Privacy Policy: The Guildhall
The Guildhall · Last updated July 12, 2026
Privacy Policy: The Guildhall
Effective date: July 12, 2026 Last updated: July 12, 2026
The Guildhall ("the App") is a free, unofficial companion application for the Pathfinder Second Edition roleplaying game by Paizo Inc. It is published by Tinkavu LLC / Extra Turn Games ("we", "us", "our"). This policy explains what data we collect, how we use it, who we share it with, and how you can control or delete your data.
This App is not affiliated with, endorsed by, or sponsored by Paizo Inc. It uses trademarks and/or copyrights owned by Paizo Inc. under Paizo's Community Use Policy (paizo.com/licenses/communityuse). Trademarks and game content referenced in the App belong to their respective owners.
Data We Collect
Data You Give Us Directly
The App is local-first: the rules compendium, the character builder, saved characters, and settings are stored on your device, and your own characters and campaigns are stored in your own Google Drive and an on-device encrypted database. An account is only needed for cloud features and the community directory, and sign-in is entirely optional.
If you choose to sign in, we collect:
- Account information: your email address, and the identity token from any provider you use. You can sign in with Google, with Discord, with an email magic link, or with an email and password.
- Display name you choose, which is shared across the company's apps via the D&D Guild Hall directory.
- Characters you create, including name, backstory, ancestry, heritage, background, class and any secondary class, level, feats, class options, ability scores, skills, equipment, spells, hit points, and other character-sheet data. Your characters live in your own Google Drive and on your device; snapshots or campaign-linked copies may be stored on our servers when you join a campaign or create a share.
- Campaigns you run or join, including campaign name, settings, sessions, session recaps and beats, Game Master notes (typed or dictated), NPCs, factions, locations, quests, lore, encounters, journal entries, party rosters, and a revelations log. Free-text fields (such as backstories, notes, and journals) are yours to write and may contain other people's names or other personal information you choose to include.
- Live play state (opt-in per campaign): your character's current and temporary hit points, conditions, resources, and spell slots, shared in real time with your party or Game Master while you play.
- Player Finder profile (entirely opt-in - requires sign-in and an explicit "Findable" toggle):
- A postal code you type in manually, and your country
- Social contact handles you choose to enter (Discord, Instagram, Telegram, Facebook, and WhatsApp; your WhatsApp handle stays hidden unless you separately mark it visible)
- Whether you have opted in to being discoverable by other players
- Store favorites you mark in the store directory (shared across all of the company's Guild Hall games).
- Looking-for-group (LFG) activity: campaign listings you post, join requests you send (which include your display name and any note you write), and venue/seat management if you host.
- Conduct reports you submit: your identity as the reporter, what you are reporting (type, ID, and label), the reason, any free-text detail, and the reported text. These go to a moderation inbox shared across the company's Guild Hall games so we can keep the community safe.
- App preferences such as accent color and calculation toggles, and, if you create homebrew content, an index of your custom books.
Location Data
The App uses your device location only for the "find game stores near you" feature, and only when you tap it:
- When you tap to find nearby stores, the App reads your device's approximate location to sort stores by distance. The coordinates are used only for that lookup and are not stored. They are sent to our own backend (the
nearby_storeslookup on the Guild Hall service), which acts as our processor. - If you search by postal code instead, that postal code is sent to OpenStreetMap's Nominatim service to look up its approximate location.
- The store map view loads map tiles from OpenFreeMap, which receives your IP address and the map viewport in order to serve the tiles.
- We do not use your location for advertising or tracking, we do not track your location in the background, and location is not linked to your identity.
Data Collected Automatically
- Sign-in metadata (timestamps, authentication provider, refresh tokens) managed by Supabase Auth on our behalf.
Data We Explicitly Do NOT Collect
- No background or continuous location. Location is approximate, read only when you tap to find nearby stores, and never persisted (see Location Data above).
