HT Alchemy Privacy Policy
Last updated: 20 September 2026
1. About this policy
HT Alchemy is an independent CHPP application for Hattrick. It is not operated by Hattrick Ltd.
This policy explains how HT Alchemy handles information when you connect your Hattrick account and use its youth, senior, Transfer Market, Club Chronicle, Games, match-order, reminder, analytics, feedback, and related functions.
HT Alchemy is designed around the following privacy principles:
- Most persistent sporting and team-management data remains in the browser on the user’s device.
- The Friendlies with Benefits tournament uses a separate, narrowly scoped server-side tournament database because registrations, pairings, fixtures, results, rule enforcement, standings, and tournament administration must remain consistent across participating managers.
- The Games tournament database is not a general server-side copy of a manager’s Hattrick account and is not used to retain private sporting or team-management payloads such as non-public player attributes, training settings, unpublished match orders, transfer bids, or private team settings.
- Limited tournament operational metadata may be stored centrally where it is necessary to operate the competition, including compact challenge/booking state and encrypted administrator-configured background read authorisation.
- HT Alchemy does not perform account-changing Hattrick actions automatically.
- Every Hattrick write operation requires both an appropriate CHPP permission and a deliberate user action.
- Optional analytics and feedback processing occur only after the user chooses to enable or submit them.
- Information about other Hattrick teams is obtained only from data that Hattrick makes publicly available and exposes through its authorised interfaces.
- HT Alchemy does not bypass Hattrick security, access private accounts, exploit vulnerabilities, impersonate users, or use any other unauthorised method to obtain information.
These principles reflect the transparency, purpose limitation, data minimisation, security, retention, and user-control principles described in Hattrick’s privacy policy.
2. Local-first storage and the Games tournament database
Most HT Alchemy tools are local-first. They do not use a central database as a persistent copy of the user’s Hattrick team, player, training, transfer, match-order, optimisation, simulation, or Club Chronicle data.
When those tools request information from Hattrick, the request passes through an HT Alchemy server route because CHPP access credentials must be protected from browser JavaScript. The server uses the authorised CHPP session to request the selected information from Hattrick and returns the result to the user’s browser. For ordinary local-first tools, the response is processed transiently by the server and is not written as a persistent central copy of the user’s private sporting or team-management data.
Persistent local-first data is stored mainly in the user’s browser through:
- localStorage; and
- IndexedDB.
2.1 What is meant by private Hattrick team-management data
In this policy, private Hattrick team-management data means sporting or team-management content that is not publicly visible to other Hattrick users. This is different from the legal concept of personal data, which may also include identifiers or publicly visible information.
HT Alchemy does not use a central database to retain private sporting or team-management payloads such as:
- non-public player attributes or skills;
- TSI, wages, form, stamina, loyalty, or other non-public player-development information;
- private training settings or training plans;
- unpublished match orders;
- private tactical setup or private lineup preparation;
- transfer bids or other private transfer activity;
- private team settings;
- a private player-roster snapshot; or
- a full private Hattrick team payload.
HT Alchemy may process such information transiently or store it locally in the user’s browser where a selected feature requires it, but it is not persisted as a general server-side team database.
2.2 Friendlies with Benefits tournament database
The Friendlies with Benefits tournament is different from the ordinary local-first tools because it is a shared competition involving multiple managers. HT Alchemy therefore uses a dedicated server-side Games database to maintain the tournament state that participating managers must share consistently.
Depending on the stage of the tournament and the actions taken, the Games database may store:
- manager invitation bindings and access entitlements;
- Hattrick manager and team identifiers, manager login names, and team names;
- team gender and relevant league or country identifiers;
- registration, withdrawal, re-entry, and skip state;
- round scheduling, eligibility, cup status, and power-rating snapshots;
- pairings, fixture assignments, and replacement or bye state;
- fixture and match identifiers and confirmed booking information;
- compact challenge-management state required for the tournament workflow;
- fixture readiness, verification state, timestamps, and reason codes;
- publicly visible match results and tournament scoring facts;
- extra-time and penalty-shoot-out facts;
- public match information used to check tournament rules;
- points, strikes, sanctions, ejections, and suspension state;
- assignment-breach responsibility and repair evidence;
- bounded processing, reconciliation, and deferred-resolution diagnostics;
- minimal retained discipline-boundary information needed to preserve the rolling tournament rules;
- the original registration date and an accumulated lifetime counted-round total that survives detailed-history cleanup; and
- administrator correction and audit records relating to tournament data.
