Legal — Parastoria
Privacy Policy
Effective July 29, 2026 · Viral Host Digital LLC
Parastoria is local-first and built by GMs who distrust data-hungry software. Your worlds live on your own computer by default, we use no third-party analytics, and we never sell your data. The little we do collect is what it takes to sign you in, bill the subscription, keep the free tier and our abuse protections honest, and — only when you ask for them — power the few features that reach beyond your machine. This page is the plain-English account of all of it, and the precise one underneath.
Who we are
This policy is issued by Viral Host Digital LLC (“Parastoria,” “we,” “us”), based in the Commonwealth of Puerto Rico. It covers the Parastoria desktop app, this website at parastoria.app, and the player companion your table joins from a phone. Marin, the co-author inside the app, is a feature of that software — not a separate service that whisks your data somewhere else.
For data-protection law, Viral Host Digital LLC is the controller of the personal data described here. We have not appointed a Data Protection Officer, because our processing doesn’t meet the threshold that requires one — but the inbox in section 19 reaches the people responsible. If you’re in the EEA or the UK, we serve you, and the same inbox reaches us — section 19 has the address.
What we collect
We collect as little as the product allows. Here is the whole list — most of it only appears if you subscribe or turn on a feature that needs it.
- Your account email
- When you create an account to subscribe, your email is held in Amazon Cognito, our sign-in provider. It exists to sign you in and to tie your subscription to you. You don’t need an account to download Parastoria or to play on the free tier.
- Billing details
- Payments go through Stripe. Your card number is entered on Stripe’s own checkout and never touches our servers — we can’t see it and don’t store it. What we keep is a Stripe customer reference and your current plan status, so the app knows whether you’re subscribed.
- A pseudonymous device hash
- Hosted Marin comes with the free tier, no account needed. So that our protections against automated abuse can work without making you log in, hosted requests carry a device hash — a one-way code derived from your computer’s operating-system machine identifier, not from your name, email, or location. Because it comes from the machine rather than the install, it survives reinstalling the app. (Where the operating system offers no stable machine identifier, we hash a per-install identifier instead.) It identifies a device, not a person, though privacy law may still treat it as personal data, so we do. If you’re signed in, your account id plays this role instead.
- An opaque campaign identifier on deep generations
- When you ask hosted Marin for a deep generation — conjuring new places, people, or truths into a world — the request also carries an opaque campaign identifier: a random id that contains no world content — no names, no text, nothing of the world itself — plus the fact that a generation occurred. We count those per campaign so the free lantern’s budget is honoured on our side as well as in the app. The record we keep is the opaque id and a count — nothing more.
- Prompts and campaign context you send to hosted Marin
- When you use hosted Marin, the turn’s prompt — and the campaign context Marin needs to answer it, which can include GM-only material — leaves your machine to reach an AI provider. This is optional and only happens on hosted turns; section 06 is the detail.
- Cloud-sync snapshots and assets
- If you turn on cloud sync (a paid option), Parastoria uploads a snapshot of the campaign you sync plus its images and maps to storage we keep for your account. Sync is off until you enable it; section 05 explains exactly what moves and how it’s protected.
- Newsletter email
- If you opt in to our newsletter, we keep your email and subscription status to send it, using Amazon SES. It’s a double opt-in you can leave at any time.
- Player companion data (from your players)
- When players join your table from their phones, they enter a display name, and we store a little seat data to keep them in the game. This comes from the players, not from you, so we disclose it here as data obtained from someone other than the account holder; section 07 is the full picture.
- What you send to support
- If you email support, we keep that correspondence — your message and address — for as long as it takes to help you and to keep a record of the fix. Support is a plain email link; there is no form and no tracking wrapped around it.
We don’t intentionally collect sensitive information — no precise location, health, biometric, or government-ID data, and no card data on our side (that stays with Stripe). The one place it could slip in is free text you type into a world or a hosted-Marin prompt, so please don’t put anything you’d consider sensitive there. Because we don’t use sensitive information to infer things about you, there’s no “limit the use of my sensitive information” link — there is nothing to limit.
Why we collect it, and our legal basis
We only use data for a specific purpose. If you’re in the EEA or the UK, each purpose also has a lawful basis under the GDPR — here is the map.
- Managing your account and subscription
- Performance of our contract with you (Art. 6(1)(b)).
- Taking payment and keeping tax records
- Contract, plus our own legal obligations (Art. 6(1)(b) and (c)).
- Hosted usage records (device hash, campaign counts)
- Our legitimate interest in keeping the free tier’s budget honest and preventing abuse (Art. 6(1)(f)).
