Privacy Policy
Last updated: 29 August 2026
What personal data we collect, why, who it is shared with, how long it is kept, and the rights you have.
Introduction
This policy explains how BlueDungeonCraft (“we”, the publisher of the Roll in One website and application) handles the personal data of the people who use its services. For any question, write to [email protected].
Data controller. The party that decides on this processing and answers for it is MONSIEUR AUDREN JEREZ, reachable at [email protected]. Its full identity — legal status, registration number, address — is on the “Legal notice” page, linked from the site footer.
1. Data we collect
We collect only what the service needs in order to work:
- Account and identity. If you sign in with Google: your email address, your display name and your Google account identifier. If you sign in with an emailed link: your email address only.
- Profile, optional. A nickname and a profile picture, if you choose to add them.
- Purchases and entitlements. The content you own, your orders and their date, together with the accounting details of each order: amount, currency, tax collected and billing country (the detail is in section 3).
- IP address. Kept transiently, for the sole purpose of limiting abuse (rate limiting).
- Device, when a licence key is activated. A hashed device identifier — a one-way fingerprint, from which the device cannot be recovered — and, if the application sends one, the name it gives that machine. They serve to tie the key to the device that activated it and to limit unauthorised sharing; they serve nothing else, and do not allow you to be recognised anywhere else.
- Audience measurement. With every page view: the page address and its title, the page you came from, your browser language and your screen size; your country is derived from your IP address. To that are added a few measured actions — a click on a download button, joining the waiting list, printing a card or a sheet, a filter applied in an index — and, for searches in the indexes, the search term itself, lower-cased and truncated to sixty characters. None of this is matched against your account (see section 6).
- Sign-in cookies. Two, both strictly necessary: a transit cookie during the trip to your identity provider, and your session cookie afterwards (see section 6).
No advertising tracker is used, no profiling is carried out, and your data is neither sold nor rented.
2. Purposes and legal bases
This data is used to:
- authenticate you and maintain your session;
- give you access, on all your devices, to the content you own;
- send you the emails the service requires (sign-in link, confirmation that a pack is available on your account);
- keep the service secure and prevent abuse;
- allow payment for your purchases and the attachment of the pack to your account.
Under the GDPR, the legal bases are performance of a contract (account, access to owned content, payments), legitimate interest (security and abuse prevention, aggregated audience measurement, tying a licence key to the device that activates it) and consent (newsletter, if you subscribed to it).
3. Service providers
Some data is handled by third parties. Most of them do so on our behalf, and for the purposes listed above only. Stripe is an exception, for a reason explained right after this list:
- Google — signing in to your account, if you choose that method.
- Cloudflare — website hosting, database and file storage.
- Vercel — hosting for the audience-measurement instance we run ourselves (see section 6).
- Resend — sending our service emails: the sign-in link, and the confirmation that a pack is available on your account. Not the purchase receipt, which comes from Stripe.
- Stripe — payment and invoicing for purchases, as the merchant of record: see the paragraph after this list. We never receive or keep card numbers: those details go straight to Stripe and never pass through our servers.
- MailerLite — sending the newsletter, only if you subscribed to it.
Those providers handle the data under their own privacy policy, within the framework of their contract with us.
Stripe, a special case. The sale of our paid packs is carried by Stripe as the merchant of record: Stripe is the party that sells you the pack, takes the payment and issues the invoice. It therefore does more than run a payment on our behalf — it handles payment and billing data on its own account, and answers for it itself, under its own privacy policy. This covers in particular your payment details, the billing address you give it and whatever it needs in order to calculate the applicable taxes.
On our side, all we keep of that purchase is what we need in order to give you access and keep our accounts: the fact that an order took place, its date, the pack concerned, the amount and currency paid, the tax Stripe collected and its rate, the billing country it passes on to us, and the payment references on its side. If a refund happens, we likewise keep its amount, date, reason and status.
We hold neither your card number nor your full billing address: of that address, Stripe passes on only the country, because that is what determines the applicable tax.