- administrator-imposed participant bans scoped to a tournament team, including the administrator manager ID, reason, round-based duration, and unban or expiry history; the reason is shown with the withdrawn status in the public participant table.
This database exists to operate, verify, score, enforce, explain, and audit the Friendlies with Benefits tournament. It is not used as a general database of participating managers’ private Hattrick team data.
2.3 Application database content
The application database may store administrator-authored announcement titles and messages, publication environment, schedule, priority, lifecycle and revision metadata, and the administrator manager user ID used for creation or updates. This content is used to deliver app-wide announcements; ordinary recipients’ read state is not stored in the application database.
HT Alchemy also provides temporary, round-scoped Friendlies with Benefits participant chat in the application database. It may store a participant’s Hattrick manager/user ID, manager login name, chat scope and round identifier, message timestamp, the filtered/redacted chat message, and limited moderation and anti-spam metadata such as a keyed one-way duplicate-detection fingerprint and whether redaction occurred. Original uncensored text is not stored. Messages are normally cleared after the round closes and authoritative result processing completes; an App administrator may also permanently purge all messages for a selected FWB tournament instance. For the closed-chat unread indicator, the server checks unread stored message text for a mention of the authenticated manager and returns only derived unread/mention metadata. Chat is not private sporting or team-management data, is not automatically supplied to Lore, and is not sent to an external AI moderation service. The browser stores chat display preferences and read/unread position locally in IndexedDB; message bodies are not cached there.
2.4 Public match and lineup-derived tournament evidence
Some tournament rules are checked using Hattrick match information that is publicly visible after the match. This can include match type, score, tactics, match events, player positions or behaviours, substitutions, and related match facts exposed by Hattrick.
For example, the Friendlies with Benefits tournament can use lineup information to determine whether non-goalkeeper players complied with the tournament’s required defensive or wing orientations during the first 90 minutes. HT Alchemy may retain limited rule-compliance or violation evidence derived from that publicly visible match information where it is necessary to explain and enforce a strike or sanction.
HT Alchemy does not retain a complete raw CHPP lineup response or use the Games database as a persistent player-roster database.
2.4 Limited non-public tournament operational metadata
The Games database may also retain limited non-public operational metadata that is necessary to perform a tournament workflow. For example, it may retain the direction and status of a pending friendly challenge, a TrainingMatchID, friendly type, match identifier, opponent team identifier, verification state, or related compact challenge/booking information.
This is narrowly scoped tournament operational state. It is not a general copy of the manager’s private team-management information and is not used to retain unrelated private player, training, match-order, transfer, or tactical data.
2.5 Information not stored in the Games database
The Games database does not store:
- the user’s Hattrick password;
- raw invitation codes;
- a full archive of CHPP XML responses;
- ordinary users’ CHPP credentials;
- private player skills, TSI, wages, form, stamina, loyalty, or training data;
- unpublished match orders;
- private transfer bids or private transfer-management data;
- a complete private player roster; or
- a general copy of the user’s private Hattrick account data.
A separately configured tournament background read authorisation may be stored for scheduled tournament processing. Its credential handling is described in section 4.
2.6 Other local-first data
Club Chronicle and Reminder data are stored locally in IndexedDB. Club Chronicle records may contain cached panel data, comparison baselines, detected updates, update history, and update timestamps. Reminder records may contain preferences, snooze and dismissal state, suppression and episode bookkeeping, dismissed-reminder history, and reminder freshness or cache data. This browser-local Reminder data is not sent to a server.
HT Alchemy does not automatically synchronise locally stored team data between devices.
