Privacy Policy

Last updated: 15 July 2026

Quick Summary

For the shortest version: we treat your data the way we’d want ours treated. The long version is below.

1. Who We Are

Oh My Lore! (“we”, “us”, “our”) is operated by:

Tomáš Holocsy, sole trader (OSVČ) registered in the Czech Republic
IČO: 07942699 · DIČ: CZ9110126344 (VAT-identified person — not a VAT payer)
Place of business: Jabloňová 1723/71, Záběhlice, 106 00 Praha 10, Czech Republic
Registered in the Czech Trade Licensing Register (živnostenský rejstřík)

Contact for privacy matters: support@ohmylore.app
Phone: (+420) 793 913 700

No Data Protection Officer has been appointed — we are not required to appoint one under GDPR Art. 37 at our current scale. You can reach us directly at the address above.

This Privacy Policy applies to our websites at ohmylore.app, ohmylore.eu, ohmylore.quest, and to the Oh My Lore! mobile application (together, the “Service”).

2. What Data We Collect

Category Examples How we get it
Account data Email address, Firebase UID, display name You provide it at signup
Campaign content Campaigns, maps, submaps, NPCs, notes, quests, characters You create it in the Service
Media Profile images, uploaded character/map images, AI-generated maps You upload it or ask us to generate it
AI prompts Text descriptions and image scans you submit to AI features You provide it when using Scan / AI Generation
Technical data IP address, browser type, device type, timestamps of use, AI-generation quotas Automatically when you use the Service
Push notification token Device identifier issued by Google Firebase Cloud Messaging (FCM) Generated when you enable push notifications
Payment data (web purchases) Billing country and subscription status. Full card details stay with Polar, our Merchant of Record — card numbers never touch our servers. You provide it at checkout on ohmylore.app
Payment data (iOS app purchases) Subscription/entitlement status and App Store receipt identifiers (no card data — Apple processes the payment) When you subscribe in the iOS app
Cookies & similar technologies See our Cookie Policy Set when you use the Service

We do not collect: health data, political opinions, biometric data, or other GDPR “special category” data. Please do not include such data in your campaign content.

A note on our iOS App Privacy label: some third-party sign-in and messaging SDKs bundled in the iOS app (Google Sign-In, Firebase) declare in their own privacy manifests that they are technically capable of accessing additional categories such as phone number, coarse location, or diagnostic data. Apple requires our App Privacy label to reflect those SDK declarations, so the label lists them — but the Service itself does not request, use, or store these categories.

3. How We Use Your Data and Legal Basis

Under GDPR Art. 6, we process your data on the following bases:

Purpose Legal basis (GDPR)
Create and maintain your account; sync campaigns across devices Performance of a contract (Art. 6(1)(b))
Generate AI content (maps, lore, note scans, recaps) Consent (Art. 6(1)(a)) — you opt in per feature
Process payments and donations Performance of a contract (Art. 6(1)(b)) and legal obligation (tax law) (Art. 6(1)(c))
Protect against abuse (rate limiting, fraud prevention, quota enforcement) Legitimate interest (Art. 6(1)(f)) — operating a safe service
Send service-related emails (account, billing, security) Performance of a contract (Art. 6(1)(b))
Send push notifications you enable (campaign invites, session reminders) Consent (Art. 6(1)(a)) — you enable them; and performance of a contract (Art. 6(1)(b))
Send marketing emails, if any Consent (Art. 6(1)(a)) — you opt in, can opt out anytime
Improve the Service and troubleshoot Legitimate interest (Art. 6(1)(f))
Comply with legal requests (e.g. court orders) Legal obligation (Art. 6(1)(c))

We do not use your content to train AI models. Our AI sub-processor (Google Cloud Vertex AI) is contractually prohibited from using your prompts, uploaded images, or generated outputs to train its foundation models under Google’s Cloud Service Specific Terms and Data Processing Addendum.

4. Who We Share Your Data With (Sub-Processors)

We share data only with the following categories of recipients, each acting as a processor on our behalf:

Recipient What we share Why
Google Ireland Ltd / Google LLC (Firebase & Google Cloud) Account data, campaign content, media, technical data, push notification tokens Hosting, authentication (incl. Google Sign-In), database (Firestore / Realtime DB), file storage, push messaging (Firebase Cloud Messaging)
Google Ireland Ltd / Google LLC (Vertex AI) AI prompts, uploaded images (maps, notes, character sheets) AI generation and OCR features — processing location europe-west1 (EU). Data is processed under Google’s Cloud Data Processing Addendum; not used to train models; limited abuse-monitoring retention may apply.
Polar Software, Inc. Email, billing country, subscription status Merchant of Record and payment processing for web purchases — Polar takes legal responsibility for VAT collection and remittance. We never see full card numbers.
RevenueCat, Inc. (US) Firebase UID, email, purchase/entitlement status, App Store receipt identifiers iOS subscription management and entitlement validation
Apple Inc. (US) Payment and receipt data for App Store purchases; Apple ID (if you use Sign in with Apple) Seller of record for iOS in-app purchases; optional sign-in
Loops, Inc. (US) Email address, name Transactional and wishlist emails
Capgo SAS (France, EU) Device/app version, IP address Over-the-air app update delivery for the mobile app
Discord Inc. (US) Basic profile data (only if you choose to sign in with Discord) Optional sign-in

Web fonts are self-hosted on our own servers — loading our pages sends no font request to Google or any other third-party CDN.

