Proposed effective date: July 23, 2026
This Privacy Policy explains how Vincent Azar, the operator of Cage Rivals (Cage Rivals, we, us, or our), collects, uses, discloses, retains, and protects information when you use the Cage Rivals application, website, and related services (the Service).
1. Who we are and how to contact us
Cage Rivals is operated by Vincent Azar in the United States.
For privacy questions, privacy-rights requests, safety concerns, or support, contact cagerivalsapp@gmail.com.
2. Age and geographic scope
The Service is intended for people age 13 and older in the United States. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account or provided personal information, contact us. We will investigate and delete the information when required.
3. Information we collect
Depending on the features you use, we collect the following categories of information:
- Account and authentication information. Your email address, internal account identifier, authentication provider, account creation and sign-in timestamps, your confirmation that you meet the minimum age, the versions of the Terms of Use, Community Guidelines, and Privacy Policy you accepted or acknowledged, the acceptance time, and security or session information. We do not ask for or store your birth date. If you use Google sign-in, Google and our authentication provider give us the account information and provider identifiers needed to sign you in.
- Profile information. Your display name, country, optional profile photo, profile preferences, and profile-update timestamps.
- League and gameplay information. League membership and settings, event selections, fight picks, scores, rankings, matchups, titles, trophies, statistics, gameplay modifiers, streaks, and Fantasy Credit calculations and payout snapshots.
- Content and communications. League names and descriptions, league-chat messages, direct messages, reactions, shared-news messages, blocks, feedback, support requests, player reports, and related moderation or enforcement records.
- Notification and account-message information. Notification choices, browser push subscription endpoints and encryption material, device or browser user agent, last-seen time, and delivery results. Your account email is used when you enable optional email notifications and to send required account, safety, moderation, and enforcement updates. Required emails may be sent even if optional notification emails are turned off.
- Profile-photo information. A photo you choose to upload. Cage Rivals crops and compresses the photo and sends the compressed image to OpenAI for automated safety screening before storing an accepted profile photo.
- Text safety-filter information. Before storing display names, league names and descriptions, league-chat messages, direct messages, and optional messages shared with news articles, Cage Rivals applies a rules-based filter on its servers for clearly prohibited terms and phrases. User text is not sent to OpenAI for this filtering. A rejected submission is not stored.
- AI recap information. When AI fight-night recaps are enabled, Cage Rivals prepares structured event and gameplay information. Before sending the request to OpenAI, Cage Rivals replaces the league name and player display names with temporary labels and removes internal account, member, league, event, and matchup identifiers. OpenAI receives public event and fight information plus gameplay facts such as picks, scores, rankings, matchup timelines, recent form, gameplay modifiers, and title implications. Cage Rivals restores the league and player display names after OpenAI returns the recap. Cage Rivals stores the resulting recap and only the output fields needed to display recap highlights and key moments; it does not store the full OpenAI request packet in the recap record.
- Device, network, security, and performance information. Request metadata, IP address or similar network information processed by our hosting and security providers, user agent, hashed rate-limit identifiers, requested route or URL, browser, device and operating-system category, network class, country, bot-detection signals, error information, and Web Vital performance measurements.
- Account-deletion recovery record. After account-deletion preparation, we create a private restore-suppression record containing a schema version, HMAC key version, pseudonymous HMAC digest derived from the internal account identifier, and preparation timestamp. It does not contain the email, display name, raw internal account identifier, message content, or league identifiers.
- Information stored on your device. Local preferences such as whether you dismissed an alert, the Patch Notes version you viewed, and notification-prompt timing. Your browser or device controls this local storage.
We do not currently collect payment-card or bank-account information, advertising identifiers, precise location, contacts, health data, or microphone recordings. Fantasy Credits have no purchase price or cash value and are not a financial account, payment method, wager, or prize.
4. How we collect information
We collect information:
- Directly from you when you create or update an account, upload a profile photo, join or manage a league, make picks, communicate, submit a report, or contact support.
- Automatically from your browser, device, and our servers when you use the Service.
- From authentication and service providers, including Supabase and Google when you choose Google sign-in.
- From MMA data providers and news publishers for event, fighter, result, and recent-article information. That sports and news information is not information about you unless you share or interact with it through the Service.
5. How we use information
We use information to:
- Create and secure accounts and provide profiles, leagues, picks, matchups, scoring, rankings, statistics, titles, trophies, Fantasy Credits, chat, direct messages, news, notifications, feedback, and support.