HT Alchemy does not intentionally send locally stored player, team, match, lineup, transfer, training, or Club Chronicle data to:
- analytics providers;
- advertising providers;
- data brokers;
- GitHub;
- YouTube; or
- general-purpose artificial-intelligence services.
4. Protection of CHPP credentials
The ordinary CHPP access token and access-token secret are stored together in an encrypted and authenticated HttpOnly cookie.
The cookie contains encrypted session data. It does not contain the encryption key.
The encryption key:
- is held in server-side environment configuration;
- is not stored in localStorage;
- is not stored in IndexedDB;
- is not placed inside the CHPP session cookie;
- is not sent to the browser;
- is not available to browser JavaScript; and
- is not available through the user’s local HT Alchemy data.
The server obtains the encryption key from the server-only CHPP_COOKIE_SECRET environment variable and uses AES-256-GCM to encrypt and authenticate the CHPP session.
An administrator may explicitly store a separate Friendlies with Benefits tournament background read authorisation for scheduled tournament processing. Its token and secret are encrypted with AES-256-GCM using GAMES_CHPP_ENCRYPTION_SECRET, bound to a stable Games-processing purpose independent of invitation access mode, and never returned to browsers. Legacy authorisations remain readable using their stored legacy mode context. This background authorisation is used for tournament processing and is not a database copy of participating managers’ ordinary CHPP credentials.
Disconnecting tournament processing removes the stored background read authorisation without deleting retained tournament sporting records.
Because the ordinary CHPP session cookie is HttpOnly, ordinary browser JavaScript cannot read the encrypted CHPP token or secret. In production, the cookie is also marked Secure and uses SameSite=Lax.
The ordinary CHPP session expires no later than 16 weeks after it is created.
Temporary OAuth request cookies are cleared after the authorisation process completes or fails.
Rotating or removing the relevant server-side encryption key invalidates credentials encrypted with that key because the server can no longer decrypt them.
5. Disconnecting HT Alchemy
You can disconnect HT Alchemy from Hattrick.
When you disconnect your ordinary CHPP session:
- HT Alchemy attempts to invalidate the CHPP token at Hattrick;
- the encrypted CHPP session cookie is cleared;
- temporary OAuth cookies are cleared; and
- the browser can no longer use the previous HT Alchemy CHPP session.
The local session is cleared even if Hattrick’s token-invalidation endpoint cannot be reached.
Disconnecting CHPP does not necessarily delete locally cached team data. Local browser data can be removed separately through HT Alchemy’s Storage Management functions or through the browser’s site-data controls.
Disconnecting an ordinary user session does not itself erase central Friendlies with Benefits tournament records that are retained under the tournament rules. The separate administrator-configured tournament background read authorisation, if present, is controlled independently through the tournament processing connection.
6. No automatic Hattrick actions
HT Alchemy does not independently or autonomously:
- submit a lineup;
- submit match orders;
- change a tactic;
- change a team attitude;
- add a substitution;
- set man marking;
- place a transfer bid;
- change training;
- buy or sell a player;
- send a Hattrick message;
- create, accept, decline, or withdraw a friendly challenge; or
- make another change to your Hattrick account.
Every operation that changes data in Hattrick requires:
- the relevant CHPP write permission granted by the user; and
- a deliberate action by the user in HT Alchemy.
Granting a CHPP permission by itself does not cause HT Alchemy to perform an action.
Friendlies with Benefits tournament challenge, accept, decline, and withdraw operations are manager-initiated actions. They are not performed by the scheduled tournament worker.
A recommendation, predicted rating, simulation, optimiser result, reminder, warning, or suggested lineup does not automatically cause a Hattrick write operation.
HT Alchemy may perform read-only requests or local calculations as part of a feature that the user has deliberately opened, enabled, or requested. For example, it may:
- refresh information requested by the user;
- retrieve information required by an opened tool;
- calculate a recommended lineup;
- calculate Team Spirit;
- calculate predicted ratings;
- analyse an opponent;
- update a locally displayed result; or
- determine whether a locally configured reminder is due.
