← Back to Data and network use

Build-specific information

Data, network use and beta applications.

The distributed 0.1.0 client and the current development source have different match-data behavior. Check the section for the build you are using; the notice shown in the app is the authority for that build.

Private-beta application notice · version 2026-09-v5

Private-beta applications

When applications are enabled, the website form sends your email address, confirmation that you can test on Windows x64 with RAID build 11.71.0, the notice version you accepted, and a Turnstile challenge token to the application service. The server records the email, compatibility confirmation, accepted notice version, consent time, request status and expiry. We use the email to review the request and, if approved, send an invitation to create a separate sign-in account. Submitting a request does not create an account or grant app access; an account must verify its email and have an active access grant before the app's access check authorizes it. Approval does not enable match sharing or send match data.

Do not include a RAID account name or ID, password, champion roster, match record or other game data. The form has no free-text field and does not ask for those details. Cloudflare Turnstile helps limit automated submissions; its script is loaded only on the application page, and the server checks the challenge with Cloudflare before saving a request. The application record does not contain your source IP address. The API uses the Cloudflare-provided client address for transient in-memory rate limits, not as an application field.

Application records are stored in PostgreSQL on the RSL Drafter server and the current server source deletes expired requests after 90 days in its daily retention pass. You may delete a request sooner by using the one-time withdrawal code shown after submission; only a hash of that code is stored. Withdrawal applies only while a request is pending. It cannot delete an approved sign-in account or revoke an access grant; those are separate records and require a separate administrator action. Save the code because it cannot be recovered if lost. The public API has no application-list endpoint; access to records requires server/database administration access. The API and Turnstile may process ordinary connection data needed to deliver and protect the services. Retention of Cloudflare, host and server access logs has not been independently verified.

After approval, a separate identity service is intended to store the sign-in email, email-verification state, password verifier and authentication/session data. The access database stores the identity provider's fixed issuer, subject and active/revoked grant status separately from the application row; it does not store the sign-in email. Identity-account and access-audit retention/deletion settings have not yet been verified. The identity provider and invitation-email path must be verified and this notice reconciled before applications or account invitations are enabled.

If the form says applications are unavailable, no request was submitted. The distributed 0.1.0 client does not contain this website form or collect application data.

Distributed client · version 0.1.0

The distributed 0.1.0 build does not collect or upload match telemetry. It has no match-sharing preference, first-run match notice or local match queue.

This statement applies to that distributed installer. Do not assume it describes a later development build.

Current development source · match sharing

The current app source contains anonymous match collection and upload. A first-run notice appears before sharing can begin. The preference is on by default, but no match is collected or sent until you review and save the notice. Uncheck sharing before saving to leave it off. You can change the choice later in Developer Tools; a changed notice version pauses sharing until it is reviewed again.

When sharing is on, an eligible observed Live Arena match is queued after it ends. Records are sent over HTTPS to the fixed host api.rsldrafter.app. The app automatically enrolls the installation when its first queued match is ready to send.

What a match record contains

Records do not contain player or opponent names, account or profile IDs, device identifiers, exact timestamps or ratings, roster inventories, equipment, screenshots, logs, legal candidate lists or raw game memory.

The event ID identifies one record only; it is not a stable contributor ID. The installation credential is kept separate from match records.

Installation credentials and network requests

When the first match is ready to send, the installation creates a random revocable ID and secret. They are sent in authentication headers for access control, quotas and revocation; they are separate from match records. The in-app notice says the service stores the ID and the secret's SHA-256 hash in a separate authentication table. The secret is protected for the current Windows user with DPAPI and is not written to logs or match payloads.

The in-app notice says Cloudflare and the API process the request's source IP to deliver and protect the connection, and that the IP is excluded from match records and training records. The app uses HTTPS, validates TLS certificates, and disables redirects and system proxies.

Local queue, retention and turning sharing off

Pending records stay on the device for up to 30 days, with a 50 MiB queue limit. If you enable sharing later, existing queued records may also be uploaded; use Delete queued matches first if you do not want them sent. You can also delete the local queue at any time.

The in-app notice states that the service retains accepted anonymous records for up to 365 days. They have no stable contributor ID, so an accepted record cannot later be found or removed by user. Turning sharing off cancels an active request, stops further collection and uploads, and deletes records still in the local queue.

Other app network use and local files

The app checks GitHub for release information at startup and when you choose Check for updates. It asks before downloading an update, then checks the package against the manifest's declared size and SHA-256 value. GitHub receives the connection information needed to serve the request; RSL Drafter has not verified GitHub's server-side logging or retention.

The champion reference catalog is bundled with the app and is not fetched from HellHades while running. Strategy and profile files stay local. Diagnostic reports are created locally and are not uploaded automatically; review and redact a report before sharing it yourself.

Website and scope

The site does not use analytics. When beta applications are enabled, the application page loads the Cloudflare Turnstile script and sends the application directly to the separate API at api.rsldrafter.app; this path is not the app's match-ingestion endpoint. The hosting provider may process ordinary request information; server-side logs and retention have not been independently verified here.

This is a technical description of the client behaviors above, not a complete legal privacy policy for every use of the application or website. RSL Drafter is an independent community tool and is not affiliated with or endorsed by Plarium.