Last updated: February 2026
Account information: When you register, we collect your username, email address, and an encrypted (hashed) password. We never store your password in plain text.
Content you create: Characters, posts, comments, direct messages, and Annals contributions are stored on our servers to operate the Platform.
Technical data: We collect basic technical data including your IP address and browser type for security purposes (rate limiting, abuse prevention, and error monitoring). We use Sentry for error tracking, which may capture anonymized technical data when errors occur. We do not use third-party tracking cookies, advertising pixels, or behavioral analytics.
Your data is used solely to operate the Poetic Goblin platform โ displaying your content, enabling social features (likes, follows, direct messages), securing your account, and diagnosing technical issues. We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes. We do not serve ads.
We use the following third-party services to operate the Platform:
Railway โ application hosting and database
AWS S3 โ image and file storage
Resend โ transactional email delivery (verification, password resets)
Sentry โ error monitoring and performance tracking
These services process data only as necessary to provide their services to us. We do not share your data with any other third parties.
We send emails only for: account verification, password resets, and critical service announcements (e.g., security incidents or major Terms changes). We will never send marketing emails without your explicit opt-in consent. You cannot opt out of security-related emails while your account is active.
Images you upload (avatars, art, maps) are stored on our secure cloud infrastructure (AWS S3). We automatically strip EXIF metadata โ including GPS location data โ from uploaded images to protect your privacy. Images are resized to reasonable dimensions to reduce storage and bandwidth.
We use a single session cookie to keep you logged in. This is a strictly necessary, first-party cookie โ not a tracking cookie. We also use browser local storage to remember your theme preference (light/dark mode). We do not use any third-party cookies, advertising cookies, or tracking technologies.
Your data is retained as long as your account is active. If you delete your account, we will delete your personal data (email, password hash, characters, posts, messages) within 30 days, except where we are required by law to retain it. Annals contributions that have been licensed under CC BY-SA 4.0 may persist in the shared world even after account deletion, as described in our Terms of Service.
You can view, edit, or delete your content at any time through the Platform. You can delete your entire account through Settings, which will remove your personal data as described above. To request a full export of your data, contact us at the email below. If you are located in the EU/EEA, you have additional rights under GDPR including the right to access, rectification, erasure, and data portability.
Passwords are hashed using industry-standard algorithms (Werkzeug/PBKDF2). All connections use HTTPS encryption. We implement CSRF protection, rate limiting, Content Security Policy headers, and input validation to defend against common attacks. While we take security seriously, no system is perfectly secure โ we encourage you to use a strong, unique password.
Poetic Goblin is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided personal information, we will delete their account and associated data promptly. If you believe a child under 13 has created an account, please contact us.
We may update this Privacy Policy from time to time. If we make material changes, we will notify users through an announcement on the Platform. The "Last updated" date at the top of this page indicates when this policy was last revised.
Questions about your privacy? Contact us at poeticgoblin@gmail.com.