Privacy policy
Effective October 4, 2026
This notice covers PulledIt at pulledit.shop, including accounts, worlds, campaign trackers, AI storytelling and billing. For privacy questions or requests, email derekosmun@gmail.com.
The short version
- We store account details, your adult self-confirmation, and the adventures, rules, messages and settings you save.
- Using AI sends relevant rules, story messages and campaign context to external AI providers. Free providers may use that content for product improvement or training.
- Publishing a world makes its published setting visible to other people; it does not publish your private adventure.
- Stripe handles payment details. Card numbers are not entered into or stored by the PulledIt application.
- You can contact us to request access, correction or deletion. Deleting a record does not instantly erase backups, logs or copies other people already made.
What information is collected
- Accounts: your email, account identifier, authentication/session information, sharing permissions and adult self-confirmation. A signed-in confirmation records that you declared you are 18 or older, the notice version and a timestamp in your Supabase account metadata. Supabase handles password authentication; do not send your password to support.
- Content: worlds, story templates, character sheets, campaign notes, uploaded rules text and filenames, AI prompts and responses, dice history, change logs, recaps and checkpoints you create or save. Fictional content may contain personal information if you include it.
- Billing and usage: plan, credit balances, request counts, token/cost information, transaction identifiers, payment status, refunds and disputes. Stripe collects checkout information such as billing email, address and payment details; its payment records are associated with your PulledIt account.
- Technical information: hosting, authentication and AI services may process IP addresses, browser/request details, timestamps, errors and security logs. Your browser stores session information and preferences such as your theme and last selected campaign.
- Support: information you email us, including your address, request and relevant account or purchase references.
PDF, Word and text rulebooks are read in your browser. AI generation sends extracted text, not the original file binary. Creating a campaign saves the extracted rules and filename to the database. A failed AI proposal does not create a campaign, but text already submitted may have been processed by the AI provider.
Why information is used
Information is used to sign you in, save and synchronize adventures, enforce sharing permissions, provide AI responses, manage subscriptions and credits, reconcile payments, investigate errors or abuse, answer support requests and meet applicable legal obligations. Usage accounting determines allowances and credit charges, not eligibility for credit or employment.
Where applicable law requires a legal basis, this processing may be necessary to provide the service you request, comply with legal obligations, pursue legitimate interests in security and reliable operation, or rely on consent where required. An upload-permission checkbox does not replace any consent or other legal basis that the law requires.
AI providers and your content
AI storytelling, ruleset generation, world/story drafts and recaps can send relevant input, rules excerpts, conversation history, world details, campaign records and tool results to Google Gemini, or through OpenRouter to the selected or routed model provider. AI tools may read and update authorized campaign records; changes and conversations can be saved in your adventure.
Keep real personal, sensitive and confidential information out of AI inputs. Google's unpaid Gemini services may use inputs and outputs to improve products, including through human review. OpenRouter's model providers have different retention and training practices. PulledIt does not currently enforce a universal zero-retention or no-training routing rule.
Free AI is tried first. If your account permits paid continuation, the same necessary context can be sent through OpenRouter when a free allowance or provider limit is reached. Paying for a PulledIt membership does not make every AI request private or change the terms of a free provider used for that request.
The current Gemini Live integration processes text with server-side generated audio/transcription; it does not request your microphone or camera. Choosing manual tracking without AI avoids sending that action to an AI provider, but saved content still uses our database and hosting services.
See Google's Gemini API terms and OpenRouter's privacy policy, including its model-provider information. Provider rules and available models can change.
Who can see information
- Service providers: Supabase supplies authentication, database and backend services; Vercel hosts the site; Stripe processes billing; Google, OpenRouter and routed providers process AI requests. Email services process support messages. Each receives information needed for its role.
- People you share with: invited editors and viewers receive access according to their role. Editors have trusted GM access. Story-template sharing may expose preparation notes. Revoking access cannot recall an export or information already read.