- Contacts, calendar, microphone, camera, biometrics, SMS, or photos.
- Browsing history outside the App.
- Advertising identifiers (GAID or IDFA).
- Analytics, crash-reporting, or advertising SDK data. The Guildhall contains no analytics, crash-reporting, or advertising SDK of any kind.
Processor Data Table
The following table summarizes what each processor receives. Several of these are engaged only if you opt into the relevant feature.
| Processor | Purpose | Data received |
|---|---|---|
| Supabase (Guildhall app database + auth) | Cloud storage of your account, campaign-linked data, AI proposals, and auth sessions | Account email and linked identities, server-side campaign data, character share snapshots, sign-in metadata |
| Supabase (D&D Guild Hall directory, EU servers) | Cross-game player directory: Player Finder, store directory and favorites, LFG, moderation, and nearby-store distance sorting | Display name, Player Finder profile, store favorites, LFG listings and join requests, conduct reports, and transient location coordinates for distance sorting |
| Google (only if you sign in with Google) | OAuth authentication | Standard OAuth identity (email, name, account ID) |
| Discord (only if you sign in with Discord) | OAuth authentication or identity linking | Standard OAuth identity |
| Google Drive (only if you connect Drive) | Optional backup, restore, and sharing of your characters and campaigns to your own Drive | The backup/share files, written to a "The Guildhall" folder in your own Google Drive |
| OpenStreetMap Foundation (Nominatim) (only if you search stores by postal code) | Geocoding a postal code to an approximate location | The postal code and country you enter, plus the App's identifying request header |
| OpenFreeMap (only when the store map renders) | Serving map tiles | Your IP address and the map viewport |
| AI provider you choose - Anthropic, OpenAI, or Google (Gemini) (only if you add your own API key) | AI session recaps and content generation you invoke | The relevant campaign or session text, passed with your API key through our proxy to the provider you selected |
| Pathbuilder 2e (only if you import a Pathbuilder character by ID) | Fetch a character build you ask to import | The public build ID you enter |
We attribute store map and geocoding data to "© OpenStreetMap contributors."
Google Drive (Optional)
Google Drive integration is entirely opt-in and separate from signing in. If you tap "Connect Drive," the App requests the narrow drive.file scope, which lets it read and write only the files it creates in your Drive. The App cannot see the rest of your Drive.
- Backups and shared files are written to a visible folder named "The Guildhall" in your own Google Drive, under your control. This data lives in your Drive, not on our servers.
- If you use a share feature that produces a public link (see Sharing), the App sets the relevant file to "anyone with the link can view" so another player can import it. You can revoke this at any time by unsharing in the App or by deleting the file in your Drive.
- You can disconnect Drive at any time in Settings, and you can revoke the App's Drive access entirely at myaccount.google.com/permissions.
AI Features and Your Own API Key
The Guildhall includes optional AI features (such as session-recap proposals and content generation). These features are off by default and do nothing until you add your own API key for a supported provider (Anthropic, OpenAI, or Google Gemini) in Settings.
- Your API key is stored on your device using the operating system's secure storage (iOS Keychain / Android Keystore). We do not store or log your API key on our servers.
- When you invoke an AI feature, the App sends the relevant text (for example, a campaign's notes, entities, and Game Master notes for a session recap) together with your API key over an encrypted connection to a Supabase Edge Function we operate. That function acts only as a proxy: it makes one call to the provider you selected and returns the result. It does not retain your key.
- The session-recap feature is Game-Master-only and fails closed for non-GMs; the resulting proposal is stored for the Game Master to review and accept or discard. These AI features provide draft assistance only and make no automated decisions about you.
- Your prompts and the returned content are processed by the third-party AI provider you chose, under that provider's terms and privacy policy. Do not include content in AI-assisted fields that you are not comfortable sending to that provider.
- If you never add an API key, no data is ever sent to any AI provider.
