1. Introduction
Al Fhoud Guild ("Al Fhoud", "we", "us"), available at alfhouds.com, is the controller of the personal data described here. This policy covers the whole platform — sign-in, your profile, social features, multiplayer games, notifications, the game information tools and content hubs, the esports hub, and the free-games feed — and the new games and features we add over time.
Al Fhoud operates from the State of Kuwait, and we handle personal data in line with the laws of the State of Kuwait and the regulations of CITRA (the Communication and Information Technology Regulatory Authority of Kuwait), including its data privacy protection regulations.
You can browse the public parts of the site without an account. Personal data is only involved once you sign in and use account features.
2. Account and identity data
Sign-in is OAuth-only through Google or Discord. From your chosen provider we receive your email address and basic profile (name and avatar) using the standard email and profile scopes. We never receive or store a password.
For your account we store: your email; a display name (which you can edit); a permanent public ID in the form AF-XXXXXX; your chosen language; and your join date. You can link both a Google and a Discord identity to the same account. When you apply for a creator or streamer role, we collect the information in your application (platform, handle, subscriber count) to evaluate your request.
4. Game and multiplayer data
When you play Zonko, we store the game rooms and seats you take part in and the server-authoritative game state. Each player’s private hand is readable only by that player; the deck order is kept server-side and is never sent to clients. This keeps multiplayer fair and private.
You control who can invite you to games with per-user privacy toggles (allow friends, followers, and people you follow). Only you can read your own toggle values; others only get a computed yes/no when they try to invite you.
5. Notifications and Web Push
Notifications are opt-in. You can turn on alerts for free games, game patch notes, and live esports, and we store those preferences.
If you enable browser (Web Push) notifications, we store the push subscription your browser provides (its endpoint and the p256dh and auth keys) so a scheduled job can deliver the alerts you asked for. You can turn any of these off at any time.
You can also subscribe to a specific match, team, or tournament to be alerted when it goes live; we store those subscriptions to send the alert.
Went-live alerts, which notified you when a streamer you follow started streaming, have been retired and are no longer sent.
6. Game profile lookups
Some features let you look up a public game profile. Today this is the League of Legends summoner lookup: when you search a summoner, you provide a public Riot ID (game name and tag line) and a region, and we use these to fetch that public profile from Riot’s and op.gg’s public resources on the server. To protect the service we apply per-IP and global rate limiting, which uses your IP address transiently for that purpose.
The League of Legends match-history feature calls the Riot Games API directly. When a player’s match history is viewed, we resolve the public Riot ID to a Riot player identifier (a "PUUID", scoped to our Riot API key) and we durably cache that PUUID together with the returned match data (such as the match list, champions, results, and per-match statistics) in our database, so the history can be shown efficiently without re-querying Riot every time.
Each match returned by Riot includes every player in that game, so for every match we cache we store the public Riot ID (game name and tag line) and the PUUID of all of its participants — typically around ten players per match — not only the player who was searched. This means we store, and durably retain, the Riot ID and PUUID of players who were never searched on Al Fhoud and who have no Al Fhoud account, purely because they appeared in a match alongside a searched player. The lookup itself works without an account and can be run for any player, including players who do not have an Al Fhoud account.
This cached match data and the PUUIDs originate from and belong to Riot Games, and your use of this Riot-sourced data is also subject to Riot’s own terms and policies. We keep it only as a cache: a searched summoner’s rank and match list are refreshed on a short cycle, and immutable finished-match records — including every participant’s Riot ID and PUUID — are kept until they are erased. The match-level record on its own (game time, duration, and result) carries no player identifier; the per-participant records that hold the Riot IDs and PUUIDs are the personal part, and are what an erasure removes. Any participant in a cached match can ask us to erase their data, whether or not they were the player searched and whether or not they have an Al Fhoud account (see "Your rights" below).
You can ask us to erase all of a player’s cached Riot match data at any time — a Right-to-be-Forgotten / deletion request — and this works even for a searched player who has no Al Fhoud account. See "Your rights" below for how to exercise it; every such erasure is logged (using only a one-way hash of the identifier, never the raw identifier) so we can prove it was carried out.
Note that if you use the share control on such a page, the link you share contains the identifier that was searched (for example the Riot ID), because it is part of the page address.