The Friendlies with Benefits tournament also uses scheduled background processing to make read-only Hattrick requests needed to maintain rounds, verify bookings and results, evaluate publicly visible match evidence, apply tournament rules, and update shared tournament state. Scheduled tournament processing does not autonomously perform Hattrick write operations.
These read-only and local operations do not modify the user’s Hattrick account.
HT Alchemy does not use automated decision-making that produces legal or similarly significant effects concerning a person.
7. Hattrick information processed
The exact information processed depends on the functions the user chooses to use.
HT Alchemy may process:
- Hattrick manager user ID and login name;
- Supporter status;
- granted CHPP permissions;
- team and academy IDs and names;
- leagues, cups, fixtures, and competition information;
- senior and youth player information;
- skills, ratings, form, stamina, experience, loyalty, age, wages, TSI, injuries, and specialties;
- match history, events, results, formations, tactics, and sector ratings;
- lineups, substitutions, behaviours, attitudes, set-piece takers, and man-marking selections;
- training and staff information;
- transfers, listings, bids, transfer searches, and market-price information;
- arena, fan club, coach, press, login, and Club Chronicle information;
- opponents and other Hattrick teams deliberately selected for analysis;
- Friendlies with Benefits tournament registrations, pairings, challenges, bookings, results, rule-compliance facts, points, strikes, sanctions, and related tournament state;
- reminders and relevant dates;
- locally entered simulations and overrides; and
- calculated, inferred, estimated, recommended, or predicted values.
This information is processed only to provide the relevant Hattrick-related or tournament function.
Some information processed for the user’s own team may be private within Hattrick. Processing does not mean that the information is centrally retained. Private sporting or team-management payloads used by ordinary HT Alchemy tools remain local or transient as described in section 2 and are not persisted as a general server-side team database.
8. Information concerning other Hattrick teams and users
Some HT Alchemy functions can analyse or infer information relating to teams, managers, or players belonging to other Hattrick users. Examples include:
- opponent analysis;
- Transfer Market searches;
- Club Chronicle watchlists;
- league analysis;
- fixture analysis;
- transfer comparisons;
- likely training assessments;
- formation or tactic assessments;
- player-position assessments;
- Friendlies with Benefits tournament verification; and
- other game-related estimates derived from available match and team information.
8.1 Only publicly available Hattrick information is used for other teams
Analysis, inference, and sporting verification concerning another Hattrick user’s team are based exclusively on information that Hattrick itself makes publicly available about the relevant team, manager, player, match, transfer, or competition and exposes through Hattrick or its authorised CHPP interfaces.
HT Alchemy does not obtain access to another user’s private Hattrick account.
HT Alchemy does not use another user’s password, CHPP token, session cookie, private messages, unpublished match orders, private team settings, or other information that Hattrick has not made publicly available.
Where HT Alchemy infers information, it does so by calculating or estimating from publicly available Hattrick game data. For example, it may compare publicly visible matches, player appearances, formations, ratings, transfers, or other historical game information.
An inference produced by HT Alchemy is not hidden information obtained from Hattrick. It is an estimate produced by applying calculations or rules to publicly available information.
8.2 No hacking, circumvention, or unauthorised access
HT Alchemy does not use and is not designed to use:
- hacking;
- exploitation of security vulnerabilities;
- password guessing;
- credential theft;
- token theft;
- account impersonation;
- session hijacking;
- access-control bypasses;
- scraping of restricted or private areas;
- interception of another user’s communications;
- unauthorised API access;
- manipulation of Hattrick systems;
- automated probing of private endpoints;
- reverse engineering intended to defeat access restrictions; or
- any other underhanded or unauthorised method
to obtain information concerning another Hattrick user.
HT Alchemy relies on Hattrick to determine which information is publicly available and which information CHPP products are authorised to access.
If Hattrick does not expose information as public or available through an authorised interface, HT Alchemy does not attempt to circumvent that restriction.
8.3 Purpose limitation
Public Hattrick information concerning other users is processed only to provide the game-related feature or shared tournament function for which it is required.
