Privacy Policy
Last updated 6 September 2026.
This explains what Hearthhall collects, why, how long it is kept, and what you can make us do about it. It is written to be read rather than to be survived.
1. Who is responsible
Tom Kremser is the data controller for Hearthhall.
Čajkovského 1481/11, 746 01 Opava-Předměstí, Czech Republic
Privacy enquiries: support@hearthhall.com
2. What we collect
Because you give it to us
- Email address: to identify your account, confirm it is yours, and let you reset your password. Never shown to other members, and not shown to a site administrator either — they can search by an address to find which account it belongs to, which is how a message sent to us gets matched to an account, but no page displays one. See section 6.
- Username, display name, avatar and bio: shown to other members of your groups, and on your profile page — which has a fixed address and can be opened by anyone who has it, with or without an account. Search engines are asked to leave that page alone, which keeps it out of results rather than out of sight. Treat a bio as public writing, because it is.
- Password: stored only as a salted hash by our authentication provider. Nobody, including us, can read it.
- Anything you write: wiki pages, posts, characters and their sheets, bios, dice roll labels.
- Anything you upload: an avatar, a character portrait, a map, a handout, a picture set into a page or a post. Section 5 says where each kind lives and who can reach it, and section 7 says how long it is kept.
Because the software generates it
- Group memberships and roles: which groups you are in, and what you may do in them.
- Timestamps and authorship: who wrote what and when, including wiki revision history and the dice log. This is a deliberate feature: an editable history would make the wiki and the dice worthless.
- Moderation records: reports made or received, and actions taken by moderators.
Technical data
Our host records standard server logs (IP address, browser user-agent, requested page, timestamp) for security and to keep the service running. These are kept for a short period and are not used to build a profile of you.
Audience measurement
We count page views, using Vercel Web Analytics. It records which page was requested, from roughly where, and on what kind of device. It sets no cookie and stores nothing on your device; a visitor is worked out from the address and user-agent, hashed with a key that changes every day. That is deliberately just enough to tell a busy page from a quiet one and deliberately not enough to follow the same person from one day to the next, and there is no way for us to turn it back into you.
If you subscribe
Premium is paid through Stripe, and we never see or hold your card details. The payment form is Stripe’s, on Stripe’s own page, which is precisely why it is not built into this site. What we store is a Stripe customer reference, a subscription reference, whether it is currently active, and the date the paid period ends — enough to know who has Premium, and nothing else.
Stripe is the merchant of record for Premium, which means it is the seller rather than merely our payment processor, and it decides for itself what it needs in order to sell to you and charge the right tax: your name, email address, card details and billing country. It holds those as a controller in its own right, under its own privacy policy, and it is named in section 6 with the others. One asymmetry is worth stating plainly rather than leaving to be discovered — closing your account cancels your subscription and deletes what we hold about it, but it does not erase the invoices Stripe is required by tax law to keep. Those are receipts for money that changed hands, and they outlive the account. Section 7 says for how long.
What we do not collect
No advertising, no tracking pixels, no third-party marketing tags, and nothing that follows you to any other site. We do not sell personal data, and we do not share it for anyone else’s marketing.
One honest exception, which is somebody else’s doing rather than ours. An avatar or a character portrait can be a link to a picture somewhere else instead of a file uploaded here, and where it is, your browser fetches that picture from whoever hosts it — so that host sees the request, as it would if you had opened their page. We do not choose those addresses, we do not send anything with the request, and we cannot vouch for the other end. The alternative is fetching every such picture through our own servers, which would hide you from that host by handing us a record of every image every member looks at, and that is the worse trade.
3. Cookies and browser storage
Hearthhall sets one cookie that matters: the one that keeps you signed in. There are no advertising cookies and no third-party cookies of any kind. The page-view counting described above sets none either — that is the specific reason we were willing to have it.
Three other things are kept by your browser rather than sent to us. Which theme you chose. Whether you last exported a character sheet with its scores swapped. And anything you have started writing and not posted, so that closing the tab does not throw twenty minutes of it away — that last one is the only one worth explaining at length. It never reaches our servers, so it is not in anyone’s campaign, not in a moderator’s queue, and not in a backup. It is discarded after fourteen days, and cleared out whenever a different account opens a composer on the same browser, so that a shared computer does not hand your unsent writing to the next person to sit at it.
