Privacy Notice
Version 2026-09-12 ยท Applies to MythosLoom
A first draft, written by the project rather than by a lawyer, and not legally reviewed. It describes what the software actually does today, which is the part worth getting right first.
What we hold
Everything below is listed because the software holds it. If something is not on this list, we are not keeping it.
| What | Why |
|---|---|
| Email address | Signing in, confirming the account, and resetting a forgotten password |
| Display name | What other players see instead of your email address |
| Password hash | Signing in. We never hold your password itself, only a hash of it |
| Authentication factors | Passkeys or two-factor secrets, if you set them up |
| Sign-in timestamps and failed attempt counts | Locking an account after repeated failures, so nobody can guess at your password indefinitely |
| Terms acceptance | Which version of the terms you accepted, and when |
| Roles | Whether the account is an administrator or a beta tester. Ordinary accounts hold neither |
| Your content | The characters, campaigns and notes you create |
What we deliberately do not hold
- Your age or date of birth. The terms state a minimum age of 13 and accepting them is the declaration. We do not ask, and there is no field for it.
- Your real name, unless you choose to use it as your display name.
- Your postal address.
- Payment card details. Paid features arrive in a later phase and will use a payment provider; card numbers will not reach us.
Who else sees it
- An email delivery provider sends your confirmation and password-reset messages, and therefore handles your email address and the contents of those messages. (Which provider is a deployment setting and has not been chosen yet. It must be named here before the service is offered publicly โ this notice is not finished until it is.)
- The hosting provider runs the servers and therefore holds the database and the logs.
- Other players, for content you deliberately share โ the other people in a campaign you join see your characters in that campaign. They never see your email address.
We do not sell your data, and we do not use it to train models.
Logs
Application logs record what happened during a request, including the identifier of the signed-in account. They do not contain passwords, password-reset links, or email addresses that did not match an account.
Administrative actions against accounts are recorded in an audit log โ who did what, to which account, and when. That record exists because it is evidence about how the service's operators behave, not only about users, and it is not editable from the console.
Retention is not yet decided. Until it is, logs and audit entries are kept. This notice will state a period before the service is offered publicly.
Your account, in your hands
- See everything we hold: your profile has a download that gives you your personal data as a JSON file.
- Delete it: your profile can close your account. It is disabled immediately and permanently removed 30 days later, so a decision made in anger or by accident can still be undone โ contact us before the date and we can put it back. After that date it cannot be recovered. The confirmation screen states the date before you commit to it.
- Correct it: your display name can be changed at any time from your profile.
Cookies
The only cookies are the ones that keep you signed in and protect forms against cross-site request forgery. There is no analytics, advertising or tracking cookie.
Changes
If this notice changes materially, we will tell the address on your account.
Getting in touch
Questions about your data, or a request to have it removed: use the contact address published on the site.