- Answering your hosted-Marin turns
- Performing our contract, and our legitimate interest in providing the feature you asked for (Art. 6(1)(b)/(f)).
- Cloud sync
- Performance of our contract, when you enable it (Art. 6(1)(b)).
- Player companion seats
- Hosting the shared table you invited players to — contract and our legitimate interest (Art. 6(1)(b)/(f)).
- The newsletter
- Your consent (Art. 6(1)(a)), which you can withdraw at any time.
Where we rely on a legitimate interest, the interest is straightforward: keeping the free tier honest and heading off automated abuse, and operating and securing the service. You can object to processing based on it — see section 15.
Do you have to give us this? No account is needed to download Parastoria or use the free tier. To subscribe, we need your email and Stripe payment details — without them we can’t set up or bill the subscription. Everything else, including the newsletter, is optional.
What stays on your machine
Your worlds, campaigns, characters, the chronicle, and your notes live in a database on your own computer. By default we don’t upload them or back them up — Parastoria is local-first on purpose, and the story stays where you can see it.
A few features can reach beyond your machine, and we’re precise about which. Each is something you turn on or invoke:
- Cloud sync uploads a campaign you choose to our cloud — section 05.
- Hosted Marin sends a turn’s prompt and context to an AI provider; the same hosted calls carry the device hash (or your account id) and, on deep generations, an opaque campaign identifier, which stay with our service for usage counting — sections 02 and 06.
- The player companion pushes GM-approved views to your players’ phones — section 07.
Everything else stays put. Your worlds are files you can export at any time, and unless you turn on sync, there’s no copy of them on our side to worry about.
Cloud sync, when you turn it on
Sync is off unless you turn it on. It’s a paid, opt-in, desktop-only feature for carrying your worlds between your own devices — nothing syncs in the background, and nothing moves until you press the button.
When you enable sync and choose to push, Parastoria uploads that campaign’s snapshot (a JSON file) and the assets it references (images, maps) to storage on Amazon S3, under keys scoped to your account. It’s encrypted at rest with server-side AES-256 (SSE-S3), and a single-writer lease keeps two devices from clobbering each other. Free or lapsed accounts can pull their own data back down, but their worlds are never uploaded.
One honest caveat: this is not end-to-end encryption. Because we manage the keys, we and our infrastructure provider can technically access what’s stored — we don’t, except as needed to operate the feature or where the law requires it. If that matters to you, keep sync off and your worlds stay purely local.
Hosted Marin and your own key
When you use hosted Marin, that turn leaves your machine. To write the reply, we send the message you typed, a window of recent history, and the campaign context Marin needs — which can include GM-only material, like Charter and Scene secrets and world-truths — to a third-party AI provider, then hand the reply back to your app.
Our primary provider is OpenRouter; if it’s unavailable we fail over to Groq. OpenRouter may in turn route your request to whichever downstream inference host it selects, serving open-weight models that may change over time. We don’t use your prompts for advertising and we don’t build a profile from them. How each provider uses or retains what it receives is governed by that provider’s own terms — we don’t currently guarantee a no-training setting on your behalf, so if that matters to you, read OpenRouter’s policy and Groq’s policy, or use one of the options below.
Hosted Marin is not rationed — there is no weekly allowance and no usage meter to watch. What exists instead is the free tier’s per-campaign world budget (the lantern), and protective limits against automated abuse, sized so that ordinary play never meets them. To keep both honest, hosted calls carry the device hash from section 02 (or your account id, if you’re signed in), and deep-generation requests additionally carry the opaque campaign identifier from section 02. The records this produces hold only opaque ids, counts, and token totals — never your world’s content.
You don’t have to use hosted Marin. Bring your own key from a provider like Google, Anthropic, or OpenAI, and your requests go straight to that provider — your key is stored encrypted on your device and never sent to us. Or point Marin at a model on your own machine (for example with Ollama), in which case the turn goes only to the endpoint you configure, which defaults to your own computer — on the free tier as on the paid one, the local engine works entirely on your own device. Both options are entirely unmetered: no device hash, no campaign identifier, and no usage record on our side — those accompany hosted calls only. If you want everything to stay local, use the local engine.
The player companion
Your players can join a table from a phone with no account and no install — they scan a QR code or type an 8-character invite code, and pick a display name (1–24 characters; a nickname is fine, it need not be real). Here is what that involves.
- What we store (on AWS DynamoDB): the display name in plain text; a random clientId kept in the phone’s local storage — a clearable identifier, not a hardware fingerprint; a hashed seat token; and any character-sheet “slip” text a player submits.