HT Alchemy does not use this information to:
- identify a manager outside Hattrick;
- discover a person’s real-world identity;
- create a commercial profile of a natural person;
- build an advertising audience;
- combine it with external personal data;
- contact the other manager outside Hattrick;
- monitor private activities;
- maintain a general cross-user profiling database unrelated to the Friendlies with Benefits tournament; or
- train a general-purpose artificial-intelligence model.
8.4 Storage of information concerning other teams
For ordinary analysis tools, where an analysis of another Hattrick team is retained, the resulting public data, cache, estimate, or inference is stored locally in the requesting user’s browser and is not added to a general central HT Alchemy profiling database.
The Friendlies with Benefits tournament is a limited exception because tournament participants must share a consistent competition state. The Games database may therefore store participating team and manager identifiers, pairings, fixture state, public match facts, public rule-compliance evidence, standings-related records, and other tournament information described in section 2.
This tournament storage is limited to operating and auditing the competition. It is not used to build a general database of another manager’s private Hattrick team information.
8.5 Accuracy of inferences
Calculated or inferred information may be incomplete, outdated, or incorrect.
HT Alchemy does not represent an inference as confirmed private knowledge about another user. Users should treat inferred values as game-related estimates based on the publicly available Hattrick information that existed at the time of analysis.
9. Information stored locally in the browser
HT Alchemy may store the following information locally:
- application settings;
- selected language;
- selected currency;
- layout and display preferences;
- analytics-consent choice;
- selected teams and academies;
- cached player and team data;
- cached Hattrick responses;
- match and lineup state;
- manually entered or simulated values;
- lineup exclusions;
- optimisation settings;
- saved Transfer Market searches and profiles;
- transfer-search results and market summaries;
- Club Chronicle tabs and watchlists;
- Club Chronicle caches, baselines, detected updates, and update history;
- analyses and estimates relating to publicly available information about other Hattrick teams;
- Team Spirit settings and calculations;
- reminders, snooze state, and dismissal state;
- announcement read revisions and a bounded administrator announcement-editor working draft;
- freshness timestamps;
- user-modification timestamps;
- locally generated estimates and recommendations; and
- other information required to restore the application state.
This local browser data remains in the browser profile and on the device where it was stored.
It is not automatically transferred to another device or shared with another HT Alchemy user.
Announcement read state remains local to the browser and is not uploaded as a read receipt.
The dedicated Friendlies with Benefits tournament database described in section 2 is separate from this ordinary browser-local persistence. Tournament records are created and updated only as required by Games participation and tournament processing; HT Alchemy does not automatically upload the user’s unrelated browser-local team data into that database.
HT Alchemy may also use encrypted HttpOnly essential or functional cookies to retain browser-specific application access or state. These cookies are not used for advertising, are not sold, are not included in settings exports, and do not store inferred player values.
10. User-initiated export and import
HT Alchemy may offer functions for exporting, importing, or transferring local application data.
These functions operate only when initiated by the user.
A user may deliberately:
- export local settings;
- import previously exported settings;
- transfer Club Chronicle watchlists;
- create or scan a transfer QR code; or
- restore application data from a local backup.
HT Alchemy does not automatically export or transmit this information.
Exported files or QR codes may contain locally stored application information. The user is responsible for:
- storing exports securely;
- not sharing QR codes with unauthorised persons;
- deleting old backups when no longer required; and
- understanding that imported data may replace existing local data.
11. Access to locally stored data
Browser storage is not an encrypted personal vault.
A person who has access to the user’s:
- device;
- operating-system account;
- browser profile;
- browser developer tools; or
- exported backup files
may be able to inspect locally stored HT Alchemy information.
The ordinary CHPP session credentials receive additional protection because they are stored inside an encrypted HttpOnly cookie and the encryption key is available only to the server.
Team-related data stored in localStorage or IndexedDB is not protected by that CHPP-cookie encryption key.
Users should avoid using HT Alchemy on a shared or untrusted browser profile unless they accept that another user of that profile may be able to access the locally stored information.
