RiftSight Privacy Policy
Last updated: October 2026
RiftSight has three parts: a browser extension (used by players and streamers in Rift Atlas, and by viewers of YouTube and twitch.tv videos), a Twitch Extension that renders the overlay for Twitch viewers, and an optional stream-overlay page for OBS.
RiftSight is an unofficial fan project. RiftSight was created under Riot Games' "Legal Jibber Jabber" policy using assets owned by Riot Games. Riot Games does not endorse or sponsor this project.
If you're a viewer
RiftSight does not collect, store, or process any personal data about viewers. On a Twitch channel that runs the RiftSight Twitch Extension, your browser verifies your session with Twitch's own Extension platform to confirm which channel you're watching — this happens entirely through Twitch's standard Extension Helper mechanism and is never stored by RiftSight. We do not use cookies, analytics, or tracking of any kind on the viewer-facing overlay.
If you watch YouTube or twitch.tv streams through the RiftSight browser extension, the same principles apply: your overlay preferences (on/off, outlines, delay) are stored locally in your own browser and never leave it. To show the overlay, the extension sends the watched page's public channel identifier to RiftSight's backend — the channel ID on YouTube, the channel name from the page address on twitch.tv — solely to look up whether that channel has a live RiftSight session (and, on twitch.tv, whether the RiftSight Twitch Extension is already showing cards there, so the two never overlap). This lookup is never tied to who you are: no account, no sign-in, no identifier of yours is sent or stored, so nothing records which channels you watch. On twitch.tv the extension also reads your Twitch player's own delay behind the broadcaster, inside your browser, to time the overlay; that number is never sent anywhere. The youtube.com and twitch.tv permissions themselves are optional and only requested if you turn the viewing feature on for that site. From 0.11.0 you can also try it on one tab first: clicking Try on this tab in RiftSight's toolbar panel on a twitch.tv or YouTube tab runs the overlay on that tab only, with the same channel lookup, until you reload the page or leave the site. Nothing runs on a tab because you opened the panel there.
Streamer decks (Deck panel). If a streamer you watch has chosen to share their deck with viewers (see "If you're a streamer: sharing your deck with viewers" below), the same request that looks up the channel also asks RiftSight's backend for that shared deck, and the extension shows it in its Deck panel over the video. Nothing about you is sent or stored for this: the request carries only the public channel identifier described above, and the deck panel's own settings (whether it is open, and any channel you choose to hide it on) stay in your own browser. Copying a deck list puts it on your clipboard on your device only.
Card recognition (from version 0.12.0). You can switch on card recognition for a
YouTube video, or a twitch.tv channel or video, with one click on the RiftSight button in the player (or
with Try on this tab in RiftSight's toolbar panel), so cards are hoverable even when the
streamer doesn't use RiftSight. It stays off until you do, and the same button switches it off. It runs entirely inside your browser: the extension reads frames from the
video player on your screen and analyses them on your own device. No frame, crop, screenshot or
recognition result is ever sent to RiftSight or anyone else; like anything an overlay draws, the card
tooltips are part of the page you are viewing, so that site's own scripts can see them. The videos and
channels you switch it on for (the last 200) are remembered only on that device. When you switch it on,
the extension downloads the recognition model files and a card reference index, about 9 MB together, from
RiftSight's asset CDN (assets.riftsight.gg); your browser caches them, so later videos usually
load from the cache. The extension also reads a small public settings file there, the published manifest
that says whether the feature is switched on: when your browser starts, when the extension is installed
or updated, and while a page asks, at most about once every five minutes over the network. These are
read-only static downloads: no sign-in, no cookies, and nothing about you, the video or the channel is
sent. RiftSight can switch the feature off for everyone through the same manifest. Recognition is
automated and can be wrong; when it isn't sure it shows nothing, and nothing about what it recognises is
reported back to us. To decide whether to offer a one-time hint on a video page, the extension reads that
page's title, description, keywords and channel name inside your browser; nothing about it is sent.