A full list of our sub-processors is available at ohmylore.app/subprocessors.

Email: Transactional and product emails (sign-up confirmation, campaign invites, session reminders, wishlist updates) are sent via Loops (Loops, Inc.); billing receipts are sent by Polar; authentication emails (e.g. password reset) may also be sent by Firebase Authentication (Google). Support correspondence goes through Google Gmail (support@ohmylore.app).

We do not sell your personal information. We do not share it for cross-context behavioural advertising.

5. International Transfers

Some of our sub-processors are based in the United States (Google, Polar, RevenueCat, Apple, Loops, Discord). Your data may therefore be transferred to the US. Vertex AI processing takes place in the EU (europe-west1), and Capgo (our over-the-air update provider) is based in France (EU).

We rely on the following safeguards under GDPR Chapter V:

You can request a copy of the relevant safeguards by emailing support@ohmylore.app.

6. Content Visibility Inside the Service

Oh My Lore! is a collaborative platform. Please understand how content visibility works:

Anything you mark public within a campaign is seen by the players in that campaign. That is intentional and necessary for the Service to work.

Public pages outside the Service: Two kinds of pages are reachable by anyone with the link, without signing in: campaign share cards (a static title-and-statistics card for a campaign, created when a member uses the Share function — it exposes no campaign content) and your Journey page at ohmylore.app/u/<your user ID>, which shows your display name and aggregate career statistics (counts of campaigns, quests, and similar — never campaign content, notes, or secrets). Journey sharing is enabled by default; you can turn it off at any time in the avatar menu under Privacy, which makes the page unavailable (HTTP 404). These pages are marked noindex so search engines are asked not to list them.

7. How Long We Keep Your Data

Data Retention
Account & campaign data As long as your account is active
Account deleted — “Keep Campaigns” mode Personal profile & claimed characters removed; campaigns you created remain accessible to other players
Account deleted — “Delete Everything” mode Campaigns you own — and all their maps, notes, quests and images — are permanently removed from active databases. Content you created inside other members’ campaigns may remain in those campaigns, with your identity unlinked.
Deleted map images in Firebase Storage Up to 30 days in a “trash” state before permanent purge
AI prompts (sent to Google Cloud Vertex AI) Not retained by us; Google may retain briefly for abuse-monitoring under its Cloud Data Processing Addendum
Technical / IP logs Up to 30 days for security and rate-limiting purposes
Backups Up to 90 days in encrypted backups before full rotation
Billing records (invoices, payment history) 10 years — required by Czech Act No. 235/2004 Sb. on VAT and Act No. 563/1991 Sb. on accounting

8. Your Rights Under GDPR

If you are in the EU, EEA, UK, or Switzerland, you have the following rights:

To exercise any of these rights: email support@ohmylore.app. We will respond within 30 days (GDPR Art. 12(3)). We may ask you to verify your identity before acting on the request.

There is no fee for a reasonable request. For manifestly unfounded or excessive requests (especially repetitive ones), we may charge a reasonable fee or refuse the request, per Art. 12(5).

9. California Residents — CCPA / CPRA

If you reside in California, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act.

Categories of personal information we collect (as defined by Cal. Civ. Code §1798.140):

Sources: directly from you; automatically from your device when you use the Service.

Purposes: as described in Section 3 above.

We do NOT sell or share personal information for cross-context behavioural advertising, in the meaning of CCPA / CPRA.

Your California rights:

To exercise these rights: email support@ohmylore.app with “CCPA Request” in the subject. We may ask you to verify your identity (at a minimum, we will verify you control the email associated with your account).

You may use an authorized agent; we will require written proof of authorization.

10. Security

We use:

No system is 100% secure. If we become aware of a personal data breach likely to result in risk to your rights and freedoms, we will notify the ÚOOÚ within 72 hours and, where appropriate, notify you directly, as required by GDPR Art. 33 and 34.

11. Children

Oh My Lore! is not intended for users under 15 years of age. This reflects the digital-consent age set by Czech Act No. 110/2019 Sb. §7 for GDPR Art. 8 purposes.

We do not knowingly collect personal data from users under 15. If you are a parent or guardian and you believe a user under 15 has provided us with personal data, please contact support@ohmylore.app and we will delete the information promptly.

Users between 15 and 18 should review this policy with a parent or guardian.

12. AI and Automated Processing

Oh My Lore! includes AI features: map generation, map scanning, lore generation, note scanning, and AI recap. These features are opt-in and clearly labelled.

When you use them:

AI-generated content is produced by a machine and may contain errors, biases, or unexpected content. You are responsible for reviewing anything you share with your campaign.

We do not make solely-automated decisions that produce legal or similarly significant effects about you. Quota enforcement and rate limiting are purely technical and do not affect your rights.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (if we have your address) and via an in-app notice before the change takes effect. The “Last updated” date at the top of this document will always reflect the most recent version.

Continued use of the Service after a change takes effect means you accept the updated Policy.

14. Contact

Oh My Lore! is a self-funded project. We process your data only as described above and only for as long as necessary. If anything here is unclear or you’d like something changed, we’d genuinely like to hear from you.