Trust & Security
This page is maintained by the SWU League organizers to answer common security and privacy questions about the SWU League tracker. It describes the controls currently in place; it is not a certification or an independent audit.
Accounts & sign-in
Accounts are protected by authenticated sign-in. Passwords are never stored by the app in readable form, and sign-in sessions are managed by our backend provider. Administrative actions are limited to approved league organizers.
Access controls
Data access is enforced at the database level with row-level security rules, not just in the app interface. Members can only edit their own profile, real names are visible only to signed-in approved members, and internal account identifiers and email addresses are never exposed publicly. Elevated permissions are granted through a dedicated roles system rather than stored on user profiles.
Data we hold
We store your email (for sign-in and recovery only) and your league profile — display name, avatar, optional Discord handle, and the matches you take part in. We never sell your data or share it with advertisers. See our Privacy & Data page for details and removal requests.
Hosting & infrastructure
The app runs on managed cloud infrastructure with encryption in transit (HTTPS). Secrets and service credentials are kept on the server side and are never shipped to the browser. Responsibility is shared: the underlying platform secures the hosting environment, while the league organizers are responsible for app configuration and data-handling practices described here.
Reporting a security issue
If you believe you have found a security or privacy problem, please contact a league administrator so we can investigate and respond. We appreciate responsible disclosure and aim to address valid reports promptly.