Privacy Policy
Effective Date: February 3, 2026
Introduction
Questwright ("we," "us," or "our") is an AI-powered virtual tabletop for Dungeons & Dragons 5th Edition. This Privacy Policy explains how we collect, use, and protect your personal information when you use our website at questwright.app and related services.
We believe in transparency. We collect only what we need to provide our service, we don't sell your data, and we'll tell you exactly what happens with your information.
Information We Collect
Account Information
When you create an account, we collect:
- Username - Your unique login identifier
- Display Name - How your name appears to others
- Email Address (optional) - For account recovery
- Password - Stored securely using industry-standard hashing
OAuth Login Data
If you sign in with Discord, Google, or Twitch, we receive:
- Discord - Your Discord ID, username, and avatar URL
- Google - Your Google ID, email, name, and profile picture
- Twitch - Your Twitch ID, username, and profile picture
We only request the minimum permissions needed. We do not access your friends lists, server memberships, or any other data beyond basic profile information.
Content You Create
When you use Questwright, we store:
- Characters - Names, stats, backstories, inventory, and other character data
- Campaigns - Campaign settings, world information, and session history
- Game Sessions - Conversations with the AI Dungeon Master, dice rolls, and story events
- NPCs and Locations - Characters and places created during play
Beta Access Requests
When you request beta access, we collect:
- Your name and email address
- Age range (to verify you are 18+)
- Your tabletop RPG experience level
- Your response about why you'd make a good tester
- Your Discord account information (required for beta)
Bug Reports
When you submit a bug report, we collect:
- Your description of the issue
- Your Discord username and ID (if submitted via Discord)
- Current session ID (if applicable)
- Timestamp of the report
How We Use Your Information
We use your information to:
- Provide and maintain the Questwright service
- Create and manage your account
- Save your characters, campaigns, and game progress
- Generate AI-powered story content for your games
- Respond to bug reports and support requests
- Send service-related communications (password resets, account notices)
- Improve our service based on how it's used
We do not sell your personal information. We do not share your data with advertisers or third-party marketers.
Third-Party Services
Anthropic (Claude AI)
Questwright uses Anthropic's Claude AI to power the Dungeon Master experience. When you play, your game conversations are sent to Anthropic's API to generate responses.
What Anthropic receives: Your messages during gameplay, character information relevant to the current scene, and campaign context needed to generate appropriate responses.
What Anthropic does NOT receive:
- Your email address
- Your password or account credentials
- Your Discord, Google, or Twitch login tokens
- Your IP address or location
- Your real name (unless you include it in your character's backstory)
- Any data from campaigns you're not actively playing
Anthropic's data practices:
- API data is retained for up to 30 days (recently reduced to 7 days for API logs)
- API customer data is not used to train Anthropic's models
- Content flagged by safety classifiers may be retained up to 2 years
- See Anthropic's Privacy Policy for full details
OAuth Providers
When you sign in with Discord, Google, or Twitch, you are subject to their respective privacy policies:
Data Retention
We retain your data for the following periods:
| Data Type | Retention Period |
|---|---|
| Account information | Until you delete your account, or 6 months of inactivity |
| Characters and campaigns | Until you delete them or your account |
| Game session logs | Until the campaign is deleted |
| Bug reports | 1 year |
| Beta access requests | Until end of beta period |
Account Deletion
You can request deletion of your account at any time by contacting us. When you delete your account:
- Your account information is permanently deleted
- Your characters are permanently deleted
- Campaigns you created are permanently deleted
- Your contributions to other players' campaigns are removed
- We may retain anonymous, aggregated statistics (e.g., "X campaigns were played") that cannot identify you
Data Security
We protect your data using:
- HTTPS encryption for all data in transit
- Secure password hashing (passwords are never stored in plain text)
- OAuth tokens that are securely managed and not stored long-term
- Database access restricted to essential services only
No system is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you promptly.
Age Requirements
During the beta period, Questwright is only available to users 18 years of age or older.
We do not knowingly collect personal information from anyone under 18 during the beta. If we learn that we have collected data from someone under 18, we will delete it promptly.
After beta, we may allow younger users with appropriate restrictions and parental consent requirements. This policy will be updated accordingly.
Your Rights
You have the right to:
- Access - Request a copy of the personal data we hold about you
- Correction - Request correction of inaccurate data
- Deletion - Request deletion of your account and associated data
- Data Portability - Request your data in a portable format
- Withdraw Consent - Unlink OAuth accounts or close your account at any time
To exercise any of these rights, contact us using the information below.
Cookies
We use essential cookies only:
- Session cookie - Keeps you logged in during your visit
- OAuth state cookies - Temporary cookies used during the login process for security
We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Posting the new policy on this page with an updated effective date
- Announcing changes in our Discord server
Your continued use of Questwright after changes take effect constitutes acceptance of the updated policy.
Jurisdiction
Questwright is operated from Pennsylvania, United States. By using our service, you consent to the processing of your data in the United States. If you are accessing from outside the US, please be aware that your data may be transferred to and processed in the US.
Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, contact us:
- Discord: Questwright Discord Server
- Email: [email protected]