Personal data processing notice

Last updated: 14 September 2026

Data controller

RollForOne is an independent project based in Agrigento (Italy) and is the controller of personal data collected through the rollforone.com website and application, under Regulation (EU) 2016/679 (the GDPR) and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018. For any request about this notice or your rights, write to info@rollforone.com. That address is already in use and is read.

Categories of data

We process the data needed to provide, protect and improve the service:

  • Account data: email address, username and authentication credentials, stored in encrypted form by the authentication provider.
  • Game content: characters, campaigns, messages, images and other materials you enter or upload, including reports.
  • Technical data: cookies and storage strictly necessary for the session, security and essential preferences. We do not use advertising profiling cookies or third-party trackers for commercial purposes.
  • Security data: technical logs, rate limits and, if you sign in with Google, the identifiers that service makes available.
  • Please do not put real personal data of third parties (identity, health or financial data) in game content unless it is necessary for play.

Purposes and legal bases

Processing is carried out for the following purposes and legal bases:

  • Providing the service (account, sheets, campaigns, chat): Article 6(1)(b) GDPR (performance of a contract).
  • Support, technical diagnosis and improvement of the platform: Article 6(1)(f) GDPR (legitimate interest in maintaining and improving the service).
  • Security, abuse prevention and, where enabled, automated review of uploaded content: Article 6(1)(f) GDPR. Product narrative artificial intelligence is not active.
  • Legal obligations, where they apply (for example accounting duties if transactions occur): Article 6(1)(c) GDPR.
  • Access to adult (Mature) content, where provided: Article 6(1)(a) GDPR (consent).

Retention

The GDPR does not set a single retention period. We apply storage limitation (Article 5(1)(e)) on the following criteria, unless a legal duty or the need to establish, exercise or defend a legal claim requires otherwise:

  • Account data and game content: for the life of the account, until deletion by you or by the controller.
  • Backups: as a rule up to 30 days after deletion.
  • Technical and rate-limit logs: as a rule up to 90 days.
  • Reports: as a rule up to 24 months, or longer if needed to investigate an offence.
  • Accounting records, if any: 10 years (Italian Civil Code, Article 2220). Records needed for legal defence may be kept within ordinary limitation (Italian Civil Code, Article 2946).

Recipients

Data are disclosed only to providers that are necessary to run the service, acting as processors or independent controllers for the services they provide:

  • Supabase: authentication, database and storage, on infrastructure in the European Union (eu-west-1, Ireland).
  • Vercel: hosting and delivery of the application, with processing in the European Union (dub1, Ireland).
  • Google (Sign in with Google): if you choose that method. Google processes data under its own notice.
  • Have I Been Pwned: k-anonymous check of compromised password prefixes, without sending the password in clear text.
  • Automated moderation: if that pipeline is active, published or reported text or images may be examined by classification services (for example OpenAI or Google Gemini) for security only. Those services are not used to generate game narrative.

Transfers outside the EEA

Core processing takes place in the European Union. Some services (in particular Sign in with Google and, if enabled, password checks or moderation) may involve a transfer to third countries. In those cases we rely on the safeguards in Chapter V GDPR, including the European Commission's standard contractual clauses where they apply.

Your rights

Under Articles 15, 16, 17, 18 and 21 GDPR, you may request access, rectification, erasure, restriction and objection to processing, in the cases provided by law.

  • Access your data and obtain rectification.
  • Request erasure or restriction of processing, where the law allows. You can delete your account from the Profile page.
  • Object to processing based on legitimate interest, on grounds relating to your particular situation.
  • Lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with the supervisory authority of your EU Member State of residence or work.

Contact

To exercise your rights or for any other question about processing, write to info@rollforone.com. We will reply without undue delay and in any event within one month, as required by Article 12 GDPR.