Privacy Policy
Quick Summary
- We’re a small, self-funded TTRPG campaign-management service operated from Czechia.
- We collect only what we need to run the Service: your email, your campaign content, and basic technical data.
- We use Google Firebase, Google Cloud Vertex AI (for AI features), and Polar (our Merchant of Record for payments) as our main sub-processors. See our Sub-processors list.
- We do not sell or share your personal information for advertising.
- You can access, export, correct, or delete your data at any time.
- Users must be 15 or older to use Oh My Lore!
For the shortest version: we treat your data the way we’d want ours treated. The long version is below.
1. Who We Are
Oh My Lore! (“we”, “us”, “our”) is operated by:
Tomáš Holocsy, sole trader (OSVČ) registered in the Czech Republic
IČO: 07942699 · DIČ: CZ9110126344 (VAT-identified person — not a VAT payer)
Place of business: Jabloňová 1723/71, Záběhlice, 106 00 Praha 10, Czech Republic
Registered in the Czech Trade Licensing Register (živnostenský rejstřík)
Contact for privacy matters: support@ohmylore.app
Phone: (+420) 793 913 700
No Data Protection Officer has been appointed — we are not required to appoint one under GDPR Art. 37 at our current scale. You can reach us directly at the address above.
This Privacy Policy applies to our websites at ohmylore.app, ohmylore.eu, ohmylore.quest, and to the Oh My Lore! mobile application (together, the “Service”).
2. What Data We Collect
| Category | Examples | How we get it |
|---|---|---|
| Account data | Email address, Firebase UID, display name | You provide it at signup |
| Campaign content | Campaigns, maps, submaps, NPCs, notes, quests, characters | You create it in the Service |
| Media | Profile images, uploaded character/map images, AI-generated maps | You upload it or ask us to generate it |
| AI prompts | Text descriptions and image scans you submit to AI features | You provide it when using Scan / AI Generation |
| Technical data | IP address, browser type, device type, timestamps of use, AI-generation quotas | Automatically when you use the Service |
| Push notification token | Device identifier issued by Google Firebase Cloud Messaging (FCM) | Generated when you enable push notifications |
| Payment data (web purchases) | Billing country and subscription status. Full card details stay with Polar, our Merchant of Record — card numbers never touch our servers. | You provide it at checkout on ohmylore.app |
| Payment data (iOS app purchases) | Subscription/entitlement status and App Store receipt identifiers (no card data — Apple processes the payment) | When you subscribe in the iOS app |
| Cookies & similar technologies | See our Cookie Policy | Set when you use the Service |
We do not collect: health data, political opinions, biometric data, or other GDPR “special category” data. Please do not include such data in your campaign content.
A note on our iOS App Privacy label: some third-party sign-in and messaging SDKs bundled in the iOS app (Google Sign-In, Firebase) declare in their own privacy manifests that they are technically capable of accessing additional categories such as phone number, coarse location, or diagnostic data. Apple requires our App Privacy label to reflect those SDK declarations, so the label lists them — but the Service itself does not request, use, or store these categories.
3. How We Use Your Data and Legal Basis
Under GDPR Art. 6, we process your data on the following bases:
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and maintain your account; sync campaigns across devices | Performance of a contract (Art. 6(1)(b)) |
| Generate AI content (maps, lore, note scans, recaps) | Consent (Art. 6(1)(a)) — you opt in per feature |
| Process payments and donations | Performance of a contract (Art. 6(1)(b)) and legal obligation (tax law) (Art. 6(1)(c)) |
| Protect against abuse (rate limiting, fraud prevention, quota enforcement) | Legitimate interest (Art. 6(1)(f)) — operating a safe service |
| Send service-related emails (account, billing, security) | Performance of a contract (Art. 6(1)(b)) |
| Send push notifications you enable (campaign invites, session reminders) | Consent (Art. 6(1)(a)) — you enable them; and performance of a contract (Art. 6(1)(b)) |
| Send marketing emails, if any | Consent (Art. 6(1)(a)) — you opt in, can opt out anytime |
| Improve the Service and troubleshoot | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal requests (e.g. court orders) | Legal obligation (Art. 6(1)(c)) |
We do not use your content to train AI models. Our AI sub-processor (Google Cloud Vertex AI) is contractually prohibited from using your prompts, uploaded images, or generated outputs to train its foundation models under Google’s Cloud Service Specific Terms and Data Processing Addendum.
