Dice and Decks Guild Hall

Privacy Policy: The Guildhall

The Guildhall · Last updated July 12, 2026

Privacy Policy: The Guildhall

Effective date: July 12, 2026 Last updated: July 12, 2026

The Guildhall ("the App") is a free, unofficial companion application for the Pathfinder Second Edition roleplaying game by Paizo Inc. It is published by Tinkavu LLC / Extra Turn Games ("we", "us", "our"). This policy explains what data we collect, how we use it, who we share it with, and how you can control or delete your data.

This App is not affiliated with, endorsed by, or sponsored by Paizo Inc. It uses trademarks and/or copyrights owned by Paizo Inc. under Paizo's Community Use Policy (paizo.com/licenses/communityuse). Trademarks and game content referenced in the App belong to their respective owners.


Data We Collect

Data You Give Us Directly

The App is local-first: the rules compendium, the character builder, saved characters, and settings are stored on your device, and your own characters and campaigns are stored in your own Google Drive and an on-device encrypted database. An account is only needed for cloud features and the community directory, and sign-in is entirely optional.

If you choose to sign in, we collect:

  • Account information: your email address, and the identity token from any provider you use. You can sign in with Google, with Discord, with an email magic link, or with an email and password.
  • Display name you choose, which is shared across the company's apps via the D&D Guild Hall directory.
  • Characters you create, including name, backstory, ancestry, heritage, background, class and any secondary class, level, feats, class options, ability scores, skills, equipment, spells, hit points, and other character-sheet data. Your characters live in your own Google Drive and on your device; snapshots or campaign-linked copies may be stored on our servers when you join a campaign or create a share.
  • Campaigns you run or join, including campaign name, settings, sessions, session recaps and beats, Game Master notes (typed or dictated), NPCs, factions, locations, quests, lore, encounters, journal entries, party rosters, and a revelations log. Free-text fields (such as backstories, notes, and journals) are yours to write and may contain other people's names or other personal information you choose to include.
  • Live play state (opt-in per campaign): your character's current and temporary hit points, conditions, resources, and spell slots, shared in real time with your party or Game Master while you play.
  • Player Finder profile (entirely opt-in - requires sign-in and an explicit "Findable" toggle):
    • A postal code you type in manually, and your country
    • Social contact handles you choose to enter (Discord, Instagram, Telegram, Facebook, and WhatsApp; your WhatsApp handle stays hidden unless you separately mark it visible)
    • Whether you have opted in to being discoverable by other players
  • Store favorites you mark in the store directory (shared across all of the company's Guild Hall games).
  • Looking-for-group (LFG) activity: campaign listings you post, join requests you send (which include your display name and any note you write), and venue/seat management if you host.
  • Conduct reports you submit: your identity as the reporter, what you are reporting (type, ID, and label), the reason, any free-text detail, and the reported text. These go to a moderation inbox shared across the company's Guild Hall games so we can keep the community safe.
  • App preferences such as accent color and calculation toggles, and, if you create homebrew content, an index of your custom books.

Location Data

The App uses your device location only for the "find game stores near you" feature, and only when you tap it:

  • When you tap to find nearby stores, the App reads your device's approximate location to sort stores by distance. The coordinates are used only for that lookup and are not stored. They are sent to our own backend (the nearby_stores lookup on the Guild Hall service), which acts as our processor.
  • If you search by postal code instead, that postal code is sent to OpenStreetMap's Nominatim service to look up its approximate location.
  • The store map view loads map tiles from OpenFreeMap, which receives your IP address and the map viewport in order to serve the tiles.
  • We do not use your location for advertising or tracking, we do not track your location in the background, and location is not linked to your identity.

Data Collected Automatically

  • Sign-in metadata (timestamps, authentication provider, refresh tokens) managed by Supabase Auth on our behalf.

Data We Explicitly Do NOT Collect

  • No background or continuous location. Location is approximate, read only when you tap to find nearby stores, and never persisted (see Location Data above).
  • Contacts, calendar, microphone, camera, biometrics, SMS, or photos.
  • Browsing history outside the App.
  • Advertising identifiers (GAID or IDFA).
  • Analytics, crash-reporting, or advertising SDK data. The Guildhall contains no analytics, crash-reporting, or advertising SDK of any kind.

Processor Data Table

The following table summarizes what each processor receives. Several of these are engaged only if you opt into the relevant feature.

