Privacy Policy

Effective 7 September 2026 · Version 2026-09-07

This policy explains what personal data Ocranthor LLC ("we", "us") collects through the Loreglass app, why, who we share it with, and what rights you have. We are the data controller for that data.

Questions, or to exercise any right below: privacy@ocranthor.com.

1. Summary

2. What we collect

Account data. A user identifier we generate, and the email address and display name Google gives us when you sign in.

Your content. Campaigns, characters, notes, session logs, generated images, and other material you create. This is synced so it follows your account across devices.

Prompts and generations. The text you send to AI features, and what comes back.

Age. The month and year of birth you give before first use, and the age band we derive from it. Never the day, and never a verified identity document. Used only to apply the 13+ limit and to restrict purchases to adults. If you tell us you are under 13 we store none of it — see section 10.

Usage counters. Counts of messages, images, and speech characters per month, to enforce plan limits and control costs.

Subscription status. Whether you have an active entitlement, and an identifier linking your account to your payment processor record. Payment card details never reach us — they are handled entirely by Stripe. We can see that a payment succeeded, not the card that made it.

Policy-block records. When the content filter blocks something, we record the category, the matched term, and the time — with no user identifier attached, deliberately, so the log cannot be traced back to a person. We keep this to tune the filter, not to watch anyone.

Safety records. Separately, and against your account, we count how many times content you asked for was refused, in which category, and when it last happened. Counts and dates only — never what you typed. This exists because the anonymous log above cannot tell one person trying repeatedly from many people trying once, and we need to be able to act on the first. It is what lets us suspend an account that persistently attempts prohibited material, and it is what we would produce if we were required by law to do so.

Diagnostics. Crash and error information, which may include technical device details.

Safety records. If our filters refuse something you asked an AI feature to make, we keep a count against your account of how many times that has happened and in which category. We keep the count and the time — never what you typed. It exists so a repeated pattern can be acted on rather than going unnoticed, and so we can respond if we are required to. It is deleted with your account.

We do not collect precise location, contacts, health data, or advertising identifiers.

3. Why we use it, and our lawful basis

For users in the EU and UK, the GDPR requires a lawful basis for each purpose:

Purpose Lawful basis
Creating and securing your account Performance of a contract
Syncing and storing your content Performance of a contract
Generating AI text, images, and speech at your request Performance of a contract
Enforcing usage limits and billing Performance of a contract; legitimate interests (preventing abuse)
Content moderation and child-safety filtering Legal obligation; legitimate interests (protecting users)
Applying age-appropriate settings Legal obligation (children's privacy law)
Diagnostics and improving reliability Legitimate interests
Responding to your support requests Performance of a contract; legitimate interests

Where we rely on legitimate interests, we have considered the impact on you and you may object — see section 8.

We do not use your content to train AI models, and we do not permit our providers to use it to train theirs where their terms give us that choice. Each provider's own policy governs their processing; links are in section 5.

4. Who can see your content

Your campaigns are private to your account unless you share them.

When you share a campaign, users who join with your code receive a player-safe copy — campaign framing, revealed characters and locations, session recaps. DM-only material (secrets, hidden characters, DM notes) is held in a separate record that our servers serve only to you and to co-Game-Masters you promote.

We do not otherwise disclose your content, except as in section 5 or 6.

5. Processors and third parties

We use these providers. Each acts on our instructions as a processor, or as an independent controller where noted.

Provider Purpose Data involved
Cloudflare, Inc. (US) Hosting, database, file storage Account data, your content, usage counters
Anthropic, PBC (US) AI text generation Prompts and conversation history you send
OpenAI, L.P. (US) AI image generation; content moderation Image prompts; images and text screened
Black Forest Labs GmbH (Germany) AI image generation Image prompts
ElevenLabs, Inc. (US) Text-to-speech The text you have read aloud
Google LLC (US) Google Sign-In Identity token (controller)
Stripe, Inc. (US) Website payments and subscriptions Email address, subscription status, and the payment details you give Stripe directly (controller for payment data)
Adobe Inc. (US) PDF viewing and generation Documents you view or export

Provider terms and privacy policies are on their own websites. We review them, but we are not responsible for their content.

6. When we may disclose data otherwise

7. Where your data is held, and transfers

Our infrastructure and most providers are in the United States. If you are in the EU or UK, your data will be transferred outside your country.

For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), or on an adequacy decision where one applies. You may request a copy of the relevant safeguards from privacy@ocranthor.com.

8. Your rights

These rights apply to everyone, wherever you live. We do not ask where you are before honouring them.

You may:

Doing it yourself, now

Two of these don't need us at all. In the app, go to Settings → Privacy:

What deletion cannot reach, and why:

Asking us instead

Write to privacy@ocranthor.com for anything else, including correction, restriction, and objection. We respond within 30 days and will tell you if we need longer. We may ask you to confirm control of the account's email address before acting — not to obstruct you, but because handing someone's campaign notes to the wrong person is itself a breach.