- IP address — read transiently to rate-limit abuse (short-lived counters, not tied to the display name).
- What the GM pushes is a player-safe projection: the map and current scene over our relay, and a per-character “pocket sheet” through the membership API — with fog, lore, GM secrets, and hidden mechanics stripped out first.
- How long it lasts — seats sit on a 180-day sliding window (renewed by activity), slips about 30 days, reclaimed seats about 45 days, live relay connections about 2 hours and rooms about 24 hours. The phone also keeps its own local seat wallet.
- Who can see a display name — anyone holding that table’s invite code can see the roster of display names, so treat a name as shared with the table, not private.
Companion data is tied to the campaign, not to your account — in normal operation we store no link between a GM’s identity and their players. (The one exception is a deletion request, which necessarily records which campaigns to clean up; see section 14.) It clears when you delete the campaign, when you delete your account (for the campaigns section 14 explains we can identify as yours), or when the retention windows above lapse. Because a player at the table might be a child, please also read section 17.
Where your data is processed
Our servers and providers are in the United States. So if you’re in the EEA or the UK, the personal data we process is transferred there.
Where we move personal data out of the EEA or the UK, we rely on a valid transfer safeguard for each recipient — the EU–US Data Privacy Framework where the recipient is certified, and otherwise the European Commission’s Standard Contractual Clauses (for the EEA) together with the UK’s International Data Transfer Addendum (for the UK). You can ask us for a copy of the safeguard that applies to a given transfer using the contact details in section 19.
No analytics, no sale, no ad-tech
This site and the app carry zero third-party analytics — no Google Analytics, no ad pixels, no session recorders, no marketing fingerprinting. The only usage signal is a local diagnostic log that stays on your machine and is never transmitted. We don’t build a profile of you.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising — not for money, not for anything of value. Because none of that happens, there’s no “Do Not Sell or Share” link to click, nothing to opt out of, and no need for us to act on Global Privacy Control or other opt-out signals for a sale that never occurs. The same holds for minors: we don’t knowingly sell or share the personal information of anyone under 16. If this ever changed, we’d update this policy first and add the controls the law requires.
Marin drafts; you decide
Parastoria doesn’t make decisions about you by automated means that produce legal or similarly significant effects. Marin drafts prose, suggestions, and rulings — the human GM at the table always decides what becomes canon. The free tier’s lantern simply pauses new gathering in a campaign once its budget is full, and our protective limits against automated abuse respond to traffic patterns, not to you personally — both are usage limits, not judgments about you. We don’t profile you.
How long we keep it
- Account email and subscription status — kept while your account is open; removed after you delete it (see section 14).
- Billing records — Stripe retains transaction records for as long as its own legal and accounting obligations require, independent of your account with us; after you delete, we keep only the legally-required tax records.
- Hosted usage records — token totals per calendar month and per-campaign generation counts, keyed to the device hash (or to your account, if you’re signed in) and holding no world content — kept for about 13 months, then deleted automatically. The purpose is preventing abuse and understanding aggregate usage — not building a profile of you.
- Cloud-sync snapshots and assets — kept in your account’s storage until you overwrite them, delete the campaign, or delete your account, which erases them (see section 14).
- Player companion data — erased when you delete the campaign, and when you delete your account for the campaigns covered in section 14. Otherwise it clears on the retention windows in section 07 (seats on a 180-day sliding window, slips about 30 days, and so on).
- Newsletter email — kept until you unsubscribe or delete your account.
- Support emails — kept only as long as needed to resolve your request and keep a reasonable record of it.
- After account deletion — we keep only Stripe’s legally-required tax records and a short-lived (about 30-day) internal deletion audit record — an internal id, your email, timestamps, and the list of campaign ids the deletion had to clean up — which then expires.
How to delete your account
You can delete your account yourself, at any time — no email or support request required. Do it in the app (Settings → Delete account) or on the web at parastoria.app/delete-account. For your security we’ll ask you to sign in again first and to type a confirmation.
Deletion is not instant: it’s scheduled after a 7-day grace window, a short, deliberate pause so an accidental or unwanted deletion can be undone. We email you a one-click cancel link the moment you request it. Nothing is destroyed until that window closes, so cancelling really does put everything back. Requesting deletion stops your subscription from renewing right away; when the window closes, we cancel and delete your Stripe customer record and purge your login and identity, device registrations, usage records, marketing opt-ins, your cloud-sync worlds and their uploaded images, and your players’ companion data (seats, slips, and invite codes). Afterwards we keep only Stripe’s legally-required tax records and the short-lived (about 30-day) deletion audit record from section 13.
