Privacy Policy
Last updated: July 25, 2026
Grimscribe (“we”, “us”) runs a solo, browser-based role-playing game with an AI Dungeon Master. This policy explains, in plain language, what we collect, why, who else touches it, and how you get rid of it. It covers grimscribe.win and the game served from it.
What we collect
- Account data. When you sign in with Google we receive your email address, display name and avatar URL. We do not receive your Google password, and we never ask for one.
- Game content. Everything your campaigns are made of: characters you create, the premises you write, your messages to the Dungeon Master and its replies, dice results, map and inventory state, and images generated during play.
- Usage counters. Per-day counts of DM turns and images so we can enforce plan limits, plus lifetime campaign counts.
- Technical statistics. Per-request token counts, model name and latency, used to measure cost and keep the service viable. These are attached to your account id, not to the text of your story.
- Billing data. Your subscription status and credit balance. Payment details (card numbers, billing address, tax data) are collected and stored by Stripe - we never see or store them.
We do not buy data about you, we do not sell or rent your data, and we do not use your campaigns to train models.
Why we can use it (legal bases)
- Performing our contract with you - running the game, saving your campaigns, enforcing plan limits, taking payment.
- Legitimate interests - keeping the service secure, preventing abuse, and measuring aggregate cost so the pricing stays honest.
- Legal obligations - tax and accounting records held by our payment provider.
Who processes your data
- An OpenAI-compatible AI provider. To generate a DM turn or an image we send the relevant campaign context - your messages, character sheet, recent story and image prompts - to a third-party model provider. Do not put information in your prompts that you would not want sent to such a provider.
- Convex hosts our database and backend functions, and therefore stores your account and campaign data.
- Cloudflare serves the website and provides network-level protection.
- Stripe is our merchant of record: it handles checkout, payment methods, taxes, invoices and refunds. Grimscribe is operated under our studio brand Frappua, so Stripe processes your payment in that name and your card statement shows LINK.COM* FRAPPUA (Link, a Stripe service, is the merchant of record).
- Google is the identity provider used for sign-in.
These providers operate internationally, so your data may be processed outside your country, including in the United States, under the providers’ own transfer safeguards.
Cookies and tracking
We set session cookies for one purpose: keeping you signed in. There are no advertising cookies, no third-party ad trackers, and no cross-site profiling. Any usage measurement we add will be cookie-less and aggregate.
How long we keep it
Campaign content and account data are kept until you delete them. Usage counters and technical statistics are retained while the account exists so limits and costs can be computed. Payment and tax records are kept by Stripe for as long as the law requires.
Deleting your data
Deletion is real, immediate and self-service - you do not have to email anyone. In the game’s Settings you can:
- Delete a single campaign - the world, hero, story, map and its generated images are removed.
- Delete your entire account - this cascades: every campaign, hero, message, image and usage row tied to you is deleted, along with the sign-in record.
Deletion cannot be undone, and we cannot restore a deleted campaign. Backups and provider logs may retain fragments for a short period before rotating out. If you have an active subscription, cancel it in the Stripe portal before deleting the account.
Your rights
Depending on where you live (for example under the GDPR or the CCPA) you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. Access and deletion are built into the app; for anything else, write to us and we will respond within the period the law allows. You may also complain to your local data protection authority.
Security
- All server-side keys (AI provider, Stripe, database) live only in backend environment configuration. They are never shipped to the browser and never stored in the repository.
- The site is served over HTTPS with HSTS,
frame-ancestors ’none’to block clickjacking,X-Content-Type-Options: nosniff, and a strict referrer policy. - Every backend function derives your identity server-side from your session; a client cannot ask for another player’s campaign.
No service is perfectly secure. If you find a vulnerability, please report it to us rather than exploiting it.
Children
Grimscribe is not intended for anyone under 16. We do not knowingly collect data from children; if we learn that we have, we delete the account.
Changes
If this policy changes materially we will update the date at the top and, for significant changes, notify signed-in players in the app.
Contact
Privacy questions, rights requests or security reports: support@grimscribe.win.