Privacy Policy
Revision of 24 July 2026
Grimhold is a text role-playing game. Making it work means storing what you write and sending some of it to other companies. This says exactly what and why, without generalities.
Who is responsible for the data
Michael Shvets, as an individual. Not a company: the game has no legal entity and no staff. Questions about your data, and requests to export or delete it: privacy@solshark.me.
What is stored
| What | Detail |
|---|---|
| Account | Email, password as a bcrypt hash (the password itself is stored nowhere), creation date, the interface language you chose, and whether the account is active |
| Login | SHA-256 hash of the session token, its expiry, when it was created, and when you last used it. The token itself lives only in your browser |
| Campaigns | Character description, appearance, equipment, location, world state, and the language that campaign is played in |
| Everything you typed | Every action of yours and every reply from the Game Master is stored in full. That *is* the game: without the record the campaign cannot continue |
| Model spend | How many tokens your campaign consumed, so the cost is known |
| Signup request | If you submitted the form on the site: email, date, the age declaration, and which revision of the terms you agreed to |
A word about the input field: you can type anything into it, and what you type is stored as written. The game does not inspect it and does not strip anything out of it. Don't put things into your character's lines that you would not want kept — real names, addresses, or anything about your health.
Purposes and lawful bases
| Purpose | Basis |
|---|---|
| Account and login | Contract — there is no game without it |
| Campaigns and turn history | Contract — this *is* the service |
| Requests to the model that runs the game | Contract |
| Cost accounting | Contract |
| Security records | Legitimate interest |
| Clarity analytics | Consent, and nothing else |
| Signup request | Consent — you decide whether to leave one |
Who receives data
Full detail on the subprocessors page. In short:
- Anthropic receives, on every turn, your line, several preceding ones and the campaign state — otherwise the Game Master could not reply, and would not remember what you were just talking about. Your email is not sent: it is not in the request.
- Google receives a description of the picture to be drawn. That description contains no email, no character name and none of your lines.
- Microsoft (Clarity) — only if you allowed it. Records where you clicked and how you scrolled. All page text is masked in the browser before anything is sent: none of your lines, none of the Game Master's replies, not the character's name, not your email leaves the page.
- Cloudflare — requests to the site and the game pass through it.
- Apple — only if you submitted a signup request. The reply comes as an ordinary email from an iCloud mailbox, so your address ends up there too. There are no automated mailings: a person writes each one, individually.
Your data is not used to train models. Both Anthropic and Google are used on paid tiers whose terms exclude it. If that ever stops being true, it will say so here — before it changes.
How long things are kept
| What | How long |
|---|---|
| Expired sessions | Deleted on every backend start. A session itself lives 14 days |
| Used and expired invitations | 30 days, then deleted |
| Campaigns and turn history | While the account exists. Nothing is deleted on a timer |
| Cost accounting | While the account exists; anonymised on deletion |
| Anonymised spend statistics | Indefinitely — there is no way to tell whose it is |
| Signup request | Until it is decided. Approved, it becomes an account and no longer exists; refused, it is deleted immediately and entirely |
Campaigns are deliberately never deleted automatically. The game has no email notifications, so there is no way to warn you first — and silently erasing a campaign you played for six months would be indefensible. While the account exists, so does the campaign.
### Images are an exception, and it needs saying plainly
Portraits and location art are not deleted along with a campaign or an account. They are stored by content rather than by owner: two campaigns that arrive at the same forest in the same weather get the same file. Deleting it on your request would erase another player's picture too.
Which is exactly why it is not alarming: the file contains no email, no campaign id and no link of any kind back to you — once the record is deleted there is no way to connect the image to you. But a portrait is drawn from an appearance description *you* typed, and staying quiet about that would be dishonest.
What you can do
Directly in the game, no emails and no waiting:
- Take everything. The export button produces a JSON file: account, all campaigns, world state and the complete turn history. Images are not included, for the reason above. If you need them, write and we will sort it out separately.
- Delete everything. Deletion erases records for real — from every table they appear in, with no "marked as deleted" and no recycle bin. Only the anonymised spend statistics remain, and you cannot be found through them. One honest caveat: the database has backups, and your records remain in them for no longer than 90 days. The backups exist in case something breaks, nobody looks inside them, and old ones are overwritten by new — but saying "gone everywhere within a minute" would not be true.
- Change your mind about analytics. The "Analytics" link at the bottom of any page brings the choice back, and a refusal takes effect immediately rather than next time.
Everything else — correcting an inaccuracy, restricting or objecting to processing, taking your data in machine-readable form — via privacy@solshark.me. A reply within a month, as the law requires, though in practice sooner.
If you only submitted a signup request, you do not have an account yet, so there are no buttons either. Write from the address you gave on the form — that is enough for us to know it is yours, and to delete the request or tell you what is in it. From a different address we will neither confirm nor deny that such a request exists: otherwise the form could be used to check who had used it.
If the reply does not satisfy you, you have the right to complain to the data protection supervisory authority where you live.
Cookies
- `aidnd_session` — how the game knows you are logged in. Lives 14 days, not readable by scripts on the page. Login does not work without it, so it needs no consent.
- `_clck`, `_clsk` — Clarity, and only after your permission. Removed if you refuse.
- Your analytics choice is stored in the browser itself (localStorage), not on the server.
How this is protected
- The password is stored only as a bcrypt hash — it cannot be recovered.
- The session cookie is not readable by scripts, so it cannot be stolen from the page.
- Server logs contain no email, no passwords, none of your lines and none of the Game Master's replies — only campaign ids.
- Registration is by invitation only. Someone else's campaign answers "not found" rather than "no access", so the response cannot be used to discover that it exists.
Age
The game is not intended for anyone under 16. Age is not verified: an "I am 16" checkbox proves nothing, and we are not going to pretend otherwise. See the Terms of Service.
Automated decisions and profiling
A language model runs the Game Master, and everything it decides stays inside the fictional world: whether a roll succeeded, what the herbalist says back, where the story turns. None of it affects you personally.
We do not assess you by how you play, do not build a profile of you, and make no automated decisions about you — not about access, not about money, not about anything outside the game.
Changes
The revision date is at the top of the page. Changes that genuinely affect you — a new recipient, a new purpose — will not be introduced silently.