7. Public content and share controls
The public content hubs — for example champions, meta and tier lists, ARAM, skins, items, the rune builder, the leaderboard, patch notes, the esports schedule and standings, and the free-games feed — do not collect personal data. They display public information cached from third-party sources. The social feed displayed embedded content from verified creators and streamers; it still stores active streaming state when a streamer declares the game they are currently playing (see section 21).
Videos on the platform (for example reviews, tips, and embedded streams) play through a third-party player provided by Google (YouTube). The player loads from YouTube’s privacy-enhanced domain (youtube-nocookie.com), and YouTube may collect data — such as your IP address and device information — as soon as the player LOADS, before you press play and whether or not you press play at all.
On the social feed this happens without you doing anything: the feed plays each video automatically, muted, as you scroll to it, so a player loads for the video in view. The feed also loads a small player script from youtube.com (not the privacy-enhanced domain) so the player can report a video that will not play and can keep sound on for the rest of your visit once you turn it on yourself using YouTube’s own control. If you would rather not have a player load at all, turning on your device’s “reduce motion” setting stops the feed from playing anything automatically — videos then load only when you tap them.
Everything YouTube collects through the player is handled under its own privacy policy, which we do not control.
The share control uses your device’s native share sheet or copies a link; it collects no data of its own and simply passes the current page address.
9. Advertising and monetization
Al Fhoud serves advertising through Google AdSense, a third-party advertising network operated by Google. Ads appear only in clearly delineated ad spaces — a slot in the mobile top bar and a skyscraper rail column on desktop — and where no ad unit is configured, those spaces collapse and show nothing. We request non-personalised ads: Google does not select them based on your past behaviour or interests, and we operate no behavioural or cross-site ad tracking of our own. Google’s ad script loads from googlesyndication.com when an ad space is live, and Google may set cookies for frequency capping, fraud prevention, and reporting; we do not control what Google does with the data it collects in providing the ads, which is governed by Google’s own privacy policy.
Our current, privacy-friendly analytics are described in the "Cookies, analytics, and similar technology" section above. If in the future we introduce additional ad networks, sponsorship measurement, or any analytics that tracks or profiles individuals, we will update this policy first to name the partners and describe the data involved, and — where the law requires it — ask for your consent before any such tracking runs.
We do not currently use affiliate or referral links. If we add them in the future, following one may pass a referral identifier to the destination store or service so a purchase can be attributed to us; from that point the destination’s own privacy policy governs what it collects, and we would not receive your card or payment details from such purchases.
We do not currently offer paid features. If we introduce them, your payment and card details would be handled by a third-party payment processor and would not be stored by us; we would receive only what we need to confirm a purchase, such as its status and, for a subscription, its renewal state.
We do not sell your personal data.
10. How we use your data
We use your data to: create and run your account; provide the social, multiplayer, and information features; deliver the notifications you opted into; remember your language and preferences; protect the platform through rate limiting and abuse prevention; and meet our legal obligations.
Our legal bases are: performing our agreement with you (running your account and the features you use); your consent (notifications and Web Push, which you can withdraw at any time); and our legitimate interest in keeping the service secure and working.
11. Who we share data with
We do not sell your data. We use a small set of service providers ("sub-processors") to run the platform:
- Supabase — our database, authentication, realtime, and storage provider, which holds your account, social, and game data;
- Vercel — our hosting provider, which serves the site, processes requests and technical logs, and provides the cookieless, aggregate Web Analytics described above;
- Google — when you choose Google sign-in;
- Discord — when you choose Discord sign-in;
- Valve Corporation (Steam) — when you choose to connect a Steam account: we ask Steam to confirm your sign-in is genuine, and then read that account’s public profile details once;
- Google AdSense — Google’s advertising network, which serves the non-personalised ads described in sections 8 and 9: where an ad space is live, Google’s ad script loads from googlesyndication.com and Google may set cookies for frequency capping, fraud prevention, and reporting; where no ad unit is configured, nothing loads;
- third-party game data providers such as Riot Games, op.gg, Data Dragon, and Community Dragon — public sources for the games we cover (currently League of Legends and VALORANT), queried (with the Riot ID you enter) when you use a game lookup or view game content;
- the lolesports feed — for public esports schedules, teams, and standings;
- GamerPower — for the free-games giveaway feed (no personal data is sent);
- your browser’s Web Push service — to deliver push notifications you subscribed to.