- Public world visitors: publishing exposes a setting snapshot such as lore, locations, characters and its opening. Publication does not itself expose private adventure sheets, transcripts or uploaded rulebooks. Unpublishing removes it from the site's public listing, not from copies others already saved.
- Administration and integrations: authorized site administrators can review account emails, sign-in dates, plan and credit information, and campaign information for support and moderation. Administrative restrictions and restorations record the administrator, target, reason and time in an audit log. Configured administrative AI connectors can also access stored content. Private campaign permissions are not an end-to-end encryption promise. Connecting an external AI assistant can disclose retrieved content to that assistant's provider.
- Legal and security needs: information may be disclosed when legally required or reasonably necessary to investigate fraud, protect users or respond to a dispute.
The current application has no targeted-advertising or data-selling feature. External services have their own data practices; AI-provider processing should not be mistaken for a promise that content is never shared or used for training.
Browser storage and external services
Local storage keeps authentication/session information, your theme and the last selected campaign. Session storage remembers a guest's adult confirmation in that browser tab; signed-in confirmation is associated with your account, not borrowed from another account's browser confirmation. Blocking or clearing storage may sign you out, repeat the age notice or reset preferences; clearing browser storage does not delete server-side content or your account confirmation.
The site loads fonts from Google Fonts and software libraries from jsDelivr. Those services receive ordinary network-request information. Stripe's hosted checkout and portal and other linked services may use cookies or similar technologies under their own policies. The current application does not include an advertising tracker or an optional analytics script.
Provider notices: Supabase, Vercel, Stripe, Google Fonts and jsDelivr.
Retention, security and international processing
Saved adventures, rules, transcripts and checkpoints currently have no automatic account-wide expiration or deletion schedule. They remain stored unless removed through available controls or a reviewed support request. Billing, audit and security records may need to be retained for accounting, dispute handling, abuse prevention or legal requirements.
Deleting a visible record may leave copies in checkpoints, change logs, backups, service-provider records or other users' exports. Account deletion and complete-content requests are handled through support rather than a self-service account-deletion button. We will explain applicable retention limits and any records that must remain; we do not promise immediate erasure from every system.
The application uses HTTPS and account/role-based database access. Administrative access and external-provider processing still exist, and no system can guarantee absolute security. Never include passwords, API keys, full card details or confidential third-party information in a campaign.
Data may be processed in the United States and other countries where our providers operate. Privacy laws and provider terms vary. Availability of the website is not a statement that all provider features are approved for every age group or country.
Your choices and privacy requests
You can keep worlds unpublished, manage invitations, use manual tools instead of AI, edit available records and use available export functions. To request a copy of personal information, correction, deletion, or another privacy right, email derekosmun@gmail.com with your account email and request. Do not include your password or full card details.
Depending on your location and applicable law, you may also have rights to portability, restrict or object to processing, withdraw consent, appeal a decision or complain to a privacy authority. We may verify account ownership and will respond within applicable legal time limits. Some requests may be limited by legal retention duties or other people's rights. Withdrawing consent does not undo processing that already occurred lawfully.
Subscription cancellation and refunds are separate from privacy deletion requests. See our refund and cancellation policy; canceling a plan does not automatically delete your content.
Adults only: 18 and older
PulledIt is only for people 18 years of age or older and is not intended for children. The application displays an age-confirmation popup and requires an affirmative checkbox before allowing use. Signed-in accounts without a recorded adult confirmation must confirm again; the AI and new-purchase endpoints check that account confirmation. Declining keeps the application blocked. Privacy and refund information, support and existing signed-in billing management remain available.
This is self-declared age confirmation, not proof of age or identity. We do not collect your date of birth or identity documents or perform automated identity-based age verification. An age popup alone does not establish compliance with every applicable law or provider's regional restrictions. If you believe someone under 18 supplied personal information, contact us so we can investigate and address it.
Changes and contact
We update this notice when data practices or providers change and show its effective date above. Material changes will be communicated as applicable law requires.
Privacy contact: derekosmun@gmail.com.