Privacy Policy
Last updated 17 September 2026.
LLM RPG is operated by Tiraisoft, Jl. Rahayu Sungai Paring, Martapura, Indonesia. This policy explains what we collect, why, who we share it with, and how to get rid of it. Questions: privacy@tiraisoft.com.
What we collect
- Your email address. That is the whole account. We use one-time sign-in codes, so we never ask for, receive, or store a password. It is also where the quiet-account emails described under Emails we send go.
- Books you upload. The
.txtor.epubfile itself, stored so it can be processed and re-processed. - Lore we derive from them. The extracted atlas of characters, factions, locations, items and events, plus numeric embeddings of that text used for search.
- Your gameplay. Your character details, everything you type as a player, the game master's narration, and the run's accumulated memory.
- Support conversations. Messages you send the chat widget and an automatic classification of them (for example "bug", with a priority) so we can route them. You can use the chat before signing in, in which case it is tied to a random id kept in your browser rather than to you. We store the IP address the conversation came from — only for the chat, only to stop abuse of a widget that needs no account, and never for counting visitors. A message you send goes to the AI model provider that answers it, and a conversation the classifier reads as a bug report or a feature request is emailed to our own feedback inbox.
- Billing records. Your plan, your credit ledger, and a record of payments. We never see or store your card number — payment details are entered on the payment provider's own pages and stay with them.
- Ordinary server logs kept by our hosting provider, including IP address, for security and debugging.
- Crash reports. When something breaks — in your browser or on our servers — we record the error message and where in the code it happened, so we can fix it. It is stripped of anything that looks like personal data (email addresses, ids, quoted text, file paths) before it is stored, it is not tied to your account, and one report covers every occurrence of the same fault rather than one per person. It goes to our own database, not to a third-party crash service.
The part worth reading twice
To extract a book's lore and to narrate your turns, the text of your uploaded book and the text of your gameplay are sent to a third-party AI model provider on our behalf. The same is true of what you type into the support chat, and of the last scene of a run when a quiet-account email is written (see Emails we send). If a book is confidential, or you are not comfortable with it leaving our systems for processing, do not upload it.
Why we process it
To run the product you asked for — extraction, narration, memory and search; to take payment and meter credits; to answer your support messages; to keep the service secure and working; and to meet our tax and accounting obligations. We do not sell your data, we do not share it with advertisers, and we do not use your books or your gameplay to train our own models.
Who else touches it
- Cloudflare — hosting, databases, file storage, search indexes and email delivery. Effectively all data lives here.
- A third-party AI model provider — lore extraction, game-master narration, support chat and the short preview passage in a quiet-account email. The text of your book and of your gameplay is sent to that provider to produce your result. The category is the disclosure: Article 13(1)(e) GDPR asks for the recipients or categories of recipients, and the provider is not named here.
- PayPal, and Stripe where card payment is offered, for taking payment. They are the ones handling your card details, under their own privacy policies.
Cookies and tracking
We use no cookies to identify you and no advertising pixels. We do not build a profile of you across visits, and we do not sell or share your data. Your sign-in session and the chat widget's visitor id are kept in your browser's local storage, which you can clear at any time by signing out or clearing site data.
We do measure how the product is used, so we can see which parts of it work. That
measurement is first-party — it goes to our own servers and nowhere else — and it is scoped
to a single visit: a random id is kept in your browser's sessionStorage and is
discarded when you close the tab. We record which steps were taken and how long they took
(for example, that a world was built and how long the build ran), the page path, and the
host a visit arrived from — say google.com — never the full link or
anything you typed into a search box. We never record what you write in the game.
We also record three broad facts about the visit itself: the kind of device
(phone, tablet, desktop, or an automated crawler), the operating system and its
major version only — iOS 17, never iOS 17.4.1 — and the
country and region the connection came from, which Cloudflare works out at its
edge so that we never see or keep the address itself. We do not keep the browser's
User-Agent string: it is read once to work out the device and the system, and then
discarded, because the full string is detailed enough to single somebody out.
Each of those three is counted on its own. We keep a daily total per device kind, and a separate daily total per country, and we never keep a row that combines them — so the numbers cannot be narrowed to "the one person on a tablet in Iceland". The cost of that, to us, is that we cannot ask which system a particular country's visitors run. We think that is the right way round.
We also measure how long each page was open and visible, so we can see which pages are actually read. The clock stops whenever you switch away from the tab, so a page left open in the background does not count as time spent reading.
We do not store your IP address for analytics. To count how many distinct people visited on a given day we keep a one-way hash of it combined with that date and a secret; it cannot be reversed, and it cannot be matched to any other day. Individual event records are deleted after 30 days — only anonymous daily totals are kept after that.
For analytics, if you have an account, we keep two dates against it: the first day it was active and the most recent one. Nothing else from analytics — not a page, not an event, not a count. It is there so we can tell how many of a day's players had been here before, which is a question the anonymous daily totals cannot answer once the individual records are deleted. Those two dates are the only analytics record kept about a signed-in person past the 30 days; the quiet-account emails keep their own small record, described under Emails we send. Both are deleted with the account, along with everything else the delete-my-account button removes.
If you submit a playthrough video
Submitting a video is entirely optional and nothing happens unless you paste a link. When you do, we keep the link you pasted, the video's id, its length, and the outcome of the review, against your account. We keep no copy of the video itself.
To review it we read what YouTube already publishes about that video — its title, channel and description — and we send the link to a third-party large-language-model provider, which watches the video and reports what is on screen. Only a public video can be reviewed at all, so nothing private is sent anywhere: the provider fetches exactly what any viewer could. We do not send your email address or anything else about your account.