4. Who We Share Your Data With (Sub-Processors)
We share data only with the following categories of recipients, each acting as a processor on our behalf:
| Recipient | What we share | Why |
|---|---|---|
| Google Ireland Ltd / Google LLC (Firebase & Google Cloud) | Account data, campaign content, media, technical data, push notification tokens | Hosting, authentication (incl. Google Sign-In), database (Firestore / Realtime DB), file storage, push messaging (Firebase Cloud Messaging) |
| Google Ireland Ltd / Google LLC (Vertex AI) | AI prompts, uploaded images (maps, notes, character sheets) | AI generation and OCR features — processing location europe-west1 (EU). Data is processed under Google’s Cloud Data Processing Addendum; not used to train models; limited abuse-monitoring retention may apply. |
| Polar Software, Inc. | Email, billing country, subscription status | Merchant of Record and payment processing for web purchases — Polar takes legal responsibility for VAT collection and remittance. We never see full card numbers. |
| RevenueCat, Inc. (US) | Firebase UID, email, purchase/entitlement status, App Store receipt identifiers | iOS subscription management and entitlement validation |
| Apple Inc. (US) | Payment and receipt data for App Store purchases; Apple ID (if you use Sign in with Apple) | Seller of record for iOS in-app purchases; optional sign-in |
| Loops, Inc. (US) | Email address, name | Transactional and wishlist emails |
| Capgo SAS (France, EU) | Device/app version, IP address | Over-the-air app update delivery for the mobile app |
| Discord Inc. (US) | Basic profile data (only if you choose to sign in with Discord) | Optional sign-in |
Web fonts are self-hosted on our own servers — loading our pages sends no font request to Google or any other third-party CDN.
A full list of our sub-processors is available at ohmylore.app/subprocessors.
Email: Transactional and product emails (sign-up confirmation, campaign invites, session reminders, wishlist updates) are sent via Loops (Loops, Inc.); billing receipts are sent by Polar; authentication emails (e.g. password reset) may also be sent by Firebase Authentication (Google). Support correspondence goes through Google Gmail (support@ohmylore.app).
We do not sell your personal information. We do not share it for cross-context behavioural advertising.
5. International Transfers
Some of our sub-processors are based in the United States (Google, Polar, RevenueCat, Apple, Loops, Discord). Your data may therefore be transferred to the US. Vertex AI processing takes place in the EU (europe-west1), and Capgo (our over-the-air update provider) is based in France (EU).
We rely on the following safeguards under GDPR Chapter V:
- Google Cloud (including Vertex AI): certified under the EU–U.S. Data Privacy Framework (DPF). See dataprivacyframework.gov.
- Polar Software, Inc.: Standard Contractual Clauses (SCCs) under EU Commission Implementing Decision 2021/914.
- RevenueCat, Inc.: Standard Contractual Clauses (SCCs) and/or the EU–U.S. Data Privacy Framework.
- Apple Inc.: Standard Contractual Clauses (SCCs) and/or the EU–U.S. Data Privacy Framework.
- Loops, Inc.: Standard Contractual Clauses (SCCs).
- Discord Inc.: Standard Contractual Clauses (SCCs) and/or the EU–U.S. Data Privacy Framework.
You can request a copy of the relevant safeguards by emailing support@ohmylore.app.
6. Content Visibility Inside the Service
Oh My Lore! is a collaborative platform. Please understand how content visibility works:
- Public (within campaign): Visible to every member of that campaign.
- Private: Visible only to the creator and users explicitly named in the “Shared With” list.
- Game Masters (GMs): Have elevated visibility to run sessions, including seeing through “Fog of War” on maps.
- Guest mode: Stored only in your browser; nothing is written to our servers.
Anything you mark public within a campaign is seen by the players in that campaign. That is intentional and necessary for the Service to work.
Public pages outside the Service: Two kinds of pages are reachable by anyone with the link, without signing in: campaign share cards (a static title-and-statistics card for a campaign, created when a member uses the Share function — it exposes no campaign content) and your Journey page at ohmylore.app/u/<your user ID>, which shows your display name and aggregate career statistics (counts of campaigns, quests, and similar — never campaign content, notes, or secrets). Journey sharing is enabled by default; you can turn it off at any time in the avatar menu under Privacy, which makes the page unavailable (HTTP 404). These pages are marked noindex so search engines are asked not to list them.
7. How Long We Keep Your Data
| Data | Retention |
|---|---|
| Account & campaign data | As long as your account is active |
| Account deleted — “Keep Campaigns” mode | Personal profile & claimed characters removed; campaigns you created remain accessible to other players |
| Account deleted — “Delete Everything” mode | Campaigns you own — and all their maps, notes, quests and images — are permanently removed from active databases. Content you created inside other members’ campaigns may remain in those campaigns, with your identity unlinked. |
| Deleted map images in Firebase Storage | Up to 30 days in a “trash” state before permanent purge |
| AI prompts (sent to Google Cloud Vertex AI) | Not retained by us; Google may retain briefly for abuse-monitoring under its Cloud Data Processing Addendum |
| Technical / IP logs | Up to 30 days for security and rate-limiting purposes |
| Backups | Up to 90 days in encrypted backups before full rotation |
| Billing records (invoices, payment history) | 10 years — required by Czech Act No. 235/2004 Sb. on VAT and Act No. 563/1991 Sb. on accounting |
8. Your Rights Under GDPR
If you are in the EU, EEA, UK, or Switzerland, you have the following rights:
- Right of access (Art. 15) — ask what data we hold about you.