Extension updates (from version 0.12.0). So that a new version doesn't wait for a browser
restart, the extension asks Chrome to check the Chrome Web Store for an update about every six hours (this is
Chrome's own request to Google; nothing is sent to RiftSight), and it applies an update only while RiftSight
isn't in use. Before applying an extension update, it reads the same public settings file on
assets.riftsight.gg, which can pause updates; while an update is paused that way, it re-reads
the file at most every five minutes. No sign-in, no cookies, and nothing about you is sent.
If you're a streamer: the browser extension
The RiftSight browser extension publishes the public board state from your own
Rift Atlas games while Rift Atlas is open and you're
connected — automatically, with no extra step, and you can pause it at any time from the
toolbar popup (for the rest of that browser session). Its content script only runs on
play.riftatlas.com — it doesn't run on, or have access to, any other site you visit.
While active, it reads card information already rendered on your screen (card art, names, positions, which
zone each card is in) and sends it over an encrypted connection (wss://) to RiftSight's backend,
which forwards it to your stream's overlay. It never sends anything Rift Atlas itself is keeping
hidden from you (an opponent's hand, a face-down card) — the same visibility rules that apply to what
you can see in the game apply to what the extension will ever publish. RiftSight's backend keeps only the
latest board state while you're live and nothing after your stream ends; the only record of your games is
the match history you can keep on your own device, described in the next section. Card art images are served as
plain static files from RiftSight's own asset CDN (assets.riftsight.gg), the same way loading
any web page fetches its images — no sign-in, and nothing that identifies you or your viewers.
The extension requests a small set of permissions, each scoped to exactly what it needs:
storageandunlimitedStorage— remember your linked account and overlay settings locally in your browser, and hold your local match history, if you keep one (below), without a browser storage warning. Publishing is on by default whenever you're connected; if you pause it, that's remembered only for your current browser session, not permanently.alarms— schedules periodic reconnect/heartbeat checks to RiftSight's backend without keeping the extension constantly active in the background.scripting— used only for the optional YouTube and twitch.tv viewing features: their overlay scripts are registered dynamically, and only after you turn that feature on for the site, or injected into a single tab when you click Try on this tab. Only code bundled in the extension package is ever registered or injected.activeTab(from 0.11.0) — lets RiftSight's toolbar panel see which site the current tab is on when you open it there, and run the overlay on that one tab when you click Try on this tab. It covers only the tab you clicked the RiftSight icon on, ends when you reload the page or leave the site, and gives no ongoing access to any site.host permissions— RiftSight's own backend domain (the only place the extension sends data to), RiftSight's asset CDNassets.riftsight.gg(read-only downloads of card art, the card index and, when you use card recognition, its model files),play.riftatlas.com(where the deck tracker and board sharing run), plusyoutube.comandwww.twitch.tvas optional permissions that are only requested if you enable watching streams on that site. It never requests access to sites it doesn't need.
No analytics, no third-party trackers, no advertising SDKs, no browsing history, no data from any site other
than play.riftatlas.com (and, if you enable or try the viewing feature, the public channel ID of the
YouTube live stream, or the channel name of the twitch.tv channel, you're watching — looked up, never
stored; card recognition reads the video and the page's title on your device and sends nothing), and no remotely loaded or dynamically evaluated code —
everything the extension does is contained in the code you install. The card-recognition model files it
downloads are data, not code, and each is checked against a published checksum before use.
If you're a player: deck tracker and match history (on your device)
In Rift Atlas the extension also shows a deck tracker for your own games and, if you choose, keeps a local match history. To do that it reads, inside the Rift Atlas page, the game-room updates the Rift Atlas server already sends your browser, filtered through a fixed allowlist: your own deck list and what you've drawn and played, the public board, and the match's start, end and result. Anything not on that allowlist — your opponent's hand or deck, the order of your own deck, any card face-down to you — is dropped inside the page and never reaches the rest of the extension, let alone the network. Rift Atlas itself only sends your browser what you're entitled to see, and the allowlist narrows that further.