12. Deleting local information
Users can remove locally stored HT Alchemy information by:
- using HT Alchemy’s Storage Management functions;
- resetting relevant application settings;
- deleting saved searches or profiles;
- deleting Club Chronicle tabs or watchlists;
- dismissing or deleting reminders where supported;
- clearing cookies;
- clearing localStorage;
- clearing IndexedDB; or
- clearing all site data through the browser.
Deleting browser data may remove:
- the ordinary CHPP session;
- cached team and player information;
- application settings;
- saved searches;
- reminders;
- watchlists;
- simulations;
- historical comparison data;
- estimates concerning other publicly visible Hattrick teams; and
- other locally persisted state.
Clearing browser-local data does not by itself delete Friendlies with Benefits tournament records held in the dedicated Games database. Those records are governed by the tournament lifecycle and retention rules described in section 18.
After local deletion, the user may need to reconnect to Hattrick and configure the application again.
13. Technical request information
When a user accesses HT Alchemy, the hosting infrastructure necessarily processes limited technical information required to deliver and secure the service.
This may include:
- IP address;
- request date and time;
- requested URL or server route;
- HTTP method;
- response status;
- browser user agent;
- referral information;
- hosting request identifier;
- deployment identifier;
- security information; and
- error or diagnostic information.
This technical processing is separate from browser-local team data and from the dedicated Games tournament records described in section 2.
HT Alchemy is designed not to include CHPP tokens, CHPP secrets, or server-side encryption keys in ordinary production logs.
OAuth error logging may include limited technical details such as:
- request host;
- request route;
- response status;
- error code;
- OAuth processing phase; and
- hosting request identifier.
Production logging deliberately limits detailed error output.
14. Analytics
HT Alchemy includes Google Analytics and Vercel Web Analytics.
Neither analytics system is loaded unless the user explicitly grants analytics consent.
If the user refuses consent:
- Google Analytics is not loaded;
- Vercel Web Analytics is not loaded; and
- the core application remains available.
The application checks the locally stored consent status before rendering either analytics component.
The consent choice is stored locally in the browser.
The user can later change the analytics choice in Settings.
Analytics is intended to provide general information about application usage and performance.
HT Alchemy does not intentionally use analytics to:
- identify individual Hattrick managers;
- collect Hattrick player or team payloads;
- collect lineups or match orders;
- collect transfer searches;
- collect Club Chronicle content;
- collect analyses of other Hattrick teams;
- collect Friendlies with Benefits tournament records;
- build advertising profiles;
- personalise advertising;
- sell user information; or
- combine analytics information with locally stored team data.
15. Feedback submissions
HT Alchemy does not automatically submit crash reports, bug reports, or feature requests.
Feedback is sent only when the user:
- opens the feedback form;
- enters information; and
- presses the submission button.
A submitted report may include:
- the text entered by the user;
- application version;
- selected language;
- submission time;
- browser user agent;
- Hattrick manager user ID;
- Hattrick login name; and
- diagnostic metadata containing localStorage key names and approximate sizes.
The diagnostic storage metadata reports key names and estimated sizes. It does not send the contents of the corresponding localStorage values.
The resulting GitHub issue may include the user’s Hattrick login name, user ID, and a Hattrick contact link.
Feedback is optional.
Users should not include:
- CHPP credentials;
- passwords;
- private messages;
- real-world contact details;
- financial information;
- medical information; or
- other sensitive personal information
in a feedback submission.
16. YouTube content
HT Alchemy contains optional YouTube links and embedded instructional videos.
A video is loaded only when the user chooses to open it.
HT Alchemy uses the youtube-nocookie.com privacy-enhanced embed domain.
Opening or playing a video creates a connection to Google or YouTube. They may receive ordinary technical request information such as:
- IP address;
- browser information;
- device information; and
- the requested video.
HT Alchemy does not automatically open or play YouTube videos merely because the user visits the application.
Locally stored Hattrick team data and Games tournament records are not intentionally included in YouTube requests.
17. When information is shared
HT Alchemy does not sell personal data.
HT Alchemy does not rent personal data.
HT Alchemy does not provide locally stored Hattrick data or Games tournament data to data brokers.
HT Alchemy does not use Hattrick data for personalised advertising.
