1. Who We Are and What This Policy Covers
Age of Aeternus is operated by NerdHonest LLC, a Georgia limited liability company ("NerdHonest," "we," "our," or "us"). We are responsible for the personal data described in this policy (in EU and UK terms, we are the "controller").
Our mailing address: NerdHonest LLC, 8735 Dunwoody Place, Suite R, Atlanta, GA 30350, United States. Privacy contact: privacy@nerdhonest.com.
This Privacy Policy explains what personal data we collect, how we use and share it, how long we keep it, and the choices and rights you have. It covers:
- the Age of Aeternus web app at app.aoathegame.com;
- our apps for mobile and desktop;
- our website at aoathegame.com; and
- the emails and other services connected to them
(together, the "Service").
Age requirement: the Service is only for people aged 18 or older who have reached the age of majority where they live. When you sign up, you confirm that you are 18 or older.
This policy describes what we do. Reading it, or using the Service, doesn't mean you consent to everything in it. Where we rely on your consent (for example, for analytics or marketing emails), we ask you separately, and you can say no.
2. Information We Collect
2.1 Information You Give Us
- Account information: Email address, password (handled by Firebase Authentication; we never see it), display name, username, profile photo, bio, featured character and profile song
- Community profile: Roles, genres, moods, playstyles, whether you are looking for a group, and your trigger and veto tags
- Age confirmation and agreements: That you confirmed you are 18 or older, and when. Which versions of our Terms of Service and Subscription Terms you accepted, which version of this Privacy Policy you confirmed you had read, when, and how
- Early-access (waitlist) record: If your email address is already verified when your account is created (for example, because you signed up with Google or Apple), we keep a record of your email address, account ID and early-access status. We use it to manage early access and to keep track of your marketing-email consent. If you joined the early-access list on our website with the same email address before creating your account, we link that earlier record to your account in the same way. A record from our website may also hold the name, story and referral source you entered, your consent choices, and your browser's user agent and the page you came from. Our website's early-access and invite-request forms are now closed
- Characters and game content: Character sheets, builds, inventory, notes, drafts and custom content
- Homebrew, ratings and reviews: Homebrew you create or publish, and ratings, reviews and votes you leave on other people's homebrew
- Party and virtual tabletop content: Party membership and roles, shared notes, maps, tokens, art, drawings, fog of war, and whispers you send to other party members
- Uploads: Images you upload (such as avatars, portraits, maps and tokens) and, on Premium and Guide, audio you upload
- Friends and invites: Friends, friend requests, people you block, and party invites. You can invite someone to a party by their exact username, from your friends list, or from community search
- Messages to us: Support emails, bug reports, feedback and ratings of the app, content reports, appeals, and DMCA notices or counter-notices (including the name, address, phone number and email address they contain). With a notice sent through the DMCA form on our website, we also keep a hash of your IP address and your browser's user agent
- Preferences: App settings, privacy choices and email preferences
What you must provide. To create an account, you need to give us an email address (or sign in with Google or Apple) and confirm that you are 18 or older. Without these, we can't create your account. Everything else is optional, but some features need it.
Bug reports include what you write, any screenshots you attach, your account ID, the screen you were on, your platform and the app version. If you turn on Include recent diagnostic activity (off by default), they also include up to 100 recent log lines and 15 recent app events from your device.
2.2 Information Collected Automatically
- Technical Diagnostics (crash reports)
- What and how: When the app hits an error, it sends us a short report: error type, a code-location fingerprint, the code frames involved, the screen (route) you were on, recent app activity (screens opened, earlier errors and failed network requests), app version, Flutter version, build mode, platform and OS version, and a random session ID. It contains no error-message text and no account, character or party ID. Runs on every platform. On by default; you can turn it off with the Technical diagnostics switch. Stored in our own Firebase project. On our mobile and desktop apps, each report is first saved on your device, including while the switch is off; reports are only sent while it is on. If you turn the switch back on, saved reports that weren't sent may be sent the next time the app starts. Your device keeps up to 200 saved reports (and at most 10 MB of them), sent or not; when there are more, the oldest are removed.
- Why: To find and fix bugs.
- How long: 30 days.
- App-health events (only if you accept Analytics)
- What and how: App version, startup and server-call timings and errors, linked to your account.
- Why: To find and fix reliability problems.
- How long: 7 days.
- Performance summaries (only if you accept Analytics)
- What and how: Summaries of frame timings, how long saving and syncing take, and how many database reads the app makes, with your app version and platform, linked to your account.
- Why: To find and fix slowness.
- How long: 30 days.
- Firebase Analytics (not currently active)
- What and how: Firebase Analytics is built into the app (web, Android, iOS and macOS), and it is covered by the Analytics choice. It isn't currently active: it isn't connected to a Google Analytics account, so no analytics data is collected, even if you accept Analytics.
- Why: If we turn it on, to understand which screens and features are used and improve the Service.
- How long: Before we turn it on, we will update this policy, including how long the data is kept.
- Crash Reporting (Firebase Crashlytics; only if you accept, Android, iOS and macOS)
- What and how: Crash details with device information (such as model, OS version and memory state), some recent settings changes, and your account ID while you are signed in. It also receives reports of some errors that don't crash the app: the error's type and message, where in the code it happened, and which step failed. These reports contain no party, character, package or product IDs.
- Why: To find and fix crashes and errors.
- How long: 90 days (Google's Crashlytics retention)
- Audio Download Usage Metrics
- What and how: A daily count of how much new audio from our library your account plays or downloads (including profile songs you hear), and a list of tracks already counted, so the same track isn't counted twice.
- Why: To enforce daily download allowances and prevent abuse.
- How long: Daily counter: 90 days after its last use. Charged-tracks list: entries older than 12 months are removed.
