This Privacy Policy explains how TheGMsCodex ("we", "us", "our") handles personal data in connection with "The GMs Codex" desktop application (the "Application") and any hosted services we operate (the "Hosted Services").

It should be read alongside our [Terms of Service](www.TheGMsCodex.com\Terms-of-Service).

---

## 1. The short version

The GMs Codex is a **local-first** application. Your worlds, characters, maps, notes and campaigns are stored as ordinary files on your own device. In normal use, **that content never reaches us at all** — we cannot see it, and we do not hold a copy of it.

We only receive your content if you choose to subscribe to our optional Hosted Services. Everything else we collect is limited to what is needed to sell you a licence, keep your account working, and provide support.

We do not sell personal data. We do not use your content to train machine-learning models. We do not serve advertising.

---

## 2. Who is responsible for your data

TheGMsCodex
Contact: TheGMsCodex@gmail.com

---

## 3. The different roles we play

| Data | Our role | Meaning |
|---|---|---|
| Your account, licence and billing details | **Controller** | We decide how it is used, and this policy governs it. |
| Content you sync to the Hosted Services (your worlds, notes, images, and any personal data you put in them) | **Processor** | We act on your instructions only. You remain the controller. |
| Data about Guests/Players you invite | **Processor** (for us), **Controller** (for you) | You decide to invite them; we only process what that requires. |
---

## 4. What we collect, and why

### 4.1 If you only buy and use the Application (no subscription)

- **Purchase and licence data** — name, email address, country, licence key, purchase date, and the payment provider's transaction reference. We do **not** receive or store your card details (see 4.5).
  *Purpose:* to sell you a licence, issue and support your key, and meet tax and accounting obligations.
  *Lawful basis:* performance of a contract; legal obligation (records).

- **Licence verification data** — where the Application performs an optional online licence check, this involves your licence key and basic technical information such as an IP address and Application version.
  *Purpose:* to validate licences and detect abuse.
  *Lawful basis:* legitimate interests (protecting against unlicensed use).
  *Note:* the Application is designed to verify licences offline. If it cannot reach us, it continues working — we do not require connectivity to let you use software you have paid for.

- **What stays on your device and never reaches us:** your Codices and all their contents, local snapshot history, and crash-recovery drafts. These are stored in ordinary files and application data on your own machine.

### 4.2 If you subscribe to the Hosted Services

In addition to the above:

- **Account data** — email address, authentication credentials, subscription tier and status.
- **Your synced content** — whatever you choose to synchronise: entities, documents, images, maps and any personal data contained within them. We process this **as your processor**, only to store it, transmit it to your authorised devices, and serve the parts you have designated to Guests.
- **Service logs** — timestamps, IP addresses, request and error data, storage and transfer volumes.
  *Purpose:* operating the service, security, diagnosing faults, and enforcing fair use.
  *Lawful basis:* performance of a contract; legitimate interests (security and service integrity).

### 4.3 If you are a Guest or Player

If a GM gives you access to their campaign content, we may process:

- the access token you present, and basic technical data (IP address, browser type) needed to serve the content and protect the service;
- any name or identifier the GM has associated with your access.

**We did not obtain your details from you — the GM who invited you introduced them.** They decide what you can see and can revoke your access at any time. If you have questions about why your details are held, contact that GM first; you may also contact us at [PRIVACY EMAIL] and we will assist.

We do not create marketing profiles of Guests and do not contact Guests other than as needed to provide access.

### 4.4 Support and correspondence

If you contact us, we keep your message and contact details in order to reply and to keep a record of the issue.

If you report a fault, we may ask you for additional diagnostic information — such as your Application version, operating system, or an error log. You are never required to send us the contents of a Codex, and we will not ask for one unless it is genuinely necessary to reproduce a problem you have reported. If you do send us a file to help diagnose a fault, we use it only for that purpose and delete it once the issue is resolved.

We may occasionally invite you to take part in a survey or give feedback. Taking part is always optional.

*Lawful basis:* legitimate interests (providing support and improving the product).

### 4.5 Payments

Payments are handled by our payment provider, **[LEMON SQUEEZY / PADDLE / STRIPE]**. Depending on the arrangement, they may act as the seller of record for your purchase. **We never see or store your full card details.** Their handling of your data is governed by their own privacy policy: [URL].

### 4.6 Website and analytics



### 4.7 Signing in with a third-party account

If you choose to create or access a Hosted Services account using credentials from another service, we receive a limited set of information from that provider — typically your name and email address, and only what that provider's own settings permit it to share.

**We never receive or store your password for that service.** We also cannot change or delete any data held by that provider — to do that, you need to use their own settings and privacy controls. Their handling of your data is governed by their privacy policy, not ours.

*Lawful basis:* performance of a contract (creating and securing your account).

### 4.8 Marketing communications

If you have asked to hear from us, or are an existing customer, we may send you occasional product news such as major releases. Every message includes an unsubscribe link, and you can change your preferences at any time in your account settings or by contacting us. We do not sell or share your details with other companies for their marketing.

