Privacy Policy
Last updated 5 August 2026.
This explains what Hearthhall collects, why, how long it is kept, and what you can make us do about it. It is written to be read rather than to be survived.
1. Who is responsible
Tom Kremser is the data controller for Hearthhall.
Čajkovského 1481/11, 746 01 Opava-Předměstí, Czech Republic
Privacy enquiries: support@hearthhall.com
2. What we collect
Because you give it to us
- Email address — to identify your account, confirm it is yours, and let you reset your password. Never shown to other members.
- Username and display name — shown to other members of your groups.
- Password — stored only as a salted hash by our authentication provider. Nobody, including us, can read it.
- Anything you write — wiki pages, posts, characters and their sheets, bios, avatar links, dice roll labels.
Because the software generates it
- Group memberships and roles — which groups you are in, and what you may do in them.
- Timestamps and authorship — who wrote what and when, including wiki revision history and the dice log. This is a deliberate feature: an editable history would make the wiki and the dice worthless.
- Moderation records — reports made or received, and actions taken by moderators.
Technical data
Our host records standard server logs — IP address, browser user-agent, requested page, timestamp — for security and to keep the service running. These are kept for a short period and are not used to build a profile of you.
What we do not collect
No analytics, no advertising, no tracking pixels, no third-party trackers. We do not sell personal data, and we do not share it for anyone else’s marketing. There is nothing to opt out of because there is nothing running.
3. Cookies
Hearthhall sets cookies for two things only: keeping you signed in, and remembering whether you chose the light or dark theme. Both are strictly necessary for a service you have asked for, which is why you are not being shown a consent banner — there is nothing here that requires consent. We set no advertising or analytics cookies.
4. Why we are allowed to hold it
| What | Why | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Account and content | To provide the service you signed up for | Performance of a contract |
| Server logs, rate limits | Security, abuse prevention, keeping it running | Legitimate interests |
| Moderation records | Enforcing the rules and handling reports | Legitimate interests |
| Confirmation and reset emails | Proving an address is yours, account recovery | Performance of a contract |
5. Your rights
If you are in the UK or EEA, you have the rights below. We will respond within one month. They are free to exercise.
- Access — a copy of what we hold about you.
- Rectification — corrections. Your display name and bio you can change yourself in settings.
- Erasure — deletion. You can delete your account yourself from account settings.
- Portability — your data in a machine-readable form. Ask us and we will produce it.
- Objection and restriction — to processing based on legitimate interests.
- Complaint — to your national data protection authority, at any time.
The honest limit on erasure
Deleting your account removes your profile, characters, and sheets, and deletes any group you solely own. Three things are not deleted, and you should know that before you sign up:
- Posts in threads stay, attributed to “deleted”. Other people wrote scenes around them, and removing yours would destroy their work too.
- Wiki pages stay, because they belong to the group and are usually written by several people. Your name is removed from the history.
- Dice rolls stay in the log. A roll is a shared record of what happened.
In each case what remains is the content, disconnected from you. If you need something specific removed — because it identifies you, or you posted it by mistake — write to support@hearthhall.com and we will deal with it individually.
6. Who else sees it
Other members of your groups see what you post there. That is the point of a group. People outside it see none of it: group content is not public, is not indexed by search engines, and is not visible to logged-out visitors.
We use these providers to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and file storage | European Union |
| Vercel | Application hosting and content delivery | European Union / United States |
| Hostinger | Sending account email: confirmations, password resets, notifications | European Union |
| Have I Been Pwned | Checking new passwords against known breaches. Only the first five characters of a hash are sent, never the password or any account detail. | United Kingdom |
Where a provider processes data outside the EEA, that transfer is covered by the European Commission’s Standard Contractual Clauses.
We will also disclose data if we are legally required to. If that happens and we are allowed to tell you, we will.
7. How long it is kept
- Account data — until you delete your account.
- Content — as described in section 5.
- Backups — deleted data persists in backups for up to 30 days, then goes.
- Server logs — a short period, typically under 30 days.
- Moderation records — kept while needed to enforce the rules, so that a suspension cannot be evaded by making a new account.
8. Security
Access is enforced in the database itself, not only in the application: every table carries row-level security policies, so a group you are not a member of returns nothing even if a bug in the interface were to ask for it. Passwords are hashed by our authentication provider. Traffic is encrypted in transit.
No system is perfectly secure. If there is a breach affecting your personal data and it is likely to put you at risk, we will tell you and the relevant authority within 72 hours of becoming aware.
9. Children
Hearthhall is not for under-16s. If we learn that an account belongs to someone younger, we will delete it. If you believe a child has an account here, write to support@hearthhall.com.
10. Changes
If we change this policy in a way that materially affects you, we will give notice in the application before it takes effect. The date at the top always shows the current version.