- Security signals
- What and how: Firebase App Check helps block requests to our server functions that don't come from our real apps. It uses Google reCAPTCHA Enterprise on the web, Google Play Integrity on Android, and Apple DeviceCheck on iOS and macOS. Our telemetry intake (crash reports, performance summaries and app-health events) keeps a keyed hash of your IP address, and a hash of your account ID, to limit abuse. When you download a game module or its key, we keep a record of your account ID, the module, the time and a keyed hash of your IP address. When you redeem a promo code, we keep a keyed hash of your IP address with the redemption. These records don't contain your IP address itself or your browser's user agent.
- Why: To protect the Service from bots and abuse, and to investigate misuse of modules and codes.
- How long: Telemetry hashes: about 20 minutes. Module download and key records, and promo-code IP hashes: 90 days, or until you delete your account if that comes first.
- Server logs
- What and how: Our cloud provider logs requests, including IP address, time and request details.
- Why: Security, troubleshooting and fraud prevention.
- How long: Google Cloud's default log retention (currently 30 days for most logs)
- Push notification tokens
- What and how: A token for your device so we can send push notifications (Android and iOS only)
- Why: To deliver notifications you have allowed.
- How long: Until the push service tells us the token is no longer valid, or you sign out on that device. Tokens are deleted with your account.
- Device identifier
- What and how: A random identifier for your device or browser.
- Why: So the music player and virtual tabletop can tell your devices apart.
- How long: Until you clear site data or uninstall the app. On iOS and macOS, it is kept in the Keychain and can survive uninstalling the app.
- Purchase SDK identifier
- What and how: RevenueCat's SDK starts when the app opens (web, Android, iOS, macOS), before you sign in, with a random anonymous ID. After you sign in, it uses your account ID.
- Why: To check subscription status and process store purchases.
- How long: See RevenueCat's privacy policy.
- Sponsor and partner counts
- What and how: Daily counts of how many people saw or clicked a sponsor or partner placement, and how many went on to act on it (for example, by using its code). We count each viewer once a day using a hash that changes daily; we don't store your account ID. We don't count you if you declined analytics.
- Why: Aggregate reporting to sponsors and partners.
- How long: Counting markers: 90 days. Daily hash keys: about 1 to 2 days.
Can a crash report be linked to me? A crash report doesn't contain your account ID. It does contain a random session ID. If you have accepted Analytics, the same session ID also appears in app-health events and performance summaries linked to your account. While both records exist (at most 30 days), a crash report could therefore be matched to your account. We don't use crash reports to identify people.
Before you choose. On Android, iOS and macOS, Firebase Analytics and Crashlytics are switched off until you accept, and any unsent crash reports are discarded if you decline. On the web, the analytics script doesn't load until you accept.
2.2a Anonymized Gameplay Telemetry
To balance the game, we count gameplay outcomes. We keep only daily totals: for example, how many times a given skill succeeded on a given day. Each total is grouped by the date, the kind of event, the skill, the outcome, the damage type, the source category and whether it was a critical hit. Only values from a fixed list are kept; anything else is grouped as "other", and skills other than the standard Age of Aeternus skills are grouped as "custom".
These totals don't include account, character or party IDs, names, notes, free text or exact times. They aren't linked to you.
This is on by default, under our legitimate interest in balancing the game. To opt out, turn off Share anonymized gameplay data in Privacy Settings. An event isn't counted if the person who recorded it, or the owner of a character involved, has opted out. Totals are deleted after 24 months.
2.3 Information from Third Parties
- Sign in with Google or Apple. If you use one, we receive your email address and, if you share it, your name or profile information from that provider. If you use Sign in with Apple in our iOS or macOS app, we also keep the token Apple issues to our app, only so that we can ask Apple to revoke it when you delete your account. We don't use it for anything else, and only our servers can read it.
- App Store and Google Play (through RevenueCat). If you subscribe in our iOS or Android app, we receive the subscription's product, status, dates and transaction identifiers. We don't receive your card details.
- Patreon. If you support NerdHonest through Patreon or connect your Patreon account in the Service, Patreon may provide your Patreon member, user, campaign and tier identifiers; email address; membership status; support amount; membership, entitlement and charge dates or statuses; and related membership history. We use this to match or link accounts, verify paid periods, deliver and maintain membership access and earned rewards, process membership changes and corrections, reconcile missed events, prevent duplicate rewards and fraud, and provide support. We don't receive your full card number or your Patreon password.
- Patreon profile names. Patreon's notifications to us may briefly include your Patreon profile name; we discard it on receipt and don't store, use or display it. We don't use Patreon profile names or email addresses for public display. The List, our planned public list of founding supporters, isn't shown publicly yet. If we launch it, being listed will be opt-in and will use the display name or alias you choose in the Service.
- Ko-fi. If you tip NerdHonest through Ko-fi, Ko-fi sends us the tip's details, including your email address, name and message. We keep only the transaction ID, message ID, payment type, amount, currency, Ko-fi tier name, whether it was a subscription payment (and the first one), and dates. We don't keep your email address, name or message, and we don't link the tip to an app account. We use this record to avoid processing the same tip twice and to answer support questions. Tips don't earn Loyalty Points. Ko-fi tips are one-time or monthly support payments to NerdHonest LLC, a for-profit company; they aren't charitable donations and aren't tax-deductible. (Ko-fi links aren't shown in the app at the moment.)
- Writerer. See Section 2.3a.
- Creator content. If you are a creator in our creator program, our team may add one of your public videos to the Service by its link. We fetch the video's public title, channel name and thumbnail from YouTube or TikTok, and keep a copy of the thumbnail.
- Discord (optional; not yet available). Discord linking is optional, and it is switched off until we launch it. When it is available and you link a Discord account:
- We ask Discord only for basic identity (the
identifypermission). Discord sends us your public profile, and we keep only your Discord user ID, username and display name. We don't receive your email address or your list of servers. - Linking finishes when you enter, in the app, the code shown in your browser after you approve on Discord.
