Privacy Policy
Last updated: March 2025
1. Who We Are
Weaver ("we", "us", or "our") is an AI-powered roleplay engine operated as an independent service. If you have any questions about this Privacy Policy, you can reach us at privacy@weaver.app.
2. What Data We Collect
- Account data: When you sign in via Google or GitHub, we receive your name, email address, and profile picture from the OAuth provider.
- Usage data: We record which AI models you use, credit consumption, and request timestamps to manage your subscription and prevent abuse.
- World data: Characters, locations, sessions, and knowledge-graph entries you create are stored in our database when cloud sync is enabled. Without cloud sync, all data stays in your browser.
- Technical data: Standard web-server logs (IP address, browser type, referring URL) for security and diagnostics.
- Cookies and tracking: See our Cookie Policy for a full list.
3. Legal Bases for Processing (GDPR)
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the service you signed up for, including billing and credit management.
- Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, and service improvement.
- Consent (Art. 6(1)(a)): Advertising cookies (Google AdSense) are only placed with your consent via our cookie banner.
4. Third-Party Services
- Google AdSense: We display ads on marketing pages. Google may use cookies and device identifiers to serve personalised ads based on your interests. You can opt out at adssettings.google.com.
- Google Analytics / PostHog: We collect pseudonymous usage analytics to understand how users interact with the product. No personally identifiable information is shared.
- Vercel: Our hosting provider. Data may be processed on servers within the EU and the United States under standard contractual clauses.
- Stripe: Handles subscription billing. Weaver never stores your full card details.
5. Data Retention
Account and usage data is retained for as long as your account is active and for up to 90 days after deletion. Analytics data is retained for 24 months. You may request earlier deletion at any time.
6. Your Rights
Under GDPR you have the right to access, rectify, erase, restrict processing, and port your data. You also have the right to object to processing based on legitimate interests and to withdraw consent at any time. To exercise these rights, email privacy@weaver.app. If you are unsatisfied with our response you may lodge a complaint with your local data-protection authority.
7. Children
Weaver is not directed at children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notice. The date at the top of this page always reflects the latest revision.