PRIVACY & DATA
How your information is handled.
Updated 10 September 2026. This notice covers the landing page, alpha applications and hosted Crawler Toolkit accounts. Applying does not create an account. The first alpha application wave is for adults aged 18 and over.
Loading the organiser's contact and hosting details. Applications remain closed until these details are configured.
Who is responsible?
Controller identity has not loaded.
Contact details have not loaded.
Alpha applications
We collect your preferred name, email, country, tabletop and GM experience, familiarity with the DCC RPG, testing setting and availability. Age range, systems played and your testing interests are optional. We record your adult declaration, application date, mailbox confirmation, review decisions, invitation acceptance, email-processing status and the consent wording version. Confirmation links expire after 24 hours. We send confirmation, decision, invitation and welcome emails through the configured mail provider. Avoid sensitive personal information in free-text fields.
With your consent, the organiser uses this information to select a mix of testers and contact them about this alpha. Selection is manual. There is no newsletter or advertising subscription. You can withdraw through Manage my data or the contact above. Withdrawal does not affect processing that was lawful before it. Declining optional answers does not prevent an application.
Accounts and campaigns
Accounts store a display name, email, password hash, group access and invitations. Session records contain sign-in times, IP address and browser information. We use the account and campaign information needed to provide the service you request under our agreement with you. We use limited security records for our legitimate interest in protecting accounts and preventing abuse.
Hosted campaigns, character sheets, images, imports, private notes, player requests and game actions save on the server. Members see material allowed by their role and the GM's sharing decisions. The host can administer the underlying server and database; GM-only does not mean encrypted from the host. Do not upload sensitive real-world information about yourself or others. The organiser handles platform/account data; the responsibilities of a group using personal information in campaign content depend on that group's use.
Cookies and device storage
The landing page has no advertising or analytics cookies. Necessary authentication cookies support sign-in. By default, sign-in uses a browser-session cookie. Selecting Remember me permits a persistent sign-in cookie lasting seven days and renewed during active use. You can end it by signing out or using Sign out on all devices under Manage my data.
The separate local/offline toolkit uses this device's localStorage and IndexedDB to save the campaigns, content and preferences you ask it to keep. The hosted toolkit uses a working copy in the open page and saves durable game changes on the server. A support feature check may briefly test local storage. Clearing browser storage removes local saves, not hosted accounts or server saves; make a backup first.
Security and service records
Alpha and privacy-form abuse protection uses short-lived keyed IP or email hashes. Login/session protection also processes IP addresses and browser information. These are different records; the two-hour application rate limit does not describe all IP processing. Operational monitoring uses aggregate request/error counts and timing, without game contents. The app avoids logging passwords, invitation links and application answers. Infrastructure and email services may process connection and delivery records.
How long information stays
- Alpha applications: unconfirmed applications expire after 7 days; confirmed applications after 90 days from submission, or earlier withdrawal. A review status change does not extend this.
- Privacy verification links: 24 hours, single-use. Rate-limit buckets: up to two days, depending on their purpose.
- Expired sessions and password-reset records: removed by periodic cleanup. Remember-me choice records: 30 days.
- Unused or consumed invitations: removed 30 days after their expiry. Security audit events: 90 days.
- Queued alpha emails: encrypted until sent, cancelled or expired (up to 7 days). Decision history and mail metadata are deleted with the application. SMTP acceptance does not establish inbox delivery; provider records have their own stated retention.
- Privacy requests: retained while open, then 90 days after resolution to document the response.
- Accounts and live game data: while the service is provided or until an agreed deletion request is completed. We review continued need at the end of the alpha. Game action receipts remain while their account/workspace needs them to prevent duplicate actions.
Expiry is followed by scheduled cleanup, normally hourly while the server is running. Open access/deletion requests are reviewed by the organiser; they are not silently discarded when overdue.
Deployment-specific backup/log retention has not loaded.
Deletion records are kept separately from database backups for the backup lifetime plus seven days, and used to reapply structured deletions before restored data is served. Redactions in shared game text need a separate review during restoration. Downloaded exports and correspondence require separate handling. Do not share full game backups as a player-safe view.
Where information goes
Hosting details have not loaded.
Email provider details have not loaded.
Transfer arrangements have not loaded.
The configured alpha organiser reviews applications. Account administrators handle verified data requests. Service providers process information needed for their tasks. The landing page does not load third-party advertising, analytics, social widgets or remotely hosted fonts.
Your requests and choices
You can request access, correction, deletion, restriction and, where applicable, portability or object to legitimate-interest processing. Use Manage my data or contact the organiser. Email verification helps prevent someone else accessing or deleting your information. Requests are handled without undue delay, normally within one month; if a lawful extension is necessary, we will explain it within that month.
The signed-in download covers structured account/application information. Personal information in shared game text, backups or correspondence requires a review, including the rights of other players. Account deletion can remove campaigns you own; we will discuss affected shared material before completing it. Cookie choices do not replace these data rights.
You may complain to Datatilsynet or your competent data-protection authority. You need not contact us first. Material changes to how we use information will be communicated to affected users.