- We store your Discord user ID, username and display name with your account, together with when you linked and when we last verified the link. Only you can see these details.
- If you tap Check membership, our Discord bot checks whether you are a member of our Discord server. We then store whether you are a member, the join date Discord reports, your role IDs there, and when we checked. We check only when you ask, and Discord doesn't send us updates, so this information can be out of date until your next check.
- We use the access token Discord gives us once, to read your identity, and then revoke it immediately. We never store Discord tokens or send them to the app.
- A record on our servers links your Discord ID to your account, so that one Discord account can be linked to only one Age of Aeternus account. It is deleted when you unlink or delete your account.
- Linking earns a one-time Loyalty Points award (currently 50), and being a member of our Discord server earns another (currently 100). Each is paid at most once per Age of Aeternus account and at most once per Discord account. The amounts can change, and we may turn off the server award separately. Your points history doesn't contain your Discord ID or username.
- To stop the same Discord account from collecting these awards again, we keep a permanent anti-abuse marker: a keyed one-way hash of the Discord ID that holds only when the awards were given. It contains no Age of Aeternus account ID, Discord ID or username, and it stays after you unlink or delete your account.
- When you unlink, we delete your Discord details and the linking record. Points you earned, and the anti-abuse marker, stay.
- While you are linking, we create a short-lived sign-in record that contains your account ID. It can be used for about 10 minutes at each step (approving on Discord, then entering the code in the app). Starting a new Discord link cancels any earlier unfinished one. A daily sweep then deletes it (usually within a day), and it is also deleted if you delete your account. Our own logs for linking record error codes, plus your account ID if you go over the rate limit for linking attempts. Our cloud provider's request logs also record the web address Discord sends your browser back to, which contains Discord's one-time authorization code and a random request value; these logs follow the server-log retention in Section 5.
- While you link Discord: after you approve on Discord, and until you enter in the app the code shown in your browser, we keep your Discord user ID, username and display name with that linking request. The code works for 10 minutes. If you enter it in time, the details are added to your account as described above. If you enter the code after it expires, or enter it wrong too many times, or the Discord account is already linked elsewhere, we delete them right away; otherwise the daily cleanup deletes them, usually within a day. So if you stop partway, the details may stay on our servers for up to about a day. The code is stored only in scrambled (hashed) form, and the request is deleted if you delete your account.
- When you delete your Age of Aeternus account, your Discord details and the linking record are deleted with it.
- We ask Discord only for basic identity (the
2.3a Cross-App Account Linking
You can choose to link your Age of Aeternus account with Writerer, another NerdHonest app. When you do:
- we send Writerer your Age of Aeternus account ID (a random identifier, not your name or email) and your Age of Aeternus subscription tier, and we update the tier when it changes;
- Writerer sends us your Writerer account ID and your Writerer subscription tier;
- both apps keep a link ID, the link's status and timestamps, so the link can be created, checked and removed.
We don't exchange email addresses, display names, profile data, activity, characters or other content, or payment details through this link. Linking gives no bonuses at the moment. Badges, titles and other cosmetic rewards stay in Age of Aeternus.
You can unlink at any time in Profile Settings › Integrations › Writerer. After unlinking, you must wait 24 hours before linking again. If you delete your Age of Aeternus account, we tell Writerer to remove the link.
3. How We Use Information and Our Legal Bases
This table shows why we use your information. For users in the EEA and UK, it also shows the legal basis we rely on under the GDPR and UK GDPR.
- Create and run your account; sync your characters and content; run parties, the virtual tabletop, friends and the music player
- Main data used: Account, game, party and social data.
- Legal basis (EEA/UK): Performing our contract with you.
- Publish homebrew you choose to publish, with your name as creator
- Main data used: Homebrew and account name.
- Legal basis (EEA/UK): Performing our contract with you.
- Show your public profile in Discover and community search, only if you turn this on
- Main data used: Community profile.
- Legal basis (EEA/UK): Consent (you can turn it off at any time)
- Show you on The List, if we launch it and you opt in
- Main data used: Display name or alias, recognition.
- Legal basis (EEA/UK): Consent.
- Deliver subscriptions, Patreon access, codes, Loyalty Points and rewards; reconcile payments and refunds
- Main data used: Purchase, Patreon and loyalty data.
- Legal basis (EEA/UK): Performing our contract; legitimate interests (preventing duplicate rewards and fraud)
- Send service emails (for example: sign-in and security messages, data export links, deletion notices, renewal reminders, report acknowledgements and legal updates)
- Main data used: Email address.
- Legal basis (EEA/UK): Performing our contract; legitimate interests (keeping you informed about your account and our terms).
- Manage early access and keep track of your marketing-email consent
- Main data used: Early-access (waitlist) record: email address, account ID and status.
- Legal basis (EEA/UK): Performing our contract; legitimate interests (keeping an accurate record of your marketing-email choices).
- Send marketing emails (promo codes, invite codes, events and product updates)
- Main data used: Email address and preferences.
- Legal basis (EEA/UK): Consent (off unless you opt in)
- Technical diagnostics and app stability
- Main data used: Crash reports.
- Legal basis (EEA/UK): Legitimate interests (keeping the app working). You can turn it off.
- Game balance
- Main data used: Anonymized gameplay totals.
- Legal basis (EEA/UK): Legitimate interests. You can turn it off.
- Analytics, app-health events, performance summaries and Crashlytics
- Main data used: Usage, device and crash data.
- Legal basis (EEA/UK): Consent.
- Security, abuse prevention and enforcing our Terms
- Main data used: Security signals, logs, reports.
