Legal

Privacy Policy

Last updated July 8, 2026.

Who to contact

The controller/operator for this site is currently The Wasans website operators and project maintainers. There is no formal company or legal entity yet, so this may be updated if the project structure changes.

For privacy questions, account deletion, or data requests, email tully@tully.sh.

Discord login data

When you log in with Discord, the site requests Discord's identify scope and may store:

  • Discord user ID
  • Discord username or display name
  • Discord avatar hash and discriminator when Discord provides them
  • Discord OAuth access token, refresh token, and token expiry

Discord login is used to create your player account, keep you signed in, connect submissions to your player profile, and support moderation/community features.

Account data
  • Internal player UUID
  • Player name, score, permission level, and date joined
  • Account status, deactivation/deletion time, and terms/privacy acceptance timestamp
  • Session tokens used to keep you logged in
Public data

Some site data is meant to be public so the leaderboard and submission archive work:

  • Player profiles, names, avatars, scores, ranks, and join dates
  • Submissions, times, trials, states, moderator notes, and moderators shown on submissions
  • Personal bests, world records, public score videos, and Discord submission thread links when used

Public submissions, scores, and videos can stay public after account deletion. Deleted accounts are shown as Deleted Account.

Legal basis
  • Account/login data is processed to provide the Discord login/account service.
  • Public scores, submissions, proof videos, PBs, WRs, and leaderboard data are processed to provide the community leaderboard and submission system.
  • Security logs, audit logs, moderation notes, and error logs are processed for legitimate interests such as security, abuse prevention, moderation, debugging, and protecting the integrity of the leaderboard.
  • Deletion and privacy requests are processed to comply with legal obligations.
Submissions and proof videos

When you submit a run, the site stores the trial, time, submission state, player information, and proof video. Uploaded videos and videos fetched from supported proof links are stored in the site's video storage and may be publicly viewable.

Logs and security data

The site stores audit logs for submissions, moderation, world record changes, and site errors. Error logs can include the page path, browser user agent, error message, stack trace, and your logged-in account if the error happened while you were signed in.

Cookies and browser storage

The site uses cookies and browser storage for login, security, preferences, and cached UI data:

  • A session cookie for logged-in accounts
  • Short-lived Discord OAuth state cookies during login
  • Sidebar and UI preference storage
  • Calculator inputs, cached leaderboard data, and recently viewed submission IDs

The site does not currently use advertising or marketing cookies. If that changes, the project maintainers should add a consent flow before using non-essential tracking.

Data retention
  • Account/login data is kept while the account exists.
  • OAuth tokens and sessions are removed when the account is deleted.
  • Public submissions, scores, PBs, WRs, and proof videos may remain after deletion because they are part of the public leaderboard/archive.
  • Deleted accounts are shown as Deleted Account.
  • Logs are kept only as long as reasonably needed for security, moderation, debugging, and audit purposes.
  • Data may be kept longer if needed to handle abuse, disputes, security issues, or legal obligations.
Third-party services

The site uses Discord for login and community features, Cloudflare for hosting/database/video storage, and proof providers like Medal when resolving submitted proof links. These services may process data under their own policies.

International transfers

Third-party services such as Discord, Cloudflare, and proof/video providers may process data outside the EU/EEA. Where required, appropriate safeguards or lawful transfer mechanisms should be used.

Deletion and deactivation

You can deactivate your account in Settings. Deactivation hides the account from normal player listings and is reversible by logging in with Discord again.

You can delete your account in Settings or request deletion by emailing tully@tully.sh. Deletion removes Discord login data, OAuth tokens, active sessions, and personal account identity from the account row. Public submissions, scores, PBs, WRs, and proof videos stay available as Deleted Account.

Age

Our website is not intended for children under the age of 13. By logging in via Discord, you confirm that you meet Discord's minimum age requirements.

Your choices and rights

You can use public pages without logging in. If you log in, you can manage account deactivation or deletion in Settings. You can also email tully@tully.sh to request:

  • Access to your data
  • Correction of inaccurate data
  • Deletion
  • Restriction
  • Objection
  • Portability, where applicable

Some rights may have limits, especially for public leaderboard/submission records, moderation integrity, security, or legal reasons. You may complain to your local data protection authority, or in Finland to the Office of the Data Protection Ombudsman.

Terms

The rules for using the site are in the Terms of Service.