01What we collect#
Just what we need to run Volvelle for you. Email and password for sign-in, the characters and maps you make, and a few small records that keep the service working. No advertising profiles. No data sold.
When you create an account, we store:
- Account: your email address and a salted password hash, handled by Supabase Auth.
- Profile: your display name and optional profile fields and settings.
- Game content: characters, maps, battles, campaigns, friend relationships, homebrew, and other things you create or save.
- Images: the avatars, portraits and blog images you upload.
- Shared relationships: a friendship, campaign membership or battle membership records that both people agreed to it, and which of the two confirmed it. Relationships that existed before this record arrived count as agreed, because both people had already chosen them.
- Operational records: to keep the service running and protect it from abuse we keep small records: how much you have uploaded recently, a note of an image upload or removal still in progress, counts of requests to the public forms, a receipt for each message you send us, daily signup-health totals, and anonymous reports of critical failures. None hold your email address, password, IP address, a complete web address, game content, or anything you typed, and the failure reports and request counts are not linked to your account. They are listed field by field near the end of this policy.
We do not run third-party advertising trackers, build a behavioral profile of you, or sell or rent your data.
02Where it lives#
Volvelle uses Supabase for sign-in, the database, live updates between players, file storage, and short-lived anonymous failure reports. On the hosted service, account data and game content are stored in the European Union, in Frankfurt, Germany. Database rules limit reads and writes to the people and roles that need them.
The hosted website runs on Vercel and its files are served from Vercel's global network. There is no separate Volvelle application server. Two small Supabase functions handle signed-in image uploads and the account deletion that erases your stored files.
Some data stays in your browser rather than on a server: appearance and accessibility settings, cached game reference data, your optional analytics choice, a local player identifier, browser-only maps and their private notes, War Table counters, roll macros, sheet preferences, and a few short-lived handoffs that carry an invitation or a return address across the new tab a confirmation email opens. Each account's browser-only data is kept under its own key, so one person's work is never shown to the next person who signs in on the same browser, and switching accounts never imports another account's cache. Records left by older versions that were not separated this way stay quarantined: Volvelle does not open them or export them to the signed-in account, and the data panel offers a separate control to delete them. Exporting or clearing browser-only data covers the signed-in account only. The cookie policy lists every one of these records by name.
Two of those deserve their own mention. The signup return journey holds the email being confirmed, the name of the journey you were on, an allowed Volvelle destination, and timing fields; it expires after 15 minutes and never holds a password, confirmation code, map content, account ID, or complete web address. The friend, campaign, and map-save handoffs each last at most 30 minutes, are removed after use or the first time they are read once expired, and are never sent to analytics. The confirmation email itself receives only an ordinary screen such as /map, never the map room key.
After a critical failure, this tab may keep up to 12 diagnostic records for two hours, or until the tab closes. You can preview, download, or clear them. Opening the preview sends nothing. Attaching diagnostics to a message you send us is a separate choice that is off by default. Only records with a live support code can attach that code. Local-only fields stay in this tab and are never included in contact email.
The error-reporting and contact forms are open to everyone, so Volvelle has to tell one visitor from another without keeping anyone's address. Supabase passes the request's forwarded network chain to the database; Volvelle uses the configured number of trusted proxy hops to pick out the visitor address, then immediately turns it into a one-way code that changes every day and cannot be turned back into an address. There is no automatic hop-count default, so this stays switched off until the operator states how the deployment sits behind its proxies. The raw address and forwarded chain are not stored in Volvelle's tables, the daily code is not linked to any account, and it is never used to restrict an account or for analytics. If the scheduled clean-up of these records ever stops working, Volvelle stops accepting new failure reports and contact messages rather than letting them pile up.
If you self-host Volvelle, you control your own Supabase project, deployment, processors, email sender and operator inbox, and data locations.
03How long we keep it#
We keep your content while your account exists, unless you delete it sooner. The small operational records expire on a fixed clock.
