This policy explains what data the Service collects, why, and your choices. By using the Service you consent to the practices described.
1. Data we collect
- Account data: your name, email address, and a hashed password (we never store passwords in plaintext).
- Gameplay content: your campaigns, chat messages, character cards, and generated images — stored so you can resume play.
- Usage counters: per-day counts of AI text, image, and speech generations, used to enforce fair-use limits.
- Technical data: IP address and request metadata used for rate limiting, abuse prevention, and error diagnostics.
2. How we use it
- To operate the Service and save your progress.
- To enforce usage limits, prevent abuse, and keep the Service secure.
- To diagnose and fix errors.
3. Third-party processors
To provide core features we send necessary data to third parties:
- AI providers (e.g. LLM, image, and speech services) receive the prompt/content needed to generate a response.
- Image object storage (Cloudflare R2, when enabled by the operator) stores the images the Service generates so they can be served back to you. When storage is not enabled, images are kept on our own server instead.
- Bot protection (Cloudflare Turnstile) receives your IP address and interaction signals to verify sign-up, sign-in, and password-reset requests are not automated.
- Email delivery (Resend, when email is configured) receives your email address to send verification and password-reset messages.
- Error monitoring (Sentry) receives diagnostic error reports. We aim to avoid sending message content in these reports.
These processors handle data under their own terms. We do not sell your personal data.
4. Cookies
We use only essential cookies required to keep you signed in. Our bot- protection provider (Cloudflare Turnstile) may set a security cookie to verify requests. We do not use advertising or non-essential tracking cookies.
5. Retention
We retain account and gameplay data while your account is active. Generated images may be preserved in your gallery even after a campaign is reset or deleted. Because generated images are stored under a key derived from their content, image files may persist in storage after the related records are removed; you can request their deletion (see Contact). You can also request deletion of your account and associated data.
6. Your choices
You may request access to, correction of, or deletion of your personal data by contacting us. Deleting your account removes your sessions, campaigns, and gallery records; on request we will also remove the underlying stored image files.
7. Contact
Privacy requests: contact@savior.sbs.