1. Scope
This Privacy Policy applies to the Kogni Player Cards website at https://fa.kogni.pro, the card studio, the Kogni accounts used to sign in, published player card pages, Duo discovery, the live feed, community features such as friends, ratings, signatures, and reports, and the backend API that powers these services.
Kogni Player Cards is a live, evolving product. Some features may change as the product evolves, but we will keep this policy updated when our data practices materially change.
2. Who Is Responsible
kogni operates Kogni Player Cards and is the data controller for the personal data described here — the controlador under the Brazilian LGPD and the controller under the European GDPR. Our data protection contact (the encarregado/DPO channel) handles privacy questions and requests through the Kogni Help page.
3. Data We Collect
Depending on how you use Kogni Player Cards, we may process the following categories of data:
- Account data (Kogni identity): name, email address, password hash, email verification status, sign-in method (email, Google, or Discord), Google or Discord account identifiers and avatar when you use those sign-ins, and basic account settings.
- Player and match data: the VALORANT game name and tag you search for, rank, competitive or ranked performance metrics (such as win rate, ACS, ADR, KAST, K/D, clutches, and first bloods), signature agents, maps, recent match summaries, and the stat snapshot period you select.
- Card content you add: display nickname, role, photo or team logo you choose, perks and play style, languages you speak, ranked preferences (group goals, availability, voice chat comfort, interests), social links you add, and card design choices (theme, gradient, background, finish).
- Duo and community data: Duo discovery activity (cards shown to you, skips, ask-to-play requests, accepted connections, pending requests in your album), presence signals such as online availability and a random per-session device identifier, friends, ratings, reviews, signatures you exchange, and reports you submit (reason, details, and the reported card).
- Live feed data: public live status of verified streamers (platform, channel, and stream title) served from our live discovery service.
- Support data: messages you send us through the Help page or in-app flows, including reports and moderation correspondence.
- Technical data: IP address, approximate country or region inferred from the IP, browser and device information, request IDs, error diagnostics, and security, rate-limit, and abuse-prevention logs needed to operate and protect the service.
- Local device storage: unsaved card drafts and creation progress stored in your browser's local storage, and temporary sign-in flow state stored in your session storage. This data stays on your device.
- Product usage data: limited events about which screens and controls are used (for example, starting a search or publishing a card), used to debug and improve the service. We do not use this data for advertising and we do not sell it.
4. Legal Bases Under the LGPD and the GDPR
We only process personal data when we have a valid legal basis. The table below maps our main purposes to the legal bases of article 7 of the LGPD and article 6 of the GDPR.
| Purpose | LGPD (art. 7) | GDPR (art. 6) |
|---|---|---|
| Creating your account, keeping you signed in, and providing cards, Duo discovery, friends, and community features | Execution of contract (V) | Performance of a contract (1)(b) |
| Sign-in with Google or Discord, and email verification codes | Execution of contract (V) | Performance of a contract (1)(b) |
| Security, fraud and abuse prevention, rate limits, and moderation of reports | Fraud prevention and security of the holder (VIII, combined with art. 10) and regular exercise of rights (V) | Legitimate interests (1)(f) |
| Diagnostics and product usage data to debug and improve the service | Legitimate interest (VIII, combined with art. 10) | Legitimate interests (1)(f) |
| Complying with legal obligations and responding to authorities | Compliance with legal or regulatory obligation (II) | Legal obligation (1)(c) |
| Any optional processing that is not necessary to run the service (we will always ask first) | Consent (I), revocable at any time | Consent (1)(a), withdrawable at any time |
When we rely on legitimate interests, we balance them against your rights and freedoms and only process the minimum data needed. You can object to processing based on legitimate interests as described in section 11.
5. How We Use Data
We use the data we collect to:
- create, authenticate, and protect your Kogni account, including email verification and sign-in with Google or Discord;
- search and import the VALORANT stats you ask for and build your competitive or ranked card;
- host, display, and export published player cards and their public pages;
- run Duo discovery, ask-to-play requests, friends, presence, ratings, signatures, and your album;
- serve the live feed of verified streamers;
- review community reports and enforce our rules and moderation decisions;
- send transactional messages such as verification codes and account security notices;
- monitor reliability, debug issues, prevent abuse, and enforce access controls;
- comply with legal obligations and protect kogni, users, and their data.
6. Published Cards and Public Data
A card you publish becomes publicly visible to anyone with its link, may appear in public galleries and in search engines, and includes the match data, nickname, role, and preferences you chose to show. Ranked cards that opt into Duo discovery are also shown to other verified players in the discovery queue, including the availability, languages, and play style you selected.
You control this. You can unpublish or delete your cards from My Cards at any time, which removes them from public view and from Duo discovery. Ask-to-play requests and accepted connections share your card with the specific player you interacted with. Data that other people have already seen, screenshotted, or downloaded cannot be recalled.
8. International Transfers
kogni and its service providers may process data in Brazil and in other countries. When personal data is transferred out of Brazil or the European Economic Area, we rely on the mechanisms allowed by article 33 of the LGPD (such as adequacy decisions, standard contractual clauses, or your specific consent) and chapter V of the GDPR (such as adequacy decisions or standard contractual clauses). You can request more details about these safeguards through the Kogni Help page.
9. Retention and Security
We keep personal data for as long as needed to provide the service, maintain your account and cards, resolve disputes, comply with legal obligations, and protect the service. Account data is kept while your account exists; published cards are kept until you delete or unpublish them; unsaved drafts remain on your device until you clear them; security and rate-limit logs are kept for a limited period (currently designed around 90 days). Backups may persist for a limited period after deletion as part of normal recovery operations.
We use administrative, technical, and organizational safeguards designed to protect data, including encrypted transport, password hashing, session cookies scoped to our own origin, strict content security policies, rate limits, allowlisted request routing, and limited access for staff and service providers. No online service can guarantee perfect security, but we work to keep protections appropriate for the sensitivity of the data.
11. Your Rights
In Brazil (LGPD, art. 18)
You can request:
- confirmation that we process your data;
- access to your data;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of unnecessary or excessive data or data processed in violation of the law;
- portability of your data to another supplier;
- information about with whom we have shared your data;
- information about the consequences of not providing consent (where consent is the basis);
- revocation of consent.
In Europe (GDPR)
You can request access, rectification, erasure, restriction of processing, data portability, and object to processing based on legitimate interests, and you can withdraw consent at any time where consent is the basis.
To exercise any of these rights, use the in-app controls (update your profile, unpublish or delete cards, sign out) or contact us through the Kogni Help page mentioning that it is a data protection request. We respond within the timeframes required by the applicable law. In some cases we may need to verify your identity before responding.
12. Children
Kogni Player Cards is designed for VALORANT players and is not directed to children under 13, or under the higher minimum age that Riot Games requires for a VALORANT account in your country. We do not knowingly collect personal data from children below those ages. If you believe a child has provided personal data without appropriate permission, contact us so we can review and take appropriate action, including deletion.
13. Changes to This Policy
We may update this Privacy Policy as Kogni Player Cards changes. When we make material changes, we will update the date above and may provide additional notice in the app or on the website where appropriate. If a change requires a new legal basis (for example, optional cookies that need consent), we will ask you before it takes effect.
14. Contact
For privacy questions; access, correction, portability, or deletion requests; or anything related to the LGPD or the GDPR, contact kogni through the Kogni Help page or the support flow available in your account. Our data protection contact (encarregado/DPO channel) handles these requests.