Service messages you cannot opt out of — such as licence key delivery, billing notices, security alerts, and material changes to these policies — are sent because they are necessary to provide what you have paid for.

---

## 5. What we never do

- We do not sell or rent personal data.
- We do not use your content to train machine-learning or AI models.
- We do not use your content for advertising, and we do not serve ads.
- We do not access the contents of your Codices except where strictly necessary to investigate a fault you have reported to us, or where legally required.

---

## 5A. Content you choose to share

Some parts of the Application and Hosted Services let you deliberately make content available to other people — for example, designating material as visible to Guests, exporting a Codex to share with another user, or producing a published output such as a sourcebook.

Where you do this, **you decide what leaves your control**. Anything you designate for sharing becomes visible to the people you have shared it with, and we cannot retrieve or un-share content once you have distributed a file to someone else. If your content contains personal data — real names of players, for instance, or notes about identifiable people — please consider that before sharing or publishing it.

Nothing is shared by default. Content is private to you unless you take a deliberate action to expose it.

---

## 5B. Other websites and services

Our website, the Application, and any player-facing portal may contain links to sites and services we do not operate — including community platforms, map-making tools, and payment providers.

This Privacy Policy does not cover those services. We are not responsible for their content, security, or privacy practices, and any information you give them is governed by their own policies. We would encourage you to read those before providing personal data.

This also applies to any **self-hosted deployment** operated by another person: if a GM invites you to a server they run themselves, that GM is responsible for it, not us.

---

## 6. Who we share data with

We share personal data only with:

- **Service providers** who help us operate (listed in section 7), under contract and only for that purpose;
- **Professional advisers** (accountants, lawyers) where necessary;
- **Authorities**, where we are legally required to do so;
- **A successor**, if our business is sold or reorganised — you would be notified.

Guests only ever see the content the relevant GM has designated for them.

---

## 7. Sub-processors and infrastructure

If you run a **self-hosted deployment**, none of the above applies to that deployment — you operate it, and you are the controller for everything on it. We receive nothing from it.

---

## 8. International transfers

Some providers may process data outside the UK. Where that happens, we rely on an appropriate safeguard — such as UK adequacy regulations, or the International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses.

---

## 9. How long we keep data

| Data | Retention |
|---|---|
| Purchase, licence and tax records | [6] years, to meet UK accounting requirements |
| Account data | For as long as your account is active |
| Synced content (Hosted Services) | While subscribed, plus a [NUMBER]-day recovery window after cancellation, then deleted |
| Service logs | [NUMBER] days |
| Support correspondence | [NUMBER] months |
| Guest access records | Until the access token is revoked or expires, plus [NUMBER] days |

---

## 10. Children

The Application and Hosted Services are not intended for use by children under [16] as account holders. If you invite a Guest who is under 18, you confirm that you have any consent required from their parent or guardian before doing so.

If you believe we hold personal data about a child without appropriate consent, contact us at TheGMsCodex@gmail.com and we will investigate and delete it where required.

---

## 11. Security

We apply appropriate technical and organisational measures, including encryption in transit, access controls, and the principle of least privilege. Content stored through the Hosted Services is held in access-controlled storage.

No system is perfectly secure and we cannot guarantee absolute security. You are responsible for keeping your licence key, account credentials and Guest access tokens secure, and for maintaining your own backups of your work.

---

## 12. Your rights

Under UK and EU data protection law you have the right to: access your data; have inaccurate data corrected; have data erased in certain circumstances; restrict or object to processing; data portability; and to withdraw consent where processing relies on it.

**How to make a request.** Contact **[PRIVACY EMAIL]**, ideally stating which right you wish to exercise so we can handle it promptly.

**Timescales.** We will acknowledge your request promptly and respond within **one calendar month**. Where a request is particularly complex, or where you have made a number of requests, we may extend this by up to two further months — if so, we will tell you within the first month and explain why.

**Verifying who you are.** Before acting on a request we need to be satisfied that it comes from you. We will use information we already hold wherever possible; only where that is insufficient will we ask for anything further, and we will ask for the minimum needed. If we genuinely cannot verify your identity, we may be unable to proceed — this is to protect your data from being disclosed to someone else.

**There is no charge** for exercising your rights. We may charge a reasonable fee, or decline, only where a request is manifestly unfounded or excessive.

**If the data concerns content a GM has stored with us**, we act as processor — we will refer your request to that GM, who is the controller, and assist them in responding.

You also have the right to complain to the **Information Commissioner's Office** ([ico.org.uk](https://ico.org.uk)) or your local supervisory authority. We would appreciate the chance to address your concern first.

---

## 13. Changes to this policy

We may update this policy. Material changes will be notified by [email / in-app notice / a prominent notice on our website] at least 90 days before they take effect. The "last updated" date above always reflects the current version.