Match history is your choice. From version 0.10.1, the extension saves no match history unless you turn on Save match history (RiftSight Settings & Help, in the Deck tracker section). While it's off, nothing about your games is recorded: the deck tracker works from the game in progress and keeps only what it needs for that game, temporarily. Version 0.10.0 and earlier saved match history automatically, so if you already had saved matches when you updated, the switch starts on; turn it off at any time.
When it's on, your match history is stored only in your own browser's local storage on that device (the
extension asks for the unlimitedStorage permission so this never triggers a storage warning).
It is never uploaded, never synced, and never seen by us. You can delete any match, or all of them, from
the match-history page; the extension also keeps only the most recent matches (200 by default, adjustable)
and removes older ones itself. Turning the switch off stops saving new games; matches already saved stay
until you delete them. Export produces a file on your device containing exactly what the page shows.
Uninstalling the extension deletes all of it.
If you're a streamer: the stream overlay (optional)
The extension can also show your deck tracker on your own stream, through an overlay page you add to OBS as a Browser Source. This is off by default, and nothing described in this section is sent unless you turn on the "OBS deck graphic" switch on the extension's Settings & Help page (the switch is named "Share deck tracker to OBS", and "Share deck tracker to stream" before version 0.10.0). While it is on (and publishing isn't paused), the extension sends RiftSight's backend a small summary of your own game:
- your own deck's card ids, how many copies of each your list has and how many are still in the deck (and, where they fit, the cards' names), plus the deck's total and remaining counts;
- your chosen champion, and, in a best-of-three, which game of the series it is (with an opaque series identifier and a revision counter and timestamp that keep the summary in order);
- the last card you played face-up;
- your legend, and your opponent's legend once it is face-up on the board.
It never sends your hand, your deck's order, anything about your opponent's hand or deck, or any card that is face-down. Be aware, though, that anyone watching your stream can work out cards in your hand: your list and how many of each card are left, together with what is on the board, show which cards you have drawn and not yet played. A stream delay makes that less useful to an opponent watching your stream. The backend forwards this summary only to your own overlay URL, keeps only the latest summary while you're live (no history), and drops it shortly after you stop. Turning the toggle off tells the backend to clear it right away. (Separately, and only if you turn it on, "Share deck with viewers" below sends a deck summary to your viewers instead; the two switches are independent.)
Your overlay URL contains a secret token that you create on the extension's Settings & Help page ("Create OBS URL"). RiftSight stores it only as a one-way hash, shows it to you once, and you can revoke it at any time ("Replace OBS URL…" makes a new one and revokes the old one; "Disable OBS URL…" revokes it). Anyone you give the URL to can see what your overlay shows, so treat it like a password. The overlay page itself uses no cookies, analytics or tracking. To label cards it also downloads the public card reference index (names, costs) from RiftSight's asset CDN, a read-only static file that needs no sign-in and carries nothing about you or your game.
If you're a streamer: sharing your deck with viewers (optional)
The extension can also let viewers who have RiftSight open your deck in a panel over your twitch.tv or YouTube stream. This is off by default, it is a separate switch from the OBS overlay above, and nothing described in this section is sent unless you turn on "Share deck with viewers" in the extension's popup (called "Deck panel for RiftSight viewers" on its Settings & Help page). While it is on (and publishing isn't paused), the extension sends RiftSight's backend a summary of your own game:
- your deck list — the card ids, and how many copies of each you play (and, where they fit, the cards' names);
- how many of each card are still in your deck, and the deck's total and remaining counts;
- your legend and your chosen champion (and, once it is face-up on the board, your opponent's legend);
- your sideboard, your battlefields and your runes;
- in a best-of-three, which game of the series it is (with an opaque series identifier and a revision counter and timestamp that keep the summary in order), and the last card you played face-up.
It never sends your hand, your deck's order, anything about your opponent's hand or deck, or any card that is face-down. Be aware, though, that a viewer can work out cards in your hand: knowing your full list and how many of each card are left, together with what is on the board, tells them which cards you have drawn and not yet played. A stream delay makes that less useful to an opponent watching your stream. Anyone with RiftSight who is watching can also copy the shared list while it is shared.
