Skip to content
Nightfall.Report

Legal

Privacy Policy

What Nightfall.Report keeps, why it keeps it and what you can ask for. We collect what we need to run fair leaderboards and keep the site safe, and nothing for advertising. We never sell your data.

Effective 29 September 202610 sections · about 6 min read

At a glance

  • We never sell your data

  • No ad trackers, no third-party analytics

  • Game stats come from the public Bungie API

  • Security checks protect the boards from cheats and ban evasion

  • Ask us any time to see or delete what we hold

01

Public game data. Bungie Names, membership ids, characters, emblems, Guardian Rank, play time, activity history and post-game reports, read from the public Bungie API. Leaderboards, Guardian pages, run reports and fair-play checks are made from this.

When you sign in. Your Bungie Name, membership ids and profile picture, and a session so you stay signed in. We never receive your Bungie password.

Security signals. When you sign in, and while you use the site signed in, we record the device id cookie, a browser fingerprint (a one-way hash of headers your browser sends, not something we can turn back into your details), your IP address, and your browser and operating system. Every sign-in is logged. These are used to protect accounts, enforce bans and stop banned players coming back on new accounts.

When you choose to share more. A linked Discord account, YouTube and Twitch links, a custom profile URL, builds, testimonials, clan, staff and verification applications, player reports and their evidence, and appeals.

Sherpa requests. The Bungie Name you ask for (yours or a friend's), your Discord username, the Nightfall, and anything you add: class, when you can play, your time zone, how far you have got and a note. To check eligibility we look up that player's clears, attempts and play time.

When you visit. Which page is open, browser and device type, and whether you are signed in, for the live visitor view and daily visit counts. Visit counts are stored as totals, not per person.

02

Section 2

How we use it

  • To build leaderboards, Guardian pages, run reports and creator pages
  • To sign you in and show your dashboard and notifications
  • To keep boards fair: checking impossible times, account sharing, boosting and ban evasion
  • To keep the site secure, including blocking VPNs, proxies and Tor where that is switched on
  • To handle what you send us, such as sherpa requests, reports, applications and appeals
  • To show the team who is online on the Team page

We do not use your data for advertising or profiling for marketing, and we do not sell or rent it to anyone.

Leaderboard integrity. For top runs we read the public post-game reports (who was in the fireteam, kills, weapons, deaths, whether they joined from the start) and each player's public account figures: play time, Guardian Rank, triumph score, weapon counts and when the account was made. These decide whether a time is believable. Runs can be struck and accounts reviewed; staff decide, and anything can be lifted.

Account-sharing checks. We compare sign-ins over time (device, browser, network and country) and changes in how an account plays, to spot shared, sold or boosted accounts. Signals are scored automatically and reviewed by the team.

VPN and threat shield. To check whether a connection comes from a VPN, proxy, Tor or data centre, the IP address is sent to proxycheck.io, which answers with the provider, country and a risk score. We keep that answer for up to a day per address.

Maintenance keys. During an emergency lockdown, anyone using a maintenance key has every attempt recorded with their device id, browser fingerprint, IP address, browser and Bungie Name if signed in. A key is bound to the device it is first used on; a shared key is revoked and the devices and account involved are banned.

Private activity history. If you hide your activity history in your Bungie settings, the site notes that it is private and when that changed. We do not try to get around it. Staff can still see data the site already held, such as leaderboard runs you appeared in.

We only use cookies the site needs to work:

  • nfc_session: keeps you signed in. Your Bungie sign-in tokens are encrypted inside it and can only be read by our server
  • nfc_oauth_state and nfc_discord_state: protect the Bungie and Discord sign-in steps
  • nf_return and nfc_discord_next: send you back to where you were after signing in
  • nfc_device: a random device id used to protect accounts and enforce device bans
  • nfc_invite: remembers a closed-beta invite
  • nf_vpn_notice: shows the VPN notice once after signing in, then is removed

Some choices are kept only in your own browser (local storage), never sent to us: your appearance settings, a collapsed sidebar, a dismissed banner, when the support prompt last showed, and your recent Guardian searches on mobile. Clearing your browser data removes them.

No advertising or cross-site tracking cookies. When you open a creator page, an embedded Twitch player and YouTube thumbnails load from Twitch and YouTube, who may set their own cookies under their own policies.

05

Section 5

Bans

The team can hide profiles and ban accounts, devices, browsers or networks. A ban stores what it applies to (a Bungie Name, device id, browser fingerprint or IP address), the reason, who made it and when it ends. If a banned player returns on a new account, address or browser, those can be banned too. Ban records are used only to enforce the ban and handle appeals, and every ban and unban is logged for the team.

  • Bungie: sign-in and game data requests go through the Bungie API
  • proxycheck.io: receives IP addresses for the VPN and threat check
  • Discord: only when you choose to link it
  • YouTube and Twitch: we read a creator's public video feed; embedded players load from Twitch
  • Ko-fi: handles donations; we receive the supporter name and amount Ko-fi sends us
  • Our hosting provider: stores the site and its database

Public game data is shown publicly on the site, the same as on Bungie's own API. Team members' online status and roles are public on the Team page. Private submissions, security signals and ban details are only visible to the team, and some (such as the owner's own details and staff identities) only to the owner.

  • Leaderboard and run data: as long as it is part of a board
  • Sign-in and security logs: 90 days
  • VPN check answers: up to a day per address
  • Device, browser and network records: as long as needed to protect accounts and enforce bans
  • Ban records: while the ban is in force, and a short history afterwards for appeals
  • Sherpa requests, reports and applications: while they are useful, then removed or anonymised
  • Visit counts: as totals only
  • Audit records of staff actions: capped, and older entries roll over
08

Section 8

Your rights

You can ask us to:

  • Show you what we hold about you
  • Correct something that is wrong
  • Delete your submissions, linked accounts or sherpa requests
  • Hide your Guardian page

Some records, such as an active ban or security records tied to one, may be kept as long as they are needed to keep the site fair and safe. We process security and fair-play data because we have a legitimate interest in running honest leaderboards and protecting accounts. If you are in the EU or UK, you can also complain to your data protection authority.

09

Section 9

Security

Sign-in tokens are encrypted and never shown to other players or staff. Browser fingerprints are stored as one-way hashes. The admin panel is limited to the team, access is split by permission, and every staff action is logged. No system is perfect, but we treat your data like our own.

For any privacy request, contact the Nightfall.Report team through the Discord linked in the footer. We update this policy as the site changes; the date at the top always shows the current version.

Nightfall.Report is a fan project, not affiliated with or endorsed by Bungie, Inc. Destiny and all associated marks are trademarks of Bungie, Inc.