Effective September 28, 2026
We do not sell your personal information or gameplay data. We do process and store limited information needed to connect your Riot account and provide the API. If you share your API key, anyone holding it can request your linked data.
Synapse VALO API is an independent third-party project operated by SynapseIX. For privacy questions or deletion requests, contact @synapseix on X. Do not send passwords, tokens, or API keys in public messages. The service is not affiliated with or endorsed by Riot Games.
When you connect through Riot Sign On, the service receives your Riot PUUID, Riot ID (game name and tag), region, OAuth access token, and refresh token. It stores these along with token expiration and your opt-in status. It stores a one-way hash of your generated API key and its creation time, not the raw API key after it is displayed. Your linked match history, match details, and available leaderboard data are requested from Riot when an authorized endpoint is called; the application does not keep a separate match-data database.
We do not ask for or store your Riot password. The application does not run advertising, analytics trackers, or marketing cookies. Riot and the hosting provider may separately process connection information under their own policies. Standard infrastructure may produce request logs, including IP addresses and requested paths, depending on host configuration; do not assume that infrastructure logs are disabled.
We use the account identifier and OAuth tokens to verify the account you chose to link and maintain that connection. We use the API key hash to authenticate callers. Authorized calls retrieve and return your linked gameplay data. The API key does not give callers your Riot password or OAuth token, but it does let them access data returned by this service.
The service exchanges account information with Riot to provide the connection and API features. Hosting and infrastructure providers process data as needed to operate the service. Anyone you give your API key to can retrieve the data exposed by the API; they may save or publish copies outside our control. We do not sell data or give others access to linked accounts for advertising.
The application retains your linked account record and key hash while your account remains connected. Use POST /v1/disconnect with your API key to delete the active local record and revoke its keys. Use POST /v1/key/rotate to invalidate previous keys. Reconnecting also rotates keys. You may separately remove Riot authorization through Riot account settings. Deletion from this application cannot remove copies already obtained by key holders, Riot, infrastructure logs, or any hosting backups. Contact us through the channel above if you cannot use the API to disconnect.
Use HTTPS and keep your key private. The current application stores Riot OAuth tokens in the server's persistent data file; access to that file must be restricted by the deployment operator. No online service can guarantee absolute security.
We may update this policy when the service changes. The effective date above will be updated when material changes are published.