The world lies.

Rascal RealmsCrownfall · in pre-production

Privacy & data protection policy

Rank Rascal Privacy Policy

Effective Date: September 29, 2026 | Version 1.3

Support mailbox not open yet. Use the project support page for the current privacy-request path.

1. Information We Collect

Rank Rascal collects the minimum information needed to operate the game website, review community submissions and preserve the paused Discord bot project:

  • Discord Account Data: Your Discord User ID, Guild (Server) ID, and channel context.
  • Roblox Identity Data: Verified Roblox User ID, Roblox username, display name, account creation timestamp, public avatar thumbnail URL, public badge count, and public profile visibility setting.
  • Rank Rascal Calculated Data: Rascal Rep score, Rotfile achievements, and server-specific preferences.
  • OAuth Processing Data: Short-lived, state-hashed authorization verifiers during PKCE verification.
  • Community Submissions: Display name, email address, review rating and focus, feedback text, Guild track, portfolio link, availability, time zone, consent choices and submission time when you use the website forms.
  • QA Recognition Data: A generated submission ID and the name printed on your personalized digital badge and certificate.

2. Token Retention Policy

We prioritize zero-token retention. After verifying your Roblox identity through PKCE OAuth 2.0, short-lived authorization tokens and access tokens are immediately discarded. We do not retain or store your Roblox OAuth access tokens, refresh tokens, or passwords.

3. Purpose of Processing

Collected data is processed strictly for:

  • Reviewing game feedback and responding when contact information is provided
  • Adding reviewers to the Founding QA candidate pool and sending their personalized badge and certificate. Joining the candidate pool does not guarantee testing access, an invitation, employment or compensation.
  • Evaluating voluntary Founders Guild and future playtesting participation
  • Moderating comments before any approved quotation is published
  • Preserving legacy bot privacy controls and account links while the bot project is paused

4. Community Submission Storage

Website submissions and confirmation emails are processed through our transactional email provider and delivered to a private Rank Rascal team mailbox. A private Discord webhook may also provide a moderator-only notification copy. Submissions are not published automatically. We retain them only as long as needed for review, Founding QA candidate pool administration, follow-up, moderation records or team selection. Do not submit passwords, precise addresses, private Roblox account data, payment information or other sensitive personal information.

5. Ask Razz

Ask Razz answers questions inside your browser from a fixed set of answers written by the Rascal Labs team (the Crownfall canon). Questions you type into Ask Razz, including quick questions and follow-ups, are processed locally on your device. They are not sent to our servers, are not stored by the website, and are not sent to Anthropic, OpenAI or any other AI provider. Ask Razz may remember one optional preference, whether Razz may interrupt, in your browser's local storage. Please do not type personal information into Ask Razz.

6. Deletion & Legacy Bot Data

The Discord bot project is paused, but previously collected bot data remains subject to deletion. If the bot is available, /unlink-roblox purges the stored Roblox account link and associated profile data. You may also request deletion of bot or community-submission data through the support path listed below.

7. Public Profile Visibility & Comment Permission

Legacy bot profiles retain their existing privacy setting while the bot is paused. Community comments are private by default. Checking the public-quotation box gives the team permission to quote that submission with the supplied display name, but does not guarantee publication. A human reviews every quotation first.

8. Age Requirement

Rank Rascal and its community forms are intended for users aged 13 and older. We do not knowingly collect data from children under 13.

9. Security Controls & Third-Party Platforms

Rank Rascal uses HTTPS encrypted transport, input validation, rate controls and restricted server-side credentials. Transactional email is delivered through Resend; Discord may be used for private moderator notifications. Those providers process the minimum delivery data required for the service.

Platform Disclaimer: Rank Rascal is an independent product and is not affiliated with, endorsed by or sponsored by Discord, Roblox, Epic Games or Riot Games.

10. User Rights & Contact Information

For privacy inquiries, manual data export, or deletion requests, contact our privacy team:

Email: not available yet