Privacy Policy
Effective date: July 8, 2026
This Privacy Policy explains how FIDA ("FIDA," "we," "us," or "our")
collects, uses, and protects information through the FIDA API
(api.yoyogavri.com, including its developer portal) and the
FIDA Core Discord application (together, the "Services").
FIDA operates a cross-server competitive ELO ranking system for the Forza Horizon and Forza Motorsport
racing community.
1. Information We Collect
We collect information in three broad categories, depending on how you interact with the Services:
a. Discord & racing-league data (via FIDA Core)
- Discord user ID and display name
- Server roles and mutual-server membership, used to sync team affiliations across partner FIDA-affiliated Discord servers
- Linked Xbox gamertag(s), used to verify identity and pull public gamerscore/profile data from Xbox Live
- Per-game ELO ratings, safety rank, tier, and race history/results for Forza Horizon 5, Forza Horizon 6 (when available), and Forza Motorsport
- Voluntarily-linked social handles (e.g. Twitch, Twitter/X, YouTube, Reddit), if you provide them
- Patreon supporter status, if you link a Patreon account for supporter perks
- A moderation flag and timestamp, recorded only if our anti-cheat check (see Section 2) detects a known cheat-tool signature
b. Developer portal / API account data (via api.yoyogavri.com)
- Email address and a salted hash of your password
- A hashed API key (the raw key is shown once at creation and never stored in plain text)
- Session tokens issued on login (expire automatically after 24 hours)
- Request logs: HTTP method, path, status code, and timestamp for authenticated API calls, and IP address for rate-limiting and brute-force protection
c. Discord Presence activity (real-time only, not stored)
See Section 2 below — presence/activity data is never written to our database. We only compare the activity name in real-time Discord events against a known cheat-tool signature.
2. Anti-Cheat / Presence Monitoring
To protect competitive integrity, FIDA Core listens for Discord presence-update events and checks whether the activity name reported by Discord matches the known signature of a modding/cheat tool ("Forza Mods AIO"). This check happens in real time against the event payload — we do not log, store, or retain your presence/activity data, what games you play, or your online status. Only if a match is detected do we write a moderation flag and a timestamp to your league record and alert server moderators.
Because this check is what protects fair competition for every league member, it is not user-configurable and cannot be opted out of — the same way conventional game anti-cheat systems cannot be disabled by the player they protect against.
3. How We Use Information
- Operate the FIDA ELO ranking, leaderboard, and race-history system
- Sync roles and team affiliations across FIDA-affiliated partner Discord servers
- Verify Xbox gamertags and detect known cheat tooling as described in Section 2
- Deliver Patreon supporter perks to linked accounts
- Create and manage FIDA API developer accounts, issue and rotate API keys, and enforce per-account rate limits
- Investigate abuse, enforce brute-force lockouts, and maintain security audit logs
4. Third Parties We Share Data With
We do not sell your data. We share limited data with the following third parties strictly to operate the Services:
- Microsoft / Xbox Live API — to resolve and verify linked gamertags
- Patreon API — to confirm supporter/membership status
- Google Sheets (via a service account) — used to export and sync leaderboard data; anyone with access to the relevant spreadsheet can view exported names, gamertags, and ratings
- Our database host (MongoDB) — stores the data described in Section 1
5. Data Retention
- Security/audit logs — 90 days, then automatically deleted
- Session tokens — 24 hours
- Email verification and password-reset tokens — 24 hours and 1 hour, respectively
- API keys — 365 days, renewable by rotation
- League/ELO records (Discord ID, gamertag, ratings, race history) — retained for as long as you remain part of a FIDA-affiliated server, since this data is what the ranking system is built on. You may request deletion at any time (Section 6).
6. Your Choices & Rights
- Leaderboard visibility opt-out — use the bot's
/fh5 opt out,/fh6 opt out, or/fm opt outcommands (and the matching opt-in commands) to hide your rating and rank from leaderboards and lookups. - Access, correction, or deletion — contact us (Section 8) to request a copy of your data or ask us to delete your league/API account records, subject to reasonable verification of your identity.
- Anti-cheat presence checks described in Section 2 are not subject to opt-out, as no presence data is ever stored.
7. Children's Privacy
The Services are only intended for users who meet Discord's own minimum age requirement (13, or higher where required by local law). We do not knowingly collect data from anyone below that age.
8. Security
API keys and account passwords are stored as salted/hashed values, never in plain text. All traffic to the API is served over HTTPS/TLS. We apply rate limiting, brute-force lockouts, and security headers (CSP, HSTS, TrustedHost, CORS) to protect the Services.
9. Changes to This Policy
We may update this policy as the Services change. Material changes will be reflected by updating the effective date at the top of this page.
10. Contact Us
Questions, data access requests, or deletion requests can be sent to support@yoyogavri.com.