Sharing Characters and Campaigns
Sharing is something you initiate. When you share a character or campaign:
- The App may create a share code or snapshot stored in our Supabase app database (for example, a short code, with an expiry, that another player enters to import a copy of your character's public build data), and/or
- The App may upload a copy to your own Google Drive and make that file link-accessible, producing a link (such as
https://ddguildhall.com/c/<id>) that anyone you give it to can open to view a read-only copy.
Character web-share snapshots include public build data (identity, ancestry, class, level, ability scores, skills, feats, equipment, spells) and exclude private fields such as backstory and Game Master notes. Anyone who has a share link or code can view the shared content until you unshare it, it expires, or you delete the underlying file or record.
How We Use Your Data
We use your data only to provide and improve the App:
- Authenticate you and keep you signed in across devices.
- Store and sync your characters and campaigns (in your own Google Drive and, for campaign play and sharing, on our servers).
- Power the community directory: Player Finder, the store directory and favorites, and looking-for-group, using only the information you have opted in to share.
- Find game stores near you when you ask, using approximate location as described above.
- Keep the community safe by receiving and acting on conduct reports.
- Run the optional AI features you invoke, using the API key you provide.
We do not sell your personal data. We do not use your data for advertising targeting. We do not show ads in the App.
Who We Share Data With
We use the following third-party processors to provide the App. Each receives only the data needed for its function.
| Processor | Privacy / DPA reference |
|---|---|
| Supabase, Inc. (both backends) | supabase.com/privacy · Art. 28 GDPR DPA signed |
| Google LLC (Sign-In and, if connected, Google Drive) | policies.google.com/privacy |
| Discord, Inc. (Sign-In only if selected) | discord.com/privacy |
| OpenStreetMap Foundation (Nominatim geocoding, only on postal-code search) | wiki.osmfoundation.org/wiki/Privacy_Policy |
| OpenFreeMap (map tiles, only when the store map renders) | openfreemap.org |
| Anthropic, OpenAI, or Google (only the AI provider whose key you add) | anthropic.com/legal/privacy · openai.com/policies/privacy-policy · policies.google.com/privacy |
| Redblade Software (Pathbuilder 2e, only if you import by ID) | pathbuilder2e.com |
We do not sell, rent, or broker your personal data to any other party.
Cross-app sharing: The D&D Guild Hall directory is a single system of record shared across the company's games (including Moonstone and Legion). One member identity, one Player Finder profile, one store-favorites list, and one moderation inbox span all of them. If you opt into the Player Finder, the contacts you choose to publish are discoverable in every Guild Hall game, not only in The Guildhall.
Where Your Data Lives & Storage Security
The App uses two Supabase backends, plus optional storage in your own Google Drive and on-device storage:
- Guildhall app database - stores your account, auth session, campaign-linked data, character share records, and AI proposals. Hosted on Supabase's managed cloud infrastructure.
- D&D Guild Hall directory - stores your display name, Player Finder profile, store favorites, LFG listings and join requests, and conduct reports. This is a shared cross-game directory used across all Extra Turn Games apps, hosted on Supabase's EU-West (Ireland) region.
- Your Google Drive (only if you connect it) - holds your character/campaign backups and shared files in a "The Guildhall" folder that you control.
- On your device - the bundled rules compendium and your character cache are stored in an encrypted (SQLCipher) local database; your API keys and other secrets are held in the operating system's secure storage; your session token and settings are stored in the app's storage. The character cache is cleared on sign-out to prevent cross-account leakage on a shared device.
Security measures:
- Encryption at rest: AES-256 for Supabase-hosted data; SQLCipher for the on-device database; Google-managed encryption for files in your Drive.
- Encryption in transit: TLS 1.2 or higher for all network traffic between the App and our servers and between our servers and processors.
- Access control: Supabase row-level security (RLS) policies ensure that users can only read and write their own data; Edge Functions run under your session and fail closed.
