Privacy Policy

Last updated July 26, 2026

Narrative Nexus (“we,” “us,” or “our”) operates the website at narrative.shand the Narrative Nexus application (the “Service”). This policy explains what data we collect, who processes it, and your rights as a user.

1. Data we collect

Account information

When you sign up, we collect your email address, display name, and profile image. This information is managed by Clerk, our authentication provider. Clerk stores credentials and issues session tokens on our behalf.

Content you create

Campaign notes, character sheets, session logs, world-building entries, maps, and any other content you create inside the Service is stored in our database. We use this content to operate the Service and, where you explicitly invoke AI features, to generate responses.

Usage and analytics

We collect product analytics through PostHog, including page views, feature interactions, and performance data. Analytics are tied to an anonymous identifier until you sign in. PostHog may also record session replays—screen recordings of your in-app activity—to help us identify usability issues; these recordings mask the text you type into form fields by default. Session replay is off by default for visitors in the EU and EEA, and anyone can turn it off at any time from Settings → Privacy. We do not sell this data to advertisers.

Artist Network interest submissions

The optional Artist Network interest form collects the name or pseudonym and email you provide, portfolio URLs, selected disciplines and media, optional genre and TTRPG-system matching preferences, optional commission availability and budget bands, the opportunities you ask to hear about, a short optional support note, and limited source information. Those opportunity choices tell us what any human reply should concern. Submitting permits a confirmation and a reply about that intake; it does not add you to a marketing list. It is not an artist profile or a request for art files.

We do not send artist-interest form fields, portfolio URLs, support notes, submission identifiers, or selections to AI providers or PostHog. The form disables replay, heatmaps, and automatic analytics capture while it is open. We only record coarse, content-free form-started, submitted, and failed funnel events.

Payment information

If you subscribe to a paid plan, payment is processed by Stripe. We do not store your full card number or CVV. Stripe provides us with a payment method summary (last four digits, card brand, expiry) and a subscription status.

Technical and log data

Our servers (hosted on Fly.io) and web hosting (Vercel) collect standard server logs: IP address, browser type, referring URL, timestamps, and HTTP request metadata. This data is retained for security and debugging purposes.

2. Cookies and tracking

We use the following cookies and local storage:

  • Authentication cookies (Clerk) — essential for keeping you signed in. These are session cookies and cannot be disabled without breaking login.
  • Analytics cookies (PostHog) — track feature usage and session activity. PostHog sets a persistent cookie to recognise returning visitors. You can disable session replay at any time from Settings → Privacy; for visitors in the EU and EEA, session replay is off unless you opt in.
  • Bot-protection storage (Cloudflare Turnstile) — when you submit a public form, Turnstile may store a short-lived value in your browser to complete its check. It is not used to track you across sites or to build an advertising profile.
  • Preference storage — we store your theme preference (dark/light) in local storage. This data never leaves your browser.

3. AI processing of your content

AI features run only when you invoke them. When you do—for example asking the DM assistant a question, generating campaign content, summarising a session, or generating artwork—only the content you include in that request is sent to the AI providers listed under Data processors and third parties below. We don't send your whole campaign, we don't use your content to train AI models, and we don't sell it.

4. How we use your data

  • To provide, operate, and improve the Service
  • To authenticate you and maintain your session
  • To process payments and manage your subscription
  • To respond to support requests
  • To send transactional emails (e.g., session digests, billing receipts)
  • To diagnose bugs and monitor system health
  • To improve product features based on aggregated usage patterns

We do not sell your personal data. We do not use your content to train AI models.

5. Data processors and third parties

We share data only with processors necessary to operate the Service:

  • Clerk — authentication and user account management
  • Stripe — payment processing and subscription billing
  • PostHog — product analytics and session replay
  • Vercel — web application hosting
  • Fly.io — API and database hosting
  • Cloudflare R2 / Tigris — file and asset storage (images, maps)
  • Resend — transactional and Artist Network intake email delivery
  • Forward Email — inbound support and privacy email forwarding
  • Cloudflare Turnstile — bot-protection challenge on public forms (the Artist Network interest form and compendium entry reports). Turnstile runs in invisible mode, so it verifies you without showing a challenge or asking you to click anything. Cloudflare processes this data under its Turnstile Privacy Addendum. Turnstile does not use your data for advertising and does not set cookies for behavioural profiling.
  • Anthropic — AI language model inference for AI features
  • Google (Gemini) — AI image generation (maps, illustrations)
  • Discord — community integration (voice transcription bot, optional)

We may disclose data if required by law, court order, or to protect the rights and safety of users or the public.

6. Data retention

We keep your account and content for as long as your account is active. You can delete your account at any time from Settings → Account (or by emailing privacy@narrative.sh). When you do, we delete your account and the personal data associated with it in a single operation. Campaigns and worlds you own that are shared with other members are transferred to a remaining member so your collaborators keep their game, and characters you created are retained by that game as non-player characters; anything you owned solo is deleted. Residual copies may remain in encrypted backups until those backups rotate out in the normal course.

Server logs and product analytics follow the standard retention periods of our infrastructure providers (Vercel, Fly.io, and PostHog). Payment and invoice records are retained by Stripe as required for tax and accounting compliance.

Artist Network interest submissions become unavailable 180 days after submission and are queued for physical deletion by a daily retention job. If the service is unavailable, that deletion resumes when it starts again. You can request a copy or earlier deletion by contactingprivacy@narrative.sh from the submitted email address, or by following the verified-email process described on the form.

7. Your rights

Depending on your jurisdiction, you may have rights including:

  • Access — request a copy of your personal data
  • Correction — update inaccurate data
  • Deletion — request deletion of your account and data
  • Portability — receive your data in a machine-readable format
  • Objection / restriction — object to or restrict certain processing

To exercise these rights, email privacy@narrative.sh. We will respond within 30 days.

8. Children's privacy

The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us data, contact us at privacy@narrative.sh and we will delete it promptly.

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by updating the “last updated” date above and, where appropriate, by email. Continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact

Questions about this policy? Email us at privacy@narrative.sh.