This Privacy Policy explains how the Your Arena TV project (“Your Arena TV”, “we”, “us”) handles information when you use the Your Arena TV desktop application and this website. Your Arena TV is an independent community project and is not affiliated with MOONTON Games or the third-party platforms it can connect to.
1. Information we may process
Depending on the features you choose to use, Your Arena TV may process account identifiers, display names, profile images, MLBB Player ID/Server ID that you provide, creator/social links, authentication identifiers, and technical information needed to keep the service secure and functional.
If you create an Your Arena TV account using email and password, authentication is provided through Firebase Authentication. Your password is handled by the authentication provider and is not intended to be stored in plain text by Your Arena TV.
Email/password accounts must confirm their email address through a Firebase verification link before the updated Your Arena TV client grants account access. Firebase sends the verification message to the registered address. A pending Firebase account record may exist before confirmation; this does not activate access in Your Arena TV. The app can resend the message with a cooldown and check confirmation status. Existing unconfirmed email accounts must also confirm their address; this preserves saved profiles, Favorites and linked-account records.
2. Third-party sign-in
When you choose to connect or sign in with services such as TikTok, Twitch, KICK or Google, authentication takes place through that provider's authorization flow. Your Arena TV does not ask you to provide the password for those third-party accounts. We request only the permissions needed for the feature being used and may receive an account identifier and basic profile information authorized by you.
The updated desktop client keeps third-party authorization credentials in its main process, outside the page renderer. For Google, KICK and TikTok, Cloudflare Workers process access and refresh tokens and return an encrypted authorization envelope that only the backend can open. Twitch tokens are handled in the desktop main process. When Remember Me is enabled, credentials for the sign-in account and linked accounts are saved locally using Windows secure storage. Renewing provider access does not extend the original 30-day remembered-session limit. Signing out clears saved authorization credentials while retaining local profile settings, Favorites and linked-account identifiers. Disconnecting a platform requests provider revocation; disconnecting the platform used to sign in also signs you out. Provider revocation may cover only the current access token, so you can also remove Your Arena TV access in the provider settings.
3. Email addresses and public profiles
Email addresses used for authentication are treated as private account information and are not intended to be displayed on public Your Arena TV profiles by default. Public-facing profile fields are kept separate from authentication data.
4. How information is used
- to authenticate users and maintain sessions;
- to provide profiles, creator links and user-selected application features;
- to protect the service against abuse and unauthorized access;
- to diagnose errors and maintain reliability;
- to comply with applicable legal obligations.
5. Legal bases and user choice
Where applicable, information is processed to provide services you request, based on your consent for optional account connections, for legitimate security and reliability interests, or where required by law. You can choose not to connect optional third-party accounts.
6. Service providers
Your Arena TV may rely on infrastructure and authentication services such as Google Firebase and, for selected integrations, authorization APIs provided by TikTok, Twitch and KICK. Each third party processes information under its own terms and privacy practices. Your Arena TV does not sell personal information.
7. Data retention
Firebase Authentication handles email/password accounts. Cloudflare Workers process authorization and public profiles, which are stored in Cloudflare D1 only after publication consent. Private desktop profiles, Favorites, Player ID settings and linked-account identifiers are stored locally for the corresponding account. Public profile fields may include the Player ID and links you choose to publish; login email addresses and tokens are not public profile fields. Remember Me is optional. Its credentials are encrypted locally using Windows secure storage; the Firebase refresh token used by the updated desktop client stays in the main process and is not sent to the profile Worker or website. The Worker receives a short-lived user ID token to verify the account. The server stores a hash of the separate remembered-session token with its identity and expiration metadata. This session stops authorizing access after 30 days; expired records are cleaned up during subsequent remembered-session creation. Logout removes the locally saved remembered credential and attempts server revocation; profile settings, Favorites and linked-account identifiers are retained. Removing a public profile does not delete the Firebase account or local data. Account deletion and privacy requests require the contact process described below.
8. Security
Your Arena TV is designed to keep provider secrets out of the desktop renderer, use provider-controlled authorization screens, restrict application permissions, and separate public profile data from authentication data. No system can guarantee absolute security, so the project will continue to review and improve its safeguards.
9. Your choices and rights
Subject to applicable law, you may request access, correction or deletion of personal information associated with your Your Arena TV account, and you may revoke connected-app access through the relevant third-party provider. To request account or data deletion, email sk.vaultapp@gmail.com using the contact process below. Removing a public profile does not delete your account.
10. Children
Your Arena TV is not designed to knowingly collect personal information from children in violation of applicable law. Users must meet the age requirements applicable to the services and identity providers they use.
11. International processing
Third-party service providers may process data in countries other than your own. Their applicable privacy notices describe their international data transfer practices.
12. Changes to this policy
We may update this policy as Your Arena TV develops. The “Last updated” date above will identify the current version. Material changes will be reflected on this page.
13. Contact and privacy requests
For support, privacy questions or requests to delete your Your Arena TV account or data, contact sk.vaultapp@gmail.com. Do not send passwords, authentication codes or tokens. Requests may require verification of account ownership. Deleting a public profile in the application does not itself delete a Firebase account or all local data.