HT Alchemy does not use Hattrick data to train general-purpose artificial-intelligence models.
Information is transmitted only where required for a function selected or authorised by the user, for operation of the Friendlies with Benefits tournament, or for the technical delivery and security of the service.
Hattrick
Hattrick receives:
- CHPP authorisation requests;
- CHPP read requests;
- user-initiated CHPP write requests; and
- token-invalidation requests.
The Friendlies with Benefits tournament scheduled worker makes read-only CHPP requests needed for tournament operation. Challenge-management writes are performed only after the relevant manager deliberately initiates the action and has granted the required permission.
Information about other Hattrick teams is obtained only from information that Hattrick itself makes public or exposes through an authorised interface. HT Alchemy does not transmit or use unauthorised requests to obtain private information about other users.
Vercel
Vercel provides hosting and application delivery. It may process ordinary technical request and hosting information.
Vercel Web Analytics receives analytics information only after analytics consent.
Games database hosting
The dedicated Games database is hosted through the application’s configured database infrastructure. The database provider necessarily stores and processes the tournament records described in sections 2 and 18 for the purpose of operating the Friendlies with Benefits tournament. HT Alchemy does not intentionally place unrelated browser-local team data or private sporting/team-management payloads into that database.
Google Analytics receives analytics information only after analytics consent.
Google or YouTube receives information when the user chooses to open YouTube content.
GitHub
GitHub receives information only when the user deliberately submits a bug report or feature request.
Authorities and security providers
Information may be disclosed where required by applicable law, a valid court order, a competent authority, or where reasonably necessary to investigate and respond to a serious security incident.
18. Retention
CHPP session
The encrypted ordinary CHPP session cookie expires no later than 16 weeks after issue.
It may be cleared earlier if:
- the user disconnects;
- the CHPP token is invalidated;
- the browser cookies are cleared;
- the session is rejected as invalid; or
- the server-side encryption key is rotated.
Temporary OAuth information
Temporary OAuth request cookies are cleared after the connection process completes or fails.
Browser-local team and application data
Persistent browser-local team-related and application data remains in the browser until:
- the user deletes it;
- the application replaces it;
- the application expires it;
- the user imports replacement data;
- the browser removes it; or
- the user clears the site’s storage.
This includes locally retained public information and estimates relating to other Hattrick teams.
HT Alchemy does not retain a permanent server-side database copy of this ordinary browser-stored team data.
Friendlies with Benefits tournament data
Games invitation bindings and manager trial entitlements are retained as access-control records beyond the sporting-history window. They are not automatically removed by team changes, withdrawal, or tournament sanctions.
The Games database retains the tournament information required to maintain registrations, sporting-entry lifecycle, current weekly classifications, confirmed bookings and their observed kickoff/finish lifecycle timestamps and compact final-score summaries, assignment-breach and rescue history, verified results, public lineup-derived rule evidence, point ledger entries, strikes, compact sanctions, and team-level suspension identity needed for the rolling 16-counted-round standings and three-global-round bans.
Expired participation, detailed strike evidence, discipline checks, point entries, sanctions, and fully retired sporting entries are removed in bounded batches using each sporting entry’s counted-round window. Before a retired sporting entry is removed, its final counted-round sequence is transferred atomically into the team registration’s lifetime aggregate. Durable sequence cursors, lifetime counted-round totals, confirmed bookings, assignment-breach history, ejections, suspension facts, and other minimal retained boundary state may remain where necessary so cleanup cannot reset tournament clocks, erase established responsibility, or reactivate consumed strikes.
Alongside bounded operational records, HT Alchemy may permanently retain a compact FWB standings visualization archive containing round identity and date windows, team identity and name, historical rank, rolling points, round point-component summaries, and counted-round state. This archive does not retain raw CHPP XML, match IDs, scores, lineups, match events, private player or team-management payloads, or detailed strike evidence for this purpose. Worker attempt metadata is bounded separately. Shared fixture evidence remains only while the tournament retention logic requires it.
The tournament database is not used to retain private sporting or team-management payloads such as non-public player skills, TSI, wages, training settings, unpublished match orders, private transfer bids, private tactical preparation, or complete private team datasets.
