Privacy Policy
Effective 7 September 2026 · Version 2026-09-07
This policy explains what personal data Ocranthor LLC ("we", "us") collects through the Loreglass app, why, who we share it with, and what rights you have. We are the data controller for that data.
Questions, or to exercise any right below: privacy@ocranthor.com.
1. Summary
- We collect the minimum needed to run your account and sync your campaigns.
- We have never sold personal information and we do not share it for advertising. We do not run ads, we do not use advertising identifiers, and we do not track you across other websites or apps.
- Your prompts are sent to AI providers so they can generate what you asked for.
- Loreglass is for ages 13 and over. We ask for a month and year of birth, refuse anyone under 13, and keep nothing at all from a refused answer.
- You can download everything we hold, or delete your account outright, yourself — in the app under Settings → Privacy, without asking us. Deleting is immediate and permanent.
2. What we collect
Account data. A user identifier we generate, and the email address and display name Google gives us when you sign in.
Your content. Campaigns, characters, notes, session logs, generated images, and other material you create. This is synced so it follows your account across devices.
Prompts and generations. The text you send to AI features, and what comes back.
Age. The month and year of birth you give before first use, and the age band we derive from it. Never the day, and never a verified identity document. Used only to apply the 13+ limit and to restrict purchases to adults. If you tell us you are under 13 we store none of it — see section 10.
Usage counters. Counts of messages, images, and speech characters per month, to enforce plan limits and control costs.
Subscription status. Whether you have an active entitlement, and an identifier linking your account to your payment processor record. Payment card details never reach us — they are handled entirely by Stripe. We can see that a payment succeeded, not the card that made it.
Policy-block records. When the content filter blocks something, we record the category, the matched term, and the time — with no user identifier attached, deliberately, so the log cannot be traced back to a person. We keep this to tune the filter, not to watch anyone.
Safety records. Separately, and against your account, we count how many times content you asked for was refused, in which category, and when it last happened. Counts and dates only — never what you typed. This exists because the anonymous log above cannot tell one person trying repeatedly from many people trying once, and we need to be able to act on the first. It is what lets us suspend an account that persistently attempts prohibited material, and it is what we would produce if we were required by law to do so.
Diagnostics. Crash and error information, which may include technical device details.
Safety records. If our filters refuse something you asked an AI feature to make, we keep a count against your account of how many times that has happened and in which category. We keep the count and the time — never what you typed. It exists so a repeated pattern can be acted on rather than going unnoticed, and so we can respond if we are required to. It is deleted with your account.
We do not collect precise location, contacts, health data, or advertising identifiers.
3. Why we use it, and our lawful basis
For users in the EU and UK, the GDPR requires a lawful basis for each purpose:
| Purpose | Lawful basis |
|---|---|
| Creating and securing your account | Performance of a contract |
| Syncing and storing your content | Performance of a contract |
| Generating AI text, images, and speech at your request | Performance of a contract |
| Enforcing usage limits and billing | Performance of a contract; legitimate interests (preventing abuse) |
| Content moderation and child-safety filtering | Legal obligation; legitimate interests (protecting users) |
| Applying age-appropriate settings | Legal obligation (children's privacy law) |
| Diagnostics and improving reliability | Legitimate interests |
| Responding to your support requests | Performance of a contract; legitimate interests |
Where we rely on legitimate interests, we have considered the impact on you and you may object — see section 8.
We do not use your content to train AI models, and we do not permit our providers to use it to train theirs where their terms give us that choice. Each provider's own policy governs their processing; links are in section 5.
4. Who can see your content
Your campaigns are private to your account unless you share them.
When you share a campaign, users who join with your code receive a player-safe copy — campaign framing, revealed characters and locations, session recaps. DM-only material (secrets, hidden characters, DM notes) is held in a separate record that our servers serve only to you and to co-Game-Masters you promote.
We do not otherwise disclose your content, except as in section 5 or 6.