ProcessorPurposeData received
Supabase (Guildhall app database + auth)Cloud storage of your account, campaign-linked data, AI proposals, and auth sessionsAccount email and linked identities, server-side campaign data, character share snapshots, sign-in metadata
Supabase (D&D Guild Hall directory, EU servers)Cross-game player directory: Player Finder, store directory and favorites, LFG, moderation, and nearby-store distance sortingDisplay name, Player Finder profile, store favorites, LFG listings and join requests, conduct reports, and transient location coordinates for distance sorting
Google (only if you sign in with Google)OAuth authenticationStandard OAuth identity (email, name, account ID)
Discord (only if you sign in with Discord)OAuth authentication or identity linkingStandard OAuth identity
Google Drive (only if you connect Drive)Optional backup, restore, and sharing of your characters and campaigns to your own DriveThe backup/share files, written to a "The Guildhall" folder in your own Google Drive
OpenStreetMap Foundation (Nominatim) (only if you search stores by postal code)Geocoding a postal code to an approximate locationThe postal code and country you enter, plus the App's identifying request header
OpenFreeMap (only when the store map renders)Serving map tilesYour IP address and the map viewport
AI provider you choose - Anthropic, OpenAI, or Google (Gemini) (only if you add your own API key)AI session recaps and content generation you invokeThe relevant campaign or session text, passed with your API key through our proxy to the provider you selected
Pathbuilder 2e (only if you import a Pathbuilder character by ID)Fetch a character build you ask to importThe public build ID you enter

We attribute store map and geocoding data to "© OpenStreetMap contributors."


Google Drive (Optional)

Google Drive integration is entirely opt-in and separate from signing in. If you tap "Connect Drive," the App requests the narrow drive.file scope, which lets it read and write only the files it creates in your Drive. The App cannot see the rest of your Drive.

  • Backups and shared files are written to a visible folder named "The Guildhall" in your own Google Drive, under your control. This data lives in your Drive, not on our servers.
  • If you use a share feature that produces a public link (see Sharing), the App sets the relevant file to "anyone with the link can view" so another player can import it. You can revoke this at any time by unsharing in the App or by deleting the file in your Drive.
  • You can disconnect Drive at any time in Settings, and you can revoke the App's Drive access entirely at myaccount.google.com/permissions.

AI Features and Your Own API Key

The Guildhall includes optional AI features (such as session-recap proposals and content generation). These features are off by default and do nothing until you add your own API key for a supported provider (Anthropic, OpenAI, or Google Gemini) in Settings.

  • Your API key is stored on your device using the operating system's secure storage (iOS Keychain / Android Keystore). We do not store or log your API key on our servers.
  • When you invoke an AI feature, the App sends the relevant text (for example, a campaign's notes, entities, and Game Master notes for a session recap) together with your API key over an encrypted connection to a Supabase Edge Function we operate. That function acts only as a proxy: it makes one call to the provider you selected and returns the result. It does not retain your key.
  • The session-recap feature is Game-Master-only and fails closed for non-GMs; the resulting proposal is stored for the Game Master to review and accept or discard. These AI features provide draft assistance only and make no automated decisions about you.
  • Your prompts and the returned content are processed by the third-party AI provider you chose, under that provider's terms and privacy policy. Do not include content in AI-assisted fields that you are not comfortable sending to that provider.
  • If you never add an API key, no data is ever sent to any AI provider.

Sharing Characters and Campaigns

Sharing is something you initiate. When you share a character or campaign:

  • The App may create a share code or snapshot stored in our Supabase app database (for example, a short code, with an expiry, that another player enters to import a copy of your character's public build data), and/or
  • The App may upload a copy to your own Google Drive and make that file link-accessible, producing a link (such as https://ddguildhall.com/c/<id>) that anyone you give it to can open to view a read-only copy.

Character web-share snapshots include public build data (identity, ancestry, class, level, ability scores, skills, feats, equipment, spells) and exclude private fields such as backstory and Game Master notes. Anyone who has a share link or code can view the shared content until you unshare it, it expires, or you delete the underlying file or record.


How We Use Your Data

We use your data only to provide and improve the App:

  • Authenticate you and keep you signed in across devices.
  • Store and sync your characters and campaigns (in your own Google Drive and, for campaign play and sharing, on our servers).
  • Power the community directory: Player Finder, the store directory and favorites, and looking-for-group, using only the information you have opted in to share.
  • Find game stores near you when you ask, using approximate location as described above.
  • Keep the community safe by receiving and acting on conduct reports.
  • Run the optional AI features you invoke, using the API key you provide.

We do not sell your personal data. We do not use your data for advertising targeting. We do not show ads in the App.