- Legal basis (EEA/UK): Legitimate interests (protecting users and the Service)
- Handle content reports, appeals and copyright notices
- Main data used: Reports, notices, account data.
- Legal basis (EEA/UK): Legitimate interests (including meeting our obligations under U.S. copyright law); legal obligation under the EU Digital Services Act
- Keep proof of your age confirmation, agreements and privacy choices
- Main data used: Acceptance and consent records.
- Legal basis (EEA/UK): Legitimate interests (being able to show what you agreed to); legal obligation where EU or UK law requires us to keep these records
- Aggregate sponsor and partner reporting
- Main data used: Daily counts with no account ID.
- Legal basis (EEA/UK): Legitimate interests.
- Comply with the law and respond to lawful requests
- Main data used: Any relevant data.
- Legal basis (EEA/UK): Legal obligation, where EU or UK law requires it; otherwise legitimate interests (complying with other laws that apply to us, such as U.S. law).
Where we rely on legitimate interests, you can object (see Section 7). Where we rely on consent, you can withdraw it at any time; this doesn't affect processing that happened before.
Automated decisions. We don't make decisions about you based solely on automated processing that have legal or similarly significant effects, with one exception: under our DMCA Policy, an account is disabled automatically when it reaches 3 copyright strikes within 12 months. Each strike follows a notice that a person on our team has reviewed. Separately, if an account's verified email address matches a repeat-infringer marker (see Section 5), the account is disabled automatically and held until a person on our team reviews it. If your account is disabled in either way, you can ask for a person on our team to review the decision, give your point of view and contest it, by emailing dmca@nerdhonest.com.
4. How We Share Information
4.1 Service Providers
These companies process data for us, under our instructions, to run the Service:
- Google LLC (Firebase and Google Cloud)
- What they do for us: Sign-in (including sending verification and password-reset emails), database, file storage, server functions, web hosting, App Check (with reCAPTCHA Enterprise and Play Integrity), push notifications (Firebase Cloud Messaging), and, if you accept, Analytics and Crashlytics.
- Data involved: Account data, content, device and usage data.
- RevenueCat, Inc.
- What they do for us: Store purchases and subscription status.
- Data involved: Anonymous or account ID, purchase and subscription data.
- Resend, Inc.
- What they do for us: Sending our service emails.
- Data involved: Email address and message content.
- EmailOctopus (Three Hearts Digital Ltd)
- What they do for us: Sending marketing emails and managing the mailing list.
- Data involved: Email address, subscription status and interest tags.
Google services the web app contacts. We host the web app's code, its rendering engine, its fonts and the Firebase libraries ourselves, so loading the app doesn't fetch them from Google. The web app still contacts Google:
- for our Firebase backend (sign-in, database, storage and server functions);
- for App Check, which loads Google reCAPTCHA Enterprise from www.google.com/recaptcha and www.gstatic.com/recaptcha;
- for Google Analytics (gtag.js), only after you accept analytics (Analytics isn't currently active; see Section 2.2); and
- when you sign in with Google, through the sign-in window. It uses apis.google.com, our Firebase sign-in domain, and Google's account pages.
4.2 Services You Choose to Use
These companies have their own relationship with you and their own privacy policies:
- Apple and Google, if you sign in with them or buy through the App Store or Google Play;
- Patreon, if you support us there or connect your Patreon account;
- Ko-fi, if you tip us through it;
- Discord, if you link your Discord account once linking is available (see Section 2.3);
- Writerer, if you link it (see Section 2.3a).
We don't send Patreon your Age of Aeternus characters, content or activity.
4.3 Other Users
- Your profile is private by default. Other people see your public profile only if you turn on Appear in community directory in Profile Settings. When it's on, anyone using the Service, including people who aren't signed in, can see your public profile: your username, profile photo, title, featured badges, username effect, selected stats, bio (if you make it public), featured character, profile song, roles, community preferences (experience level, genres, moods, playstyles, vibes, preferred format and frequency) and whether you are looking for a group. Your display name isn't part of your public profile. Your trigger tags and veto list are included only if you choose to share them (Profile Settings › Profile safety).
- Even when your profile is private, people who know your exact username can send you friend requests and party invites. Your friends and party members see your display name, username and photo.
- Party members see what you share with the party, such as characters, notes, maps, tokens and art, and any whispers you send them. They also see whether you are currently online in the party and whether you have Focus mode on. This status clears itself when your app disconnects.
- Published homebrew is public and shows you as its creator. Your ratings and reviews show your name.
- Profile songs. If your profile is visible and has a profile song, signed-in visitors hear it play automatically unless they have turned off Autoplay profile songs.
- Stream overlays. If you create a stream overlay link, anyone who has that link can see the overlay's character information (display name, level, current and maximum HP, state and conditions). If you turn on music for the overlay, they can also hear your party's music. If you turn on dice, people with the link can also see your party's dice rolls, including roll notes and rolls the overlay doesn't display. Treat the link like a password. Links expire, and you can revoke them.
- The List. The List isn't shown publicly yet. If we launch it, being listed will be opt-in. If you opt in, the display name or alias you choose, your recognition and whether you are an active supporter would be public, and you could hide or remove your entry at any time without losing the underlying qualification.
4.4 Legal, Safety and Business Transfers
- Copyright counter-notices. If you send a DMCA counter-notice, the law requires us to send a copy, including your contact details, to the person who sent the original notice.
- Legal requirements. We may disclose information when the law requires it or to respond to valid legal process.
- Safety. We may disclose information to protect someone's safety, or to prevent fraud or abuse.
- Business transfers. If NerdHonest is involved in a merger, acquisition or sale of assets, your information may be transferred as part of that deal. The new owner will remain bound by this policy, or must give you notice of any changes.
4.5 What We Don't Do
- We don't sell your personal information.
- We don't share it for cross-context behavioral advertising, and we don't use it for targeted advertising.
