Privacy policy
Draft pending final legal review before public launch. It isn't legal advice, but we've tried to make it true and readable.
RPG Enclave lets you build a shareable tabletop-RPG identity card. This page explains, factually, what we collect, why, who it's shared with, and the choices you have.
Who we are (data controller)
Grzegorz Kegel, a private individual, is the controller for the data described here. Privacy questions: contact@rpgenclave.com. No Data Protection Officer is appointed — one isn't required for a service of this size.
What we collect and why
Account
- Email address — to sign you in with a one-time link. We don't store a password.
- Discord account details (if you sign in with Discord) — the identifier, username, avatar, and email Discord shares with us, to create your account.
Your profile (public by design)
- Handle and display name, timezone, chosen theme, language, and whether you have a Player and/or GM card.
- Player/GM card content — tagline, bio, “how I play” answers, personality/GM chart, abilities, equipment, badges, stamps, experience level, languages you play in, and (GM) safety tools.
- Content boundaries / safety preferences you choose to list.
- Location (optional, e.g. a city, for in-person play).
- Characters — name, one-liner, system, class, and an optional portrait.
- Systems you play and edition.
- Availability — the days/times you list.
- Portrait and banner images you upload (profile portrait, character portraits, campaign banners). These are stored in a public image bucket because cards are public.
Campaigns & contact
- Campaign listings — name, pitch, system, format, slots, schedule, requirements, tone, language, age restriction, and whether you advertise it on the public Notice Board.
- Campaign join requests — when you ask to join a game, your message and, only if you tick the box, the email and/or Discord you choose to share with that GM. Sharing contact details is always your explicit choice.
Other
- Feedback and system requests you send us — the text and your account id, in a private inbox only we can read.
- Local drafts — while you build a card before publishing, it lives only in your own browser (local storage) and is never sent to us until you publish.
- Product analytics — see the “Analytics and cookies” section.
- Technical logs — our hosting and database providers keep basic request logs (including IP address) for security and reliability.
We don't intentionally collect special-category data (health, beliefs, sexuality, etc.). Because some fields are free text, please don't put such details in your bio unless you're comfortable making them public — if you do, you're choosing to publish them.
Legal bases (GDPR)
- Contract — running your account and showing your card.
- Consent / your instruction — publishing your profile publicly; sharing your contact details on a join request. You can withdraw by editing your profile, or by emailing us to unpublish or delete it.
- Legitimate interests — security, abuse prevention, feedback, and privacy-minimising analytics.
- Legal obligation — responding to lawful requests and mandatory abuse reporting.
Who we share it with (processors)
We don't sell your data. We use a small set of service providers, each bound by a data-processing agreement:
- Supabase — authentication, database, and image storage (EU region).
- Vercel — application hosting and delivery (US company; EU–US transfer safeguards apply).
- PostHog — product analytics on the EU cloud (eu.i.posthog.com).
- Discord — sign-in, if you use it.
- Cloudflare Turnstile — anti-bot check at login, when enabled.
- forwardemail.net — forwards mail sent to our contact@/report@ addresses.
- Tolgee — powers our interface translations.
Your published profile and advertised campaigns are public — anyone with the link can view them and search engines can index them.
International transfers
Your profile and account data are stored in the EU (Supabase, PostHog EU cloud). Some providers are US-based (Vercel, Discord, forwardemail.net); where data reaches them it's protected by the EU–US Data Privacy Framework and/or the Standard Contractual Clauses in each provider's data-processing agreement.
Analytics and cookies
We keep this deliberately light:
- We use only strictly necessary storage: a login session cookie, and — when enabled — a Cloudflare Turnstile security check. Building a card uses your browser's local storage for drafts. None of this is advertising or cross-site tracking.
- Our analytics (PostHog) runs without cookies (in-memory only) and identifies your events by a one-way hashed account id — never your email or handle. We measure aggregate usage, including anonymous click and navigation patterns and page-level heatmaps, to see which features get used. Session recording is off.
- Because we set no advertising or tracking cookies, we don't show a cookie consent banner. If that ever changes, we'll ask for your consent first. See our Cookies & tracking notice for the full list.
Retention
We keep your account and profile data while your account exists. When you delete content or your account, we remove it within 30 days, allowing for short-lived backups and caches. Logs and analytics are kept for limited periods set by our providers. Local drafts live only in your browser until you clear them.
Your rights
You can access, correct, delete, export, restrict, or object to processing of your data. You can edit your profile yourself in the editor; to delete it or close your account, email contact@rpgenclave.com and we'll respond within one month. If you're in the EU/EEA you can also complain to your data-protection authority (in Poland, the UODO); if you're elsewhere, your local regulator.
Children
RPG Enclave is for adults — you must be 18 or older to use it, and it isn't directed to children. If you believe someone under 18 has given us data, email contact@rpgenclave.com and we'll remove it.
Changes
We'll update this page as the product grows and note the date above.