Who We Share Data With

We use the following third-party processors to provide the App. Each receives only the data needed for its function.

ProcessorPrivacy / DPA reference
Supabase, Inc. (both backends)supabase.com/privacy · Art. 28 GDPR DPA signed
Google LLC (Sign-In and, if connected, Google Drive)policies.google.com/privacy
Discord, Inc. (Sign-In only if selected)discord.com/privacy
OpenStreetMap Foundation (Nominatim geocoding, only on postal-code search)wiki.osmfoundation.org/wiki/Privacy_Policy
OpenFreeMap (map tiles, only when the store map renders)openfreemap.org
Anthropic, OpenAI, or Google (only the AI provider whose key you add)anthropic.com/legal/privacy · openai.com/policies/privacy-policy · policies.google.com/privacy
Redblade Software (Pathbuilder 2e, only if you import by ID)pathbuilder2e.com

We do not sell, rent, or broker your personal data to any other party.

Cross-app sharing: The D&D Guild Hall directory is a single system of record shared across the company's games (including Moonstone and Legion). One member identity, one Player Finder profile, one store-favorites list, and one moderation inbox span all of them. If you opt into the Player Finder, the contacts you choose to publish are discoverable in every Guild Hall game, not only in The Guildhall.


Where Your Data Lives & Storage Security

The App uses two Supabase backends, plus optional storage in your own Google Drive and on-device storage:

  1. Guildhall app database - stores your account, auth session, campaign-linked data, character share records, and AI proposals. Hosted on Supabase's managed cloud infrastructure.
  2. D&D Guild Hall directory - stores your display name, Player Finder profile, store favorites, LFG listings and join requests, and conduct reports. This is a shared cross-game directory used across all Extra Turn Games apps, hosted on Supabase's EU-West (Ireland) region.
  3. Your Google Drive (only if you connect it) - holds your character/campaign backups and shared files in a "The Guildhall" folder that you control.
  4. On your device - the bundled rules compendium and your character cache are stored in an encrypted (SQLCipher) local database; your API keys and other secrets are held in the operating system's secure storage; your session token and settings are stored in the app's storage. The character cache is cleared on sign-out to prevent cross-account leakage on a shared device.

Security measures:

  • Encryption at rest: AES-256 for Supabase-hosted data; SQLCipher for the on-device database; Google-managed encryption for files in your Drive.
  • Encryption in transit: TLS 1.2 or higher for all network traffic between the App and our servers and between our servers and processors.
  • Access control: Supabase row-level security (RLS) policies ensure that users can only read and write their own data; Edge Functions run under your session and fail closed.
  • Data minimization: the narrow Google drive.file scope, on-device encryption, and BYO AI keys that we never store.

Our relationship with Supabase, Inc. as a data processor is governed by a signed Data Processing Addendum (DPA) under GDPR Article 28. Supabase's Transfer Impact Assessment (TIA) is available on request from info@guillotine-life.com.


Security & Breach Notification

In addition to the technical measures described above, we:

  • Limit access to personal data to personnel and automated systems that need it to operate the service.
  • Require all processors to maintain appropriate security measures under contract.
  • Periodically review our security practices.

No security system is perfect. If you believe you have discovered a security vulnerability, please report it to info@guillotine-life.com.

Breach notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where a breach is likely to result in a high risk to you personally, we will also notify you directly without undue delay, as required by GDPR Article 34, using the contact information in your account.


Data Retention

We keep your data only as long as necessary.

Data typeRetention
Account information (email, display name)Until you delete your account
Player Finder profile (postal code, country, contact handles, findability status)Until you delete your account or clear the relevant field; turning off "Findable" removes you from search immediately
Store favoritesUntil you remove them or delete your account
LFG listings and join requestsUntil you remove them or delete your account
Characters and campaign data (sessions, notes, NPCs, quests, encounters, party rosters, etc.)Until you delete them or delete your account
Character share codes / snapshotsUntil you revoke the share or the code's expiry passes
Live play stateTransient; exists only during active play
Conduct reports and reported contentRetained while needed for community safety and dispute resolution; anonymized rather than deleted where we must keep a moderation record
Location coordinatesNot retained; used only for the in-session nearby-store lookup
Sign-in metadataManaged by Supabase Auth; cleared on account deletion
AI API keysStored only on your device; removed when you clear them in Settings or uninstall the App. Never stored on our servers
Google Drive backup/share filesStored in your own Google Drive; we have no retention schedule over them, and you delete them from your Drive
On-device data (offline characters, compendium, settings)Removed automatically when you uninstall the App

You may request earlier deletion of any data at any time via email to info@guillotine-life.com or through the web form at https://ddguildhall.com/remove-my-information?app=pathfinder.