- We don't give it to third parties for their own marketing.
- We don't allow advertising trackers in the Service.
5. How Long We Keep Data
We keep personal data only as long as we need it for the purposes in this policy. Records with a set expiry are deleted automatically, usually within a day or so after they expire. Our database keeps earlier versions of records for up to 1 hour so we can recover from mistakes; we don't keep longer-term database backups. Our file storage keeps deleted files for 7 days before they are permanently removed.
- Account, profile, characters, content and settings: While your account exists. Deleted after you delete your account (see Section 6)
- Crash reports (Technical Diagnostics): 30 days
- Performance summaries (Analytics): 30 days
- App-health events (Analytics): 7 days
- Crashlytics crash data: 90 days
- IP and account-ID hashes used to limit abuse of our telemetry intake: About 20 minutes
- Module download and key records, and promo-code IP hashes: 90 days. Deleted earlier if you delete your account
- Rate-limit counters (how often your account used a feature in a short time): Deleted automatically, most within about 2 hours and the music player's within about a week. Most counters tied to your account are also deleted when you delete your account; the rest expire on their own as described here
- Anonymized gameplay totals: 24 months
- Audio Download Usage Metrics: Daily counter: 90 days after last use. Charged-tracks list: 12 months
- Sponsor and partner counting markers: 90 days. Daily hash keys: about 1 to 2 days
- Limits on report acknowledgement emails: 2 days
- Server logs: Google Cloud's default (currently 30 days for most logs)
- Data exports: The download link works for 7 days, and the file is then deleted. The record of each export request (when you asked, its status, and the email address we sent the link to) is kept while your account exists and deleted with it
- Proof of your age confirmation, agreements and privacy choices, after account deletion: 3 years after deletion. Keeps only a keyed hash of your account ID, what you agreed to or chose, the version, how and when. No email address or name
- DMCA notices, counter-notices and strike records: 3 years after the case closes, then deleted. A case is kept while it is under review and while a counter-notice is being handled. If we removed material and the case is never formally closed, it is kept 3 years from the removal; a strike whose case never closes is kept 3 years from the strike. These records are kept for that period even if you delete your account, to enforce our repeat-infringer policy and as legal records. A notice sent through our website's form also leaves a short-lived rate-limit record (a hash of your IP address and browser), deleted after about an hour
- Repeat-infringer marker: If we terminate an account as a repeat infringer, we keep keyed one-way hashes of the account ID and of its verified email address, with the termination dates, but no case details. We keep it with no end date, to stop re-registration (see Section 7 of our DMCA Policy). An admin can remove it. To run this check, we also keep with each account a keyed hash of its verified email address and when we checked it; this is deleted with the account
- Early-access (waitlist) record: While your account exists; deleted when you delete your account
- Marketing opt-out (suppression) records: Kept after account deletion, keyed by a keyed hash of your email address, so we never send marketing email to an address that unsubscribed, and never email an address that bounced or complained
- Marketing contact record, if you opted in to marketing emails: When your account is deleted, we mark this record "opted out" so that our email provider stops mailing you. Once the opt-out has reached our email provider, or at the latest when our daily job runs after 30 days (about 31 days), we remove your email address and account IDs from the record, keeping only the hashed suppression entry above. Records tied to an earlier email address you used for early access are removed too. We find these records, and your early-access record, by your account ID and by your verified email address; an address you never verified isn't treated as yours
- Published homebrew: Kept after account deletion, credited to "Deleted user" (see Section 6)
- Content reports about a deleted account: Kept as moderation history. Once a report has been resolved or dismissed, whether before or after the deletion, the account ID in it is replaced by a keyed hash and the content preview is removed. Until then, an open report keeps the account ID
- Reviews we removed after a report: An admin-only copy is kept so that we can restore the review if an appeal succeeds. It is deleted after 180 days, or earlier if we restore the review or its author deletes their account
- Ko-fi tip records: 1 year, then deleted. They hold no email address, name or message
- Sign in with Apple token: While your account exists. When you delete your account, kept only until Apple confirms it has revoked the token. If revocation fails permanently, up to 90 days so we can fix the problem, then deleted
- RevenueCat access-removal retry record: Kept only until RevenueCat confirms it removed the access we granted. We retry up to 10 times over several hours; if it still fails, up to 90 days so we can fix the problem, then deleted
- RevenueCat deletion retry record: Kept only until RevenueCat confirms the deletion; we keep retrying through outages. If RevenueCat keeps rejecting the request, up to 90 days so we can fix the problem, then deleted
- Record of a completed account deletion: 3 years, as proof that we completed the deletion. Once deletion is complete, it holds a one-way hash of your account ID (not the ID itself); the reason you gave, or, for deletions started by our team, only a general category (we don't keep internal notes or error details); your platform, app version, dates and counts of what was deleted; and, if our team ran the deletion, the ID of the staff member who ran it
- Patreon membership and reward records: While your account exists. Removed when your account is deleted
- Discord link details and linking record (if you link Discord): Until you unlink Discord or delete your account
- Discord linking records (the sign-in record, and the Discord details held until you enter the linking code): Usable for about 10 minutes at each step. If you enter the code after it expires, or enter it wrong too many times, or the Discord account is already linked elsewhere, we delete the Discord details right away; otherwise the daily cleanup deletes them, usually within a day. Starting a new link cancels any earlier unfinished one. All of these records are deleted when you delete your account
- Discord Anti-Abuse Reward Marker: Kept permanently, including after you unlink Discord or delete your account. Prevents the same Discord account from collecting the linking and server awards again. Holds only the award times, under a keyed one-way hash of the Discord ID; no account ID, Discord ID or username
- Patreon Anti-Fraud Membership Marker: Up to 3 years after account deletion. Prevents the same Patreon membership from collecting one-time founding rewards again on another account. Keeps only the Patreon membership ID and a hashed reference to the deleted account; no email, name or profile data
- Unmatched Patreon Supporter Records: Up to 180 days after the most recent Patreon event. Used to match supporters who haven't yet created or verified an account, and for support, refund and chargeback reconciliation
- Patreon webhook processing markers: 90 days. Used to prevent duplicate events; no name or email
- Patreon reconciliation reports: 90 days, or sooner when your account is deleted
- Cross-app link records: While the link or account exists. Unlink delivery records: kept, with your account ID, until Writerer confirms the unlink (we keep retrying), then up to 30 days. If the unlink fails because the two apps' records don't match, the record is kept, with your account ID, until our team resolves it
- Data covered by a legal preservation request: If law enforcement or another authority validly asks us to preserve data, or we report child sexual abuse material to the National Center for Missing & Exploited Children as U.S. law requires, we keep the data concerned for as long as the law requires, even if it would otherwise be deleted
6. Deleting Your Account and Exporting Your Data
6.1 Deleting Your Account
How: open Account › Privacy Settings in the side menu (or Profile Settings › Privacy, Data & Legal), then Your Data › Danger Zone › Delete Account. You may need to sign in again first. You can also email privacy@nerdhonest.com from your account email address.
