Privacy Policy
What we collect, why we need it, and where it goes.
Last updated 23 August 2026
1. Controller
The individual operating MVP Royale is the controller for the data described here. The legal name and service address will be published before paid ordering opens. You can reach the privacy contact at privacy@mvproyale.com or support at support@mvproyale.com. Checkout stays disabled until the remaining legal details are complete.
2. Data we collect
- Account: name, email, avatar, provider account identifier, sign-in time, session and OAuth security records supplied by Google or GitHub. Our servers also receive the IP address and user agent that accompany a request.
- Products: submitted URL, ownership evidence, public page text, logo, desktop and mobile captures, automated checks, AI draft, corrections, moderation state and versions.
- Arena: assigned matchup, choice, reason, timing, essential session identifier, security signals and whether the answer was accepted.
- Usage and security: request metadata, errors, rate-limit events, aggregate online/daily activity and evidence needed to detect bots, abuse or coordinated voting. Product measurement keeps the event, country and continent supplied by Cloudflare, device, browser and operating-system family, landing path, traffic class and referring domain. It does not keep the full referring URL or user agent. For approximate daily visitors, the server derives a secret-keyed value from the network address. It is different for each product and changes each UTC day; the raw address is not written to product analytics.
- Payments: Creem customer, checkout, order, invoice, refund and dispute identifiers and status. Creem receives payment details directly; we do not store full card numbers.
3. Why we use it
We process account and order data to perform our contract; security, moderation, service measurement and fair matching for our legitimate interests; payment and compliance records for legal duties; and optional communications only with consent where required.
4. Public and private data
Published product profiles, page captures, aggregate findings, accepted totals, rankings and version summaries are public. Account email, raw security evidence, OAuth tokens, rejected answers, moderation notes and payment identifiers are not public. We do not publish a voter’s identity with an answer.
5. Service providers
- Cloudflare: hosting, D1, R2, Workers AI, Browser Rendering, Turnstile, traffic security and delivery.
- Google and GitHub: OAuth sign-in when you choose that provider.
- Creem: Merchant of Record, checkout, tax, invoicing, refunds and payment support.
These providers may process data outside your country under their own safeguards. We do not sell personal data or share it for behavioural advertising.
6. AI and automated checks
Public product-page material and captures may be sent to Cloudflare-hosted AI models to draft descriptions and find clarity, UX, accessibility and mobile issues. The draft does not publish without filtering and human confirmation. Account secrets, raw OAuth tokens and payment details are not included in AI prompts.
7. Cookies
MVP Royale does not use analytics or advertising cookies, and product measurement does not use localStorage or sessionStorage. The only first-party cookies are strictly necessary for a feature you request: signing in, protecting an OAuth return, or keeping an issued arena round tied to the browser that opened it. The arena cookie is a browser-session cookie rather than a 30-day tracker. Turnstile may process browser and interaction signals to distinguish people from abusive automation.
Measurement stays on MVP Royale. We do not append a visitor identifier to outbound links, combine activity across customer websites or build an advertising profile. Referrers are reduced to a source group and domain, without their path or query. Global Privacy Control and Do Not Track disable optional page, click and live-presence measurement in browsers that send those signals.
8. Retention
Active account and product data is kept while the service is provided. OAuth state and verification records expire quickly; sessions expire or are revoked; live-presence entries age out after about 10 minutes and its approximate daily estimate resets at 00:00 UTC; daily visitor keys remain only in the live analytics object for up to two days and never enter the 30-day warehouse; minimized event rows are deleted after 30 days; raw security logs are normally kept for up to 90 days; rejected arena evidence for up to 180 days; product reports and accepted aggregate findings while the profile remains public; payment and tax records for the period required by law. Backups age out on their normal cycle.
9. Your rights
Depending on your location, you may ask for access, correction, deletion, restriction, portability or object to processing, and may complain to your data-protection authority. We may need to verify your identity and may retain records the law requires.
10. Security and contact
We use encrypted transport, secure OAuth, encrypted provider tokens, least-privilege bindings, rate limits, human checks, access controls and audit records. No system is perfectly secure. For privacy and incident reports, email privacy@mvproyale.com. The operator’s legal name and service address will be added before paid ordering opens.