Privacy Policy

Last updated: June 15, 2026

This Privacy Policy explains what information TTRPG Terminal Simulator collects, how we use it, and the choices you have. We designed the product to be privacy‑respectful and to only collect what’s needed to operate your account, secure access, and handle subscriptions.

What we collect

  • Account information: email address and a username you choose. We also store basic account state (for example, whether your email is verified) and subscription tier information access).
  • Authentication and security data: we use Firebase Authentication. If you enable multi‑factor authentication (MFA), we store TOTP keys in Firebase Auth and, if you add phone MFA, your phone number is managed by Firebase Auth. We use reCAPTCHA during sign‑up and MFA SMS to prevent abuse.
  • Product content you create: terminals you create (names, descriptions, button configurations, including any text you enter, YouTube links, and Google Docs/Sheets share URLs), and media files you upload to your Media Library (images, audio, and video). When you share a terminal, we store the email addresses you share with. Live collaboration state (e.g., a currently open YouTube/Docs modal) may be stored briefly in Firestore to synchronize operators.
  • Subscription and billing metadata: we integrate with Stripe. Stripe processes payment details; we do not store full payment card data. We store subscription tier info (e.g., tierId, status, related Stripe price IDs) to provide features and limits.
  • Analytics and diagnostics: we use Google Analytics 4 to record basic usage events (e.g., page views, sign‑ups, logins, feature usage) and device/browser metadata. Google Analytics may set cookies and collect information about your use of the service. We also use Sentry to capture errors and performance information and, on error, anonymized session replays with text masking and media blocking enabled. We do not sell this information.
  • Service logs: our backend and providers (Firebase/Google, Stripe, email provider) may log standard technical information like IP address, timestamps, user agent, and error details for security, abuse prevention, and troubleshooting. We also maintain limited admin audit logs for sensitive actions (e.g., access changes).
  • Contact form submissions: when you submit a message via our contact form, we collect your name, email address, subject, message, and optionally your category, username, and whether you are a current user. We also capture browser/OS information, IP address, and page URL for context. This information is stored in Firestore for support and customer service purposes.

How we use information

  • Provide and operate the app (authentication, terminals, sharing, subscriptions).
  • Secure accounts (MFA, reCAPTCHA, abuse detection) and protect users.
  • Communicate about your account (verification, receipts, support).
  • Improve reliability and troubleshoot issues.
  • Comply with legal obligations and enforce terms.

Sharing and processors

We do not sell your personal information. We share data only with service providers necessary to run the app:

  • Firebase (Google) for authentication, database (Firestore), and security tooling (reCAPTCHA). When reCAPTCHA is displayed, Google may collect hardware and software information, device and app data, and may set cookies to perform risk analysis. See Google’s Privacy Policy.
  • Google Analytics 4 to understand feature usage and improve the product. Analytics events may include page views, clicks, scrolls, and generic event names. Google may use this data in accordance with their privacy policy.
  • Stripe for payment processing and subscription management. Stripe receives billing details you provide during checkout and returns subscription status/IDs we store.
  • Email provider (Resend) to send account, system, and support emails (for example, verification, receipts, invites, and contact form replies).
  • Sentry for error monitoring, performance data, and privacy‑preserving session replay to diagnose production issues (with text masked and media blocked by default).
  • Embedded content you choose to add (YouTube videos and Google Docs/Sheets). When you open these, your browser connects directly to YouTube/Google; their use is governed by their policies. Other content types (audio, video, and images from your Media Library) are served from our own infrastructure and do not create connections to third-party services.

Cookies and similar technologies

We use essential cookies and similar local storage mechanisms to keep you signed in and secure your session (Firebase Auth). Stripe and Google reCAPTCHA may set their own cookies during checkout and abuse protection. Google Analytics may store cookies and identifiers to measure usage and track user behavior across sessions. You can control cookies via your browser settings or opt out of Google Analytics tracking; disabling essential cookies may prevent login.

Retention

We retain account and terminal data while your account is active. For free-tier or canceled accounts, if there is no account activity for 30 days, the account and associated content may be automatically deleted as part of our retention cleanup process. You can delete terminals you create at any time. If you close your account, we will delete or anonymize associated data within a reasonable period, subject to requirements that may mandate longer retention (e.g., billing, fraud prevention, or legal compliance records).

Your choices and rights

  • Access/Update: you can update your username and email in the app; contact support for any issues.
  • Security: enable MFA (TOTP or SMS) for stronger protection; keep your recovery codes in a safe place.
  • Deletion: delete terminals you own; contact support to request account deletion.
  • Sharing: when you add collaborators by email, they can view your terminal as permitted. Remove shares anytime.

Children's privacy

The service is not directed to children under 13, and we do not knowingly collect information from children. If you believe a child has provided us personal information, contact us to request deletion.

International transfers

We primarily use US‑based infrastructure (Firebase/Google Cloud). Using the service may transfer your information across borders in accordance with applicable law and provider safeguards.

Changes to this policy

We may update this Privacy Policy from time to time. We’ll change the “Last updated” date above and, when appropriate, provide additional notice in the app.

Contact

Questions or requests? Email us at support@terminalsim.tiesthatbindgaming.com .


Key technologies we use: Firebase Authentication (email/password, optional TOTP/SMS MFA and reCAPTCHA), Firestore for data storage, Cloud Functions for server logic, Stripe for payments, Resend for email, Google Analytics 4 for usage insights, and Sentry for error monitoring and privacy‑preserving session replay.