Privacy Policy

Last updated: 14 August 2026

RollCamp (“the App”, “the Service”, “we”) is a tool for creating Dungeons & Dragons characters and for running campaigns and live game sessions. This policy explains what personal data we process, why, who else gets to see it, and what you can ask us to do with it, in accordance with Regulation (EU) 2016/679 (“GDPR”).

In short: we process what an account needs, what you choose to create, and what the Service technically needs in order to run. We keep anonymous usage statistics on our own server, without cookies and without ever identifying you; we use no advertising cookies, we do not profile you, and we do not sell your data. Webcam and microphone in a live session travel directly between players and are never recorded by us. The one thing that leaves that perimeter is voice transcription, which happens only if you allow it, one person at a time: before you decide, read §6 — it also says that the provider uses that audio to train its own models, and that opting out is not possible.

1. Who is responsible for your data

The data controller is Giuseppe Gioi, sole trader, Italian VAT number 01776480053, reachable at [email protected]. No Data Protection Officer has been appointed: for anything concerning your data, write to that address.

2. What we process

Not everything below applies to everyone: what we hold depends on how you sign in and on what you create.

Account and profile

  • Sign-up with email and password: your name, your email address, and your password stored only as a salted scrypt hash. We never see and never store passwords in readable form.
  • Sign in with Google: your name, your email address and, where available, your profile picture, plus the OAuth tokens that keep the connection working. We never receive your Google password.
  • Profile: the display name you are known by at the table and, if you upload one, a profile picture.
  • Verification: whether your address has been confirmed, and the short-lived tokens used to verify it or to reset your password.

The content you create

  • Characters: the sheet itself (class, species, background, ability scores, spells, equipment, coins, hit points), the portrait you upload, and any free text you write — appearance, personality, notes.
  • Campaigns: name, description, invite code, background image, the date of the next session, and the state of the game board.
  • Membership: which campaigns you belong to, and with which role — Dungeon Master or player.
  • Your creations: tactical maps and the tokens on them, homebrew monsters, NPCs.
  • Campaign Archive: the images, soundtracks and documents you upload, together with the sharing choices attached to each of them.
  • Notes and tags: the personal notes you write in the App and the labels you organise them with.

Preferences

Your 3D dice style and the language you chose for the interface.

Technical data

  • A strictly necessary session cookie, which is what keeps you signed in.
  • For every session we store its token and expiry, the IP address and the browser user agent it was opened from. This is how we keep sessions valid and how we spot abuse. Signing out deletes the record; an expired session no longer gives access, and its record goes with your account.
  • The server logs that normal operation produces.

Usage statistics

We count page views with Umami, which runs on our own server: for each visit it records the page, where you arrived from, your browser, operating system, device type, screen size and language, and roughly where you are connecting from — country, and the region and city your network is attributed to. It sets no cookies, it does not follow you across other websites, and none of it reaches a third party — the statistics never leave the machine that already runs the App.

A returning visit is recognised only through a one-way hash that mixes your IP address and browser with a secret of ours that changes every month. The IP address itself is never stored, and once that secret rotates, older visits can no longer be tied to anyone at all.

Storage

For each file you upload we record its size and kind, which is how the gauge in your profile knows how much of your allowance you are using.

Live game sessions

  • While a session is running we handle in real time presence and “ready” status, dice rolls, chat messages, pings and reactions, token movements, and the values that change during play: hit points, coins, spell slots, inventory. Two things out of that traffic remain: the character’s values, which are written onto their sheet — it is the sheet that changes, not an archive of the evening — and the notable facts, which become the campaign’s chronicle (below). The rest — presence, pings, token movements — simply passes through.
  • Webcam and microphone work peer-to-peer (WebRTC): the streams travel straight between participants and are never recorded or stored by us. Our server only helps to set the connection up. Voice transcription does not capture this stream but your own microphone, inside your own browser: how it works, who processes it and what survives it is all in §6.
  • Because that connection is direct, participants’ IP addresses are exchanged between their browsers and with the STUN/TURN servers used to negotiate a route. This is how WebRTC works everywhere it is used, not a choice specific to RollCamp — if you would rather not, leave camera and microphone off.
  • The chat and the dice on screen are ephemeral: whoever joins later does not see what came before, and closing the room leaves nothing to reopen. What is written down from a game night are its notable facts, which make up the campaign’s chronicle: dice rolls with their label and result, chat messages, the start and end of a fight, tokens and maps brought into the scene, who went down, and the name of whoever did each of these. Token movements are not.