Transfers outside the European Union. Some of these providers — Google, Cloudflare, Stripe, Resend and Vercel — are established in the United States, so the data entrusted to them is transferred there. Those transfers rely on the EU-US Data Privacy Framework, to which these companies are certified, together with the European Commission’s standard contractual clauses provided for in their processing agreements.
MailerLite, for its part, is established in the European Union, in Lithuania: the newsletter does not leave the Union.
4. Retention
Your account data is kept for as long as that account exists.
Deleting an account takes the form of anonymisation: personal data (email addresses, name, nickname, profile picture, external identifiers, the address a licence key attached to your account was sent to) is erased and signing in is permanently disabled. Orders, on the other hand, are kept to meet accounting and tax obligations — the next paragraph says exactly in what form, and what remains.
What closing your account does not erase, and why. Your orders remain: the fact that a payment took place, its date, its amount, the tax collected, the billing country and the payment references at Stripe. The right to erasure does not cover those records — accounting and tax obligations require keeping them for ten years. On our side they are no longer attached to an account that names anyone; but let us be exact: a payment reference is still a handle into Stripe, which does know the buyer. Calling these orders “anonymous” without qualification would therefore be inaccurate. They move into intermediate archiving: they no longer serve the running of the service, and access to them is restricted to what requires it — accounting, an audit, a claim.
The newsletter does not close with your account. The two are kept separately: signing up for the launch announcement knows nothing of any account, so closing yours does not unsubscribe you. The unsubscribe link at the bottom of every message is there for that.
A delay before final erasure. Our host keeps restore points of the database for around thirty days — enough to put it back in working order after a failure or a mistake. During that period, whatever an account closure erased still exists in those backups, before disappearing from them in turn. We do not use them to bring a closed account back: it is a technical safety net, not a recycle bin.
Sign-in links and pairing codes expire within minutes. Technical logs, which may contain an IP address, are kept for a limited period and then erased.
5. Your rights
Under the GDPR, you have the right of access, rectification, erasure, restriction of processing, portability of your data and objection to processing.
You can delete your account yourself from your account page, at any time and without having to ask. You can likewise export your data from there: a JSON file, readable by a program and by you, which serves both the right of access and portability. To exercise the other rights, write to [email protected].
If an answer does not satisfy you, you may lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL), the French supervisory authority.
6. Cookies and audience measurement
The website sets two cookies, and only around signing in. The first accompanies the trip to your identity provider and expires after ten minutes; the second is your session cookie, set once you are signed in. Both are strictly necessary for the service you asked for: no consent is required for that kind of cookie, and no banner is therefore shown to you. As long as you do not sign in, the site sets no cookie at all.
Public pages do measure their audience, and that deserves saying plainly rather than hiding behind “no third-party tracker”. The tool is called Umami; we host it ourselves rather than hand this measurement to an advertising network. It sets no cookie, does not follow you from one site to another, and the measurement is limited to our own domain.
Two things need separating. The instance receives one line per page view — that is what audience measurement is, and claiming otherwise would boast of a discretion we do not have. What we read from it, on the other hand, are totals: page views, most-visited pages, referrers, countries, and the count of each measured action, a few dozen lines per period. We never open the visitor-by-visitor detail, and nothing in it is matched against your account.
No consent is required for measurement of that nature, and no banner is therefore shown to you. The administration pages are not measured at all.
7. Security
No password exists on this service. Signing in happens through Google or through a link sent to your email address, which is single-use and short-lived. Sessions stored by the desktop application are encrypted at rest on your machine.
That choice has a consequence you should be aware of: whoever can read your inbox can reach your account. Protect your mailbox at least as carefully as this account.
8. Children
This service is not intended for people under 15, and we do not knowingly collect their data. If you become aware that an account was created by a child, write to us: it will be deleted.
9. Changes
This policy may change. The date shown at the top of this page is that of the latest version, and any substantial change will be brought to your attention through the service’s usual channels.
10. Contact
For any question about this policy or about your personal data: [email protected].