Privacy Policy

Last updated August 22, 2026

Narrative Nexus (“we,” “us,” or “our”) operates the website at narrative.sh and the Narrative Nexus application (the “Service”). This policy explains what data we collect, who processes it, and your rights as a user.

1. Data we collect

Account information

When you sign up, we collect your email address, display name, and profile image. This information is managed by Clerk, our authentication provider. Clerk stores credentials and issues session tokens on our behalf.

Content you create

Campaign notes, character sheets, session logs, world-building entries, maps, and any other content you create inside the Service is stored in our database. We use this content to operate the Service and, where you explicitly invoke AI features, to generate responses.

Voice transcription (optional)

When a GM turns on voice transcription for a live session — over a linked Discord voice channel or in-app browser microphone capture — audio streams to our speech-to-text provider (Soniox or Groq, whichever our system is configured to use) to be converted to text. We do not store the raw audio ourselves: it is held in memory and streamed transiently for conversion, never written to a file or object storage on our side. Audio is processed transiently by that provider to produce a transcript; only the resulting text persists, as part of that session's transcript. Speaker attribution is identity-based — which connected Discord account or browser session is speaking — never a voiceprint or other biometric identification. Transcription cannot start for a campaign until its GM confirms everyone currently present is informed and consents; our server enforces that confirmation and refuses to start a stream without it. Transcript text follows the same account and content retention described below. See Voice Transcription for the full explainer.

Usage and analytics

We collect product analytics through PostHog, including page views, feature interactions, and performance data. If you are signed out, this runs by default in a cookieless mode: no analytics cookies and no persistent identifier are set, and identity is a privacy-preserving hash, scoped to your current session, computed from information like your IP address and browser rather than a stored identifier. No cookie banner is needed for this default state, because nothing non-essential is stored.

If you are signed in, we link your usage analytics to your account using a persistent identifier, so we can support your account and understand how the product is used — this is necessary to provide the Service you signed up for. Session replay (screen recordings of your in-app activity, with the text you type into form fields masked by default) is a separate, stricter gate: it only turns on after you explicitly turn on recording from Settings → Privacy, or if that setting already defaults to on for your region (see Cookies and tracking below). You can turn recording off again at any time from that same setting. We do not sell this data to advertisers.

Artist Network interest submissions

The optional Artist Network interest form collects the name or pseudonym and email you provide, portfolio URLs, selected disciplines and media, optional genre and TTRPG-system matching preferences, optional commission availability and budget bands, the opportunities you ask to hear about, a short optional support note, and limited source information. Those opportunity choices tell us what any human reply should concern. Submitting permits a confirmation and a reply about that intake; it does not add you to a marketing list. It is not an artist profile or a request for art files.

We do not send artist-interest form fields, portfolio URLs, support notes, submission identifiers, or selections to AI providers or PostHog. The form disables replay, heatmaps, and automatic analytics capture while it is open. We only record coarse, content-free form-started, submitted, and failed funnel events.

Payment information

If you subscribe to a paid plan, payment is processed by Stripe. We do not store your full card number or CVV. Stripe provides us with a payment method summary (last four digits, card brand, expiry) and a subscription status.

Technical and log data

Our servers (hosted on Fly.io) and web hosting (Vercel) collect standard server logs: IP address, browser type, referring URL, timestamps, and HTTP request metadata. This data is retained for security and debugging purposes.

2. Cookies and tracking

We use the following cookies and local storage:

  • Authentication cookies (Clerk) — essential for keeping you signed in. These are session cookies and cannot be disabled without breaking login.
  • Analytics (PostHog) — cookieless by default for signed-out visitors: no analytics cookies, no persistent identifier, nothing that survives beyond your current session. If you are signed in, analytics events are linked to your account through a persistent identifier so we can support your account and understand usage. Session replay is a separate, stricter gate on top of that: it only turns on if you explicitly opt in from Settings → Privacy, or if it defaults to on for visitors outside the EU/EEA (visitors in the EU and EEA, and anyone whose region can't be determined, default to off). You can change this choice at any time from that same setting.
  • Bot-protection storage (Cloudflare Turnstile) — when you submit a public form, Turnstile may store a short-lived value in your browser to complete its check. It is not used to track you across sites or to build an advertising profile.
  • Theme preference — your chosen theme is stored in local storage, and mirrored to a nn-theme cookie (so the server can render the right theme without a flash) only after you explicitly choose a theme from the theme picker. If you never choose one, neither is set.
  • Sidebar preferences (nn-sidebar-collapsed, nn-sidebar-width) — remember your sidebar layout while you are signed in.
  • Report anti-abuse identifier (nn:compendium:anon-reporter) — if you submit compendium feedback or report content while signed out, we store a random identifier in local storage so rate limits work per browser instead of one shared bucket. It is created only when you submit a report, is not an analytics identifier, and is never linked to the cookieless analytics identity or used to profile your browsing.