- Right to rectification (Art. 16) — correct inaccurate data.
- Right to erasure / “right to be forgotten” (Art. 17) — delete your data. You can trigger this from Account Settings.
- Right to restrict processing (Art. 18).
- Right to data portability (Art. 20) — export your campaign data in a machine-readable format.
- Right to object (Art. 21) — to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3)) — for AI features and marketing, at any time.
- Right not to be subject to solely automated decision-making (Art. 22) — we do not make automated decisions with legal or similarly significant effects about you. AI generation produces content; it does not decide anything about your access or rights.
- Right to lodge a complaint with the Czech supervisory authority: Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic — https://www.uoou.cz/. You may also complain to the supervisory authority in your country of residence.
To exercise any of these rights: email support@ohmylore.app. We will respond within 30 days (GDPR Art. 12(3)). We may ask you to verify your identity before acting on the request.
There is no fee for a reasonable request. For manifestly unfounded or excessive requests (especially repetitive ones), we may charge a reasonable fee or refuse the request, per Art. 12(5).
9. California Residents — CCPA / CPRA
If you reside in California, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act.
Categories of personal information we collect (as defined by Cal. Civ. Code §1798.140):
- Identifiers (email, user ID, IP address)
- Customer records (billing name, country)
- Internet / device activity (browser type, usage)
- Geolocation data — approximate, derived from IP only
- User-generated content (your campaigns, notes)
Sources: directly from you; automatically from your device when you use the Service.
Purposes: as described in Section 3 above.
We do NOT sell or share personal information for cross-context behavioural advertising, in the meaning of CCPA / CPRA.
Your California rights:
- Right to know what personal information we collect, use, disclose, and share.
- Right to delete.
- Right to correct.
- Right to opt out of sale or sharing (we don’t sell or share — included for completeness).
- Right to limit use of sensitive personal information.
- Right to non-discrimination for exercising these rights.
To exercise these rights: email support@ohmylore.app with “CCPA Request” in the subject. We may ask you to verify your identity (at a minimum, we will verify you control the email associated with your account).
You may use an authorized agent; we will require written proof of authorization.
10. Security
We use:
- HTTPS (TLS) for all traffic.
- Strict Content Security Policy and HTTP Strict Transport Security headers.
- Firebase Security Rules to ensure only authorised users access specific campaign data.
- Encryption at rest provided by Google Cloud Storage and Firestore.
- Rate limiting and abuse prevention.
No system is 100% secure. If we become aware of a personal data breach likely to result in risk to your rights and freedoms, we will notify the ÚOOÚ within 72 hours and, where appropriate, notify you directly, as required by GDPR Art. 33 and 34.
11. Children
Oh My Lore! is not intended for users under 15 years of age. This reflects the digital-consent age set by Czech Act No. 110/2019 Sb. §7 for GDPR Art. 8 purposes.
We do not knowingly collect personal data from users under 15. If you are a parent or guardian and you believe a user under 15 has provided us with personal data, please contact support@ohmylore.app and we will delete the information promptly.
Users between 15 and 18 should review this policy with a parent or guardian.
12. AI and Automated Processing
Oh My Lore! includes AI features: map generation, map scanning, lore generation, note scanning, and AI recap. These features are opt-in and clearly labelled.
When you use them:
- Your prompt (text and/or image) is sent to Google Cloud Vertex AI (processing location europe-west1, EU) for processing.
- The AI returns generated content.
- Google processes the data under its Cloud Data Processing Addendum and does not use it to train models; limited abuse-monitoring retention may apply on Google’s side. We do not retain your prompts beyond serving the request.
- We do not use your content to train AI models, and Google Cloud Vertex AI is contractually prohibited from using your prompts, uploaded images, or generated outputs to train its foundation models under the Google Cloud Data Processing Addendum.
- You retain ownership of inputs and outputs under our Terms and Conditions.
- You can withdraw AI-processing consent at any time in the app’s AI consent settings or via support@ohmylore.app.
AI-generated content is produced by a machine and may contain errors, biases, or unexpected content. You are responsible for reviewing anything you share with your campaign.
We do not make solely-automated decisions that produce legal or similarly significant effects about you. Quota enforcement and rate limiting are purely technical and do not affect your rights.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (if we have your address) and via an in-app notice before the change takes effect. The “Last updated” date at the top of this document will always reflect the most recent version.
Continued use of the Service after a change takes effect means you accept the updated Policy.
14. Contact
- Email: support@ohmylore.app
- Post: Tomáš Holocsy, Jabloňová 1723/71, Záběhlice, 106 00 Praha 10, Czech Republic
- Phone: (+420) 793 913 700
- Czech supervisory authority: https://www.uoou.cz/
Oh My Lore! is a self-funded project. We process your data only as described above and only for as long as necessary. If anything here is unclear or you’d like something changed, we’d genuinely like to hear from you.