Last updated 22 July 2026
Privacy Policy
This policy explains what data Pisces RPG handles, why, and what your rights are. The short version: we keep little — your account, a credit ledger, and your stories themselves, which we store so you can resume them and play them with others. Compiled tales you archive to your bookshelf stay in your own browser.
1. Who is responsible
The data controller is Alexander Arnesen, a private individual based in Norway, reachable at alexanderarnesen+pisces@gmail.com.
2. What we process
Pisces processes the following, and nothing more:
- Account: your Google account ID, name and email, received when you sign in with Google. Used to identify your account and show who is signed in.
- Credit ledger: your credit balance and a record of grants, purchases and spends. Needed to run the prepaid-credit model and for bookkeeping.
- Game inputs: the story text and actions you type are sent to Google’s Gemini API to generate the game’s responses, and are stored on Pisces servers so you can resume the story and play it with others — see the next point.
- Stories: when you play a story — on your own or with others — its narrative, chronicle and generated images are stored on Pisces servers (database and file storage) so every seated player’s device, and your own on return, can resume the same run and stay in sync. See “What stays in your browser” below and “How long we keep things”.
- Payments: handled entirely by Stripe. Pisces never sees your card details — it records only which credit pack was bought and the Stripe reference.
- Technical basics: rate-limit and daily-spend counters keyed to your account, and the ordinary short-lived request logs our hosting provider produces.
3. What stays in your browser
Your compiled tales (archived to the bookshelf) and preferences (language, tone settings) are stored locally in your browser (IndexedDB and localStorage), not on our servers. Clearing your browser data removes them; we could not recover them if we wanted to. The stories you play, by contrast, are stored on our servers so you can resume them — see “Stories” above.
4. Why we may process data (legal bases)
- To run the game you asked for — account, ledger, game inputs (contract, GDPR Art. 6(1)(b)).
- To keep the service safe and affordable — rate limiting, abuse prevention, spend ceilings (legitimate interest, Art. 6(1)(f)).
- To keep purchase records — bookkeeping law requires retaining transaction records (legal obligation, Art. 6(1)(c)).
- There is no advertising, no marketing mail, and no sale or sharing of data for others’ purposes.
5. Processors and transfers
Four service providers process data on Pisces’ behalf, each under a data-processing agreement:
Some of these providers process data in the United States. Transfers rely on the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses built into each provider’s data-processing agreement.
- Google (Gemini API, paid tier): generates the game content from your inputs. On the paid tier Google does not use your prompts or the outputs to train its models, and retains them only briefly for abuse monitoring. Google also provides the sign-in.
- Vercel: hosts the application and provides its cookieless, aggregated page-view analytics.
- Neon: hosts the small database holding accounts and the credit ledger.
- Stripe: processes payments and is an independent controller for the payment itself.
6. How long we keep things
Account and ledger data are kept while your account exists. Purchase records are kept as long as Norwegian bookkeeping rules require (up to five years) even after account deletion. If you ask for deletion, everything else is removed.
Stories are stored on our servers precisely so you can resume them — that is the point. A story with no move for 90 days is treated as abandoned and its stored text and images are deleted; a completed story is deleted 90 days after it ends. Once a run is compiled into a tale, your archived copy lives only in your own browser and is unaffected by this schedule.
7. Your rights
You can ask for access to, correction of, or deletion of your data, ask for a copy (portability), and object to or ask us to restrict processing — email alexanderarnesen+pisces@gmail.com. You also have the right to complain to the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no).
8. Children
Pisces accounts are for adults (18+). Children play together with a parent or guardian on the adult’s account, and Pisces does not knowingly collect personal data about children. If you believe a child has created an account, contact us and it will be removed.
9. Cookies and local storage
Pisces sets only the strictly necessary session cookie that keeps you signed in, plus local preferences in your browser’s storage. Page views are counted with Vercel Web Analytics, which is cookieless and aggregated — no cookies, no cross-site tracking, no individual profiles. There are no ad trackers.
10. Changes
If this policy changes, the date above is updated and material changes are announced in the app.