Privacy Policy
Last updated: July 23, 2026
1. Overview
This Privacy Policy explains how Omniarole ("Omniarole", "we", "us") processes personal data when you visit the marketing website at omniarole.com and when you use the Omniarole platform (world building, campaigns, session desk, bestiary, initiative tracker, AI features, and related tools).
Omniarole is currently offered in early access on a free basis. This notice is provided under the EU General Data Protection Regulation (GDPR) and applicable Italian privacy law.
2. Data controller
Omniarole is operated by an independent individual creator (Luca), not a company entity. The data controller is the operator of Omniarole.
For identity and background information about the operator, see the About page. For contact channels, see the Contact page.
Privacy requests can be sent to admin@omniarole.com. You may also reach us via Discord as described on the Contact page.
3. Categories of personal data we process
Depending on how you use Omniarole, we may process:
- Account data: email address, password (stored as a one-way hash, never in plain text), display/account preferences (such as language or theme), email verification status, and password-reset / email-verification token hashes with expiry timestamps.
- User-generated content: worlds, handbook categories and articles, timelines and events, bestiary groups and creature sheets, campaigns, party data, game-session notes, maps, relationships, gallery images you upload, DM screen usage context, and other content you create or import into the platform.
- Combat / initiative data: live battle state shared between DM and players (including battle codes and combatant information entered during a session).
- AI-related data: prompts you submit to the AI assistant or generation tools; retrieved context derived from content you choose to train/embed (for example handbook articles and session notes); embeddings/vector representations of that content; and model responses returned to you. Token/usage counters used to operate free early-access limits may also be stored on your account.
- Community sharing data: if you publish or share a Community world (or make content visible to others), the shared content and related metadata become visible according to the sharing settings you choose.
- Technical / security data: IP address, user agent, timestamps, and similar request context when needed for authentication, abuse prevention, diagnostics, and account audit events (for example sign-in, password change, or account deletion events).
- Local device data: the browser may store session tokens and offline drafts/queues on your device (for example locally saved article or session-desk edits waiting to sync) so features keep working when connectivity is limited.
- Support communications: messages you send us by email or Discord when you ask for help or report issues.
We do not currently collect payment card data or subscription billing data through Omniarole, because the platform is in free early access. If you support the project through voluntary external platforms (for example Ko-fi or Patreon), those platforms process payment data under their own privacy policies; Omniarole does not receive your full payment card details.
4. Purposes and legal bases
We process personal data only for the purposes below, and on the legal bases indicated (GDPR Art. 6):
- Provide the service you request (create and manage your account; store and display your content; run campaigns, session desk, bestiary, timelines, maps, gallery, and initiative tracker; sync offline drafts when you reconnect).
Legal basis: performance of a contract (Art. 6(1)(b)): providing Omniarole under the Terms of Service. - AI features you choose to use(assistant answers, one-shot / scenario generation, embedding/"Train AI" so retrieval can ground answers in your content).
Legal basis: performance of a contract (Art. 6(1)(b)) for features included in the service you activate; where a specific optional processing requires consent under applicable law, we will ask for it. - Security, abuse prevention, and service integrity (authentication, rate limiting, fraud/abuse detection, incident investigation, account audit logging).
Legal basis: legitimate interests (Art. 6(1)(f)): keeping the platform secure and usable for all users; and/or contract performance where inseparable from delivering the service. - Support and communications you initiate (replying to requests, bug reports, and collaboration inquiries).
Legal basis: legitimate interests (Art. 6(1)(f)) and/or contract performance (Art. 6(1)(b)), depending on the request. - Legal compliance (responding to lawful requests, exercising or defending legal claims, complying with mandatory retention where applicable).
Legal basis: legal obligation (Art. 6(1)(c)) and/or legitimate interests (Art. 6(1)(f)).
We do not currently run broad product-analytics or advertising tracking on the marketing site or inside the product. If that changes, we will update this Policy and, where required, obtain consent (for example for non-essential cookies).