We do not sell or share personal information as defined by the CCPA, so there is nothing for a Global Privacy Control (GPC) signal to switch off. We honor GPC by design: because we don't sell or share data with third parties for cross-context advertising, sending a GPC signal doesn't change what we collect from you.

3. AI processing of your content

AI features run only when you invoke them. When you do—for example asking the DM assistant a question, generating campaign content, summarising a session, or generating artwork—only the content you include in that request is sent to the AI providers listed under Data processors and third parties below. We don't send your whole campaign, and we don't sell it.

We do not train or fine-tune AI models on your personal information or content, and our AI providers are contractually barred from training on the API traffic we send them.

If you supply your own API key (bring-your-own-key, where offered), that carve-out doesn't extend to that traffic: your content goes directly to the provider you chose, under your own agreement with that provider, not ours. We can't extend our contractual no-training protections to a request made under your account with your key — check that provider's own terms if that matters to you.

4. How we use your data

  • To provide, operate, and improve the Service
  • To authenticate you and maintain your session
  • To process payments and manage your subscription
  • To respond to support requests
  • To send transactional emails (e.g., session digests, billing receipts)
  • To diagnose bugs and monitor system health
  • To improve product features based on aggregated usage patterns

We do not sell your personal data. We do not use your content to train AI models (see AI processing of your content above for the bring-your-own-key carve-out).

5. Data processors and third parties

We share data only with processors necessary to operate the Service:

  • Clerk — authentication and user account management
  • Stripe — payment processing and subscription billing
  • PostHog — product analytics and session replay
  • Vercel — web application hosting
  • Fly.io — API and database hosting
  • Cloudflare R2 / Tigris — file and asset storage (images, maps)
  • Resend — transactional and Artist Network intake email delivery
  • Forward Email — inbound support and privacy email forwarding
  • Cloudflare Turnstile — bot-protection challenge on public forms (the Artist Network interest form and compendium entry reports). Turnstile runs in invisible mode, so it verifies you without showing a challenge or asking you to click anything. Cloudflare processes this data under its Turnstile Privacy Addendum. Turnstile does not use your data for advertising and does not set cookies for behavioural profiling.
  • Anthropic — AI language model inference for AI features
  • OpenAI — AI language model inference for AI features
  • Google (Gemini) — AI image generation (maps, illustrations)
  • Discord — community integration (voice transcription bot, optional)
  • Soniox / Groq — live speech-to-text conversion when a GM turns on voice transcription for a session; see Voice Transcription for what is captured and how it is attributed.

We may disclose data if required by law, court order, or to protect the rights and safety of users or the public.

6. Data retention

We keep your account and content for as long as your account is active. You can delete your account at any time from Settings → Account (or by emailing privacy@narrative.sh). When you do, we delete your account and the personal data associated with it in a single operation. Campaigns and worlds you own that are shared with other members are transferred to a remaining member so your collaborators keep their game, and characters you created are retained by that game as non-player characters; anything you owned solo is deleted. Residual copies may remain in encrypted backups until those backups rotate out in the normal course.

Server logs and product analytics follow the standard retention periods of our infrastructure providers (Vercel, Fly.io, and PostHog). Payment and invoice records are retained by Stripe for tax and accounting compliance. Voice transcription text follows the same account and campaign retention as other session content — deleted when the owning account or campaign is deleted, per the account deletion behavior above; raw audio is never retained by us in the first place, so there is nothing further to delete on that front.

Artist Network interest submissions become unavailable 180 days after submission and are queued for physical deletion by a daily retention job. If the service is unavailable, that deletion resumes when it starts again. You can request a copy or earlier deletion by contactingprivacy@narrative.sh from the submitted email address, or by following the verified-email process described on the form.

7. Your rights

Depending on your jurisdiction, you may have rights including:

  • Access — request a copy of your personal data
  • Correction — update inaccurate data
  • Deletion — request deletion of your account and data
  • Portability — receive your data in a machine-readable format
  • Objection / restriction — object to or restrict certain processing

To exercise these rights, email privacy@narrative.sh. We will respond within 30 days.

8. Children's privacy

The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us data, contact us at privacy@narrative.sh and we will delete it promptly.

If we obtain actual knowledge that an account belongs to a child under 13, we suspend that account, delete it through our standard account-deletion process, and record that we did so.

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by updating the “last updated” date above and, where appropriate, by email. Continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact

Questions about this policy? Email us at privacy@narrative.sh.