Privacy Policy

Effective Date: December 30, 2024

1. Introduction

Grimoire ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, store, and protect your information when you use our web application and services.

2. Information We Collect

We collect the following types of information:

  • Account Information: Email address, display name, and authentication data when you create an account via OAuth (Google, Discord, or GitHub).
  • Campaign Data: All content you create within Grimoire, including NPCs, locations, factions, items, wiki pages, and other campaign materials.
  • Usage Data: Information about how you interact with our service, including features used, pages visited, and session duration.
  • Technical Data: IP address, browser type, device information, and other technical identifiers.
  • Payment Information: When you subscribe to a paid plan, payment processing is handled by Stripe. We do not store your full credit card information.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve Grimoire services
  • Process your subscription and payments
  • Send service-related communications (account updates, security alerts)
  • Respond to your support requests and inquiries
  • Analyze usage patterns to improve the product
  • Protect against fraud and abuse

We do not sell your personal data to third parties.

4. Data Storage and Security

Your data is stored on secure servers with industry-standard encryption. Campaign content is stored in PostgreSQL databases with regular backups. We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.

All data transmission is encrypted using TLS/SSL protocols.

5. AI Integration and MCP

Grimoire offers integration with AI assistants via the Model Context Protocol (MCP). When you connect an AI assistant:

  • The AI accesses only the campaign data you authorize
  • AI queries and responses are processed using your own AI subscription (e.g., Claude, ChatGPT)
  • We do not store AI conversation history on our servers
  • You maintain control over what data is shared with AI assistants

6. Data Retention

We retain your data for as long as your account is active. If you delete your account:

  • Your campaign data will be deleted within 30 days
  • Some anonymized usage data may be retained for analytics
  • Backup copies may persist for up to 90 days before automatic deletion

You can export your data at any time from your account settings.

7. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data
  • Export: Download your data in a portable format
  • Objection: Object to certain processing of your data

To exercise these rights, contact us at privacy@campaigngrimoire.com.

8. Cookies and Tracking

We use essential cookies for authentication and session management. We use minimal analytics to understand product usage. You can control cookie settings in your browser.

9. Children's Privacy

Grimoire is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly.

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes via email or in-app notification. Your continued use of Grimoire after changes constitutes acceptance of the updated policy.

11. Contact Us

For privacy-related questions or concerns, contact us at:

Email: privacy@campaigngrimoire.com