rsltool.com
← Back to site

Privacy Policy

Last updated: 2 June 2026 · Effective immediately

This policy explains what data RSL Tool collects, why, how long we keep it, and who else sees it. We try to collect the minimum needed to deliver and support the Service.

1. What we collect

DataWhenWhyRetention
Email addressYou enter it at checkout or on /accountDeliver license, send purchase receipts, allow self-serve license recoveryUntil you ask us to delete or 5 years after last license expiry, whichever is sooner
Payment information — card (card number, billing address, country, VAT data)You enter it on Stripe’s checkout page when you pick the Card payment methodProcess paymentWe never see or store the card number itself. Stripe acts as the payment processor and stores the card data PCI-compliantly on their side.
Payment information — crypto (cryptocurrency wallet address, transaction hash, payer asset and amount)You authorize the transaction on OxaPay’s hosted checkout page when you pick the Crypto payment methodProcess paymentWe never see your wallet’s private keys. OxaPay handles the crypto flow and reports back only the on-chain transaction summary needed to deliver your license.
License token (JWT) and metadata (tier, expiry, issue date)On successful purchaseVerify your access to paid featuresFor the lifetime of the license; lifetime Founders licenses are retained indefinitely so we can re-deliver if you contact us
Device fingerprint (one-way hash of your Mac’s IOPlatformUUID, salted)First time you activate a license in the appBind license to your device(s); prevent unbounded license sharingFor the lifetime of the license
Web server logs (IP, user-agent, request path, timestamp)Every visit to rsltool.comCloudflare DDoS mitigation, debugging, rate-limiting30 days, then aggregated only
Country / region (derived from your IP)Every visitShow prices in your local currency, route you to the correct languageNot stored; computed at request time
Cookies and localStorage: language preference, last-issued license cacheYou interact with the site / complete a purchaseUX convenience (remember language; show you your latest license)30 days (cookies) / until you clear browser storage (localStorage)

2. What we do not collect

3. Optional gameplay telemetry (opt-in)

RSL Tool can optionally contribute anonymous gameplay data — your champion teams, their gear and stats, and battle outcomes — to a shared community database. In return, every user gets the pooled «top teams» and best-build recommendations back inside the app (e.g. which compositions clear Hydra Nightmare, with which gear and average damage). This data is pooled and shared back to all players; it is never sold, rented, or licensed to third parties. It is off by default: on first launch an explicit consent dialog asks you to opt in (you can decline, and change your mind any time in Settings).

What is sent when you opt in

FieldExampleWhat it is
idUUID v4Random event identifier — used only for server-side deduplication
anon_idopaque hex stringPer-installation random identifier created on first launch and stored locally in the app. Not linked to your email, license, payment, IP, or device fingerprint.
source"hydra" / "chimera" / "cb"Which boss / dungeon the battle was against
sighex hashDeterministic hash of your team’s hero IDs (used to group identical compositions across users)
team_power, damage, difficulty, pointsintegers / floatsBattle outcome metrics
heroes[]list of {type_id, grade, level, gear (sets, slots, exact artifact stat rolls), effective stats (HP / ATK / DEF / SPD / Crit / ACC / RES), damage_dealt, damage_taken, restored_hp, speeds}Per-hero build & performance — only Plarium’s public type IDs plus numeric stats and gear; no names, no avatars, and no per-account artifact identifiers
day"YYYY-MM-DD"Date bucket (UTC)

What is NOT sent: your email, your license JWT, your Plarium account ID, your Mac’s device fingerprint, your IP address (Cloudflare strips it before storage), or any free-text field of any kind.

Retention: raw events are retained for up to 12 months for aggregation work; periodic aggregates (e.g. «top 100 Hydra teams as of week N») are baked into the next app release and the underlying raw events are then deleted.

How to opt out: in the app, open Settings → Privacy → Share anonymous gameplay data and uncheck. The local queue is purged immediately and no further events are sent. You can also clear already-uploaded events by writing to [email protected] with your anon_id (visible in Settings).

Legal basis (GDPR): consent, Art. 6(1)(a). You may withdraw consent at any time as described above.

4. Who else sees your data (sub-processors)

ProviderRoleData shared
Stripe Payments Europe Ltd. (Ireland)Card and wallet payment processing (PCI-compliant card handling, subscription management, refunds). Stripe Tax calculates and remits VAT / sales tax to applicable jurisdictions on our behalf where Tax registrations exist.Email, payment details (card stored at Stripe, never reaches us), billing address, transaction history
OxaPay (crypto payment gateway)Cryptocurrency invoice creation and settlement (USDT / USDC / BTC / ETH / TON / TRX). Used only when you pick the Crypto payment method at checkout. Auto-converts received crypto to USDT in our settlement balance.Email (so OxaPay can send you a receipt), invoice amount and currency, post-payment transaction hash and payer wallet address (visible on public blockchain regardless). We do not see your wallet’s private keys.
Resend.com (Resend, Inc.)Transactional email deliveryEmail, license-email body, delivery timestamps
Cloudflare, Inc.DNS, CDN, edge compute, KV storage, R2 file storage, D1 SQL storage (anonymous telemetry only), Email RoutingWeb server logs, KV records (license + quota counters), D1 rows (anonymous telemetry events — only if you opt in per Section 3), email forwarding ([email protected])

Each sub-processor has its own privacy policy and Data Processing Agreement covering GDPR, CCPA, and other consumer-protection laws applicable to the regions they operate in.

5. Your rights (GDPR / CCPA / similar)

You may at any time, by writing to [email protected], request:

We respond within 30 days. No fee for reasonable requests.

6. Cookies and storage we use

We use a small number of strictly-necessary cookies and browser-storage items. No consent banner is required for these because they are essential to delivering the Service you explicitly requested.

You can clear all of these at any time from your browser’s privacy settings.

7. Cross-border data transfers

Our infrastructure (Cloudflare, Resend, Stripe) operates globally. Your data may be processed in jurisdictions outside your home country, including the United States, Ireland, and elsewhere in the European Union. All sub-processors named above have published Standard Contractual Clauses or equivalent safeguards for cross-border transfers under GDPR Article 46.

8. Children

RSL Tool is intended for users who have reached the age of majority in their jurisdiction. We do not knowingly collect data from anyone under 16 (EU) or under 13 (US). If you believe we have, contact us and we will delete it.

9. Security

We hold your data inside Cloudflare’s edge infrastructure with TLS in transit and encryption at rest. License tokens are signed with RSA-2048 keys; the signing key never leaves our build environment. Admin endpoints require a Bearer secret. Sub-processors have their own SOC 2 / ISO 27001 attestations.

That said, no system is 100 % secure. If you suspect your license has been compromised, email us — we’ll revoke it and issue a fresh one tied to a new device.

10. Changes to this policy

Material changes will be announced via the rsltool.com homepage and by email to all active license holders at least 14 days before they take effect.

11. Contact

Data protection enquiries, deletion requests, and any privacy concerns: [email protected].

RSL Tool is an independent third-party utility. Not affiliated with, endorsed by, or sponsored by Plarium Global Ltd.
Raid: Shadow Legends® is a trademark of Plarium Global Ltd.
© 2026 rsltool.com