Privacy Policy
Last updated: April 17, 2026
1. Information We Collect
ForzaTunes is operated by the open-source ForzaTunes community. We keep the data we collect to the minimum we need to run the site.
When you sign in with Discord, we store:
- Your Discord user ID (numeric identifier)
- Your Discord username
- Your Discord avatar URL
When you submit a tune, we also store:
- The submitted share code, title, description, tune metadata, and in-game gamertag you enter
- The time of submission and updates
When you interact with the site (stars, reports), we store a reference to the action and the user who took it. We log your IP address temporarily for rate limiting and abuse prevention. IP addresses are not retained in a way that identifies you long-term.
2. How We Use Information
- Authenticate you by linking your Discord account to your ForzaTunes profile.
- Display your username and avatar on tunes you submit.
- Let you star tunes, report tunes, and manage your submissions.
- Prevent abuse via rate limiting, content filtering, and moderation.
We do not sell your information, run advertising, or use tracking analytics.
3. Data Storage
Data is stored in Cloudflare D1 (SQLite at the edge) and served through Cloudflare's global network. Some data may be replicated across Cloudflare edge locations to serve requests close to you. Cloudflare's processing of your data is governed by Cloudflare's own privacy and security practices.
4. Third-Party Services
ForzaTunes relies on a small number of third parties:
- Discord for OAuth authentication — subject to Discord's Privacy Policy.
- Cloudflare for hosting, DNS, CDN, and database — subject to Cloudflare's Privacy Policy.
We do not use analytics, advertising, or tracking services.
5. Cookies
We use a single session cookie (ft_session).
It is encrypted with AES-GCM, marked httpOnly,
secure, and SameSite=Lax.
It contains your user ID, username, avatar URL, and an expiration timestamp,
and is valid for seven days. We also set a short-lived cookie during OAuth
login to prevent CSRF attacks; it is deleted immediately after login completes.
We do not use tracking, analytics, or advertising cookies.
6. Data Retention and Deletion
Account data is retained as long as your account exists. To request account deletion, open an issue on our GitHub repository linked below. Upon deletion, your user record and all associated tunes, stars, and reports are removed. Removed tunes are deleted; we do not retain soft-deleted copies.
7. Children's Privacy
ForzaTunes requires Discord authentication, and Discord requires users to be at least 13 years old (or higher per local law). We do not knowingly collect information from children under 13.
8. Compliance with Microsoft Game Content Usage Rules
ForzaTunes is built in compliance with Microsoft's Game Content Usage Rules. We display community-submitted tune share codes and metadata referring to Forza games. We do not claim to represent, or be affiliated with, Microsoft or Playground Games. Manufacturer logos and other restricted assets are not used.
9. Changes to This Policy
We may update this policy as the project evolves. Material changes will be communicated on the site. Continued use after changes constitutes acceptance.
10. Contact
Questions about this policy, or requests concerning your data? Open an issue on GitHub.