Privacy Policy
Last updated: July 3, 2026
1. Who we are
Dystopia Engine (“the Service,” “we,” “us”) is an AI-powered interactive world-building platform operated by Tamas Sebok as an independent project, established in Hungary. For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the processing described here. You can contact us about this policy at support@dystopia-engine.com, or by post at Szilágyi utca 12., 8000 Székesfehérvár, Hungary.
2. Data we collect
Account information
When you register, your name, email address, and authentication credentials are managed by Clerk (our authentication provider). We do not store raw passwords. We store a Clerk user ID in our database to associate your content with your account.
Content you create
Worlds, characters, stories, story turns, discoveries, and any other content you create within the Service are stored in our database. This content is associated with your account and is private by default. You may choose to make stories public.
AI usage logs
Each time an AI feature is used (world generation, story turns, character generation, etc.), we log the model used, approximate token counts, feature name, and estimated cost. These logs are used for quota enforcement, cost tracking, and abuse prevention. We do not log the raw content of AI prompts or responses beyond what is saved as part of your worlds and stories.
Billing information
If you purchase credits or a subscription, payment is handled through Stripe Managed Payments, with Stripe acting as merchant of record (see Sub-processors and recipients). We do not receive or store your full payment-card details. We retain a record of your purchases — such as the Stripe checkout session or subscription identifier, plan, subscription status, and credit amounts — to provide the Service and maintain your credit balance.
Usage and analytics data
We use Vercel Analytics, a privacy-friendly, cookieless analytics tool, to measure aggregate traffic and page performance. It processes limited technical data (such as page visited, referrer, approximate location derived from IP, device and browser type) to produce aggregated statistics. We do not use it to build advertising profiles or to identify you individually.
Contact messages
If you submit a message via the Contact page, we store your email address and message text to allow us to respond to you.
Technical data
Standard server logs (IP addresses, request paths, timestamps) may be retained temporarily by our hosting providers for operational and security purposes. We do not use cookies for tracking beyond what Clerk requires for authentication.
3. How we use your data
- To operate the Service and provide its features to you
- To authenticate you and maintain your session
- To enforce per-account usage quotas and prevent abuse
- To process payments, manage subscriptions, and maintain your credit balance
- To send AI-generated content requests on your behalf (worlds, story turns, characters)
- To automatically screen the content you submit and the AI-generated output for compliance with our Acceptable Use Policy and applicable law, and to block, remove, report, and take action on prohibited content
- To detect and report illegal content — in particular child sexual abuse material — to the relevant authorities, and to cooperate with their investigations (see “Disclosure to authorities” below)
- To respond to your support or contact messages
- To improve the Service based on aggregate, non-identifiable usage patterns
- To comply with our legal obligations and to establish, exercise, or defend legal claims
We do not sell your personal data. We do not use your content to train AI models. We do not send marketing emails. Automated screening may block content that appears to violate our Acceptable Use Policy or the law; decisions that significantly affect you, such as suspending your account, involve human review.
4. Legal bases for processing
Under the GDPR we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to provide the Service, your account, AI features, purchases, and credit balance.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, enforce quotas, prevent abuse and fraud, and understand aggregate usage through privacy-friendly analytics. You may object to processing based on legitimate interests (see Your rights).
- Legal obligation (Art. 6(1)(c)) — to keep records we are required to retain, to respond to lawful requests, and to detect and report illegal content (in particular child sexual abuse material) to the relevant authorities.
- Substantial public interest / protection of others(Art. 6(1)(e)–(f), and Art. 9(2)(g) where special-category data is involved) — to keep the Service and the public safe by screening for, and reporting, seriously harmful or illegal content.
- Consent (Art. 6(1)(a)) — where we ask for it for a specific purpose; you can withdraw consent at any time.
5. Sub-processors and recipients
We share data with the following third parties to operate the platform. Those that process personal data on our behalf do so under data processing agreements; Stripe acts as the merchant of record for payments and, for the payment data you provide at checkout, as an independent data controller (and, depending on the context, a processor) under its own privacy terms.
Clerk — Authentication
Processes your email address, name, and authentication credentials to manage sign-in and sessions. Data is stored in Clerk's infrastructure. Clerk's Data Processing Agreement is incorporated into their Terms of Service. See also their Privacy Policy.
Supabase — Database & Storage
Stores all application data: worlds, characters, stories, usage logs, preferences, and contact messages. Data is hosted in Supabase's managed PostgreSQL infrastructure. See their Data Processing Agreement.
Anthropic — AI Generation (Claude API)
When you use any AI feature (generating world bibles, story turns, characters, or extractions), the relevant content is sent to Anthropic's Claude API for processing. Anthropic processes this data under their API usage policies. By default, Anthropic does not use API inputs to train their models. See their Data Processing Agreement.