5. Processors and third parties
We use these providers. Each acts on our instructions as a processor, or as an independent controller where noted.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare, Inc. (US) | Hosting, database, file storage | Account data, your content, usage counters |
| Anthropic, PBC (US) | AI text generation | Prompts and conversation history you send |
| OpenAI, L.P. (US) | AI image generation; content moderation | Image prompts; images and text screened |
| Black Forest Labs GmbH (Germany) | AI image generation | Image prompts |
| ElevenLabs, Inc. (US) | Text-to-speech | The text you have read aloud |
| Google LLC (US) | Google Sign-In | Identity token (controller) |
| Stripe, Inc. (US) | Website payments and subscriptions | Email address, subscription status, and the payment details you give Stripe directly (controller for payment data) |
| Adobe Inc. (US) | PDF viewing and generation | Documents you view or export |
Provider terms and privacy policies are on their own websites. We review them, but we are not responsible for their content.
6. When we may disclose data otherwise
- To comply with a law, court order, or valid legal request.
- To report suspected child sexual abuse material to the relevant authorities. This is not optional and not subject to your consent.
- To protect the rights, safety, or property of users, the public, or us.
- To a buyer, in a merger or sale of assets, with notice to you.
7. Where your data is held, and transfers
Our infrastructure and most providers are in the United States. If you are in the EU or UK, your data will be transferred outside your country.
For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), or on an adequacy decision where one applies. You may request a copy of the relevant safeguards from privacy@ocranthor.com.
8. Your rights
These rights apply to everyone, wherever you live. We do not ask where you are before honouring them.
You may:
- access the personal data we hold about you;
- correct it if it is inaccurate;
- delete it, including the whole account;
- export it in a portable format;
- restrict or object to processing based on legitimate interests;
- withdraw consent where we rely on it, without affecting past lawful processing;
- not be subject to solely automated decisions with legal or similarly significant effects. Our content filtering is automated but affects only whether a piece of content is generated; you can contact us to have a block reviewed by a person.
Doing it yourself, now
Two of these don't need us at all. In the app, go to Settings → Privacy:
- Download my data gives you a single JSON file containing everything we hold about your account — your campaigns, characters, notes and session logs with their full contents, your plan, your usage counters, and a list of every file you have uploaded. Live sign-in credentials are the only thing left out, because they are stored as irreversible hashes and would be a security risk to hand over.
- Delete my account erases it. Not a flag or a queue: your records, your uploaded maps and PDFs, your usage history, your sign-in credentials and the account row itself are removed as you watch, and any subscription is cancelled immediately. We then re-check the account is empty and show you what was removed. It cannot be undone, and there is no export afterwards — take a copy first if you want one.
What deletion cannot reach, and why:
- Anonymous policy-block counts. These carry no user identifier by design, so they cannot be linked to you or picked out for removal.
- Stripe's payment and invoice records. Our payment processor must keep these for as long as tax and financial law requires. We cancel your subscription and unlink you from the customer record, but we cannot order Stripe to destroy an invoice.
- Encrypted backups, which roll off within 30 days and are then gone.
Asking us instead
Write to privacy@ocranthor.com for anything else, including correction, restriction, and objection. We respond within 30 days and will tell you if we need longer. We may ask you to confirm control of the account's email address before acting — not to obstruct you, but because handing someone's campaign notes to the wrong person is itself a breach.
Authorised agents. You may use an agent to make a request on your behalf. We will ask for written permission signed by you and may still ask you to confirm the request directly.
No penalty for asking. We will not deny you service, charge you a different price, or give you a worse experience because you exercised any of these rights.
If you are unhappy with our response, you may complain to your data protection authority. In the UK that is the Information Commissioner's Office (ico.org.uk); in the EU, your national authority. In California, the Attorney General or the California Privacy Protection Agency.
9. How long we keep data
| Data | Retention |
|---|---|
| Account and your content | Until you delete it or close your account |
| Backups | Up to 30 days after deletion, then removed |
| Usage counters | Rolling 13 months, for billing and limits |
| Policy-block records | Up to 24 months (contains no identifier) |
| Safety records (refusal counts) | Up to 24 months, or until you delete your account |
| Diagnostics | Up to 12 months |
| Records required by law (e.g. tax) | As long as the law requires |
Sign-in sessions expire automatically; refresh credentials are valid for 60 days and are revoked when you sign out.
10. Children
Loreglass is for ages 13 and over. Before you can use the Service we ask for your month and year of birth. If that puts you under 13 we refuse the account and go no further.