- Authenticate users, prevent duplicate or unauthorized activity, enforce rate limits, detect bots and abuse, moderate profile photos and user content, investigate reports, and enforce our Terms of Use and Community Guidelines.
- Generate and display AI fight-night recaps when that feature is enabled.
- Maintain game integrity, preserve accurate shared league history, apply official sports-result corrections, and resolve gameplay disputes.
- Monitor reliability and performance, debug errors, protect our infrastructure, and improve the Service.
- Comply with law, respond to valid legal process, protect users and the public, and establish, exercise, or defend legal claims.
6. How information is visible to other users
Your display name, country, profile photo, gameplay history, rankings, statistics, titles, trophies, and league activity may be visible to other signed-in users where the Service is designed to show them.
League chat is visible to authorized members of that league. Direct messages are intended for the conversation participants, subject to limited authorized access needed to operate and secure the Service, investigate abuse, enforce our rules, or comply with law.
When you open a news publisher's link, you leave Cage Rivals. The publisher receives the information normally sent by your browser, and the publisher's privacy policy applies to its website.
7. When we disclose information
We disclose information only as needed for the purposes described in this policy, including to:
- Supabase for authentication, database hosting, realtime features, and profile-photo storage.
- Vercel for website hosting, server functions, operational logs, anonymous performance measurement through Speed Insights, and the private account-deletion restore-suppression record described in this policy.
- Cloudflare Turnstile for bot and abuse prevention during account access.
- Google when you choose Google sign-in.
- OpenAI for profile-photo safety screening and, when enabled, AI fight-night recap generation.
- Browser push services selected by your browser or operating system to deliver notifications you enable.
- Resend. Resend delivers optional notification emails and required account, safety, moderation, and enforcement emails.
- Professional advisers, service providers, authorities, or other parties when reasonably necessary to operate the Service, comply with law, protect safety or rights, investigate fraud or abuse, or complete a properly disclosed business transaction.
We require service providers that process information for Cage Rivals to handle it only for authorized purposes and to protect it appropriately.
We do not sell personal information. We do not use personal information for cross-context behavioral advertising, and the current Service does not include third-party advertising trackers.
8. Automated safety and AI processing
Before storing display names, league names and descriptions, league-chat messages, direct messages, and optional messages shared with news articles, Cage Rivals applies a rules-based filter on its servers for clearly prohibited terms, common disguised spellings, and clear harmful phrases. User text is not sent to OpenAI or another AI provider for this filtering. A rejected submission is not stored. Rules-based filtering can make mistakes, and content that passes the filter remains subject to the Community Guidelines, user reports, and human review.
Before an optional profile photo is stored, Cage Rivals compresses it and sends it to OpenAI's moderation service to identify prohibited imagery. OpenAI returns a moderation result, and Cage Rivals stores the photo only if it passes the applicable checks. Cage Rivals does not keep a separate copy of a rejected photo.
When AI fight-night recaps are enabled, Cage Rivals replaces the league name and player display names with temporary labels and removes internal account, member, league, event, and matchup identifiers before sending the request to OpenAI. OpenAI receives public event and fight information plus the gameplay facts described above. After OpenAI returns a recap using the temporary labels, Cage Rivals restores the league and player display names. Cage Rivals stores the resulting recap and only the output fields needed to display its highlights and key moments, not the full OpenAI request packet. AI output may be inaccurate or incomplete. An AI recap does not change official picks, scores, rankings, titles, or Fantasy Credit calculations.
OpenAI states that API data is not used to train its models unless the API customer chooses to share it for that purpose. Cage Rivals recap requests set store to false, so they do not request Responses API application-state storage. Under OpenAI's default controls, the temporary-label recap request and response may still be included in abuse-monitoring logs for up to 30 days unless a different approved OpenAI data-control setting applies. OpenAI currently lists its moderation endpoint as having no abuse-monitoring or application-state retention.
9. Retention and account deletion
We retain information only as long as reasonably needed to provide and secure the Service, preserve shared game integrity, meet the specific periods below, or comply with legal obligations.
- Account and identifying profile information is kept while your account is active. When account deletion is completed, active sessions, sign-in access, email and provider identity, profile details, profile photo, notification data, and other direct account-access information are removed or de-identified.
- Your minimum-age confirmation and policy-acceptance record is kept while your account is active and deleted when authentication-provider account deletion completes.
