Draft dated July 22, 2026 — not legally approved

Privacy policy

This draft describes the personal data currently handled by The Blind Raven. The controller, legal bases and retention periods must be confirmed before publication.

Legal draft. Every item in square brackets must be completed and the full text must be approved by a lawyer before publication.

Controller and privacy contact

[TO COMPLETE: identity and address of the data controller].

[TO COMPLETE: privacy or data protection contact email and, if applicable, the identity of the Data Protection Officer].

Data processed

Depending on how the service is used, the application processes:

  • account data: name, email address, password hash, language, time zone, role and account status;
  • technical session data: session token, expiry, IP address, browser user agent and authentication events;
  • profile and role-playing data: biographies, player or game-master profile, preferences, universes, characters, images and availability;
  • user-generated content: adventures, sessions, role-play publications, stories, comments, messages and reviews;
  • social and safety data: follows, blocks, reports, moderation decisions and impersonation audit records;
  • technical data: request identifiers, security logs and error reports, which may include the technical context needed to diagnose an incident.

Purposes and legal bases

The data is used to create and secure accounts, provide the requested features, display content according to its visibility, deliver notifications, match members and characters, prevent abuse, moderate the service and diagnose failures.

[TO VALIDATE WITH COUNSEL: contractual necessity for account and requested features; legitimate interests for security, abuse prevention and service improvement; legal obligations for enforceable requests; consent only where it is actually required].

Visibility and matching

Public profiles, public characters, open adventures and public role-play content may be visible without an account and indexed by search engines. Private messages, notifications, drafts and management data are restricted to their authorised recipients.

Exact availability remains private. Only a broad day and period summary may be shared, according to the member’s PRIVATE, MEMBERS or PUBLIC choice. Matching uses preferences, universes, broad compatibility signals and exact availability on the server to rank suggestions. It does not produce legal or similarly significant effects, and no paid visibility is used.

Recipients and processors

Data is accessible to authorised members according to each feature, to authorised moderators or administrators when necessary, and to technical providers strictly needed to operate the service.

The currently configured categories include infrastructure and database hosting [TO COMPLETE], Scaleway transactional email and object storage, and self-hosted Bugsink error reporting. [TO COMPLETE: exhaustive processor list, legal entities, locations, contractual safeguards and support access]. Data is not sold and is not used for advertising in the current version.

Cookies and local identifiers

The application uses Better Auth cookies to maintain and protect the session, PARAGLIDE_LOCALE to remember the interface language, tbr_selected_character_id to remember the active role-play character, and an additional short-lived audit identifier during authorised administrator impersonation.

No advertising or audience-measurement cookie is currently installed. [TO VALIDATE: qualification as strictly necessary cookies, exact lifetimes and whether a consent mechanism or settings panel is required before adding any optional tracker].

Retention

[TO COMPLETE AND VALIDATE: a retention schedule for active and closed accounts, expired sessions and verification tokens, public content, private messages, reports and moderation evidence, impersonation audits, security and error logs, backups and orphaned media].

Account deletion and data export are not yet exposed as self-service features. A documented request process and the technical deletion or anonymisation workflow must be completed before public launch.

International transfers and security

[TO VERIFY: production data locations and any transfer outside the European Economic Area; document the relevant adequacy decision or contractual safeguards where applicable].

The application uses access controls, signed sessions, email verification in production, input validation and restricted media uploads. No system can guarantee absolute security; suspected incidents can be reported to [TO COMPLETE: security contact].

Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, portability or objection, and withdraw consent where processing relies on consent. Contact [TO COMPLETE: privacy email]. Identity verification may be required before fulfilling a request.

[TO COMPLETE: expected response process]. You may also lodge a complaint with your competent supervisory authority; in France, this is the CNIL.

Children and policy changes

[TO VALIDATE WITH COUNSEL: minimum age, parental-authorisation rules and handling of accounts identified as belonging to children]. Material changes will be dated here and, where required, notified to members or submitted for renewed consent.