12. International transfers
Our providers may process data on servers outside your country. Where that happens, we rely on the providers’ own safeguards for international transfers.
13. Data retention
We keep your account data for as long as your account exists. When you delete your account, your authentication record is permanently deleted and, by database cascade, every row you own — profile, social graph, game data, notification preferences, and push subscriptions — is deleted with it. Transient technical data such as rate-limit counters is short-lived by design. Records related to your requests (such as content-creator or streamer access applications) are retained while your account is active and for a reasonable time after to maintain platform integrity.
Cached League of Legends match data (described in "Game profile lookups" above) is kept only as a cache: a searched summoner’s rank and match list are refreshed on a short cycle, and immutable finished-match records are retained until a Right-to-be-Forgotten / deletion request erases a player’s data. Because each cached match stores the Riot ID and PUUID of all of its participants — around ten players per match, including people who were never searched and have no Al Fhoud account — this cache can hold data about players well beyond the searched summoner, so deleting your Al Fhoud account does not, by itself, remove it. Any such player’s data is removed by a match-data erasure request (see "Your rights"). An erasure removes every stored record tied to that player’s Riot identifier and writes a log entry containing only a one-way hash of the identifier; we also add that one-way hash to a suppression list so that a later search does not re-cache the player, which is what keeps the erasure durable.
14. Your rights
You can: see and update your display name and language in Settings; withdraw notification and push consent with the in-app toggles; and delete your account yourself at any time (Settings sends a request that hard-deletes your account and cascades to all your data). Depending on where you live you may also have rights to access, correct, export, restrict, or object to the processing of your data, including under the applicable Kuwaiti data-protection framework.
You also have the right to have cached League of Legends match data erased (a Right-to-be-Forgotten request), including for a player who has no Al Fhoud account, and including anyone who only appears as a participant inside someone else’s cached match. To request this, contact us at the address below with the Riot ID (game name, tag line, and region) whose data should be erased; we verify the request and then permanently delete every stored record tied to that player’s Riot identifier across our cache. So the deletion is durable, we also add a one-way hash of that identifier to a suppression list, which prevents a later search from re-caching that player; the only thing we retain is that one-way-hashed audit and suppression entry proving the erasure was carried out.
To exercise any of these rights, use the in-app controls or contact us at info@alfhouds.com.
15. Children
Al Fhoud is not directed to children under 13, and we do not knowingly collect data from them. If you are under the age of majority where you live, you should only use Al Fhoud with a parent or guardian’s consent. If you believe a child has given us data, contact us and we will remove it.
16. Security
We protect your data with row-level security so each person can only read their own private data, with private-by-default multiplayer hands, and with OAuth-only sign-in so no password is ever stored with us. No online service can be perfectly secure, but we work to keep your data safe.
17. Changes to this policy
We may update this policy from time to time. When we make a material change we will update the effective date at the top of this page.
18. Contact
For any privacy question, or to exercise your rights, contact us at info@alfhouds.com. You can also manage your data directly from the in-app Settings.
You can also reach us through the public channels listed on our Contact page — email, Instagram, Discord, and WhatsApp. When you contact us through any of these, we receive your message and the contact details you choose to share, only to respond to you; those third-party platforms carry the message on their own side under their own privacy policies, which we do not control. Using them is your choice, and the Contact page is informational only — it hosts no form and stores nothing itself.
19. Player feedback and reports
Al Fhoud includes an in-app feedback tool — the "!" report-and-suggest control — that lets anyone, whether or not they are signed in, flag something on a page that is wrong, outdated, or broken, or send us a suggestion or idea. We only collect the information described below when you actually submit a report or a suggestion; opening the tool and closing it without sending stores nothing.