- Data minimization: the narrow Google
drive.filescope, on-device encryption, and BYO AI keys that we never store.
Our relationship with Supabase, Inc. as a data processor is governed by a signed Data Processing Addendum (DPA) under GDPR Article 28. Supabase's Transfer Impact Assessment (TIA) is available on request from info@guillotine-life.com.
Security & Breach Notification
In addition to the technical measures described above, we:
- Limit access to personal data to personnel and automated systems that need it to operate the service.
- Require all processors to maintain appropriate security measures under contract.
- Periodically review our security practices.
No security system is perfect. If you believe you have discovered a security vulnerability, please report it to info@guillotine-life.com.
Breach notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where a breach is likely to result in a high risk to you personally, we will also notify you directly without undue delay, as required by GDPR Article 34, using the contact information in your account.
Data Retention
We keep your data only as long as necessary.
| Data type | Retention |
|---|---|
| Account information (email, display name) | Until you delete your account |
| Player Finder profile (postal code, country, contact handles, findability status) | Until you delete your account or clear the relevant field; turning off "Findable" removes you from search immediately |
| Store favorites | Until you remove them or delete your account |
| LFG listings and join requests | Until you remove them or delete your account |
| Characters and campaign data (sessions, notes, NPCs, quests, encounters, party rosters, etc.) | Until you delete them or delete your account |
| Character share codes / snapshots | Until you revoke the share or the code's expiry passes |
| Live play state | Transient; exists only during active play |
| Conduct reports and reported content | Retained while needed for community safety and dispute resolution; anonymized rather than deleted where we must keep a moderation record |
| Location coordinates | Not retained; used only for the in-session nearby-store lookup |
| Sign-in metadata | Managed by Supabase Auth; cleared on account deletion |
| AI API keys | Stored only on your device; removed when you clear them in Settings or uninstall the App. Never stored on our servers |
| Google Drive backup/share files | Stored in your own Google Drive; we have no retention schedule over them, and you delete them from your Drive |
| On-device data (offline characters, compendium, settings) | Removed automatically when you uninstall the App |
You may request earlier deletion of any data at any time via email to info@guillotine-life.com or through the web form at https://ddguildhall.com/remove-my-information?app=pathfinder.
Your Rights & Choices
In-app controls:
- Edit your Player Finder profile at any time, including clearing individual contact handles, and keep your WhatsApp handle hidden.
- Toggle "Findable" off to immediately remove yourself from in-app player search everywhere.
- Remove store favorites at any time.
- Delete characters and campaigns individually from their management screens.
- Unshare a shared character or campaign to revoke access, or let a share code expire.
- Disconnect Google Drive, and clear your AI API keys, from Settings.
- Delete your account from the account screen. This anonymizes your entry in the shared Guild Hall directory (email, display name, and contact handles) via a
forget_my_memberroutine, deletes the campaigns you own and their content and then your account via a server-sidedelete_my_accountroutine, and clears your local character cache.
Account and data removal:
- Email info@guillotine-life.com to request full account and data deletion keyed to your verified email address.
- Use the self-service web form at https://ddguildhall.com/remove-my-information?app=pathfinder for verified deletion without contacting us directly.
- Files you saved to your own Google Drive are yours; deleting your account does not remove them, so delete them from your Drive if you wish (see the Data Deletion page).
- On-device data (offline characters, cached compendium, settings) is removed automatically when you uninstall the App.
Withdrawal of consent: Where we process your data on the basis of consent (for example, your opt-in to the Player Finder, location for nearby stores, Google Drive, or AI features), you may withdraw that consent at any time by turning off the feature or clearing the relevant fields. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.
Response timeframe: We will respond to all data-subject rights requests within 30 days of receipt. In cases of complexity or high volume we may extend by an additional 60 days; if so, we will notify you within the initial 30-day period.
GDPR: EEA & UK Users
This section applies if you are located in the European Economic Area (EEA) or the United Kingdom.