5. AI processing in more detail
When you use AI features, relevant content (such as your prompt and, for grounded answers, retrieved excerpts from content you trained) is sent to AI service providers so they can generate embeddings or responses. That processing is necessary to deliver the AI feature you requested.
Embedding / "Train AI" is intentional and user-triggered: content is not embedded for AI retrieval merely because you saved it. You decide when to train articles or session notes.
Please avoid putting unnecessary real-world personal data about third parties into worlds, notes, or prompts. You are responsible for the lawfulness of content you upload.
6. Recipients and processors
We use trusted service providers that process data on our behalf only as needed to operate Omniarole. Categories include:
- Cloud database and storage providers for account and application data.
- AI infrastructure providers for embeddings, retrieval, and language-model generation when you use AI features.
- Hosting and infrastructure providers that serve the website and APIs.
- Communication tools you choose to use with us (for example email or community support channels listed on the Contact page).
- Voluntary support platforms if you decide to donate or support the project externally; those platforms process data under their own privacy policies.
We do not sell your personal data. We share data with third parties only to operate the service, comply with law, or protect rights and security.
7. Where data is stored and international transfers
Omniarole application data is primarily stored in Europe. Some providers (especially AI providers) may process data in other countries, including outside the European Economic Area (EEA).
Where personal data is transferred outside the EEA, we rely on appropriate safeguards recognized by applicable law (for example the provider's Standard Contractual Clauses and related transfer mechanisms), together with technical and organizational measures.
8. Retention periods
We keep personal data only as long as needed for the purposes above:
- Account and user content: for the life of your account, until you delete the account (or specific content), unless a shorter deletion applies to a feature.
- Email verification / password reset tokens: until they expire or are consumed, then discarded.
- Live combat battles: temporary session state; inactive live battles are cleaned up automatically after about 7 days without updates.
- Account audit / security logs: retained for a limited period for security and accountability (typically up to about 1 month), then deleted by automated cleanup.
- AI embeddings: kept while the related account / world content remains and embeddings are needed for AI features; removed when you delete the related content/account or when embeddings are otherwise cleared as part of normal operations.
- Support messages: kept as long as needed to handle your request and for a reasonable follow-up period.
- Local drafts on your device: remain in your browser storage until synced, cleared by you, or removed by browser/storage cleanup.
9. How deletion works
You can delete personal data in these ways:
- Delete specific content inside the product (for example an article, world, campaign, or creature) using the normal in-app delete actions.
- Delete your entire account from Account settings (danger zone). Account deletion removes your account and cascades to associated world/content data held by Omniarole for that account, including related AI embedding collections where applicable.
- Request deletion by email at admin@omniarole.com if you cannot access the account. We may need to verify that you are the account holder before acting.
After a deletion request is completed, residual copies may persist for a short technical period in backups or caches until they rotate out, and limited records may be retained where required for security or legal reasons (for example a deletion audit event).
10. Your rights
Under the GDPR, you may have the right to:
- access your personal data;
- rectify inaccurate data;
- erase data ("right to be forgotten"), subject to legal limits;
- restrict or object to certain processing;
- data portability, where applicable;
- withdraw consent, where processing is based on consent;
- lodge a complaint with a supervisory authority. In Italy, that is the Garante per la protezione dei dati personali (garanteprivacy.it).
To exercise these rights, contact admin@omniarole.com. We will respond within the timeframes required by law.
11. Cookies and local storage
Omniarole uses technical storage needed to keep you signed in and to make core features work (for example authentication tokens and offline draft queues). These are necessary for the service and are not used for advertising profiling.
If we introduce non-essential cookies or analytics in the future, we will update this Policy and request consent where required.
12. Children
You must be at least 16 years old to create and use an Omniarole account, consistent with our Terms of Service. Omniarole is not directed at children under 16.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The version published on this page is the current version. For material changes, we will provide reasonable notice through the service or other appropriate channels.
14. Contact
Privacy questions and GDPR requests: admin@omniarole.com.
More operator information: About. Other contact options: Contact.