- Account and saved content: kept until you delete the item or delete your account.
- Images: kept until you remove them or delete your account.
- Shared relationships: the record that both people agreed to a friendship or membership lasts as long as the relationship, and goes when it is removed or when either account is deleted.
- Friend invite links: expire 30 days after creation, and expired ones are deleted.
- Map handovers: an offer to hand one of your saved maps to a friend keeps the map, both accounts, and the map's name as it stood when you offered it. It expires seven days after you make it and is then deleted; cancelling, declining or accepting removes it straight away.
- Signup return journey: expires after 15 minutes. The friend, campaign, and map-save handoffs expire after 30 minutes and are removed after use or at the next expiry check.
- Unconfirmed accounts: removed within seven days if the email address was never confirmed. You can sign up again later.
- Notifications: kept until dismissed; a read notification is kept for no more than 90 days.
- Contact messages: your email address and message pass through Supabase's email provider to the operator's inbox and are not copied into Volvelle's own records. Resend and the operator's inbox keep what reaches them under their own policies. What Volvelle keeps is a receipt with no email address and no message content, deleted within 48 hours; neither a queued response nor provider acceptance confirms delivery to the operator inbox. If you attached diagnostics, the email includes only the live support codes you picked, and local-only diagnostic fields are not emailed.
- Operational records: request counts and message receipts go within 48 hours, an individual failure report within seven days, and daily failure and signup-health totals within 90 days. Two things do not run on that clock: your upload limits stay while your account exists and are deleted with it, and an image upload or removal that fails in a way we cannot confirm either way stays until it is sorted out, with account deletion waiting for it so no file is left behind.
- Optional analytics: aggregate counts and performance summaries only, and only if you allow them.
If measured automated traffic threatens confirmation or password-recovery email, Volvelle may temporarily switch on the Cloudflare Turnstile check for signup, sign-in, code resend, passwordless, and password-recovery forms. Cloudflare then processes the network and browser signals it needs to issue and verify a short-lived, single-use challenge, and its own service may show aggregate challenge statistics by country, browser, operating system, network, and IP address. Volvelle does not copy those into its database, use the challenge for advertising or product analytics, or treat its result as a label on your account. The check remains off in ordinary operation.
A restricted admin view can count how many current accounts share an email domain, and only when at least five signups share it within seven days. That is a volume observation, never a label on anyone or a reason to restrict anyone, and the domain is never added to the stored daily counts.
Signed-in sessions end after 90 days without activity or 180 days in total, whichever comes first, and Supabase applies those limits when the session refreshes.
04Optional analytics#
Plausible usage analytics and Vercel Speed Insights performance measurement are optional. They do not load while your choice is missing, undecided, or declined. One Volvelle choice covers both providers. You can allow or decline from the first-run choice and change that decision in your profile later. Withdrawing permission stops new measurements immediately, including measurements already queued in the current page.
Both providers receive only a general Volvelle route template, such as /sheet/:characterId, rather than the address in your browser. Query strings, invitation and campaign codes, and map, character, campaign, or content identifiers are removed before an optional event is sent.
Do Not Track and Global Privacy Control always override an earlier allowance. Core Volvelle features continue to work if you decline.
If optional analytics is allowed, an email-code result may contain only whether the flow was signup or sign-in, a broad result category, and a named journey such as saving a battle. It never contains the email address, confirmation code, account or resource ID, invitation or campaign join code, free text, or complete URL.
05Your rights#
You can access, export, correct, or delete your data. Most information can be viewed or changed directly in Volvelle. The profile page provides export and account-deletion controls. Contact us through the maintainer profile linked from the homepage footer if you need help exercising these rights.
If stronger local law applies to you, including the GDPR, UK GDPR, or California privacy law, those rights continue to apply.
