Privacy Policy
Last updated: August 14, 2026
SC2 Tools is a free, donation-supported analytics tool for StarCraft II players. This policy explains what data we collect, why, and how you can exercise your rights over it.
What we collect
- Account identity. Your Clerk user id, email, and (if you signed in with Google) your Google account name and avatar. We do not see your Google password.
- Replay data and original files. Each .SC2Replay file in a replay folder you add is read by the SC2 Tools agent on your PC. The agent uploads structured data such as map, matchup, build orders, APM, MMR, opponent identity, and the original replay file. Originals are kept in a private cloud archive so you can download your own replays from the dashboard.
- Personal builds and notes. Anything you type into the build editor.
- Device fingerprints. When you pair an agent we store a hashed device token, the agent version, and the OS string.
- Operational telemetry. Standard request logs (IP, user-agent, timestamp), retained for 30 days for security and debugging. If Sentry crash reporting is enabled (opt-in via settings), unhandled exceptions are forwarded to Sentry with PII scrubbed.
- Usage analytics (opt-in). Only if you click "Accept" on the cookie banner, we load Google Analytics 4 to understand which pages and features get used. It records pseudonymous data such as pages viewed, approximate location (country/region, from a truncated IP), device type, and referring site. We enable IP anonymization and disable advertising signals. Nothing analytics-related loads until you opt in, and you can withdraw consent at any time by clicking "Reject" on the banner (clear the banner choice in your browser storage to see it again).
What we do NOT collect
- Anything from outside your Replays folder.
- Voice or video.
- Payment information (we don't take payments).
Where the data lives
Structured replay data lives in MongoDB Atlas. Original replay files and larger replay-detail payloads live in a private Cloudflare R2 bucket. Render hosts the API, and Vercel hosts the website. Data is sent over TLS; access to replay downloads requires your signed-in account and a short-lived private download link.
Replay files remain stored until you delete the matching history or your account. Temporary download links expire after a short period and do not make the bucket public. Incomplete temporary uploads are not exposed in your library and are covered by a one-day automatic expiration rule.
Sharing
We do not sell or rent your data. We share it only with the subprocessors above (Clerk for auth, MongoDB Atlas for database hosting, Cloudflare R2 for private replay-file storage, Render for API hosting, Vercel for the website, Sentry for opt-in crash reporting, and Google Analytics for opt-in usage analytics).
Community publishing
Publishing a build is optional and user-controlled. Community builds show your profile or chosen community name by default; you can explicitly choose Post anonymously for an individual build. We publish its title, description, build metadata, and signature, but not source replays, opponent identities, or personal notes. You can remove the listing from Community at any time.
Aggregated opponent data
Public aggregated opponent statistics are a separate feature. We strip contributor names and apply k-anonymity: we never publish an aggregate row that fewer than 5 unique users have contributed to. Pulse IDs are public information from Blizzard's ladder.
Your rights
You can export your structured account data as a JSON archive, download stored replay originals from replay history, or delete your replay history or account permanently from Settings → Backups → Export / delete (GDPR). Deletion is hard — there is no recovery. If you live in the EU, UK, or California, you have additional rights under GDPR and CCPA; open a ticket at github.com/ReSpOnSeSC2/sc2tools/issues to exercise them.
Cookies
By default we use only strictly-necessary cookies: session login (Clerk) and CSRF protection. Your banner choice is stored in your browser's local storage, not a cookie.
If — and only if — you opt in via the banner, Google Analytics sets its own first-party analytics cookies (e.g. _ga) to measure usage. These are never set before you accept, and we do NOT use advertising or cross-site tracking cookies.
Children
SC2 Tools is not directed at children under 13. If you believe a child has signed up, open a ticket at github.com/ReSpOnSeSC2/sc2tools/issues and we will delete the account.
Changes to this policy
When we make material changes, we update the "last updated" date and provide additional notice when required by applicable law or when a change materially affects how we use personal data.