3. Why we process it, and on what legal basis

  • Running the Service — your account, your saved characters and campaigns, the live table: performance of a contract (Art. 6(1)(b) GDPR).
  • Sending transactional email — address verification, password reset: performance of a contract and pre-contractual steps.
  • Authentication, security, the storage allowance and abuse prevention: legitimate interest (Art. 6(1)(f)) in keeping the Service working and available to everyone.
  • Counting page views, to know which parts of the Service are used and which are not: legitimate interest (Art. 6(1)(f)) in improving it. The measurement is anonymous and sets no cookies, which is why it does not rest on consent — §2 says exactly what it records.
  • Answering what you write to us, including requests about your own data: legitimate interest and legal obligation.
  • Transcribing the voice during a game night and writing the Recap from it: consent (Art. 6(1)(a) GDPR), given when the account is registered, together with accepting the Terms. It is the only basis this rests on. See §6, which describes the processing in full.

We do not use your data for advertising or profiling, and no decision that affects you is taken by automated means.

4. Who else can see your content

RollCamp is a shared tool, so part of what you create is meant to be seen by other people. These are the rules:

  • Your character sheets are visible to you and to the Dungeon Master of the campaign they belong to. The other players see only what surfaces during a session — the token, the name, what is shared on the board.
  • Archive media uploaded by the Dungeon Master are shared as they decide: with the whole table, or only with the players they pick one by one.
  • Your personal notes are always private. Nobody else sees them — not the other players, not the Dungeon Master — and the tags you file them under are yours alone.
  • Maps, homebrew monsters and NPCs are the Dungeon Master’s material: players see them only once they are put in play.
  • During a live session, what you write in chat, the dice you roll, and your camera and microphone if you switch them on are visible to everyone in the room.
  • A game night’s Recap starts as the Dungeon Master’s private draft, which they can correct; once they publish it, the whole table of that campaign can read it.
  • Your display name and profile picture are visible to the other members of the campaigns you join.

5. Where your data lives, and who we share it with

The application and the database run on a virtual server operated by IONOS in the European Union. The database is not reachable from the internet, and its backups are kept in a separate, private storage bucket.

To provide the Service we also rely on the providers below. They process data on our instructions (processors), except where stated otherwise:

  • IONOS — the server that runs the application and the database (EU).
  • Cloudflare (R2) — storing and delivering the files you upload.
  • Resend — transactional email: address verification and password reset. Established in the United States.
  • Google — “Sign in with Google”, if you use it, and the public STUN servers that help negotiate live-session connections.
  • A TURN server, where one is configured, used only to relay live-session traffic when a direct connection cannot be established.
  • Modulate — voice transcription during game nights. Established in the United States, where the audio is also stored, and it uses that audio to train its own models: it is all in §6, which is worth reading before you sign up.
  • Anthropic — the language model that writes a game night’s Recap. Established in the United States; it receives the night’s facts and, where there is one, the Transcript, and does not use them to train its own models.

Some of these providers may process data outside the EU/EEA, for instance in the United States. Where that happens the transfer rests on the safeguards the GDPR allows — Standard Contractual Clauses or an adequacy decision — except for voice transcription, which rests on the consent given at registration and has a section of its own, §6. We do not sell your data, and we do not share it for advertising.

6. Your voice, and what we do with it

RollCamp transcribes what is said during a game night and turns it into a Recap, the story of how the evening went. Consent to this processing is given by registering an account, together with accepting the Terms: it is not asked a second time, and there is no switch that takes it away. This section tells you in full what happens to your voice, unpleasant parts included — it is written to be read before you create the account, because that is where the choice is made.

How it is captured

The recorder is your own browser, and only your own microphone: there is no central recorder collecting everybody’s voice. The control you keep follows from that, and it is a real one: with your microphone off you produce no audio at all — it is not filtered out afterwards, it is never produced. You can switch it off whenever you like, without asking anyone; the Dungeon Master can additionally pause recording for the whole table.

Who processes it, and where

The audio is sent to Modulate, Inc., which transcribes it on our behalf. Processing and storage take place in the United States: fragments of your voice leave the European Economic Area and remain on the provider’s systems, which it states keeps them for 35 days and then deletes them. The provider also states that audio may undergo automated analysis estimating the speaker’s age and gender: it is not something we ask for, nor is it returned to us, but it happens on its systems and it belongs here. For this transfer we hold no safeguards equivalent to the European ones: it rests on your explicit consent (Art. 49(1)(a) GDPR), given after being informed of that risk.