06Sub-processors#
- Supabase: authentication, database, realtime synchronization, file storage, the temporary contact-provider queue, short-lived anonymous failure reports, and the temporary request counts for the public forms. It handles account details and the Volvelle content you save. Hosted project region: European Union, Frankfurt. Supabase DPA.
- Vercel: website hosting, content delivery, and optional Speed Insights. Serving the app necessarily handles standard request metadata such as IP address and user agent. Performance timings are sent only after optional analytics is allowed. Vercel is a United States company with a global edge network. Vercel DPA.
- Resend: transactional account email, contact delivery, and product or roadmap email that you separately choose. It receives email addresses and message contents needed for those sends, including live support codes only when you choose to attach them. Local-only diagnostic fields are not sent. Hosting region: United States. Resend DPA.
- Plausible: optional cookieless aggregate usage analytics, served through a first-party Volvelle path. It does not create a personal profile or track you across sites and does not load before permission. Hosting region: European Union. Plausible DPA.
- Cloudflare Turnstile: a security challenge used only when measured automated traffic threatens account email availability. While active, Cloudflare processes challenge, network, browser, and device signals and returns a short-lived verification token to Supabase Auth. Volvelle keeps no identity-level copy of Turnstile analytics. Cloudflare privacy policy.
Account emails such as confirmation codes, password resets, and sign-in links are necessary to operate an account. Product news, welcome messages, and roadmap email are off by default and send only after a separate opt-in. After an email address is confirmed, Volvelle may send the maintainer a non-identifying notice that an account was confirmed. Unusual growth in new unconfirmed accounts may create at most one aggregate notice per UTC day. Those notices contain counts, not email addresses, display names, account IDs, domains, or IP addresses, and never restrict an account automatically.
Where personal data reaches a United States provider, the transfer is covered by that provider's data-processing agreement and the safeguards described there.
07The operational records in detail#
The sections above are the whole promise. This part is for anyone who wants to check it field by field.
- Image upload or removal in progress: while one is unresolved, a private record holds your account ID, which operation it is, the storage area and the internal path involved, its state, and when it started. Upload records also hold the file type, the declared size, and a one-way fingerprint of the avatar reference that was in place when your browser started, so a change you make later is not overwritten. A normal success, or a safe refusal before storage is touched, removes the record immediately. A failed or uncertain storage call has no automatic expiry and blocks account deletion until the stored details and the real files are reconciled.
- Upload limits: an account-linked record of the image operations and upload bytes you have left and when they refill. It holds no IP address, image bytes, filename, browser information, or history of failures, updates in place rather than recording a request history, and is deleted with your account.
- Public-form request counts: the daily one-way code described above, and capped counts of failure reports and contact messages. Removed within 48 hours.
- Message delivery receipts: a random submission identifier, a one-way fingerprint used only to stop the same submission reaching the provider twice, the provider's queue and request identifiers, and whether the outcome was queued, provider-accepted, failed, or delivery-unknown. No email address and no message content. Removed within 48 hours. A request still sitting with the provider after more than two hours with no outcome is cleared hourly.
- Signup health totals: daily counts of new unconfirmed email accounts, confirmations, and expired unconfirmed accounts. No email address, account ID, domain, IP address, or browser information. Kept for no more than 90 days.
- Failure reports: a fixed list of failure categories, the release, the general route, the product surface, and a limited amount of detail about the operation, kept for no more than seven days. Daily totals count how many distinct daily codes reported the same failure and are kept for no more than 90 days. They are unverified reports from browsers, not proof of how the service actually performed.
- Clean-up schedule: a deletion job counts as broken if it is missing, inactive, has failed since its last successful purge, or is overdue. The full daily purge must succeed within 26 hours and the hourly purge of daily codes within two hours. Until both are healthy again, new failure reports and contact messages are refused.
08Changes to this policy#
If this policy changes, we update the date and version above. Material changes, such as a new data category or processor, will be called out prominently and recorded in the changelog.
09Contact#
For privacy, support, or data questions, use the maintainer profile linked from the homepage footer.