When you submit a report or a suggestion, we store: whether it is a report or a suggestion, and for a report the category you chose (wrong, outdated, or broken); the note or idea you write in your own words; which page you were on — its path and the full web address, including anything after the "?" in it — and, when you point at a specific element, that element’s identifier, a short label, the visible text snippet you saw, a coarse indication of where it sits in the page, and, if it shows a translated label, the translation key for it (which also lets us flag reports about translated wording for our translation review); the size of your screen (its width, height, and pixel ratio) and your browser’s general user-agent line (which broadly identifies your browser and operating system), which help us reproduce a display or layout problem; the interface language you were using; and the date and time. If you are signed in, we also store your account, so we can follow up with you — a report or suggestion can equally be sent without signing in, and then no account is attached to it.
To keep the tool from being flooded with automated spam, we also compute a salted, one-way hash of your IP address and store only that hash, used solely as an anti-abuse rate-limit key. We never store your actual IP address, and the hash cannot be turned back into it.
We use what you send only to review, reproduce, and act on the issue or idea you raised, and to protect the tool from abuse; we do not use it for advertising and we do not sell it. Our legal bases are your consent, given when you choose to submit, and our legitimate interest in improving and securing the platform. A report or suggestion is about the platform rather than about you, so we keep it in order to act on it: if you delete your Al Fhoud account, a report or suggestion you filed is not deleted with your account — instead the link to your account is removed, so that the report becomes anonymous, and the report itself is retained so we can still resolve the issue you raised.
20. Who reviews your feedback and reports
Reports and suggestions you submit are reviewed by authorized Al Fhoud guild staff so that we can act on them. Access to this internal review console is granted by role — only people we have explicitly authorized can open it — and everyone who opens it is signed in to their own Al Fhoud account, so each review action is attributable to a specific person.
When authorized staff review a report or suggestion, they see what you sent — the note or idea, the page and the element it was about, the interface language, and the date and time — together with your public Al Fhoud handle (AF-XXXXXX) if you were signed in, or the fact that it was sent anonymously if you were not. They do NOT see the salted hash of your IP address, which stays a server-side anti-abuse key and is never shown in the console. Staff use this access only to review, reproduce, resolve, or dismiss the issue or idea you raised, and each resolution is recorded together with who actioned it and when.
21. Content creator and social feed data
If you are an approved content creator or streamer, additional data is stored when you declare the game you are currently playing. Publishing new content has been retired; the data described below was collected while that feature was available and, except where a paragraph below says otherwise, is still held.
Published content (feed_items): while content publishing was available, when you published a video or stream highlight we stored your creator ID (which links to your Al Fhoud profile), the game you selected, the type of content (such as a review, tips, or comparison), the platform it came from (YouTube), its video identifier, its title, and counts of how many times it has been viewed (impressions) and clicked through (outbound clicks). We stored content impressions (views) and outbound clicks to improve the social feed experience. This data was stored so your published content could appear in feeds, and it is still held, except the video title. The title we stored was the public YouTube title of your video, as you published it; we have since deleted every stored video title and we no longer hold any.
Active streaming state (streamer_sessions): when you declare the game you are currently streaming, we store your streamer ID, the game you selected, the time you declared it, and whether it is currently active. Only one active session is stored at a time; declaring a new game deactivates the previous one.
Live detection has been retired. While it was available, if you were an approved streamer we automatically detected when you went live on your verified YouTube channel using the YouTube Data API, stored your live status (in the streamer_sessions and feed_items tables), and broadcast a went-live notification to your followers. We no longer detect live status and no longer send went-live notifications; the live status stored before the feature was retired is still held.
The game you select is looked up in or added to our game catalog (games table), which stores only public game information — the game name, its cover image, its release date, its platforms and genres, and an age-rating-based safety flag. The catalog itself carries no personal data.
Your published content and your active streaming status are public by design: published feed items remain visible on the social feed page to anyone browsing the platform (and to search engines), and content we have approved also appears on the page of the channel that published it, at alfhouds.com/channel/ followed by that channel's platform and channel identifier, and is linked from the review bylines on the pages of the games it covers. Publishing new content and the live indicator have been retired. There is no self-service way to unpublish your own content — to have published content removed, contact our moderators using the contact details in this Policy. Delinking your verified channel removes your access to publish.
22. Verified channel data
If you choose to verify a channel you own on an external platform (today, YouTube), we process two separate kinds of data.