30-day grace period. When you ask to delete your account:
- your public profile is hidden right away, and your bio and featured character are removed from it. If you change your bio or featured character during the grace period, the change is copied to your public profile, but the profile stays hidden;
- you are signed out on every device. Another device can stay signed in for up to about an hour, until its sign-in token expires;
- you can sign back in and keep using the Service during the 30 days; and
- you can cancel with Cancel Deletion Request, which restores your public profile, including its featured character. Your bio isn't restored automatically; it appears again the next time you change it or its visibility in Profile Settings. Signing in doesn't cancel the request by itself.
If you request deletion in the app, we email you then, if you cancel, and when deletion is complete. If our team deletes your account directly (for example, after you ask by email), we don't send these emails.
After 30 days, our daily deletion job permanently deletes your account. The job handles up to 10 accounts a day, so it usually reaches yours within a day after the grace period ends, but it can take longer if many deletions are due at once. If any step fails, the deletion isn't treated as complete: the job tries again on later runs, up to 5 times in all, and if it still can't finish, it is flagged for our team to complete. Until then, the deletion request keeps your account ID. We delete:
- your account, profile, settings, characters and everything else stored under your account;
- your uploads (avatar, images, audio and your virtual tabletop asset library), drafts, data exports and bug reports with their attachments;
- homebrew you haven't published, and private or party homebrew;
- your private notes, including in parties you have left, and your entries in shared notes in parties you still belong to;
- your ratings, reviews and votes on other people's homebrew;
- your friends, friend requests, party memberships, join requests and invites;
- your early-access (waitlist) record;
- your module download and key records, promo-code IP hashes, and most rate-limit counters (the rest expire on their own, see Section 5);
- your Loyalty Points, notifications, consent history and agreement records (after we keep the 3-year proof described in Section 5); and
- referral and code records, except as described below.
What stays, and how:
- Published homebrew stays available to other players, credited to "Deleted user". Your name, username and photo are removed from it. Its images move to a location not tied to your account. The item keeps its internal ID, which contains your former account ID (a random identifier, not your name or email). To remove a published item, delete it before you delete your account.
- Copies other players saved of your homebrew keep working. Where their credit matched your name or username, it changes to "Deleted user".
- Party content you uploaded (maps, art and tokens) stays with the party. Your name is removed, and the uploader field is replaced with a keyed hash.
- Shared note sheets you worked on stay, credited to "Deleted user".
- Other shared party records, in the parties you belong to when your account is deleted, stay with the party: for example, dice rolls, map annotations, scheduling availability and RSVPs, shop purchases and party audio. Where they show your name, it is replaced with "Deleted user", and your account ID in them is replaced with a keyed hash. In notifications you sent to other users, your name is replaced with "Deleted user" and your photo is removed.
- Parties you own pass to another member: the party's Guide first, then an admin, then any other member. The new owner can see what owners and admins can see. A party with no other members is deleted.
- Reports you filed stay as moderation history, with your account ID replaced by "deleted_user".
- Content reports about you stay as moderation history. Once a report is resolved or dismissed, your account ID in it is replaced with a keyed hash and the preview of your content is removed. A report that is still open keeps your account ID until we resolve it.
- Referral and code history stays in pseudonymized form (your account ID replaced by a keyed hash), so that codes and rewards can't be reused. This covers invite-code, promo-code and supporter-code redemptions and usage, referral records, and the Loyalty Points entries your referrer earned for referring you.
- Proofs, DMCA records, any repeat-infringer marker, marketing suppression records, Patreon and Discord anti-abuse markers and the deletion record stay as described in Section 5.
- Anonymous totals, such as feedback totals and review "helpful" counts, stay because they no longer identify you.
Known limits. We want to be clear about what deletion doesn't reach yet:
- On the virtual tabletop, some party data still carries your account ID after deletion: fog-of-war zones, drawings, map tokens and whispers you sent.
- Whispers other members sent you stay with the party.
- Some other shared party records keep your name or account ID: area-of-effect templates, "added by" on party inventory, scene-import sessions, "performed by" names in the party treasury, and the creator of recurring session rules.
- Shared records in parties you had already left aren't changed. Note entries you wrote in note sections that someone else owns, in parties you had already left, aren't removed either.
- Dice rolls made under an earlier display name keep that name. A roll by someone else who used the same name as you, such as a former party member, may also be relabelled "Deleted user".
- In notifications you sent to other users, we replace your name in the message text, not in the title. Titles are standard text that doesn't contain names.