Two details matter about how that works:
- A refused answer is stored nowhere. We do not keep a record that someone told us they were 11, because keeping it would mean knowingly holding a child's personal information — the very thing this gate exists to prevent.
- The answer is recorded against the account, not in your browser. Clearing your browser data or reinstalling will not reopen the question, which is what stops a refusal from simply being retried until it is accepted.
We ask for a month and year, not a full date of birth: it is the least we can ask and still apply the limit.
If you believe a child under 13 has an account, write to privacy@ocranthor.com and we will delete the account and its data. A parent or guardian may make that request, and we will not require the child's involvement.
Users aged 13 to 17 may use the whole Service, but cannot buy a subscription — we check the date of birth on the account and refuse checkout. A parent or guardian may subscribe on their own account. We recommend that anyone under 18 uses the Service with a parent or guardian's involvement.
11. California privacy rights
This section is for California residents and explains our practices in the terms the California Consumer Privacy Act, as amended by the CPRA, uses. The rights it describes are extended to everyone, so nothing here is available only to Californians.
Notice at collection
| CCPA category | Do we collect it? | Why, and for how long |
|---|---|---|
| Identifiers (account id, email, display name) | Yes | To run your account and sync your content. Until you delete the account. |
| Customer records (§1798.80: email, subscription) | Yes | To run your account and your plan. Until you delete the account. |
| Protected classifications — age | Yes: month and year of birth | Only to apply the 13+ limit and restrict purchases to adults. Until you delete the account. |
| Commercial information (plan, usage counters) | Yes | To apply plan limits and bill correctly. Counters roll off after 13 months. |
| Internet or network activity | Limited | Crash and error diagnostics. Up to 12 months. |
| Audio, electronic, visual information | Yes, your own | Files you upload or generate — maps, tokens, portraits, PDFs, speech. Until you delete them. |
| Biometric information | No | — |
| Precise geolocation | No | — |
| Professional or education information | No | — |
| Inferences or profiles about you | No | We do not profile you. |
| Sensitive personal information | No | We do not ask for it and do not use it to infer characteristics. |
We collect all of it from you, directly, and from Google when you sign in. We do not buy personal information from data brokers or anyone else.
We do not sell or share your personal information
We have never sold personal information, and we do not share it for cross-context behavioural advertising — in the twelve months before this policy's effective date, or ever. We do not run ads. There is therefore no "Do Not Sell or Share My Personal Information" link to offer you, and a Global Privacy Control signal has nothing to act on here. If that ever changes, this policy changes first.
We do disclose personal information to service providers who work on our instructions — the ones named in section 5, under contracts that forbid them from using it for their own purposes. Under the CCPA that is a business purpose, not a sale.
We do not knowingly sell or share the personal information of anyone under 16. Loreglass is 13+ and we do not sell anyone's information at any age.
Your California rights
- Know what we collect, why, who we disclose it to, and how long we keep it — set out above and in sections 2, 5 and 9.
- Access a copy of the specific pieces of personal information we hold.
- Delete your personal information.
- Correct anything inaccurate.
- Opt out of sale or sharing — nothing to opt out of, as above.
- Limit the use of sensitive personal information — none collected, as above.
- Not be discriminated against for exercising any of these.
How to exercise them. Access and deletion are buttons, not requests: Settings → Privacy → Download my data and Delete my account. Both act immediately, and deletion tells you what it removed. For anything else, write to privacy@ocranthor.com. We verify a request by confirming control of the account, and we answer within 45 days, extendable once to 90 with notice to you.
Authorised agents may act for you with written permission signed by you; we may still confirm the request with you directly.
Under-18 users: see section 20 of the Terms of Service for the right to remove content you posted.
Shine the Light (Civil Code §1798.83): we do not disclose personal information to third parties for their own direct marketing, so there is nothing to request under that law.
12. Security
We protect data in transit with TLS. Sign-in credentials are stored in the device keychain, not in ordinary app storage. Refresh credentials are stored only as irreversible hashes on our servers, and rotate each time they are used. Access to production systems is limited to those who need it.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant authority as the law requires.
13. Changes
We will update this policy as the Service changes. If a change is material we will notify you in the app and, where the law requires, ask for your consent again. The version and effective date are at the top.
14. Contact
Ocranthor LLC Privacy and data requests: privacy@ocranthor.com General support: support@ocranthor.com