Challenge and acceptance writes require the manager’s explicit fixture action and the relevant optional CHPP permission. Scheduled tournament processing is read-only in Hattrick.
Tournament background read authorisation
If the administrator configures the Friendlies with Benefits tournament background read connection, the encrypted credential remains stored until tournament processing is disconnected or the credential otherwise becomes unusable. Removing that authorisation does not itself delete retained sporting records.
Feedback
Submitted GitHub issues may remain available for:
- investigating defects;
- assessing feature requests;
- avoiding duplicate reports;
- maintaining development history; and
- documenting completed work.
Analytics
Analytics data is retained according to the configured analytics settings and the applicable provider’s retention rules.
Future analytics processing stops when consent is withdrawn.
Technical logs
Technical hosting, security, and error logs are retained only for the period provided by the hosting infrastructure or for as long as reasonably necessary to investigate a specific operational or security incident.
19. Security
HT Alchemy uses security measures intended to reduce unauthorised access, including:
- HTTPS;
- encrypted and authenticated CHPP-session storage;
- AES-256-GCM encryption for the ordinary CHPP session;
- AES-256-GCM encryption for the separately configured Games background read authorisation;
- server-side encryption keys that are not provided to the browser;
- HttpOnly ordinary CHPP session cookies;
- Secure cookies in production;
SameSite=Laxcookie restrictions;- same-origin validation for sensitive actions;
- user-selected CHPP permissions;
- separation between browser-side team-data storage and server-side credential handling;
- clearing of temporary OAuth cookies;
- limits on feedback-field lengths;
- use of Hattrick-authorised interfaces; and
- separation of ordinary local-first tool data from the narrowly scoped Games tournament database.
No internet service, cookie mechanism, browser-storage system, database system, or encryption system can guarantee absolute security.
Although encryption keys are not locally available and ordinary CHPP credentials cannot be directly read by browser JavaScript, a stolen valid encrypted session cookie could potentially be replayed until it expires or the upstream CHPP token is invalidated.
Users are responsible for:
- securing their device;
- securing their browser profile;
- protecting exported data;
- protecting transfer QR codes;
- reviewing write operations before confirming them;
- reviewing feedback before submitting it; and
- disconnecting HT Alchemy when it is no longer used.
20. User control
Users retain direct control over most persistent information because ordinary HT Alchemy team data is stored locally in their browser.
Users can:
- decline analytics consent;
- withdraw analytics consent;
- decline optional CHPP permissions;
- avoid all Hattrick write functions;
- review a proposed operation before submitting it;
- disconnect CHPP;
- invalidate the CHPP token;
- delete local application data;
- clear cookies;
- clear localStorage;
- clear IndexedDB;
- delete exported data;
- avoid opening YouTube content;
- avoid submitting feedback; and
- stop using HT Alchemy.
Clearing browser storage does not itself delete records already retained in the Friendlies with Benefits tournament database. Tournament records are managed according to the tournament lifecycle and retention rules described in section 18.
Where applicable law provides additional rights, those rights may include:
- access;
- correction;
- erasure;
- restriction;
- objection;
- data portability; and
- withdrawal of consent.
Most ordinary team-related data can be removed directly by deleting browser data because HT Alchemy does not maintain a persistent central copy of that local-first data. The Games tournament records described in this policy are the limited exception required to operate a shared competition.
Privacy-related matters must not be submitted through a public feedback issue where they would expose additional personal information.
21. Children
HT Alchemy does not request a date of birth and does not attempt to determine the user’s age.
The application is not intended for children under 13.
A person who cannot legally consent to the relevant online processing should use HT Alchemy only with appropriate authorisation from a parent or legal guardian and in accordance with Hattrick’s rules.
22. Changes to this policy
This policy may be updated when:
- application functions change;
- data-processing practices change;
- service providers change;
- security practices change; or
- legal requirements change.
The current version will remain available through:
Help > Privacy
Where a change affects optional consent-based processing, the user will be asked for any new consent required before that processing begins.
The “last updated” date identifies the current version.