Privacy Policy
Last updated: May 11, 2026
This Privacy Policy explains how Gold & XP ("we", "us", "our") collects, uses, and shares information when you use our service at goldandxp.com (the "Service"). By using the Service you agree to the practices described here.
1. Information we collect
Information you provide
- Account information: username, password (stored hashed with bcrypt), and optional email address.
- Profile information: display name, bio, avatar image, preferred editions and roles. All optional.
- Campaign and character data: campaigns, characters, locations, NPCs, sessions, blog entries, messages, and other content you create on the Service.
- Uploaded images: avatars, character portraits, location/map images, blog images, etc. Stored in our object storage at Cloudflare R2.
- AI prompts: text prompts you submit for AI character portraits or blog image generation.
- Payment information: when you subscribe or buy credits, payment details are collected directly by Stripe. We do not see or store your full card number; we only receive a Stripe customer ID, the last four digits, card brand, and subscription metadata.
- Communications: messages you send to other users, support emails, and form submissions (e.g. early access signup).
Information collected automatically
- Session tokens stored in your browser's local storage to keep you logged in.
- Theme preferences (light/dark mode, accent color) stored in local storage and on your account.
- Server logs: IP address, request paths, timestamps, error traces — used for debugging and abuse prevention. Retained for a limited period and then deleted.
We do not use third-party advertising or behavioral tracking cookies.
2. How we use your information
- To create and maintain your account and operate the Service.
- To process payments and manage subscriptions through Stripe.
- To generate AI images at your request, by sending your prompt to our AI provider.
- To deliver in-app notifications and (if you opt in) email notifications.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To improve the Service, including aggregate usage analytics.
- To comply with legal obligations and enforce our Terms.
3. How we share your information
We do not sell your personal data. We share information only with:
- Stripe, Inc. — payment processing. Stripe's privacy policy: stripe.com/privacy.
- Google Gemini (Nano Banana 2) — when you request AI image generation, your prompt and the generated image transit through the AI provider's infrastructure. We do not send your account identifiers to the provider.
- Cloudflare, Inc. — image storage (R2) and CDN delivery.
- Railway Corp. — application hosting and database hosting.
- Other users of the Service — content you mark as public (your public profile, public campaign pages, published blog entries) is visible to other users and unauthenticated visitors. Direct messages and private campaign data are visible only to authorized members.
- Law enforcement — if required by valid legal process, or to investigate fraud, abuse, or threats to safety.
- Successors — if we transfer ownership of the Service (e.g. acquisition), your data may be transferred under equivalent privacy protections.
4. Public content
Some content is public by default or by your choice. This includes:
- Your username and basic profile information.
- Public campaign pages and published blog entries you create as a DM.
- Group posts in public groups.
Be thoughtful about what you choose to make public. We cannot control how third parties view, save, or share publicly visible content.
5. Data retention
We retain your account data while your account is active. You can delete your account from Account Settings; deletion starts a 30-day recovery window during which your account is locked but nothing is removed, and you can cancel by signing back in or using the emailed cancellation link. After the window ends:
- Your personal account record, profile, and characters you own are deleted.
- Campaigns you run as DM and groups you created are deleted, including their content.
- Content you contributed to shared campaigns you don't own may be retained where deletion would compromise the campaign for other members. We anonymize or detach your name from such content where feasible.
- Backups containing your data are retained for up to 30 days and then purged.
- Records we are legally required to keep (e.g. invoices for tax purposes) are retained for the applicable statutory period.
See our Account Deletion and Data Deletion / Data Requests pages for request instructions.
6. Security
We use industry-standard measures to protect your data, including TLS encryption in transit, bcrypt password hashing, JWT-based authentication, signed Stripe webhooks, and principle-of-least-privilege access to our infrastructure. No system is perfectly secure — if you suspect a vulnerability, please contact us at support@goldandxp.com.
7. Your rights
Depending on your jurisdiction (notably under GDPR for EU/EEA/UK residents and CCPA for California residents), you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your account and personal data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email us at support@goldandxp.com. We will respond within 30 days. You can also review our Data Deletion / Data Requests page.
8. Children
The Service is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us data, please contact us and we will delete it.
9. International transfers
Our servers and service providers (Stripe, Cloudflare, Railway, our AI provider) may be located outside your country of residence. By using the Service, you consent to your data being transferred to and processed in those countries, which may have different data protection laws. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for transfers out of the EU/UK.
10. Cookies and local storage
We use browser local storage (not third-party cookies) for:
- Storing your authentication token to keep you logged in.
- Remembering your theme preference and other UI settings.
- Tracking whether you've passed the site passcode gate (during early access).
These are strictly necessary for the Service to function. Clearing your browser storage will log you out. See our Cookie Policy for more detail.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or an in-app banner at least 14 days before they take effect.
12. Contact
Questions, complaints, or requests regarding your data? Email us at support@goldandxp.com or visit our Support / Contact page.