Your Rights & Choices

In-app controls:

  • Edit your Player Finder profile at any time, including clearing individual contact handles, and keep your WhatsApp handle hidden.
  • Toggle "Findable" off to immediately remove yourself from in-app player search everywhere.
  • Remove store favorites at any time.
  • Delete characters and campaigns individually from their management screens.
  • Unshare a shared character or campaign to revoke access, or let a share code expire.
  • Disconnect Google Drive, and clear your AI API keys, from Settings.
  • Delete your account from the account screen. This anonymizes your entry in the shared Guild Hall directory (email, display name, and contact handles) via a forget_my_member routine, deletes the campaigns you own and their content and then your account via a server-side delete_my_account routine, and clears your local character cache.

Account and data removal:

  • Email info@guillotine-life.com to request full account and data deletion keyed to your verified email address.
  • Use the self-service web form at https://ddguildhall.com/remove-my-information?app=pathfinder for verified deletion without contacting us directly.
  • Files you saved to your own Google Drive are yours; deleting your account does not remove them, so delete them from your Drive if you wish (see the Data Deletion page).
  • On-device data (offline characters, cached compendium, settings) is removed automatically when you uninstall the App.

Withdrawal of consent: Where we process your data on the basis of consent (for example, your opt-in to the Player Finder, location for nearby stores, Google Drive, or AI features), you may withdraw that consent at any time by turning off the feature or clearing the relevant fields. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.

Response timeframe: We will respond to all data-subject rights requests within 30 days of receipt. In cases of complexity or high volume we may extend by an additional 60 days; if so, we will notify you within the initial 30-day period.


GDPR: EEA & UK Users

This section applies if you are located in the European Economic Area (EEA) or the United Kingdom.

Controller

Tinkavu LLC, TINKAVU LLC, 2865 Apaloosa Trl, Deltona, FL 32738, is the data controller for personal data processed through the App. Contact: info@guillotine-life.com.

Lawful Bases (GDPR Article 6)

Processing activityLawful basis
Account creation and authenticationPerformance of a contract (Art. 6(1)(b))
Character and campaign storage and syncPerformance of a contract (Art. 6(1)(b))
Player Finder, store favorites, and LFG (contact handles, postal code, findability opt-in)Consent (Art. 6(1)(a))
Finding nearby stores using approximate locationConsent (Art. 6(1)(a))
Google Drive backup / sharing (opt-in)Consent (Art. 6(1)(a))
AI features using your own API key (opt-in)Consent (Art. 6(1)(a))
Receiving and acting on conduct reports (community safety)Legitimate interests (Art. 6(1)(f))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))

Your Data Subject Rights

Under the GDPR and UK GDPR you have the right to:

  • Access (Art. 15): request a copy of your personal data.
  • Rectification (Art. 16): correct inaccurate data.
  • Erasure (Art. 17): request deletion of your data.
  • Restriction (Art. 18): ask us to restrict processing in certain circumstances.
  • Data portability (Art. 20): receive your data in a machine-readable format. Your characters and campaigns are already JSON in your own Google Drive, and you can export them from within the App.
  • Object (Art. 21): object to processing based on legitimate interests.
  • Not to be subject to automated decision-making (Art. 22): we do not make automated decisions with legal or similarly significant effects on you. The optional AI features provide suggestions a Game Master reviews and make no decisions about you.

To exercise any of these rights, contact us at info@guillotine-life.com. We will respond within 30 days (see #rights above).

International Data Transfers

The D&D Guild Hall directory backend is hosted in the EU-West (Ireland) region. The Guildhall app backend and some Supabase sub-processors may be located in the United States. If you use the optional integrations, Google (Sign-In and Drive), Discord (Sign-In), and any AI provider whose key you add (Anthropic, OpenAI, or Google) are also based in the United States; OpenStreetMap Nominatim and OpenFreeMap are used only for the store finder. Those transfers are governed by:

  • Standard Contractual Clauses (Module Two, controller to processor) incorporated into the Supabase DPA and the corresponding provider agreements.
  • The EU-U.S. Data Privacy Framework adequacy decision (10 July 2023), where a processor or its sub-processors are certified participants.

