← Pisces RPG

Last updated 30 September 2026

Privacy Policy

This policy explains what data Pisces RPG handles, why, and what your rights are. The short version: we keep little — your account, a credit ledger, and your stories themselves, which we store so you can resume them and play them with others. Compiled tales you archive to your bookshelf stay in your own browser.

1. Who is responsible

The data controller is Arnesen KI, a Norwegian sole proprietorship (org. no. 938 043 345), reachable at alexanderarnesen+pisces@gmail.com.

2. What we process

Pisces processes the following, and nothing more:

  • Account: your Google account ID, name and email, received when you sign in with Google. Used to identify your account and show who is signed in.
  • Credit ledger: your credit balance and a record of grants, purchases and spends. Needed to run the prepaid-credit model and for bookkeeping.
  • Game inputs: the story text and actions you type are sent to the AI provider that runs your story (OpenAI by default, Anthropic when selected, or Google Gemini for older stories) to generate the game’s responses, and are stored on Pisces servers so you can resume the story and play it with others — see the next point.
  • Stories: when you play a story — on your own or with others — its narrative, chronicle and generated images are stored on Pisces servers (database and file storage) so every seated player’s device, and your own on return, can resume the same run and stay in sync. See “What stays in your browser” below and “How long we keep things”.
  • Moderation: policy categories, enforcement events and suspension status linked to your account, used to prevent abuse and review restrictions.
  • Images in public blob storage can be accessed by anyone holding their URL. Keep image and invite links private if you do not want others to access them.
  • Payments: handled entirely by Stripe. Pisces never sees your card details — it records only which credit pack was bought and the Stripe reference.
  • Product-usage events: a small log of what happens in the product — for example signing up, starting a story, taking a turn, and starting or completing a checkout — linked to your account and story. It contains no story text and no card details. Used to understand and improve how the service is used.
  • Signup-grant abuse limiting: when a new account receives the free signup credits we store a salted hash of your IP address (not the address itself) on your account record, together with the time of the grant, only to limit repeated grants from one network. The raw IP address is not stored by Pisces.
  • Technical basics: rate-limit and daily-spend counters keyed to your account, and the ordinary short-lived request logs our hosting provider produces.

3. What stays in your browser

Your compiled tales (archived to the bookshelf) and preferences (language, tone settings) are stored locally in your browser (IndexedDB and localStorage), not on our servers. Clearing your browser data removes them; we could not recover them if we wanted to. The stories you play, by contrast, are stored on our servers so you can resume them — see “Stories” above.

4. Why we may process data (legal bases)

  • To run the game you asked for — account, ledger, game inputs (contract, GDPR Art. 6(1)(b)).
  • To keep the service safe and affordable — rate limiting, abuse prevention, spend ceilings (legitimate interest, Art. 6(1)(f)).
  • To understand how the service is used, and to stop repeated abuse of the free signup credits — product-usage events and the salted IP hash (legitimate interest, Art. 6(1)(f)).
  • To keep purchase records — bookkeeping law requires retaining transaction records (legal obligation, Art. 6(1)(c)).
  • There is no advertising, no marketing mail, and no sale or sharing of data for others’ purposes.

5. Processors and transfers

Pisces uses the following service providers. Stripe acts as an independent controller for payments:

Some of these providers process data in the United States. Transfers rely on the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses built into each provider’s data-processing agreement.

  • Google (Gemini API, paid tier): generates the game content from your inputs. On the paid tier Google does not use your prompts or the outputs to train its models, and retains them only briefly for abuse monitoring. Google also provides the sign-in. All images and narration are generated by Google.
  • Anthropic (Claude API): generates story text only for stories where you chose Claude as the storyteller. Anthropic does not use API inputs or outputs to train its models, and retains them only briefly for abuse monitoring.
  • Vercel: hosts the application and provides its cookieless, aggregated page-view analytics.
  • OpenAI: generates text for stories using the Chronicler, including safety classification. Inputs include story context and a pseudonymous safety identifier.
  • Neon: hosts accounts, credit records, stories, party membership and moderation records.
  • Stripe: processes payments and is an independent controller for the payment itself.

6. How long we keep things

Account and ledger data are kept while your account exists. Purchase records are kept as long as Norwegian bookkeeping rules require (up to five years) even after account deletion. If you ask for deletion, everything else is removed.

Stories are stored on our servers precisely so you can resume them — that is the point. Stories are scheduled for cleanup after 90 days without a server update. New bookshelf saves copy illustrations into your browser before reporting success. Older archives may still link to server images and can lose those images at cleanup; export them while those images remain available.

Product-usage events are kept for up to 400 days and then deleted. The salted IP hash kept for the signup grant is automatically cleared 30 days after the grant (the grant time itself stays with the account).

7. Your rights

Moderation: we record account and story identifiers, the time, surface and reason for safety rejections, and suspension status. Three severe violations within thirty days can automatically suspend paid use. These records currently remain while the account exists; the thirty-day strike window is not a deletion period. Contact the operator for human review or to challenge a decision.

You can ask for access to, correction of, or deletion of your data, ask for a copy (portability), and object to or ask us to restrict processing — email alexanderarnesen+pisces@gmail.com. You also have the right to complain to the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no).

8. Adults only

Pisces is only for people aged 18 or older. Participation through a parent or another adult’s account is not permitted for minors. Contact us if you believe a minor is using the service.

9. Cookies and local storage

Pisces sets only the strictly necessary session cookie that keeps you signed in, plus local preferences in your browser’s storage. Page views are counted with Vercel Web Analytics, which is cookieless and aggregated — no cookies, no cross-site tracking, no individual profiles. There are no ad trackers. One first-party cookie (pisces_src) records the ad or referral source of your first visit — campaign tags in the link and the referring site’s name — for up to 90 days, only so we can measure which marketing brings in players; it is attached to your sign-up and checkout records if you create an account.

10. Changes

If this policy changes, the date above is updated and material changes are announced in the app.