Controller
Tinkavu LLC, TINKAVU LLC, 2865 Apaloosa Trl, Deltona, FL 32738, is the data controller for personal data processed through the App. Contact: info@guillotine-life.com.
Lawful Bases (GDPR Article 6)
| Processing activity | Lawful basis |
|---|---|
| Account creation and authentication | Performance of a contract (Art. 6(1)(b)) |
| Character and campaign storage and sync | Performance of a contract (Art. 6(1)(b)) |
| Player Finder, store favorites, and LFG (contact handles, postal code, findability opt-in) | Consent (Art. 6(1)(a)) |
| Finding nearby stores using approximate location | Consent (Art. 6(1)(a)) |
| Google Drive backup / sharing (opt-in) | Consent (Art. 6(1)(a)) |
| AI features using your own API key (opt-in) | Consent (Art. 6(1)(a)) |
| Receiving and acting on conduct reports (community safety) | Legitimate interests (Art. 6(1)(f)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
Your Data Subject Rights
Under the GDPR and UK GDPR you have the right to:
- Access (Art. 15): request a copy of your personal data.
- Rectification (Art. 16): correct inaccurate data.
- Erasure (Art. 17): request deletion of your data.
- Restriction (Art. 18): ask us to restrict processing in certain circumstances.
- Data portability (Art. 20): receive your data in a machine-readable format. Your characters and campaigns are already JSON in your own Google Drive, and you can export them from within the App.
- Object (Art. 21): object to processing based on legitimate interests.
- Not to be subject to automated decision-making (Art. 22): we do not make automated decisions with legal or similarly significant effects on you. The optional AI features provide suggestions a Game Master reviews and make no decisions about you.
To exercise any of these rights, contact us at info@guillotine-life.com. We will respond within 30 days (see #rights above).
International Data Transfers
The D&D Guild Hall directory backend is hosted in the EU-West (Ireland) region. The Guildhall app backend and some Supabase sub-processors may be located in the United States. If you use the optional integrations, Google (Sign-In and Drive), Discord (Sign-In), and any AI provider whose key you add (Anthropic, OpenAI, or Google) are also based in the United States; OpenStreetMap Nominatim and OpenFreeMap are used only for the store finder. Those transfers are governed by:
- Standard Contractual Clauses (Module Two, controller to processor) incorporated into the Supabase DPA and the corresponding provider agreements.
- The EU-U.S. Data Privacy Framework adequacy decision (10 July 2023), where a processor or its sub-processors are certified participants.
Article 27 EU Representative
Tinkavu LLC is established in the United States. We rely on the small-scale-processing exemption in GDPR Article 27(2)(a): the App does not process special-category data (Art. 9), does not process criminal-offence data (Art. 10), involves no large-scale systematic monitoring, and currently serves a limited number of EU users on an occasional basis. On this basis we have not designated a formal EU representative. We will designate a representative under Art. 27 if any of the triggers in Art. 27(2) are no longer satisfied (for example, if EU user volume grows substantially or if we add any special-category processing).
DPO
We are not required to designate a Data Protection Officer under Art. 37 GDPR given our processing activities. Privacy queries should be directed to info@guillotine-life.com.
Supervisory Authority
If you are in the EEA, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu/about-edpb/about-edpb/members_en. UK users may contact the ICO at ico.org.uk.