The claim phrase shown on your account page is worked out from your account id and a secret. It is not stored, and it cannot be turned back into anything about you — but it is a string you choose to publish in your own video description, so treat it as public once you have put it there.
All of it is deleted with your account, by the same button as everything else.
If you set a run on a real street
Choosing a real place is optional, and a run without one involves none of this. When you do choose one, we keep against that run the name of the place you picked, its coordinates, and the id of the street photograph it is standing on. That is a place you searched for, not a place you were found at: nothing here reads your device's location, and we have no way to.
Your search text is sent from our server to OpenStreetMap's public place search, so your browser never contacts it and your IP address never reaches it. We cache the answers, which are facts about the map rather than about you.
The street photograph itself is loaded by your own browser, directly from Google, in the same way any embedded map is. That visit is between you and Google under their terms, and it happens only on a run you set in a real place. Our server separately fetches a few still frames of that corner and has them described in text, so the game master can rule on what is actually there; the description is stored under the photograph's id, shared by everyone who stands on that corner, and says nothing about who asked for it.
The place on a run is deleted with the run, and with your account, like everything else. The description of the corner is not yours and is not deleted — it is a note about a public street, tied to no account.
One copy of a book, not one per person
Two people can upload the same novel, and everyone who picks the same ready-made world starts from identical text. We store such a file once, under a fingerprint computed from its contents, and we extract its lore once. If the book you upload is identical — byte for byte — to one that has already been extracted, your campaign is given its own copy of that lore instead of being charged to extract the same book again, and it is ready in seconds.
What this does not share is anything about you. Only the lore of the book itself is copied: never your runs, your character, your turns, or anything you wrote. Nobody can read a book you uploaded. We never serve an uploaded file back to anyone, and a stored file can only be matched by someone who already has the identical file in their hands.
Because the copy is shared, it outlives any one of us deleting our own: the stored file goes when the last person who has it deletes their campaign or their account, and the shared lore goes with it. Everything that ties you to that book is erased immediately either way.
Emails we send
Apart from the one-time sign-in code, we send one kind of email: a note when your account has gone quiet. The first goes out three days after your last sign-in or turn, the second a week after the first, and then one a month for as long as the account stays quiet. Signing in or playing a turn starts the count over. A no-account trial has no email address and gets none.
Each note quotes the last scene of your most recent run, or describes a world you could start, and adds a short passage written for the email alone by the same game-master model that narrates your turns: what might happen if you wrote one particular action next. That passage is never added to your run and costs you no credits.
Every one of these emails carries a link that stops them. It works without signing in, it takes effect at once, and mail programs that support one-click unsubscribing are given the same link in the message headers. A checkbox under "Emails" on your account page does the same while signed in, and is the way to turn them back on; turning them back on starts the count over. To run this we keep, against your account, which of these emails has gone out and when, whether you have turned them off, and the random token that identifies your stop link; all of it is deleted with the account.
Keeping and deleting
- Deleting a campaign really deletes it. The lore extracted from it, the search embeddings, and every run underneath it are purged — and the uploaded file with them, unless somebody else uploaded a file identical to yours down to the byte. We keep one copy of a book rather than one per person, so that copy is equally theirs; it stays for them, and nothing of yours — no record that you uploaded it, no lore, no run — stays with it. See One copy of a book.
- Deleting a run purges that run's memory.
- Deleting your whole account is a button on your account page. It erases the account, your campaigns, their lore and embeddings, every run and its memory, your uploaded books (on the same terms as above), and the support conversations you had while signed in. It happens immediately and cannot be undone. If you have a paid subscription we stop it at the payment provider first — and if we cannot reach them, nothing is deleted and we tell you to try again, rather than leaving you being billed for an account you can no longer sign in to.
- Support conversations have no automatic expiry. The ones you had while signed in are erased with your account, above. One you had before signing in is tied to the random id in your browser and to nothing we can trace back to you, and it stays until we remove it by hand.
- Billing records outlive the rest: we keep what we need to for accounting and tax law, even after an account closes.
- Otherwise we keep your content while your account is open, because it is the product — your campaigns are meant to still be there next month.
Your rights
Depending on where you live, you may have the right to access, correct, export, or erase your personal data, or to object to some processing. Two of those you can exercise yourself, right now, without asking us: Download your data and Delete your account are both on your account page. The export is a JSON file containing your account details, your campaigns, their extracted lore and every turn you have played. For anything else — including correcting something that is wrong — email privacy@tiraisoft.com. Sending from your account's address is the quickest way for a request to be matched to an account, but it is not a requirement: correction is the right you need precisely when the address on the account is the thing that is wrong. GDPR Article 12(2) places the duty to facilitate that on the controller rather than on you. From another address, name the account the request is about. Your rights of access, correction, deletion, portability and objection come from the law — GDPR Articles 15–22 — which also requires that exercising them costs you nothing (Article 12(5)). This page does not grant those rights and cannot take them away.
Children
LLM RPG is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has an account, tell us; such accounts are removed.
International transfers
Our providers operate globally, so your data may be processed outside your country, including in the United States and the European Union.
Security
Data is encrypted in transit, sign-in is passwordless, and your campaigns and runs are scoped to your account. No system is perfectly secure. Article 34 GDPR requires that you be told of a breach likely to result in a high risk to your rights, and that duty comes from the regulation rather than from this page.
Changes
Material changes are reflected here with a new date at the top. The emails described above are about your own account, never about changes to this page: this page is the record, and it is the version in force.
Contact
Privacy: privacy@tiraisoft.com · Anything else:
support@tiraisoft.com
Tiraisoft, Jl. Rahayu Sungai Paring, Martapura, Indonesia