🔒 Privacy Policy

1. Introduction and data controller

This privacy policy explains what personal data DiceRoll (the "Service") collects, how and why we use it, with whom we share it, and what rights you have. The data controller is the operator of DiceRoll, whom you can reach at info@dicerollvtt.com. We process personal data in accordance with the EU General Data Protection Regulation (GDPR).

2. Data we collect

Depending on how you use the Service, we may collect the following categories of personal data:

  • Account data: e-mail address, nickname, and a securely hashed password.
  • Profile data: an optional profile picture and any details you choose to add to your profile.
  • Sign-in data: if you sign in through a third-party provider (Google, Facebook, or Discord), we receive basic profile information such as your name, e-mail, and profile picture.
  • Content and game data: characters, maps, tokens, rooms, notes, and other content you create or upload.
  • Communications: chat messages, room invitations, and support requests.
  • AI interaction data: the prompts and context you submit when you use optional AI features.
  • Economy data: your in-app coin balance, marketplace purchases, referral rewards, and plan or subscription status.
  • Device and push data: if you enable notifications, a device push token (for Android or iOS).
  • Technical data: IP address, browser or device type, and access times, recorded in server logs.

3. Purposes of processing

We use your personal data to:

  • Provide, operate, and maintain the Service;
  • Authenticate and authorise users;
  • Store and synchronise your content and game data;
  • Enable communication between users (chat, invitations, notifications);
  • Operate the in-app economy, marketplace, plans, and referral rewards;
  • Provide optional AI features when you choose to use them;
  • Keep the Service secure and prevent abuse and fraud;
  • Analyse and improve the Service (analytics only with your consent).

4. Legal bases for processing

We process your personal data on the following legal bases under the GDPR:

  • Performance of a contract (Art. 6(1)(b)): to provide the Service you sign up for.
  • Consent (Art. 6(1)(a)): for analytics cookies, push notifications, and other optional features; you can withdraw consent at any time.
  • Legitimate interests (Art. 6(1)(f)): to keep the Service secure, prevent abuse, and improve our product.
  • Legal obligation (Art. 6(1)(c)): where we are required by law to process or retain certain data.

5. How we store and secure data

Your data is stored in a secured database and protected by technical and organisational measures, including:

  • HTTPS encryption for all communication;
  • Password hashing with bcrypt (passwords are never stored in readable form);
  • Signed session tokens for authentication;
  • Rate limiting and abuse protection;
  • Access controls and regular security updates.

6. Sharing and processors

We do not sell your personal data. We share it only with service providers (processors) who help us operate the Service, and only as needed:

  • Sign-in providers: Google, Facebook, Discord (only if you choose to sign in through them).
  • AI providers: OpenAI, which processes the prompts you submit when you use AI features.
  • E-mail delivery: providers used to send verification and transactional e-mails (e.g. Resend, Amazon SES).
  • Analytics: Google Analytics (only with your consent).
  • Push notifications: Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS), if you enable notifications.
  • Media and GIFs: third-party providers such as Tenor when you search for and insert GIFs.
  • Hosting and storage: the infrastructure and database providers that host the application, files, and data.
  • Legal requirements: authorities, where required by law or to protect our rights.

We do not share your personal data with third parties for their own marketing purposes.

7. International data transfers

We aim to store data within the European Union. However, some of our providers (for example AI, analytics, and push-notification services) may process data outside the EU, including in the United States. Where this happens, we rely on appropriate safeguards permitted by the GDPR — such as the European Commission's Standard Contractual Clauses or an adequacy decision — to protect your data.

8. Cookies and analytics

DiceRoll uses essential cookies and similar technologies that are necessary for sign-in, maintaining your session, and basic security. These cannot be switched off without breaking core functionality.

With your consent, we also use analytics (Google Analytics 4) to measure traffic and improve the product. We enable analytics only after you grant consent in the cookie banner.

You can change or withdraw your consent at any time by updating your choice in the cookie banner or by contacting support.

For signed-in users, first-party product analytics stores only technical categories (access method, device type, operating system, browser, language, time zone, and signup source). We do not store the IP address or the full user-agent for this purpose.

9. AI processing and automated decisions

When you use optional AI features, the content you submit is processed by a third-party AI provider to generate the requested output. We do not use your personal data to make solely automated decisions that produce legal or similarly significant effects on you. AI features are used only to generate game content at your request.

10. Your rights

Under the GDPR you have the following rights:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct inaccurate data in your profile.
  • Erasure: request deletion of your account and associated data.
  • Portability: obtain your data in a structured, machine-readable format.
  • Restriction and objection: restrict or object to certain processing.
  • Withdraw consent: withdraw any consent you have given, at any time.

11. Data retention

We keep your personal data for as long as your account is active. After you delete your account, your data is permanently erased from the database within 30 days, except where we must retain certain data to meet legal obligations. Server logs are kept for a maximum of 90 days.

12. Children's privacy

The Service is not intended for children under 13. We do not knowingly collect personal data from children under this age without the consent of a parent or legal guardian. If we learn that we have collected such data without the required consent, we will delete it promptly.

13. Changes to this policy

We may update this privacy policy from time to time. We will inform you of significant changes by e-mail or through a notice in the Service. We recommend reviewing this page periodically.

14. Contact and complaints

If you have any questions about how we handle your personal data, or if you wish to exercise your rights, you can contact us through the Service or by e-mail at info@dicerollvtt.com.

You also have the right to lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů) in the Czech Republic, or with the supervisory authority in your country of residence.

Last updated: 22. 7. 2026