Privacy Policy

Effective September 7, 2026

What this covers

This policy covers Formation as a whole — the web app your organization uses to manage rosters, scheduling, strategy, and communication. The Discord bot component has its own, more detailed Bot Privacy Policy covering exactly what it collects inside Discord.

Information we collect

Account information: name, email address, password (stored as a salted hash, never in plain text), timezone, time-format preference, and an optional avatar, phone number, and Discord handle.

Organization data: whatever your organization enters — rosters, jerseys, positions, in-game names, player bios and tracker links, schedules, match results, availability, strategies and playbooks, match/practice discussion messages, recruitment prospects, gear inventory, expenses, and audit logs of sensitive actions.

Device information: if you enable browser push notifications, we store the subscription your browser gives us so we can deliver them — we can't read anything else about your device from this.

Usage data: if analytics are enabled for this deployment, aggregate, anonymized-where-possible usage data (pages visited, general location by country/region, device type) via Google Analytics — see "Cookies & analytics" below.

How we use it

Strictly to operate Formation for your organization: authenticating you, displaying and syncing the data your org enters, sending the reminders and notifications your org or you individually configure, and understanding how the product is used well enough to improve it. We don't sell data, and we don't use your organization's roster or strategy data for advertising.

Cookies & analytics

Formation sets a session cookie so you stay logged in — this one is required for the app to function and isn't optional. If Google Analytics is enabled for this deployment, it sets additional cookies to measure usage; those only load after you accept them in the cookie banner, and you can decline them without losing access to anything.

Third parties

Data is shared only with the services needed to run features you or your organization turn on: Discord (if you connect the bot or a webhook), your browser's push service (if you enable push notifications), Riot Games or Steam (only if you sync game stats, and only for the account you give us), and Google Analytics (only if enabled and only after cookie consent). None of these receive more than the specific data their feature requires.

Data retention & deletion

Your organization's data persists as long as the organization exists in Formation. You can disconnect individual integrations (Discord, push notifications) at any time from your account or organization settings, which deletes the associated stored data immediately. To request deletion of an account or an entire organization's data, contact us using the details below.

Security

Passwords are hashed, never stored or logged in plain text. Sensitive endpoints (login, signup, password reset) are rate-limited. Every sensitive change — role changes, permission grants, data resets — is written to an audit log your organization's admins can review. Traffic is served over HTTPS only.

Children's privacy

Formation is not directed at children and is not intended for use by anyone under 13.

Built with AI assistance

In the interest of transparency: substantial parts of Formation's codebase were built with the assistance of AI tools (Claude, by Anthropic), directed and reviewed by a human developer. No user or organization data is used to train any AI model — AI assistance here refers to how the software was written, not how your data is processed once the app is running.

Changes to this policy

This page may be updated as Formation's features change. Material changes will update the effective date above.

Contact

Questions or data requests: [email protected]. See also our Terms & Conditions.