It is used to train the provider’s models

This is the part you need before you decide, so we write it out in full. On the plan we use, Modulate enrols its customers in its own model-improvement programme as a condition of using the platform: the audio we send and the text drawn from it also serve to train its speech-recognition systems, and opting out is not possible — there is no setting to switch off, not on your side and not on ours. We chose this provider knowing that, and telling you is the only thing we can put in place of a switch that does not exist. If that is not acceptable to you, the only way to withhold consent is not to create the account: it is part of registration, and there is no box to leave unticked. If you already have an account, what remains in your hands is the microphone — switched off it produces no fragment at all, and that is a real control because the recording is done by your own browser — and closing the account.

The Transcript lasts only as long as it is needed

The Transcript — the text of what was said — exists only for as long as it takes to write that night’s Recap, and is then deleted. While it exists it is readable by nobody, the Dungeon Master included: it is not the record of the evening, it is the scaffolding used to build one. The audio, for its part, never enters our storage and is discarded as soon as it has been transcribed.

The Recap, by contrast, stays

The Recap is drawn from the facts the night produces on its own — dice rolls, chat messages, tokens brought into the scene — and, where there is one, from the Transcript. It is written by a language model from Anthropic (United States), which receives that material in order to generate it and does not use it to train its own models. It starts as the Dungeon Master’s private draft, which they can correct and choose to publish to the table; from then on it is part of the campaign’s chronicle, and it lives as long as the campaign does.

What you can stop, and what does not come back

There is no per-person withdrawal: consent is part of registering the account, and the only way to take it back entirely is to close the account. What you can stop at any time, without asking anyone, is your microphone: switched off it produces nothing, and it is a real control because the recorder is your own browser. Two things do not come back either way: Recaps already written stay — they are the campaign’s shared story and they concern the other people at the table too — and audio already sent to Modulate has already entered its training and cannot be recalled.

7. How long we keep it

  • Account and content: for as long as your account exists.
  • Sessions: a session record lasts until you sign out; once expired it gives no access, and it is deleted with your account. Verification and password-reset tokens expire within hours.
  • Live sessions: video and audio are not kept at all. What does remain are a game night’s notable facts — dice rolls, chat messages, the start and end of fights, tokens and maps brought into the scene, who went down, with the name of whoever did each of them — because they are the campaign’s chronicle: they live as long as the campaign, and go with it.
  • Voice, Transcript and Recap: the audio never enters our storage and is discarded as soon as it has been transcribed; the Transcript is deleted as soon as the Recap is written. The Recap stays for as long as the campaign does. On its own side the provider states that it keeps the audio for 35 days — see §6, which also covers what it does with it in the meantime.
  • Backups: database copies rotate and are overwritten, so what you delete from the live database also leaves the backups within the rotation window.

When you delete your account, everything attached to it goes with it and the files you uploaded are removed from storage. Read the Terms of Service first: deleting your account also deletes the campaigns you own, and their other members lose access to them.

8. Your rights

You have the right to access your data, to rectify it, to erase it (“right to be forgotten”), to restrict its processing, to object to processing based on legitimate interest, and to receive your data in a portable format.

Some of these you exercise yourself, without asking us: from your profile you can change your name, your picture and your password, and you can delete your account together with everything attached to it.

For anything else, write to [email protected]: we reply within one month. You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali.

9. Cookies

We use only strictly necessary cookies: the one that keeps you signed in, and the one that remembers the language you picked. No advertising or profiling cookies, ours or anyone else’s — and the usage statistics of §2 set none either, which is why the App never asks you for cookie consent.

Your browser also keeps a few interface preferences locally; they never leave your device.

10. Security

We take reasonable technical and organisational measures: passwords stored as a salted scrypt hash, encrypted connections (HTTPS), a database unreachable from the internet, real-time access authorised by short-lived signed tokens, permission checks on every operation, and regular backups.

No system is completely secure and we cannot promise otherwise. Should a breach occur that is likely to result in a high risk to your rights, we will tell you, as Art. 34 GDPR requires.

11. Children

The Service is not intended for children under 16. If you are under 16 you may use it only with the consent and supervision of a parent or guardian. If we learn that we hold the data of a child under 16 without it, we delete it.

12. Changes to this policy

We may update this policy as the Service grows. The date at the top of the page always tells you which version you are reading; if a change materially affects how we use your data, we will tell you by email or with a notice in the App.

13. Contact

For anything about your privacy — a request, a doubt, a complaint — write to [email protected]. See also our Terms of Service.