Stripe — Payments (merchant of record)
When you purchase credits or a subscription, payment is processed through Stripe Managed Payments. Stripe acts as the merchant of record and seller of record (through its subsidiary Sold Through Link, LLC, “Link SMP”) and, for the payment data you provide, as an independent data controller under its own Privacy Policy. It collects and processes the payment details you enter (such as card information and billing address) to complete the transaction, calculate and remit tax, and prevent fraud; we do not receive or store your full card details. See Stripe's Privacy Policy and its Consumer Terms of Service.
Render — Backend Hosting
The backend API server is hosted on Render. Server logs and ephemeral request data pass through Render's infrastructure. Render's Data Processing Addendum is incorporated into their Terms of Service. See also their Privacy Policy.
Vercel — Frontend Hosting & Analytics
The web application is hosted on Vercel, and we use Vercel's cookieless Analytics to measure aggregate traffic. Edge request logs and analytics data may be retained by Vercel for a limited period. See Vercel's Data Processing Agreement.
Disclosure to authorities
Where we detect or are notified of seriously harmful or illegal content — in particular child sexual abuse material — we may disclose the content and associated account data (such as your user ID, email, and relevant metadata) to the competent authorities and cooperate with their investigations. In Hungary this is the Internet Hotline operated by the National Media and Infocommunications Authority (Nemzeti Média- és Hírközlési Hatóság, NMHH) and, where applicable, the police and other law-enforcement bodies. Where the law requires it, such content and data may be preserved and disclosed even after you request deletion of your account.
6. International data transfers
Some of our providers (including Anthropic, Clerk, Vercel, Render, and Stripe) process data outside the European Economic Area, such as in the United States or the United Kingdom. Where data is transferred outside the EEA, we rely on an appropriate safeguard recognised under the GDPR — typically an adequacy decision (for example, the UK adequacy decision), the EU Standard Contractual Clauses, or a provider's certification under the EU–US Data Privacy Framework. You can ask us for more detail about the safeguards that apply to a particular provider.
7. Data retention and what remains after deletion
Your account data and all associated content are retained for as long as your account exists. If you delete your account, the following data is deleted immediately:
- All worlds, characters, and stories you own that are not publicly released
- All story turns, character growth records, and experience logs tied to your worlds
- Your credit transaction history (subject to records we must retain by law — see below)
- Your preferences and account settings
The following records are not deleted but are anonymised by removing your user ID from them:
- AI usage logs — retained indefinitely for cost accounting and abuse prevention, with your user ID replaced by a null value
- Admin audit log entries — administrative actions taken against your account are retained for accountability; your user ID is replaced by a null value
- Experience log entries on other users' worlds — contributions your characters made to stories in worlds you did not own are anonymised in place
The following content may be retained in full at our discretion:
- Released worlds— worlds you have marked as “released” for other users to play in may be retained as orphaned public content with no owner attribution, so that ongoing stories in those worlds are not disrupted
- Completed public stories — stories marked as public at the time of deletion may be retained with owner attribution removed
Contact messages are retained for up to 12 months. Server logs are typically retained for a short period (generally up to 30 days) by our hosting providers. Where we are required under Hungarian accounting law to keep tax and transaction records, we retain them for the statutory period (generally up to 8 years); this obligation applies to us regardless of which payment provider we use. As merchant of record, Stripe holds the invoice records for your purchases and retains personal information for as long as necessary to meet its own legal, accounting, and reporting obligations, as described in its Privacy Policy. Backup copies of all data may persist for an additional period consistent with our backup rotation schedule (generally up to 30 days). Retention for any of the above may be extended where required by law or for legitimate fraud-prevention purposes.
8. Your rights
Depending on your jurisdiction, you may have rights including:
- Access to the personal data we hold about you
- Correction of inaccurate data
- Deletion of your account and associated data
- Portability of your content (worlds, characters, stories) — contact us and we will provide an export
- Objection to or restriction of certain processing, including processing based on our legitimate interests
- Withdrawal of consent at any time, where processing is based on consent (this does not affect processing carried out before withdrawal)
To exercise any of these rights, email support@dystopia-engine.com. You also have the right to lodge a complaint with a data protection supervisory authority — in Hungary, the National Authority for Data Protection and Freedom of Information (NAIH, naih.hu), or the authority in your country of residence.
9. Security
We use industry-standard practices to protect your data: authentication tokens are short-lived JWTs validated server-side, database access uses service-role keys not exposed to the frontend, and all traffic is encrypted in transit via HTTPS. No system is perfectly secure; we cannot guarantee that your data will never be compromised, but we take reasonable precautions and will notify affected users and the relevant supervisory authority of a personal-data breach where required by law.
10. Children
The Service is intended for adults and is restricted to users aged 18 and over. It is not directed at, and may not be used by, anyone under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided us with personal data or is using the Service, please contact us and we will close the account and delete the data promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be noted in the changelog and, where feasible, communicated to registered users by email. The “last updated” date at the top of this page reflects the most recent revision. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.
12. Contact
For any privacy-related questions or requests, contact: support@dystopia-engine.com