LEGAL
Privacy Policy
Effective August 25, 2026
Init to Crit collects only the information needed to run, sync, support, and check Patreon-based access for the service. We do not sell personal information. You can delete your Init to Crit account and its associated app data from the Account & Data screen.
1. Who operates this service
Init to Crit (“we,” “us,” or “our”) is an independent tabletop companion operated from Ontario, Canada. Privacy questions and access or deletion requests can be sent to cocky.rooster.miniature.gaming@gmail.com.
2. Information we collect
Guest and account information
- A Firebase anonymous identifier is created when the app is used as a guest.
- If you choose Google sign-in, Firebase Authentication provides your account identifier, display name, and email address.
- We do not receive your Google password.
Game and campaign content
We store the encounters, combatants, campaign notes, rosters, templates, combat logs, conditions, voice profiles, and other tabletop content you choose to save. Synced content is linked to your Firebase account identifier.
Voice generation information
When you request a generated voice, the dialogue text and selected voice settings are sent through a protected Firebase function to the OpenAI speech API. Generated audio is returned to your browser. Audio, dialogue text, and its voice profile are saved to Firebase Storage and Firestore only if you choose to save the clip.
OpenAI states that API data is not used to train its models by default. Its standard abuse-monitoring logs may retain API content for up to 30 days unless a different retention control applies. See OpenAI API data controls.
Patreon membership information
If you connect Patreon in the Account & Data screen, we store your Patreon member identifier, pledge/membership status, tier, pledged amount, a Patreon refresh token used to re-check your pledge, and when we last checked. This links Patreon's own account and payment data (which we don't have) to matching voice and cinematic-recap allowances in Init to Crit. We do not receive your Patreon password or complete payment-card numbers. Patreon handles your account and payment information under its own Privacy Policy.
Feedback, diagnostics, and product activity
If you send feedback, we store its category, rating, message, and app context. Privacy-conscious product events record actions such as opening the app, creating an encounter, or connecting Patreon. They include a Firebase identifier and random session identifier, but not encounter text, dialogue, payment-card data, or Google passwords.
Browser and offline data
The installable web app uses local storage, IndexedDB, and a service-worker cache for settings, offline resilience, guest continuity, and skirmish-mode autosaving. You can remove this local data using your browser’s site-data controls.
3. How we use information
- Provide combat tracking, saved campaigns, cloud sync, voice generation, voice storage, and billing.
- Authenticate users, protect records, enforce voice allowances, and prevent abuse.
- Respond to feedback and support requests.
- Measure aggregate adoption, reliability, and conversion so the service can be improved.
- Meet legal, accounting, security, and fraud-prevention obligations.
4. Service providers and disclosure
We use Google Firebase for authentication, Firestore, Storage, Hosting, and Cloud Functions; Patreon for membership verification (Patreon itself handles any related payment); and OpenAI for generated speech. These providers process information to deliver their services and may process data outside Canada. Firebase describes its role and security practices in Privacy and Security in Firebase.
We do not sell or rent personal information. We may disclose information if required by law, to protect users or the service, or as part of a business transfer with appropriate safeguards.
5. Retention and deletion
Saved app content is generally retained until you delete it or delete your account. Product activity used for the private dashboard is limited to a rolling 30-day view, although underlying security records may be retained longer when reasonably needed. Patreon may retain its own membership and transaction records under its legal and financial obligations.
The Account & Data screen permanently removes the Firebase login, encounters and event logs, campaigns, rosters, templates, feedback, product events, voice clips and files, voice usage, and app entitlement records associated with that identifier, including the stored Patreon link and refresh token. Deletion disconnects Patreon and ends Init to Crit-side access immediately, but does not cancel your Patreon pledge — that is managed on Patreon. Provider backups or legally required records may take additional time to expire.
Free trial: to allow one free 7-day trial per person, we keep a one-way hash (SHA-256) of your normalized verified email address. It is not your email address and cannot be read back as one, and it is not removed when you delete your account, because removing it would allow a second trial. It is used only to enforce that limit.
6. Safeguards
We use Firebase authentication, owner-based database and storage rules, protected server functions, encrypted HTTPS connections, restricted secrets, and Patreon's OAuth flow for membership verification. No internet service can guarantee absolute security, so users should avoid entering sensitive personal, medical, financial, or confidential information into campaign notes or voice dialogue.
7. Your choices and rights
You can use core features as a guest, choose whether to sign in, decide whether to generate or save voice clips, connect or disconnect Patreon and manage your pledge directly on Patreon, remove individual records in the app, or delete the entire Init to Crit account. You may also contact us to request access, correction, or information about our handling of personal information.
We aim to follow applicable Canadian privacy requirements, including the principles of accountability, consent, limiting collection and retention, safeguards, openness, and individual access described by the Office of the Privacy Commissioner of Canada.
8. Children
Init to Crit is not directed to children under 13. If you believe a child has provided personal information without appropriate consent, contact us so it can be reviewed and removed.
9. Changes
We may update this policy as the service changes. The effective date will be revised, and material changes may also be announced in the app.