- Your online and Focus status in a party isn't removed by the deletion job; it clears itself when your app disconnects.
- If your name appears in the free text of published homebrew (for example, in a description), it isn't removed.
- Saved copies of your homebrew that have no image keep their original creator credit.
If you want any of this removed, email privacy@nerdhonest.com and we will deal with it by hand.
Other services. When your account is deleted:
- we tell RevenueCat to remove access we granted through it (for example, from Patreon or a code). If that fails, we retry up to 10 times over several hours; if it still fails, we keep your account ID in a retry record for up to 90 days so we can fix the problem, then delete it;
- we ask RevenueCat to delete the data it holds about your account, after any pending access changes settle (normally within minutes). We keep retrying this request, including through RevenueCat outages. If RevenueCat keeps rejecting it, we keep your account ID in a retry record for up to 90 days so we can fix the problem, then delete it;
- we tell Writerer to remove any link; and
- if you used Sign in with Apple in our iOS or macOS app, we ask Apple to revoke the token it issued to our app (see Section 5).
Your store subscription itself isn't cancelled by deleting your account: cancel it with the App Store, Google Play or Patreon (see our Subscription Terms).
6.2 Exporting Your Data
How: open Account › Privacy Settings › Your Data › Export My Data and choose Request Export. You can also email privacy@nerdhonest.com.
The export is prepared in the background. When it's ready, we email you a download link and show it in the app. The link works for 7 days. Anyone who has the link can download the file, so don't share it. You can request one export every 7 days; if an export fails, you can try again straight away.
What's included (export format version 1.7), as machine-readable JSON:
- Your profile: email, display name, username, photo, bio, preferences (including privacy and notification switches), experience levels, preferred genres and account creation date. Also your public profile.
- Your characters, with every section.
- Friends and pending friend requests (their usernames and display names only), and the parties you belong to, with your role.
- Your block list: how many accounts and when you blocked them. Each blocked account appears only as a label.
- Party invites you received and sent: the party, its name, status and dates. The other player appears only as a label.
- Content you created:
- homebrew in every scope;
- your ratings and reviews, including ones removed by moderation;
- party notes and note sheets you wrote;
- draft modules and their content;
- sound scenes, and custom or saved sound sets;
- shop and location templates;
- your virtual tabletop asset library, and the party virtual tabletop assets you uploaded.
- Files you uploaded, listed by path, type, size and date (not as links). Bug-report images come with links that expire after 7 days.
- Scheduling: your general availability, your availability in each party's scheduling cycles, and your session RSVPs.
- Billing: your current plan and entitlements as last synced from RevenueCat, and your billing event history, with a guide to the fields.
- Rewards and access:
- Loyalty Points ledger, streaks, awards and monthly bonus claims;
- spin history and allowance;
- quest progress and competition contributions;
- your invite codes.
- Linked accounts: Patreon support and tenure, the Writerer link, and your Discord and Sign in with Apple connections (never the tokens).
- Consent and notices:
- consent history;
- legal acceptances and acceptance events, including the age confirmation;
- marketing-consent events;
- records of legal-change emails we sent you;
- your early-access (waitlist) record.
- Settings and usage:
- privacy settings and audio settings;
- music usage and upload records, with your upload licence confirmations;
- scene-import quota;
- devices registered for push notifications (platform and dates only).
- Notifications you received, bug reports you submitted, and your content-feedback answers.
- Notes on any part of the export that failed, with a flag if the export is partial.
- Any other record stored under your account, except the ones listed below.
What's left out:
- Other people's IDs, photos and names. They appear only as labels such as "other-user-1", consistent within one export but not across exports. Friends' and friend requesters' usernames and display names are the one exception.
- Passwords, sign-in and access tokens, push device tokens and other credentials.
- Values kept only for matching: keyed hashes, the repeat-infringer sign-in check, and internal duplicate-request records.
- Records kept after deletion for legal reasons (Section 5).
- A history longer than 25,000 entries is cut there, and the file says so.
Available on request. These aren't in the self-serve export yet. You can ask for them at privacy@nerdhonest.com:
- DMCA notices, counter-notices and strike records;
- reports you filed;
- party join requests;
- earlier saved versions of your characters;
- your module download and key records;
- access grants and their history;
- whispers, dice rolls, map annotations and custom tokens you created in parties; and
- fields of your account record that aren't listed above.
7. Your Rights and Choices
7.1 Rights for Everyone
Wherever you live, you can:
- access your personal data and get a copy (export);
- correct inaccurate data;
- delete your account and data;
- withdraw consent for analytics, crash reporting or marketing at any time;
- object to technical diagnostics and gameplay totals by turning them off;
- control your profile's visibility (and, if we launch The List, whether you appear on it);
- disconnect linked products such as Writerer; and
- unsubscribe from marketing emails, using the link in any marketing email or the Marketing Emails switch.
7.2 How to Exercise Your Rights
In the app: open Account › Privacy Settings in the side menu (also reachable from Profile Settings › Privacy, Data & Legal). There you can:
- switch Analytics, Technical diagnostics, Crash Reporting (Android, iOS and macOS only), Share anonymized gameplay data and Marketing Emails on or off;
- export your data; and
- delete your account.
Profile visibility (Appear in community directory) and Autoplay profile songs are in Profile Settings.
By email: write to privacy@nerdhonest.com from your account email address. Tell us which right you want to use and give any details that will help. We may need to confirm your identity before we act.
- Export (in the app): We email a link when it's ready, usually soon after you ask
- Requests by email (access, correction, objection, other): Within 30 days
- Deletion: Deletion is complete about 30 days after your request (the grace period), plus processing time
If we need more time, we will tell you why, as the law allows.
7.3 EEA and UK Users
Under the GDPR and UK GDPR, you also have the right to restrict our processing, to object to processing based on legitimate interests, to data portability, and to complain to a data protection authority, in particular in the country where you live or work.