- League-chat and direct-message text you authored is replaced with
Message deleted. Your public identity on retained conversation structure becomesFormer Player. Your reactions, league-chat read state, and account-linked blocking data are removed. Other participants' messages remain. - Ordinary feedback and support requests linked to your account are removed during account deletion. De-identified player-report, fraud-prevention, safety, enforcement, or legal records may be retained when reasonably needed to protect users, prevent repeat abuse, comply with law, or handle a dispute.
- AI fight-night event and matchup recaps associated with matchups in which you participated are removed during account deletion, including recaps generated under an earlier display name.
- Shared competitive records needed to preserve other players' standings, matchups, scores, records, titles, trophies, and Fantasy Credit history remain under
Former Player. These records retain an internal non-login historical player identifier but no active sign-in, email, profile photo, country, or public personal identity. A pending scored event may retain theFormer Playerassignment until scoring and ranking adjustments finish. - Detailed records for an archived league are scheduled for deletion one year after the league is archived. Minimal de-identified aggregate, lifetime, achievement, and shared competitive history may remain while the Service operates so historical results stay accurate.
- Direct-message conversation structure has no separate automatic expiration. Participants may delete their own message text, and account deletion redacts the deleting participant's authored text and makes the conversation read-only for the surviving participant.
- News article metadata is cached for up to 30 days. A shared-news message may retain a publisher-supplied preview as part of league-chat history until that message or the applicable league history is deleted.
- Hashed rate-limit records become eligible for deletion after two days and are removed during subsequent rate-limit processing. Hosting, authentication, security, and operational logs expire under the applicable provider and plan settings unless a specific incident or legal obligation requires a narrowly scoped longer hold.
- A minimal deletion confirmation record may remain after deletion. It contains a non-identifying request code, status, and processing timestamps, but no email or active account identifier.
- To prevent a deleted account from reappearing after a database restore, we retain the private pseudonymous account-deletion recovery record described above until every database backup or manual copy capable of restoring the pre-deletion account has expired or been destroyed, plus a documented safety margin. Required HMAC key versions are protected for the same period and are used only to match completed deletions during a controlled restore.
- Deleted information may remain temporarily in restricted provider backups until those backups expire under the applicable backup-rotation schedule. Backups are not used as active application data. If a backup is restored, we will take steps to prevent completed deletions from being returned to active use.
We may retain narrowly scoped information longer when required by law or a documented safety, fraud, security, or legal hold. Access is restricted during the hold, and the information is deleted or de-identified when the exception no longer applies.
You may delete your account from Settings > Delete Account. If you are not signed in, start from the public account-deletion page, sign in through your browser, and follow the Settings > Delete Account flow. Account deletion is permanent and does not provide a cancellation window. If the final authentication-provider step cannot finish immediately, Cage Rivals removes your profile information and league access, signs you out, and automatically retries the remaining sign-in deletion. You do not need to submit another request.
10. Your choices and privacy rights
Depending on where you live, you may have rights to request access to, correction of, or deletion of personal information and to appeal a denied request. Cage Rivals does not require a self-service download to exercise those rights.
You can:
- Update your display name, country, email, password, profile photo, and notification choices through available account settings.
- Decline to upload a profile photo.
- You can disable optional push or email notifications. Required account, safety, moderation, and enforcement emails may still be sent.
- Delete your own league-chat or direct-message text. The Service retains a deleted-message placeholder when needed to preserve conversation structure.
- Archive a direct-message conversation or block another user through available controls.
- Delete your account through the in-app or public web paths described above.
- Email cagerivalsapp@gmail.com to request access, correction, deletion, or another privacy right available under applicable law.
We may need to verify that you control the account or email associated with a request before disclosing or changing account information. We will not discriminate against you for exercising an applicable privacy right.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transport, access controls, row-level database security, environment separation, rate limits, bot protection, upload validation, content moderation, and restricted administrative credentials. No system can guarantee absolute security. Contact cagerivalsapp@gmail.com if you believe your account or information is at risk.
12. Processing locations
Cage Rivals and its providers may process information in the United States and other countries where the providers or their subprocessors operate. Those countries may have different privacy laws from where you live. We use appropriate provider agreements and safeguards where required.
13. Changes to this policy
We may update this Privacy Policy as the Service, our providers, or applicable requirements change. We will post the revised policy with a new effective date and provide additional notice or request renewed acknowledgement when appropriate. We will not use a policy update to retroactively expand an optional use that requires consent without providing the required choice.
14. Contact
For privacy questions or requests, safety concerns, or support, contact:
- Vincent Azar / Cage Rivals
- Email: cagerivalsapp@gmail.com