RiftSight's backend forwards the summary, over the same encrypted connection the board overlay uses, only to viewers who have the RiftSight extension and are watching your channel (the extension requests it as part of the channel lookup described above, whether or not the viewer opens the panel). It keeps only the latest summary while you're live — no history — and drops it shortly after you stop. Turning the switch off, pausing publishing, or ending your session withdraws it from viewers right away. If you revoke your RiftSight connection, viewers stop seeing it at your next connection or once your session expires, the same as your board overlay. RiftSight does not sell it or share it with anyone else.
Connecting your Twitch account (OAuth)
To use RiftSight as a streamer, you connect your Twitch account through Twitch's own OAuth authorization flow. We store:
- Your Twitch user ID and Twitch login name, so we know which channel to publish card data to.
- A one-way cryptographic hash of a connection credential we issue you (never the credential itself), so we can verify future connections came from you.
- Basic timestamps (when your account was linked, when a credential was last used or rotated).
We never store your Twitch password — that's handled entirely by Twitch's own OAuth consent screen and never passes through RiftSight. We do not sell or share this data with any third party.
Connecting your YouTube channel (Google OAuth)
To stream to YouTube viewers, you connect your YouTube channel through Google's own OAuth authorization flow. When you authorize RiftSight, we use the YouTube Data API to look up exactly one thing: the ID and title of the YouTube channel your Google account owns, so we know which channel to attach your RiftSight account to. That lookup happens once, at the moment you link. The Google access token is used for that single request and then discarded — RiftSight never stores Google access or refresh tokens, and never reads your videos, subscriptions, comments, contacts, or anything else from your Google account.
What we store after linking:
- Your public YouTube channel ID and channel title, so viewers watching that channel can find your overlay session.
- The same connection-credential hash and timestamps described in the Twitch section above.
RiftSight's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: Google user data is used only to provide the channel-linking feature described above; it is never sold, never transferred to third parties, never used for advertising, and never read by humans except with your explicit consent for support, for security purposes, or where required by law.
You can disconnect at any time from the extension (Sign out, or Clear on the YouTube card), and can revoke RiftSight's access from your Google account permissions page.
How we secure and protect your data
RiftSight is built to hold as little of your data as possible and to protect what it does hold. This applies to all data described above, and specifically to any Google user data obtained through the YouTube Data API:
-
Encrypted in transit. All communication between the extension, your browser, RiftSight's
backend, and Google's APIs travels over encrypted connections — HTTPS/TLS for API requests and a TLS
WebSocket (
wss://) for the live overlay stream. Google user data is never transmitted over an unencrypted connection. - Minimal, non-sensitive storage. The only information RiftSight retains from your Google account is your public YouTube channel ID and channel title — both already public. The Google access token is used for a single channel-ownership lookup and then discarded; RiftSight requests no refresh token and never stores Google access or refresh tokens.
- Credentials are hashed, never stored in plaintext. The connection credential RiftSight issues you is stored only as a one-way cryptographic hash, never as the credential itself. Your Google and Twitch passwords are handled entirely by their own OAuth consent screens and are never seen or stored by RiftSight.
- Restricted access. Stored data lives in a managed, access-controlled database reachable only by RiftSight's backend over an authenticated, encrypted connection. Access is limited to the small number of RiftSight maintainers who operate the service, solely to run and support it, and credential values and access tokens are kept out of our operational logs.
- No third-party sharing. Google user data is never sold, never transferred to third parties, and never used for advertising, in line with the Google API Services User Data Policy described above.
- You stay in control. You can disconnect and revoke RiftSight's access at any time, and request deletion of your stored data, as described in the sections above and below.
Operational logs
RiftSight's backend keeps short-lived operational logs (connection counts, error rates, timestamps) to keep the service running reliably. These logs never include card data, viewer identities, or full credential values.
Removing your data
If you stop using RiftSight, you can ask us to remove your linked account and all associated data by emailing riftsight.support@gmail.com.
Contact
Questions about this policy: riftsight.support@gmail.com