you choose to request it. You may withdraw consent at any time by not using the coach.
How we use your data
- To identify you across sign-ins and keep you logged in.
- To fetch, store, and display your match history and the reports built from it.
- To compute your six-axis scores and compare them against benchmarks for your rank and region.
- To generate AI coaching when you request it, and to meter that usage against your plan.
- To take and reconcile payments, and to grant or revoke plan access.
- To calibrate the scoring model against measured ladder performance, so a score means the same thing for every player.
- To detect and prevent abuse of paid features.
We do not use your data for advertising, profiling for marketing purposes, or automated decisions producing legal effects.
Game data comes from Riot Games
All Teamfight Tactics game data in Hexa — matches, placements, boards, ranks, and ladder standings — is obtained from Riot Games’ public developer API. We do not obtain game data from any other source, and we do not modify it.
That data originates with Riot Games and remains subject to Riot’s own terms and privacy notice, which you can read at https://www.riotgames.com/en/privacy-notice. Deleting data from Hexa does not delete it from Riot.
We do not sell or broker your data
Hexa does not sell, rent, trade, or broker personal data. We do not act as an intermediary passing Riot API data to another company for that company’s own purposes, which Riot’s developer policy prohibits.
Every third party listed in this policy acts as a processor on our instruction and for the purpose we specify — hosting, storing, taking a payment, or analysing a match summary we send. None of them is permitted to use your data for their own ends.
We do not de-anonymise players
Hexa shows only information that Riot Games already makes publicly available through its API — in-game names, ranks, placements, and board contents. We make no attempt to identify a player who could not reasonably be identified from that public information, and we do not link in-game identities to real-world identity, location, or contact details.
What linking a Riot account means
Linking a Riot ID tells Hexa which player you are, so your reports and coaching resolve to your own games. It also means the game data for that Riot ID becomes visible within Hexa, including through the publicly accessible report pages described below.
The underlying match and rank data is already public through Riot’s API, so linking does not expose anything Riot keeps private. You can ask us to unlink your Riot ID at any time using the contact address in this policy.
Data about people who never used Hexa
Some of the data we hold describes players who have never visited or signed up for Hexa. We want to be explicit about this rather than leave it to be inferred:
- Opponents in your games. A Teamfight Tactics match has eight players. When a match is fetched, the whole match is stored — including every participant’s account identifier, board, units, items, and placement.
- Lobby snapshots. For each participant in a stored match we record the in-game name, placement, rank, and the units and items they played, so comps can be identified and scored.
- Ranked ladder players. To calibrate scores against real performance, we periodically read public ranked ladders and compute scores for the players on them, storing the Riot ID, account identifier, tier, and league points of those players.
All of this comes from Riot’s public API. If you are one of these players and want your data removed, you have exactly the same rights and the same removal route as a registered user — write to the contact address below and include your Riot ID.
Player report pages are public
A Hexa player report has a shareable address of the form https://hexa.tools/player/<region>/<name>/<tag>. Those pages require no login: anyone who knows or guesses a Riot ID can open the report for it, and search engines may index them.
The reports are built entirely from data Riot publishes. If you would rather your report were not publicly reachable, contact us and we will remove it.
Who else processes your data
We use the following providers. Each acts only on our instruction, for the stated purpose:
- Vercel — hosts the application and provides cookieless page-view analytics. Receives requests and IP addresses at the network edge.
- Vercel Postgres — the managed database. Stores everything described in this policy.
- Discord — the sign-in provider. Returns your account identifier, email, display name, and avatar when you authorise it.
- Mercado Pago — processes payments. Receives your CPF, the amount, and the card or Pix details you enter on their own checkout page.
- Anthropic — analyses the match summary we send when you request AI coaching. That summary can include in-game names.
- Voyage AI — generates search embeddings for our knowledge base. Receives no personal data.
- Riot Games — the source of all game data. Receives the Riot IDs and account identifiers we look up.
International transfers
Our hosting and database (Vercel), our payment processor, and our AI provider operate outside Brazil and, depending on the provider, outside the European Economic Area. Using the service therefore involves transferring your data internationally.
Where data leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses as incorporated in our providers’ data processing terms. Where the LGPD applies, we rely on the equivalent contractual safeguards for international transfer.
How long we keep it
- Account data, sessions, and coach usage — kept while your account exists, and erased within 30 days of a deletion request. Sessions also expire on their own.
- Payment records — retained for at least five years even after an account is deleted, because tax and commercial law requires it. This obligation overrides a deletion request; we keep only the record, not your card details, which we never had.
- Match data — kept as a cache of information Riot publishes. On deletion it is disassociated from your account. Deleting it here would not delete it at Riot.
- Lobby snapshots, per-unit item records, ladder samples, and ladder standings — kept as aggregate measurement data. Rows identifying a specific player are removed on request.
- Waitlist entries — removed on request, or when the waitlist for that plan closes.
Separately from any request you make, our agreement with Riot Games requires us to delete all game information in our possession if our access to their API ends. In that event the game data described above is deleted regardless of retention periods.
When we erase your data we keep one thing: a suppression record. It contains an irreversible one-way fingerprint of your Riot account identifier and nothing else — not your identifier, not your name, and nothing that could be turned back into either. We keep it because your matches are re-fetched from Riot whenever another player from one of your old games is looked up, and without it your data would silently reappear. The record is what makes the erasure permanent rather than true only on the day we ran it. You can ask us to remove the suppression at any time if you want to use the service again.
Your rights
Under the GDPR, the LGPD, and comparable laws you have the following rights over your personal data:
- Access — obtain confirmation of what we hold about you and a copy of it.
- Correction — have inaccurate or incomplete data corrected.
- Deletion — have your data erased, subject to the retention obligations described above.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing we carry out on the basis of legitimate interests, including the ladder measurement described above.
- Restriction — ask us to limit how we process your data while a dispute is resolved.
- Withdrawal of consent — stop the processing that relies on your consent, without affecting what was lawful beforehand.
- Complaint — lodge a complaint with your supervisory authority: the ANPD in Brazil, or your national data protection authority in the EEA or UK.
How to make a request
Write to the address below. Requests are handled by a person, not an automated flow, so please include enough information for us to find your data and to be confident the request is yours:
- The Riot ID (game name and tag line) and region the request concerns.
- If you have an account, the email address or Discord username you signed in with.
- What you are asking for — access, correction, deletion, portability, or objection.
We respond within 30 days. If we cannot act on a request — for example where a payment record must legally be retained — we will tell you why. We will not ask you for identity documents; matching an account or a Riot ID is sufficient, and we may decline a request we cannot reasonably attribute to you rather than risk deleting a stranger’s data.
We also honour deletion requests that Riot Games forwards to us on a player’s behalf, and treat them exactly as we would a request made to us directly.
Cookies and local storage
We use only what the service needs to function. There are no advertising cookies and no cross-site tracking.
- Strictly necessary cookies — a session cookie holding an opaque login token (we store only its hash), a short-lived cookie protecting the sign-in flow against cross-site request forgery, and a cookie remembering the page to return you to after sign-in.
- Functional local storage — your chosen language and colour theme, and a temporary copy of the player view you loaded, which your browser discards when the tab closes.
- Analytics — our host provides page-view counts without setting a cookie or assigning you a visitor identifier.
Children
Hexa is not directed at children. You must be at least 13 years old to hold an account, or older where your country sets a higher minimum age for consenting to online services — 16 in much of the EEA. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
When this policy changes we update the date shown at the top of the page. If a change materially affects how we handle your data, we will make it clear in the application before the change takes effect.
Contact
Questions about this policy, or about anything Hexa holds about you, go to: