← Back to Home

Privacy Policy

Last updated: March 23, 2026

1. Information We Collect

Account information: Email address and optional display name, collected during registration.

Shipping address: Name, street address, city, state, zip code, and country, provided voluntarily for merchandise orders.

Campaign content: Session notes, audio recordings, character descriptions, world lore, and other content you provide to the Service. Audio recordings are processed solely for transcription and are not retained after transcription is complete.

Recording consent: If you use our audio recording feature, you are responsible for obtaining consent from all participants before recording, as required by applicable laws in your jurisdiction.

Generated content: AI-generated images, journal entries, scene descriptions, and merchandise mockups created through the Service.

Usage data: API usage metrics, generation costs, and feature usage for billing and service improvement.

2. How We Use Your Information

  • Authenticate your account and provide access to the Service
  • Generate AI art and process campaign content as requested
  • Process and fulfill merchandise orders
  • Send transactional emails (magic link login, order confirmations)
  • Track usage for cost management and rate limiting

3. Third-Party Services

We share specific data with these third-party services as necessary to provide the Service:

  • Google (Gemini): Campaign context, character descriptions, and scene prompts — for AI image generation
  • OpenAI (GPT): Session text, entity descriptions, and review content — for AI text processing and art direction
  • AssemblyAI: Audio recordings — for transcription
  • Stripe: Email, shipping address — for payment processing
  • Production Partners: Shipping address, product art — for merchandise production and fulfillment
  • Cloudflare R2: Generated images and uploaded files — for storage and CDN delivery

4. Data Storage & Security

Account and campaign data is stored in a PostgreSQL database hosted on Neon. Files and images are stored on Cloudflare R2. All data is transmitted over HTTPS. Authentication uses JWT tokens stored in httpOnly cookies with 7-day expiration.

5. Cookies

We use a single authentication cookie (rpgsage-auth) containing a JWT token. This is essential for the Service to function and cannot be opted out of. We do not use tracking cookies, analytics scripts, or advertising cookies.

6. Data Retention

Your account data, campaign content, and generated images are retained for as long as your account is active. You may request deletion of your account and associated data at any time by contacting us. Merchandise order records are retained for legal and accounting purposes.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your campaign content and generated images

To exercise any of these rights, contact us at the email below.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes via email or in-app notification.

9. Contact

Questions about privacy? Contact us at support@rpgsage.ai.