Authorised agents. You may use an agent to make a request on your behalf. We will ask for written permission signed by you and may still ask you to confirm the request directly.

No penalty for asking. We will not deny you service, charge you a different price, or give you a worse experience because you exercised any of these rights.

If you are unhappy with our response, you may complain to your data protection authority. In the UK that is the Information Commissioner's Office (ico.org.uk); in the EU, your national authority. In California, the Attorney General or the California Privacy Protection Agency.

9. How long we keep data

Data Retention
Account and your content Until you delete it or close your account
Backups Up to 30 days after deletion, then removed
Usage counters Rolling 13 months, for billing and limits
Policy-block records Up to 24 months (contains no identifier)
Safety records (refusal counts) Up to 24 months, or until you delete your account
Diagnostics Up to 12 months
Records required by law (e.g. tax) As long as the law requires

Sign-in sessions expire automatically; refresh credentials are valid for 60 days and are revoked when you sign out.

10. Children

Loreglass is for ages 13 and over. Before you can use the Service we ask for your month and year of birth. If that puts you under 13 we refuse the account and go no further.

Two details matter about how that works:

We ask for a month and year, not a full date of birth: it is the least we can ask and still apply the limit.

If you believe a child under 13 has an account, write to privacy@ocranthor.com and we will delete the account and its data. A parent or guardian may make that request, and we will not require the child's involvement.

Users aged 13 to 17 may use the whole Service, but cannot buy a subscription — we check the date of birth on the account and refuse checkout. A parent or guardian may subscribe on their own account. We recommend that anyone under 18 uses the Service with a parent or guardian's involvement.

11. California privacy rights

This section is for California residents and explains our practices in the terms the California Consumer Privacy Act, as amended by the CPRA, uses. The rights it describes are extended to everyone, so nothing here is available only to Californians.

Notice at collection

CCPA category Do we collect it? Why, and for how long
Identifiers (account id, email, display name) Yes To run your account and sync your content. Until you delete the account.
Customer records (§1798.80: email, subscription) Yes To run your account and your plan. Until you delete the account.
Protected classifications — age Yes: month and year of birth Only to apply the 13+ limit and restrict purchases to adults. Until you delete the account.
Commercial information (plan, usage counters) Yes To apply plan limits and bill correctly. Counters roll off after 13 months.
Internet or network activity Limited Crash and error diagnostics. Up to 12 months.
Audio, electronic, visual information Yes, your own Files you upload or generate — maps, tokens, portraits, PDFs, speech. Until you delete them.
Biometric information No
Precise geolocation No
Professional or education information No
Inferences or profiles about you No We do not profile you.
Sensitive personal information No We do not ask for it and do not use it to infer characteristics.

We collect all of it from you, directly, and from Google when you sign in. We do not buy personal information from data brokers or anyone else.

We do not sell or share your personal information

We have never sold personal information, and we do not share it for cross-context behavioural advertising — in the twelve months before this policy's effective date, or ever. We do not run ads. There is therefore no "Do Not Sell or Share My Personal Information" link to offer you, and a Global Privacy Control signal has nothing to act on here. If that ever changes, this policy changes first.

We do disclose personal information to service providers who work on our instructions — the ones named in section 5, under contracts that forbid them from using it for their own purposes. Under the CCPA that is a business purpose, not a sale.

We do not knowingly sell or share the personal information of anyone under 16. Loreglass is 13+ and we do not sell anyone's information at any age.

Your California rights

How to exercise them. Access and deletion are buttons, not requests: Settings → Privacy → Download my data and Delete my account. Both act immediately, and deletion tells you what it removed. For anything else, write to privacy@ocranthor.com. We verify a request by confirming control of the account, and we answer within 45 days, extendable once to 90 with notice to you.

Authorised agents may act for you with written permission signed by you; we may still confirm the request with you directly.

Under-18 users: see section 20 of the Terms of Service for the right to remove content you posted.

Shine the Light (Civil Code §1798.83): we do not disclose personal information to third parties for their own direct marketing, so there is nothing to request under that law.

12. Security

We protect data in transit with TLS. Sign-in credentials are stored in the device keychain, not in ordinary app storage. Refresh credentials are stored only as irreversible hashes on our servers, and rotate each time they are used. Access to production systems is limited to those who need it.

No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant authority as the law requires.

13. Changes

We will update this policy as the Service changes. If a change is material we will notify you in the app and, where the law requires, ask for your consent again. The version and effective date are at the top.

14. Contact

Ocranthor LLC Privacy and data requests: privacy@ocranthor.com General support: support@ocranthor.com