CCPA / CPRA: California Residents
This section applies to residents of California and supplements the rest of this policy. It is provided under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
Categories of Personal Information Collected
In the preceding 12 months we have collected the following CCPA categories of personal information:
| Category | Examples collected by the App | Collected? |
|---|---|---|
| Identifiers | Email address, user ID, display name, social contact handles you add | Yes (when signed in) |
| Personal information (Cal. Civ. Code §1798.80) | Email address | Yes (when signed in) |
| Geolocation data | Approximate location when you tap to find nearby stores (not stored), and a postal code you optionally type | Approximate only, on request |
| Internet or other electronic network activity | Sign-in timestamps, session metadata | Yes (when signed in) |
| Inferences | None; we draw no inferences or profiles about you | No |
| Sensitive personal information | Precise geolocation, racial/ethnic origin, health, financial, or biometric data | No |
| Commercial information | None | No |
| Audio, electronic, visual, or similar information | None | No |
Do Not Sell or Share My Personal Information
We do not sell your personal information as defined under CCPA. We do not share your personal information for cross-context behavioral advertising. You therefore do not need to opt out of a sale or share; however, you may contact us at info@guillotine-life.com if you have questions.
Your California Rights
California residents have the right to:
- Know: request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties with whom it is shared.
- Delete: request deletion of personal information we have collected, subject to limited exceptions (for example, completing a transaction, detecting security incidents, or complying with legal obligations).
- Correct: request correction of inaccurate personal information.
- Limit Use of Sensitive Personal Information: we do not process sensitive personal information for purposes beyond those permitted without this right, so no opt-out is required.
- Non-Discrimination: we will not discriminate against you for exercising any of these rights. We will not deny you the App, charge different prices, or provide a different level of service because you exercised a CCPA right.
Authorized Agent
You may designate an authorized agent to submit a request on your behalf. The authorized agent must provide written proof of authorization signed by you, and we may verify your identity directly with you as permitted by law.
How to Submit a Request
Email info@guillotine-life.com with the subject line "California Privacy Request." We will respond within 45 days (extendable by a further 45 days with notice if reasonably necessary).
LGPD: Brazilian Users
This section applies to residents of Brazil and supplements the rest of this policy. It is provided under Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD, Law 13,709/2018).
Legal Bases (LGPD Article 7)
We process your personal data under the following LGPD legal bases:
- Performance of a contract (Art. 7, VII): to provide the App's core cloud functions (account, character and campaign storage, community directory).
- Consent (Art. 7, I): Player Finder, location, Google Drive, and AI opt-in features.
- Legitimate interest (Art. 7, IX): community safety and moderation of conduct reports.
- Compliance with a legal obligation (Art. 7, II): where required by law.
Your LGPD Rights
Under the LGPD you have the right to: confirm the existence of processing; access your data; correct incomplete or inaccurate data; anonymize, block, or delete unnecessary data; request portability; request information about third parties with whom we share data; object to processing; and withdraw consent at any time.
To exercise these rights, contact info@guillotine-life.com. We will respond within 15 business days.
Encarregado (DPO)
We have not formally designated an Encarregado under the LGPD given the small scale and nature of our processing. Privacy requests should be directed to info@guillotine-life.com.
Supervisory Authority
You may also file a complaint with Brazil's Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
PIPEDA: Canadian Users
This section applies to residents of Canada and supplements the rest of this policy. It is provided under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
Accountability
Tinkavu LLC is responsible for personal information under its control. Privacy questions and rights requests should be directed to info@guillotine-life.com.
Consent
We collect, use, and disclose your personal information only with your knowledge and consent (express for sensitive data; implied for routine service data), except where otherwise permitted or required by law. You may withdraw consent at any time by contacting us or using the web deletion form, subject to legal and contractual restrictions and reasonable notice.
Your Rights
You have the right to: access your personal information held by us; challenge the accuracy and completeness of your information and request correction; and withdraw consent to certain uses or disclosures.
To exercise these rights, contact info@guillotine-life.com. We will respond within 30 days.
Supervisory Authority
You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.
APPI: Japanese Users
This section applies to residents of Japan and supplements the rest of this policy. It is provided under Japan's Act on the Protection of Personal Information (APPI), as amended effective April 2022.
Third-Party Provision and Cross-Border Transfers
Where we transfer your personal information to processors located outside Japan (for example, Supabase in Ireland/EU, or Google, Discord, and any AI provider whose key you add in the United States), we take the following measures in accordance with APPI Article 24:
- We enter into contracts with each overseas processor that require them to implement personal information protection measures equivalent to those required by APPI.