First, the sign-in details of the provider account you verify with: the provider’s stable account identifier and the email address on that account. These are kept in a separate, restricted store, are never shown on your profile, and are not published or shared. We keep them so we can tell you which account a verified channel is linked to.
Second, public information about the channel itself: the channel identifier, its name and @handle, its avatar image, and its subscriber count where the channel publishes one. If a channel hides its subscriber count we record no number rather than a zero.
That second set is collected in order to be made PUBLIC, and it IS published, in two kinds of place. On your profile — at alfhouds.com/u/ followed by your public AF handle — anyone can see your Al Fhoud display name, your verified channel with its channel avatar and subscriber count, and the content you have published on your profile. And where the channel is one we have curated or endorsed, the channel's name, @handle, avatar and subscriber count also appear in the Content Creators directory at alfhouds.com/content-creators and on that channel's own page at alfhouds.com/channel/ followed by its platform and channel identifier; those two surfaces carry no Al Fhoud display name, no public AF handle, and no Al Fhoud account identifier in the address. Where we hold no verified record for a channel, no avatar and no subscriber count are shown for it, and never a zero in their place. All of these pages are visible to anyone and are indexable by search engines. There is no separate setting to hide a verified channel; removing it means delinking it.
We ask the provider for read-only access once, to confirm the channel is yours, and we do not store a long-lived credential for your account. The public channel information above is first recorded at the moment you verify. We then refresh the channel’s @handle, avatar image and subscriber count from the platform’s public data at least once every 30 days, using our own server-side key and never the access you granted at verification; if the channel hides its subscriber count we continue to record no number rather than a zero. We do not read private account data.
We keep this data for as long as the channel stays verified on your account. Delinking the channel in Settings deletes both the channel record and the stored provider sign-in details. Deleting your Al Fhoud account removes them as well.
The third party involved is Google (YouTube). Your use of that platform remains subject to its own terms and privacy policy.
If you connect a Steam account, we process a different and smaller set of data. Steam confirms that you own the account through its own sign-in, which returns an identity assertion and no access token, so we hold no credential for your Steam account: we cannot post, trade, or act on your behalf, and we cannot read anything that is not already public.
What we store for a connected Steam account is your Steam ID (the numeric identifier Steam uses for the account), your Steam display name, and your Steam avatar image. We do not store your Steam password. If your Steam profile is set to private or friends-only, Steam discloses none of those details to us, and we store no display name and no avatar — only the fact that the account is linked. These records are held in our database, which runs on Amazon Web Services in the eu-central-1 region (Germany).
A connected Steam account is collected in order to be made PUBLIC, and it IS published: on your profile at alfhouds.com/u/ followed by your public AF handle, anyone can see it next to your Al Fhoud display name, with your Steam display name, your Steam avatar, and a link to your public Steam community profile. That page is visible to anyone and is indexable by search engines. Your Steam ID is never shown as text anywhere on the page, but it is stored, it forms part of that link address, and it may be readable in the public interface that supplies the profile page. Where your Steam profile is private, the badge shows only that an account is linked — no name, no avatar, and no link. Delinking the account in Settings is the only way to remove it.
The Steam details we hold are recorded ONCE, at the moment you connect the account, and are NOT refreshed afterwards. If you later change your Steam display name or your avatar, what Al Fhoud shows stays as it was when you connected; delinking and connecting again records the current values. This is different from a verified channel, whose public details we do refresh on a schedule.
The third party involved is Valve Corporation (Steam). Your use of Steam remains subject to the Steam Subscriber Agreement and to Valve’s own privacy policy, which we do not control.
23. Language of this Policy
The Arabic and English versions of this Privacy Policy are the official, authoritative versions. Any version provided in another language is a convenience translation only. In the event of any discrepancy, ambiguity, or error between a translated version and the Arabic or English version, the Arabic and English versions govern and prevail.
3. Social data
If you use the social features, we store your follows (one-directional) and your friendships (which require a mutual follow and approval). Removing a follow also removes the related friendship.
You can add someone by their public handle (AF-XXXXXX). This lookup only returns the public profile fields — display name, avatar, and public ID — and never exposes email, contact details, or language.
All Al Fhoud profiles (display name, public ID, and avatar) are publicly visible to anyone browsing the platform.