Article 27 EU Representative

Tinkavu LLC is established in the United States. We rely on the small-scale-processing exemption in GDPR Article 27(2)(a): the App does not process special-category data (Art. 9), does not process criminal-offence data (Art. 10), involves no large-scale systematic monitoring, and currently serves a limited number of EU users on an occasional basis. On this basis we have not designated a formal EU representative. We will designate a representative under Art. 27 if any of the triggers in Art. 27(2) are no longer satisfied (for example, if EU user volume grows substantially or if we add any special-category processing).

DPO

We are not required to designate a Data Protection Officer under Art. 37 GDPR given our processing activities. Privacy queries should be directed to info@guillotine-life.com.

Supervisory Authority

If you are in the EEA, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu/about-edpb/about-edpb/members_en. UK users may contact the ICO at ico.org.uk.


CCPA / CPRA: California Residents

This section applies to residents of California and supplements the rest of this policy. It is provided under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

Categories of Personal Information Collected

In the preceding 12 months we have collected the following CCPA categories of personal information:

CategoryExamples collected by the AppCollected?
IdentifiersEmail address, user ID, display name, social contact handles you addYes (when signed in)
Personal information (Cal. Civ. Code §1798.80)Email addressYes (when signed in)
Geolocation dataApproximate location when you tap to find nearby stores (not stored), and a postal code you optionally typeApproximate only, on request
Internet or other electronic network activitySign-in timestamps, session metadataYes (when signed in)
InferencesNone; we draw no inferences or profiles about youNo
Sensitive personal informationPrecise geolocation, racial/ethnic origin, health, financial, or biometric dataNo
Commercial informationNoneNo
Audio, electronic, visual, or similar informationNoneNo

Do Not Sell or Share My Personal Information

We do not sell your personal information as defined under CCPA. We do not share your personal information for cross-context behavioral advertising. You therefore do not need to opt out of a sale or share; however, you may contact us at info@guillotine-life.com if you have questions.

Your California Rights

California residents have the right to:

  1. Know: request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties with whom it is shared.
  2. Delete: request deletion of personal information we have collected, subject to limited exceptions (for example, completing a transaction, detecting security incidents, or complying with legal obligations).
  3. Correct: request correction of inaccurate personal information.
  4. Limit Use of Sensitive Personal Information: we do not process sensitive personal information for purposes beyond those permitted without this right, so no opt-out is required.
  5. Non-Discrimination: we will not discriminate against you for exercising any of these rights. We will not deny you the App, charge different prices, or provide a different level of service because you exercised a CCPA right.

Authorized Agent

You may designate an authorized agent to submit a request on your behalf. The authorized agent must provide written proof of authorization signed by you, and we may verify your identity directly with you as permitted by law.

How to Submit a Request

Email info@guillotine-life.com with the subject line "California Privacy Request." We will respond within 45 days (extendable by a further 45 days with notice if reasonably necessary).


LGPD: Brazilian Users

This section applies to residents of Brazil and supplements the rest of this policy. It is provided under Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD, Law 13,709/2018).

Legal Bases (LGPD Article 7)

We process your personal data under the following LGPD legal bases:

  • Performance of a contract (Art. 7, VII): to provide the App's core cloud functions (account, character and campaign storage, community directory).
  • Consent (Art. 7, I): Player Finder, location, Google Drive, and AI opt-in features.
  • Legitimate interest (Art. 7, IX): community safety and moderation of conduct reports.
  • Compliance with a legal obligation (Art. 7, II): where required by law.

Your LGPD Rights

Under the LGPD you have the right to: confirm the existence of processing; access your data; correct incomplete or inaccurate data; anonymize, block, or delete unnecessary data; request portability; request information about third parties with whom we share data; object to processing; and withdraw consent at any time.

To exercise these rights, contact info@guillotine-life.com. We will respond within 15 business days.

Encarregado (DPO)

We have not formally designated an Encarregado under the LGPD given the small scale and nature of our processing. Privacy requests should be directed to info@guillotine-life.com.

Supervisory Authority

You may also file a complaint with Brazil's Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.


PIPEDA: Canadian Users

This section applies to residents of Canada and supplements the rest of this policy. It is provided under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.

Accountability

Tinkavu LLC is responsible for personal information under its control. Privacy questions and rights requests should be directed to info@guillotine-life.com.

We collect, use, and disclose your personal information only with your knowledge and consent (express for sensitive data; implied for routine service data), except where otherwise permitted or required by law. You may withdraw consent at any time by contacting us or using the web deletion form, subject to legal and contractual restrictions and reasonable notice.