All of it is either strictly necessary for a service you asked us for, or a setting you chose by pressing something. That is why you are not being shown a consent banner: consent is what the law asks for before something is put on your device, and nothing here is on your device that you did not put there. Counting page views does not change that, because it puts nothing there at all. If we ever add something that does, the banner arrives in the same release as the thing that made it necessary, and this section will say so before it does.
4. Why we are allowed to hold it
| What | Why | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Account and content | To provide the service you signed up for | Performance of a contract |
| Imported message history | Bringing a campaign’s writing with it when it moves here from Discord | Legitimate interests |
| Server logs, rate limits | Security, abuse prevention, keeping it running | Legitimate interests |
| Moderation records | Enforcing the rules and handling reports | Legitimate interests |
| Page-view counts | Knowing which parts of the site are used before changing them | Legitimate interests |
| Confirmation and reset emails | Proving an address is yours, account recovery | Performance of a contract |
5. Your rights
If you are in the UK or EEA, you have the rights below. We will respond within one month. They are free to exercise.
- Access: a copy of what we hold about you. You can download most of it yourself, immediately, from account settings. Ask us for anything that file does not cover.
- Rectification: corrections. Your display name and bio you can change yourself in settings.
- Erasure: deletion. You can delete your account yourself from account settings.
- Portability: your data in a machine-readable form. Download it as JSON from account settings, whenever you like and without asking anyone.
- Objection and restriction: to processing based on legitimate interests.
- Complaint: to a data protection authority, at any time, and without asking us first.
Where to complain
Tom Kremser is established in the Czech Republic, so the authority that supervises this service is the Úřad pro ochranu osobních údajů (Czech Data Protection Authority), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic — uoou.gov.cz.
If you live elsewhere in the EEA you may complain to your own country’s authority instead; you do not have to bring a complaint to a foreign one. Article 77 gives you the choice, and naming ours is not meant to suggest it is the only door.
We would rather you wrote to us first at support@hearthhall.com, and you can do both. Asking us is not a step you have to exhaust before complaining, and nothing here asks you to waive anything.
The honest limit on erasure
Deleting your account removes your profile, characters, and sheets, and deletes any group you solely own. Your avatar and your character portraits are deleted from our file storage as well, not merely unlinked from the pages that showed them. Four things are not deleted, and you should know that before you sign up:
- Posts in threads stay, attributed to “deleted”. Other people wrote scenes around them, and removing yours would destroy their work too.
- Wiki pages stay, because they belong to the group and are usually written by several people. Your name is removed from the history.
- Dice rolls stay in the log. A roll is a shared record of what happened.
- Pictures you uploaded into a group stay, if that group outlives your account — a photograph of a place, a picture set into a wiki page or a post. They are part of that campaign in the way your posts are, and pulling them out would leave the same holes in other people’s work. These live in storage that is readable by anyone holding the exact address of the file, which is a long random string that is never published and cannot be guessed or listed, but is not a password: if you have shared the address of a picture, you have shared the picture. That has been true of every image uploaded here since the feature existed. Maps, handouts and files brought over from Discord are not in that storage and never have been; those are readable only by the campaign, and every request for one is checked against who is asking.
In each case what remains is the content, disconnected from you. If you need something specific removed, because it identifies you or you posted it by mistake, write to support@hearthhall.com and we will deal with it individually.
Writing brought here from Discord
A campaign that has been played on Discord can have its history imported into a board here. That copies the messages, and with each message the display name and the avatar of whoever wrote it — including people who have no account on Hearthhall and were never asked. The campaign’s GM decides that an import happens; we are the ones holding what it produces, which makes it ours to tell you about rather than theirs.
It copies the files too, where it can: pictures and documents posted in the channel — PNG, JPEG, WebP and GIF images, and PDF, plain text and Markdown documents, each up to 10 MB — are brought into the campaign’s own private storage and appear in the post where they were posted. Anything else, video and audio and archives among them, is left on Discord, and the imported post names the file it did not bring so that what is missing is visible rather than silently absent.
What arrives lives inside that one private campaign, readable by the people its owner has admitted and by nobody else — files as much as writing: every request for a copied file is checked against that same membership. It is not published, not indexed, and not used to train anything. The lawful basis is legitimate interests, and the interest is a group’s in keeping its own writing when it moves.
If you would rather we did not hold yours, write to support@hearthhall.com and say which Discord account and which server. You do not need an account here to ask. By default we strip the identity and leave the writing: the Discord id, the display name and the avatar go, and the posts stay attributed to nobody — for the same reason posts survive a deleted account, which is that other people wrote the scenes around them. If you want the posts themselves gone, say so and we will delete them, and the files that came with them.