We are based in the United States and don't currently offer the Service specifically to people in the EEA or UK. We have not appointed a representative in the EU or UK under Article 27 of the GDPR or UK GDPR.
7.4 U.S. State Privacy Rights
Depending on where you live (for example, California, Colorado, Connecticut, Virginia and other states with privacy laws), you may have rights to know and access your personal data, to correct it, to delete it, to get a portable copy, and to opt out of its sale, of targeted advertising and of certain profiling.
- We honor requests to access, correct, delete and export your data from every user, whichever state you live in. See Section 7.2.
- We don't sell your personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or use it for profiling that produces legal or similarly significant effects. So there is nothing to opt out of.
- We don't use or disclose sensitive personal information to infer characteristics about you.
- We won't discriminate against you for using your privacy rights.
- Authorized agents may make a request for you if they show us your written permission and we can confirm your identity.
- Appeals: if we decline your request, you can appeal by replying to our answer or emailing privacy@nerdhonest.com with "Appeal" in the subject. If you are not satisfied with the result, you may contact your state's attorney general.
California: the categories of personal information we collect are listed in Section 2, the purposes in Section 3, how long we keep it in Section 5, and who receives it in Section 4. We don't sell or share personal information as those terms are defined in the California Consumer Privacy Act. Section 5 of our Cookie Policy explains how we respond to Do Not Track signals.
Nevada: we don't sell covered information as defined under Nevada law. Nevada residents can send requests about the sale of covered information to privacy@nerdhonest.com.
8. Security
We protect personal data with technical and organizational measures, including:
- encryption in transit (TLS) and encryption at rest by our cloud provider;
- database and file-storage security rules that limit who can read and write each record;
- App Check, which helps block requests to our server functions that don't come from our real apps;
- short-lived signed links for media files;
- limiting administrative access to the people who need it; and
- keyed hashes in place of account IDs in the records we keep after deletion.
No system is perfectly secure, and we can't guarantee absolute security. If a security breach affects your personal data, we will notify you and the authorities as the law requires.
9. International Data Transfers
We are based in the United States, and our service providers mainly process data in the United States. If you use the Service from outside the United States, your data will be transferred to and processed in the United States.
For transfers from the EEA, UK or Switzerland, we rely on each provider's data processing terms, including the EU Standard Contractual Clauses where they apply, such as Google Cloud's Data Processing Terms. Google LLC is also certified under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions.
10. Children's Privacy
Age of Aeternus is only for people aged 18 or older who have reached the age of majority where they live. Everyone confirms they are 18 or older when they sign up. The Service isn't directed to children, and we don't knowingly collect personal information from anyone under 18. That includes children under 13, who are protected by the U.S. Children's Online Privacy Protection Act (COPPA).
If we learn that someone under 18 has an account, we will delete it and their data, except records we must keep by law. If you believe a child has given us personal information, contact privacy@nerdhonest.com.
11. Third-Party Privacy Policies
- Google Firebase and Google Cloud: firebase.google.com/support/privacy
- Google (reCAPTCHA, Analytics, Sign in with Google, Google Play): policies.google.com/privacy
- Apple (Sign in with Apple, App Store): www.apple.com/legal/privacy/
- RevenueCat: www.revenuecat.com/privacy
- Patreon: privacy.patreon.com/
- Ko-fi: more.ko-fi.com/privacy
- Discord: discord.com/privacy
- Resend: resend.com/legal/privacy-policy
- EmailOctopus: emailoctopus.com/legal/privacy
12. Cookies and Similar Technologies
Our Cookie Policy explains the cookies, browser storage and device storage we use, and how to control them.
13. Changes to This Policy
We may update this Privacy Policy. When we do, we will change the "Last Updated" date and add an entry to the Document History below.
For material changes, we will tell you in advance by email and in the app. When you next open the app while signed in, we will ask you to confirm that you have read the updated policy before you continue. Changes apply going forward. They don't change how we handled your data before the change. Where a change needs your consent, we will ask for it.
14. Contact Us
NerdHonest LLC 8735 Dunwoody Place, Suite R, Atlanta, GA 30350, United States (mailing address)
- Privacy questions and requests: privacy@nerdhonest.com
- Copyright (DMCA): dmca@nerdhonest.com
- Legal notices: legal@nerdhonest.com
- General support: support@nerdhonest.com
We aim to respond to privacy requests within 30 days.
Document History
- Version 2.0 (October 2, 2026). Rewritten to match how the Service works today. NerdHonest LLC is named, with its address. The policy now covers the web, mobile and desktop apps and the website. Added a legal basis for each purpose. Profiles are private by default. Analytics and Crashlytics run only after you accept; technical diagnostics and gameplay totals can be turned off. Crash reports no longer contain error-message text, and crash reports and diagnostics are deleted after 30 days. Gameplay data is now daily anonymous totals, kept 24 months. Sponsor counts carry no account ID. Added a full retention table. Explained what account deletion removes and keeps, and its known limits, and what the data export (version 1.7) contains. Disclosed the early-access (waitlist) record and the repeat-infringer marker. Disclosed the keyed IP hashes kept for 90 days for module downloads and promo codes, and that party members see your online status. Disclosed RevenueCat starting on the web before sign-in, App Check and reCAPTCHA, push tokens, Ko-fi, optional Discord linking, Writerer linking and stream overlay links. Firebase Analytics is built in but not currently active. DMCA records and completed-deletion records are kept 3 years; the marketing contact record is stripped of your email address and account IDs after deletion. Removed Stripe, the "Data Protection Officer" label and the incorrect COPPA note. Updated the settings paths and the U.S. state rights section.
- Version 1.5 (August 10, 2026). Previous version.
Effective Date: October 2, 2026
Version: 2.0