Your Rights

You have the right to: access your personal information held by us; challenge the accuracy and completeness of your information and request correction; and withdraw consent to certain uses or disclosures.

To exercise these rights, contact info@guillotine-life.com. We will respond within 30 days.

Supervisory Authority

You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.


APPI: Japanese Users

This section applies to residents of Japan and supplements the rest of this policy. It is provided under Japan's Act on the Protection of Personal Information (APPI), as amended effective April 2022.

Third-Party Provision and Cross-Border Transfers

Where we transfer your personal information to processors located outside Japan (for example, Supabase in Ireland/EU, or Google, Discord, and any AI provider whose key you add in the United States), we take the following measures in accordance with APPI Article 24:

  • We enter into contracts with each overseas processor that require them to implement personal information protection measures equivalent to those required by APPI.
  • The relevant receiving countries include Ireland (EU, subject to GDPR), and the United States (governed by Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework).

Your APPI Rights

You have the right to request disclosure of retained personal information, correction, addition, or deletion where the data is inaccurate, and suspension of use or third-party provision in certain circumstances. To exercise these rights, contact info@guillotine-life.com.

Supervisory Authority

You may direct inquiries to Japan's Personal Information Protection Commission (PPC) at ppc.go.jp.


Australia: Australian Users

This section applies to residents of Australia and supplements the rest of this policy. It is provided under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Tinkavu LLC is subject to the Privacy Act to the extent its acts or practices have an Australian link. Given our current scale, we may qualify for the small-business operator exemption (annual turnover below AUD 3 million); however, we voluntarily apply the Australian Privacy Principles as good practice.

We collect, hold, use, and disclose personal information only for the purposes described in this policy. We take reasonable steps to secure personal information against misuse, interference, loss, and unauthorized access.

You have the right to access your personal information and to request correction of inaccurate information. To exercise these rights, contact info@guillotine-life.com. We will respond within 30 days.

If you believe we have breached the APPs, you may first contact us to resolve the matter. If unresolved, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.


Children

The App is intended for users who are 13 years of age or older. We do not knowingly collect personal information from children under 13. The App is not directed at children under 13, and we do not target content or advertising at children.

Some community features, including the Player Finder, publish contact handles and a postal code to other users. These features are strictly opt-in and off by default. We encourage parents and guardians of users between 13 and the age of majority to be involved in their use of these features.

If you believe a child under 13 has provided us with personal information, please contact us at info@guillotine-life.com and we will promptly delete that information from our systems.

This App is not designed to comply with the Children's Online Privacy Protection Act (COPPA) requirements for child-directed services, because it is not child-directed.


Cookies, Identifiers & Advertising

No advertising: The App contains no advertisements. We do not use advertising networks or sell advertising space.

No advertising identifiers: We do not collect or process Google Advertising IDs (GAID), Apple Advertising Identifiers (IDFA), or any other advertising identifier.

App Tracking Transparency (ATT): Because we do not use advertising identifiers or cross-app tracking, we do not present an ATT prompt on iOS.

Session tokens: Supabase Auth uses standard session tokens stored in device storage to keep you signed in. These are not advertising cookies and are not shared with third parties.

The Guildhall does not integrate any third-party analytics or crash-reporting SDK. If this ever changes, this section will be updated to disclose the SDK, the data it collects, and how to opt out.


Changes to This Policy

We may update this policy from time to time. If we make a material change (one that meaningfully expands the data we collect, the purposes for which we use it, or the parties we share it with), we will:

  1. Update the "Last updated" date at the top of this policy.
  2. Post a notice within the App on the first launch after the change takes effect.
  3. Where required by applicable law, obtain fresh consent before processing your data under the new terms.

Continued use of the App after a material change is not your only means of acceptance; we will give you adequate notice and opportunity to review changes before they take effect where required by law.


Contact

For privacy questions, data rights requests, data export requests not covered by the self-service web form, or to report a security issue:

Publisher: Tinkavu LLC / Extra Turn Games Email: info@guillotine-life.com Mailing address: TINKAVU LLC, 2865 Apaloosa Trl, Deltona, FL 32738 Data deletion web form: https://ddguildhall.com/remove-my-information?app=pathfinder

Effective date: July 12, 2026 Last updated: July 12, 2026


Pathfinder is a registered trademark of Paizo Inc. This App is unofficial and is not affiliated with, endorsed by, or sponsored by Paizo Inc. It uses trademarks and/or copyrights owned by Paizo Inc. under Paizo's Community Use Policy (paizo.com/licenses/communityuse).