- The relevant receiving countries include Ireland (EU, subject to GDPR), and the United States (governed by Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework).
Your APPI Rights
You have the right to request disclosure of retained personal information, correction, addition, or deletion where the data is inaccurate, and suspension of use or third-party provision in certain circumstances. To exercise these rights, contact info@guillotine-life.com.
Supervisory Authority
You may direct inquiries to Japan's Personal Information Protection Commission (PPC) at ppc.go.jp.
Australia: Australian Users
This section applies to residents of Australia and supplements the rest of this policy. It is provided under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Tinkavu LLC is subject to the Privacy Act to the extent its acts or practices have an Australian link. Given our current scale, we may qualify for the small-business operator exemption (annual turnover below AUD 3 million); however, we voluntarily apply the Australian Privacy Principles as good practice.
We collect, hold, use, and disclose personal information only for the purposes described in this policy. We take reasonable steps to secure personal information against misuse, interference, loss, and unauthorized access.
You have the right to access your personal information and to request correction of inaccurate information. To exercise these rights, contact info@guillotine-life.com. We will respond within 30 days.
If you believe we have breached the APPs, you may first contact us to resolve the matter. If unresolved, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Children
The App is intended for users who are 13 years of age or older. We do not knowingly collect personal information from children under 13. The App is not directed at children under 13, and we do not target content or advertising at children.
Some community features, including the Player Finder, publish contact handles and a postal code to other users. These features are strictly opt-in and off by default. We encourage parents and guardians of users between 13 and the age of majority to be involved in their use of these features.
If you believe a child under 13 has provided us with personal information, please contact us at info@guillotine-life.com and we will promptly delete that information from our systems.
This App is not designed to comply with the Children's Online Privacy Protection Act (COPPA) requirements for child-directed services, because it is not child-directed.
Cookies, Identifiers & Advertising
No advertising: The App contains no advertisements. We do not use advertising networks or sell advertising space.
No advertising identifiers: We do not collect or process Google Advertising IDs (GAID), Apple Advertising Identifiers (IDFA), or any other advertising identifier.
App Tracking Transparency (ATT): Because we do not use advertising identifiers or cross-app tracking, we do not present an ATT prompt on iOS.
Session tokens: Supabase Auth uses standard session tokens stored in device storage to keep you signed in. These are not advertising cookies and are not shared with third parties.
The Guildhall does not integrate any third-party analytics or crash-reporting SDK. If this ever changes, this section will be updated to disclose the SDK, the data it collects, and how to opt out.
Changes to This Policy
We may update this policy from time to time. If we make a material change (one that meaningfully expands the data we collect, the purposes for which we use it, or the parties we share it with), we will:
- Update the "Last updated" date at the top of this policy.
- Post a notice within the App on the first launch after the change takes effect.
- Where required by applicable law, obtain fresh consent before processing your data under the new terms.
Continued use of the App after a material change is not your only means of acceptance; we will give you adequate notice and opportunity to review changes before they take effect where required by law.
Contact
For privacy questions, data rights requests, data export requests not covered by the self-service web form, or to report a security issue:
Publisher: Tinkavu LLC / Extra Turn Games Email: info@guillotine-life.com Mailing address: TINKAVU LLC, 2865 Apaloosa Trl, Deltona, FL 32738 Data deletion web form: https://ddguildhall.com/remove-my-information?app=pathfinder
Effective date: July 12, 2026 Last updated: July 12, 2026
Pathfinder is a registered trademark of Paizo Inc. This App is unofficial and is not affiliated with, endorsed by, or sponsored by Paizo Inc. It uses trademarks and/or copyrights owned by Paizo Inc. under Paizo's Community Use Policy (paizo.com/licenses/communityuse).