Privacy Policy

Effective date: April 1, 2026  ·  Last updated: April 1, 2026

This Policy explains how Threadfall collects, uses, and protects your personal data. We try to be direct and avoid legalese — if anything is unclear, email us at hello@thread-fall.com.

1. Who We Are

Threadfall is a campaign tracking service for tabletop RPGs. For the purposes of applicable data protection law, Threadfall is the data controller of your personal information. Contact: hello@thread-fall.com.

2. Information We Collect

Account data

Email address, display name, password (stored as a bcrypt hash — we never see your plaintext password), and optional avatar image.

Campaign & session data

Campaign names and settings, session transcripts you record or upload, AI-generated summaries, codex entries, quest logs, maps, and character data.

Usage data

Approximate timestamps of actions (session creation, recap generation, etc.), feature usage counts, and AI cost logs associated with your account. We do not use third-party analytics trackers.

Payment data

If you subscribe to a paid plan, payment is processed by our payment provider. We do not store full card numbers or sensitive financial data on our servers.

3. How We Use Your Data & Legal Basis (GDPR)

For users in the European Economic Area (EEA) and UK, we process personal data on the following legal bases:

For users outside the EEA, we process data based on the same purposes described above.

4. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service, subject to the following schedules:

5. Data Sharing & Third-Party Processors

We do not sell, rent, or trade your personal data. We share data only with the following service providers, strictly to operate the Service:

All processors are bound by data processing agreements and are required to process data only as instructed by us.

6. International Data Transfers

Threadfall is operated from the United States and our processors are primarily US-based. If you are located in the EEA, UK, or Switzerland, your personal data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, and/or other appropriate safeguards, to legitimise these transfers where required.

7. Your Rights

All users

EEA / UK users (GDPR)

In addition to the above, you have the right to: object to processing based on legitimate interests; restrict processing; withdraw consent at any time (where processing is based on consent); and lodge a complaint with your local data protection authority (e.g., your national Data Protection Authority or the UK ICO).

California users (CCPA)

California residents have the right to know what personal information we collect and how it is used, to request deletion, and to opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact hello@thread-fall.com.

8. Cookies

Threadfall uses only functional cookies and browser local storage necessary to operate the Service (e.g., your authentication token). We do not use advertising cookies or third-party tracking pixels. No cookie consent banner is required because we do not set non-essential cookies.

9. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we become aware that we have inadvertently collected such data, we will delete it promptly. If you believe a child under 13 has provided us with personal data, please contact hello@thread-fall.com.

10. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users without undue delay and, where required by law, notify the relevant supervisory authority within 72 hours of becoming aware of the breach.

11. Changes to This Policy

We may update this Privacy Policy periodically. For material changes, we will notify you by email or by displaying a prominent notice in the Service at least 30 days before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent revision.

12. Contact

For any privacy questions, data subject requests, or concerns, contact us at hello@thread-fall.com. We aim to respond within 30 days.