Tale LedgerCampaign StudioBack to Tale Ledger

Privacy

Privacy Policy

Tale Ledger keeps campaign management local by default and limits cloud processing to services a user deliberately chooses.

Plain-language boundary. Signing into Tale Ledger does not upload your campaign database. Hosted images, account operations, support requests, and future included AI are separate, optional flows.

Scope and operator

This policy describes information handled by Tale Ledger’s website, optional account service, hosted image publishing, support channels, and future hosted features. Tale Ledger is operated by Allen Ross. It does not govern third-party websites or a user’s independently configured API account.

Information that stays local

Your campaigns, sessions, story notes, characters, NPCs, quests, encounters, maps, scenes, local artwork, backups, and imports remain in the workspace on your device unless you deliberately export, present, or upload particular material. Tale Ledger’s account service does not receive the local campaign database merely because you sign in.

Player-session notes remain in each player’s browser unless the player deliberately submits selected text to the GM. The GM’s application remains responsible for saving accepted notes into a campaign.

Information hosted services collect

Depending on the features you use, Tale Ledger may process:

  • Account email address, account status, plan, allowances, deletion requests, and subscription state.
  • Device label, session identifiers, token hashes, sign-in timestamps, revocation state, and limited operational audit events.
  • Hosted-image files, sanitized derivatives, filenames, media properties, dimensions, cryptographic hashes, storage usage, lifecycle state, and moderation decisions.
  • Public reports, optional reporter contact details, privacy-preserving network fingerprints used for duplicate suppression, moderator notes, preservation holds, and case history.
  • Support messages and information you choose to include.

Do not send passwords, full API keys, payment card information, government identifiers, or unrelated sensitive personal information through support or hosted content.

Why information is used

Tale Ledger uses this information to authenticate accounts, operate requested services, enforce quotas, deliver images, prevent abuse, moderate content, respond to reports, provide support, maintain security and audit trails, comply with legal obligations, and understand service reliability and cost.

Tale Ledger does not sell personal information or use hosted campaign material for targeted advertising.

Service providers

Limited information is processed by vendors that support the service. Cloudflare provides account-service infrastructure, storage, queues, delivery, and security. Resend delivers account sign-in email. OpenAI receives only a metadata-free, reduced image derivative when an owner submits a hosted image for publication screening. Future hosted AI features will separately disclose what campaign context is sent before they are enabled.

These providers process information under their own agreements and privacy practices. Tale Ledger may also disclose information when reasonably necessary to comply with law, protect users or the service, investigate abuse, or complete a business transfer subject to appropriate protections.

Retention and deletion

Short-lived login codes expire quickly; device sessions expire or may be revoked. Hosted images moved to trash are ordinarily recoverable for 30 days and continue consuming storage until permanently deleted. Original and derivative image objects are removed on permanent deletion unless a valid preservation obligation applies.

Operational records, moderation decisions, public reports, blocked-content hashes, and safety history may be retained longer when needed to prevent repeat abuse, preserve evidence, resolve disputes, or comply with law. Account deletion uses a grace period before final processing and may not erase records that must be retained for those limited purposes.

Your choices

You can use the local application without an account; sign out; revoke individual or all devices; download private hosted images; unpublish, trash, restore, or permanently delete eligible images; export available account metadata; cancel a deletion request during its grace period; or request account deletion.

For access, correction, deletion, or privacy questions not available in the application, use the contact page. Tale Ledger may need to verify the request and may retain information where legally permitted or required.

Security, children, and changes

Tale Ledger uses access controls, short-lived credentials, protected device storage where supported, private buckets, sanitized public derivatives, audit records, and server-side secrets. No security system is perfect; report suspected compromise promptly.

Hosted accounts are not directed to children under 13 and are intended for adults participating in the controlled beta. This policy may change as features, providers, and legal obligations develop. Material changes will carry a new effective date.

Questions or concerns

Write to the keeper of the ledger.

Visit the contact page to copy support@taleledger.com or open a browser-based email composer. Include the relevant account email, asset link, or request identifier when available—never send passwords or API keys.