Privacy,
in plain language.
Explore freely. Share only what you want to. Saved characters and portraits are private.
Taking the quiz
You can complete the quiz without an account. Quiz answers and measurements are stored in this browser to preserve your draft. They are not sent to our database while you answer. Anyone using this browser profile could see the draft. Use “Clear local draft” in the footer to remove it. Downloaded character sheets are files you control.
Saving a character
Email sign-in is provided by Supabase. When you choose to save, the app sends your answers to its server to calculate the character consistently. It stores the resulting character, evidence descriptions, portrait appearance instructions, account identifier, and timestamps. It does not separately retain the complete quiz. Saved lore and evidence may still contain details you entered, so use an alias and avoid private information you do not want to save.
Characters are accessible only to their owner through the app. The application operator and infrastructure providers have administrative access necessary to operate the service. There is no public profile directory or public sharing link.
Generating art and story
When you request a portrait, selected character details and optional appearance instructions go to OpenAI to create fantasy prose and an image. If you attach a photo, it is processed only after your explicit consent. The app decodes and re-encodes it to remove metadata, bounds its dimensions, and sends it to OpenAI for appearance guidance. The original photo is not saved in our database or portrait storage.
Photos never determine scores, intelligence, health, personality, or alignment. Upload only your own photo or one you have permission to use. This initial version is designed for adults.
Generated portraits are stored in a private Supabase bucket. The app displays them through temporary signed links. Anyone you give a still-valid signed link to may be able to view that image until the link expires.
OpenAI processing has its own retention rules. Requests disable optional response storage; this does not disable standard abuse-monitoring retention. See OpenAI’s data controls. We do not claim that provider processing is immediately deleted.
Limits and operational data
To control spending and abuse, the service keeps usage reservations, user identifiers, timestamps, and request outcomes. Hosting providers may process IP addresses and operational logs. We do not add third-party advertising or behavioral analytics. Authentication uses persistent browser storage (localStorage) and email links; infrastructure may use essential security cookies.
Deleting data
Delete a saved character from “My characters” to remove its database record and generated portrait. This does not clear your browser draft or any downloads; clear those separately. Usage entries are retained for quota enforcement and are not reset by deleting a character.
To remove your sign-in account and its saved characters and portraits, use “Delete account” in the footer while signed in and confirm the deletion. If cleanup fails, repeat the request to finish it. Generation usage records remain for spending controls; provider backups and security records may persist according to their retention policies.
Service providers
The planned production stack uses personal Vercel hosting, Cloudflare DNS, Supabase authentication/database/storage, and OpenAI generation. Cloud features remain unavailable until their personal service accounts are configured. These notes describe the implemented data flow; they are not a promise that an unconfigured feature is live.
Last updated September 7, 2026.