One thing is kept when we do that, and it is there to make the removal stick: a one-way fingerprint of the Discord id, scrambled with the campaign it was in. A GM can import the same channel twice, and without it the second import would simply put your name back. The scrambling only goes one way, so your Discord id cannot be read back out of the fingerprint; and because the campaign is mixed in, the value kept in one campaign is unrelated to the value kept in any other, so it cannot be used to recognise you across them.
The Discord bot privacy notice is the longer version: what the bot reads, what it cannot reach, and how long each part is kept.
6. Who else sees it
Other members of your groups see what you post there. That is the point of a group. People outside it see none of it: group content is not public, is not indexed by search engines, and is not visible to logged-out visitors.
Anybody at all sees the few things somebody has chosen to publish, and each of those is a switch rather than a default. A campaign appears in the directory only if its owner lists it, and what appears is the name, the pitch, the system and how many members it has — never who they are, because listing a game is the GM’s decision and must not publish anybody else’s membership. A character has a public page only if its player published it, and that page shows the sheet and the biography and nothing else; the play state and the owner’s account id are not columns the query returns. Both can be found by a search engine. A notice on the player board is visible to people with an account and to nobody else. Your profile is as described in section 2. Everything else stays inside the campaign it was written in.
Site moderators see reports, and what a report points at. Nothing else: moderating this site does not come with a way into a campaign.
Site administrators — whoever runs Hearthhall — see the list of accounts: username, display name, avatar, when the account was made, how many campaigns and characters it has, its site role, and whether it is suspended. All but the last two are already visible to anyone using the site. They can also search by an email address to find the account behind it, which is how a message sent to the address at the top of this page is matched to an account; the search finds the account, and no page shows the address.
Administrators can see that a campaign exists, and its name, size and owner. They cannot read one. The wiki, the boards, the maps, the handouts, the dice and the character sheets inside a private campaign are as closed to whoever runs this site as to anybody else who is not a member, and the database enforces that rather than the interface. Acting on a report about something written inside a campaign means being let into it.
Changing somebody’s role, suspending an account and removing content are each written to a log that is added to and never edited.
We use these providers to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and file storage | European Union |
| Vercel | Application hosting, content delivery, and counting page views. The analytics part sets no cookie and keeps no identifier that outlives the day it was made. | European Union / United States |
| Hostinger | Sending account email: confirming an address, and resetting a password | European Union |
| Stripe | Selling and taking payment for Premium as merchant of record, and keeping the invoices tax law requires | European Union / United States |
| Have I Been Pwned | Checking new passwords against known breaches. Only the first five characters of a hash are sent, never the password or any account detail. | United Kingdom |
Where a provider processes data outside the EEA, that transfer is covered by the European Commission’s Standard Contractual Clauses.
We will also disclose data if we are legally required to. If that happens and we are allowed to tell you, we will.
7. How long it is kept
- Account data: until you delete your account.
- Content: as described in section 5.
- Uploaded files: until the thing they belong to is deleted. Deleting a campaign deletes its maps, its handouts and anything an import copied over from Discord; deleting your account deletes your avatar and your character portraits. The rest of section 5 says what survives and why.
- Subscription records: what we hold — the Stripe references, the status and the period end — is deleted with your account. The invoices held by Stripe are kept for as long as tax law requires, which in the Czech Republic is ten years. We cannot shorten that and neither can they; it is the one thing here that survives an erasure request, and it survives it because keeping it is a legal obligation rather than a choice.
- Backups: deleted data persists in backups for up to 30 days, then goes.
- Server logs: a short period, typically under 30 days.
- Moderation records: kept while needed to enforce the rules, so that a suspension cannot be evaded by making a new account.
8. Security
Access is enforced in the database itself, not only in the application: every table carries row-level security policies, so a group you are not a member of returns nothing even if a bug in the interface were to ask for it. Passwords are hashed by our authentication provider. Traffic is encrypted in transit.
No system is perfectly secure. If there is a breach affecting your personal data and it is likely to put you at risk, we will tell you and the relevant authority within 72 hours of becoming aware.
9. Children
Hearthhall is not for under-16s. If we learn that an account belongs to someone younger, we will delete it. If you believe a child has an account here, write to support@hearthhall.com.
10. Changes
If we change this policy in a way that materially affects you, we will give notice in the application before it takes effect. The date at the top always shows the current version.