One detail worth naming, because it decides what we can reach. Your players’ companion data is tied to the campaign, not to your account — deliberately, so that hosting a table doesn’t create a standing record linking your identity to your players. The trade-off is that we can only erase what a deletion request can identify as yours: the campaigns on the computer you delete from (your app names them, and proves they’re yours, as part of the request), and any campaign you’ve synced to the cloud. If you delete from the web alone and a campaign was never synced, we have no way to tell it was yours, so its seats and slips clear on their retention windows instead (section 07) — or immediately, if you delete the campaign from the app first. Deleting the campaign is always the most complete way to remove player data. That campaign list is held only until the deletion audit record expires (section 13).
Your worlds also live on your own machine, and deleting your account never touches that local copy — export or keep it as you like.
Your privacy rights
Depending on where you live, you have rights over your personal data — and we honor them for everyone. You can ask us to access a copy of the data we hold, correct it, delete it, restrict or object to certain processing, and receive it in a portable form.
How to exercise them. The fastest routes are built into the product: self-service deletion in the app and at parastoria.app/delete-account, and your local worlds export as files (which covers portability). For access, correction, or anything else, email hello@parastoria.app. We respond free of charge and without undue delay — within one month under the UK/EU GDPR, and within 45 days (with one 45-day extension where allowed) under US state laws.
Withdraw consent. Where we rely on your consent — the newsletter — you can withdraw it at any time with the one-click unsubscribe in any issue, or by emailing us. It’s as easy to withdraw as it was to give, and it doesn’t affect anything we did beforehand.
Appeal. If we decline a request, you can appeal by replying to our decision or emailing hello@parastoria.app; we’ll respond within the legal window (up to 60 days under most US state laws that grant an appeal). If we still say no, we’ll tell you how to contact your state attorney general.
Complain. EEA and UK users can lodge a complaint with a supervisory authority — in the UK, the Information Commissioner’s Office (ICO); in the EEA, your local data-protection authority. We’d appreciate the chance to put it right first. See section 19.
No penalty for asking. We won’t charge you a different price or give you a worse service for exercising these rights. There’s a no-account free tier and a single subscription, and the only change from deleting is the unavoidable consequence of closing the account.
Security and breach notice
We protect your data with current, sensible measures and we don’t overpromise. Connections travel over HTTPS/TLS; cloud-sync data is encrypted at rest (SSE-S3, AES-256); sign-in is managed by Amazon Cognito, with a step-up re-authentication before account deletion; your sync storage is scoped to your account; and your card details never reach our servers.
No system is perfectly secure, and we can’t promise absolute security — but we work to protect your data and to keep only what we need. If a breach affecting your personal data occurs, we’ll notify the people and authorities the law requires, within the timeframes it sets — including, where they apply, the GDPR’s 72-hour authority notification and Puerto Rico’s breach-notice rules.
Children’s privacy
Parastoria is made for the adult hosting the game and isn’t directed to children. You must be at least 13 to use Marin, and we don’t knowingly collect personal data from children under 13.
We’ll be plain about the exposure: the player companion doesn’t ask a player’s age. If a child at your table scans the QR code and types a display name, we have no age gate to catch it — we rely on the GM to decide who joins, and the data is minimal (a display name and the seat records in section 07). In the EEA, the minimum age for consent-based features like the newsletter is 16 (or lower where a member state allows, down to 13); in the UK it’s 13.
If you believe a child under 13 has given us personal information, email us and we’ll delete it. We don’t knowingly sell or share any minor’s data (section 11).
Changes to this policy
If we change how we handle data, we’ll update this page and move the effective date at the top. For anything material — a new provider, a new kind of data — we’ll say so plainly here before it takes effect, and we review this policy at least once a year. The current version was last effective July 29, 2026.
Contact, and how to complain
Questions about your privacy, or a request about your data? Write to a real person:
Email hello@parastoria.app
Viral Host Digital LLC
1654 Calle Tulipan Ste 100, San Juan, PR 00927-6242
EEA and UK users. Write to us at the address above — it reaches the people responsible for this policy, and we handle requests from everywhere the same way. You can also lodge a complaint with a supervisory authority — in the UK with the Information Commissioner’s Office (ICO), and in the EEA with your local data-protection authority — though we’d welcome the chance to resolve it with you first.
We have not appointed a Data Protection Officer, as our processing doesn’t meet the threshold that requires one; the inbox above reaches the people responsible for this policy.
Your world stays yours. — P.S., we love you.