Privacy Policy
Last updated: 20 May 2026
This policy explains how Evolve Simulations Pty Ltd(“Evolve”, “we”, “us”) collects, uses, stores and discloses personal information through the Evolve RPG service at evolve-rpg.com(the “Service”).
We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles. If you are in the European Economic Area, the United Kingdom, or California, additional rights are described in the regional sections below.
1. Who we are
The data controller is Evolve Simulations Pty Ltd, a company registered in New South Wales, Australia. Contact us at gamemaster@evolve-rpg.com.
2. What we collect
We collect only what we need to run the Service:
- Account data— email address, username, hashed password (or the Google account identifier if you sign in with Google), display name, and an optional avatar URL.
- Profile data— accessibility preferences, opt-in flags for retention emails, coin balance and transaction history.
- Game content— campaigns, characters, party membership, session transcripts, Director narration, voice transcripts (when voice input is used), session events, recap text, generated scene images, and world-event records you create or that the AI creates on your behalf.
- Real-time presence and voice/video— if you join a live session with WebRTC voice or video enabled, the audio and video streams are sent peer-to-peer between session participants. We do not record or store them on our servers.
- Payments— processed by Stripe. We never see or store your card number. We store the Stripe customer ID, subscription/SKU references, and a record of which coin packs you purchased.
- Technical data— IP address, browser user-agent, request logs, error traces, and similar diagnostic information generated by our hosting and CDN.
- Communications— any email you send us, plus a record of transactional and (if opted in) retention/marketing emails we send you.
3. How we use it
- To create and operate your account and let you log in.
- To run game sessions: persist campaigns, route player turns, generate narration, mint scene images, and broadcast events to other party members.
- To process payments and grant the coins you bought.
- To send transactional emails (signup confirmation, password reset, receipt, invite, recap).
- To send retention or re-engagement emails to dormant users who have opted in. You can opt out at any time via your profile.
- To detect abuse, debug errors, monitor service health, and enforce our Terms of Service.
- To improve the Service through aggregate, de-identified usage analysis.
4. Lawful basis (GDPR)
If you are in the EEA or UK, our lawful bases under Article 6 GDPR are:
- Performance of a contract— for account creation, authentication, game-session operation, and payment processing.
- Legitimate interests— for fraud detection, security logging, service improvement, and aggregate analytics. Where we rely on this basis we have balanced our interests against your rights and freedoms.
- Consent— for retention and re-engagement emails, and for any optional analytics cookies. You can withdraw consent at any time.
- Legal obligation— where we must retain records (e.g. tax or accounting records relating to your purchases).
6. International transfers
We are based in Australia and our sub-processors operate globally (Australia, EU, US, Sweden). Where personal information is transferred outside your country, we rely on appropriate safeguards including the European Commission’s Standard Contractual Clauses, the UK Addendum, and equivalent transfer mechanisms required by the Australian Privacy Principles.
7. AI processing of game content
Evolve RPG is powered by large language models. When you take a turn, the AI Director is sent the recent session context (recent turns, your character sheet, party roster, relevant SRD rules excerpts, world-pulse summary). This data is sent to Microsoft Azure AI Foundry under our enterprise agreement, which prohibits the use of your inputs and outputs to train foundation models.
Generated narration, NPC dialogue, scene images, and recap text are stored against your session so you can read or replay them later. Cross-campaign “world pulse” events are stripped of player identifiers before being read by another campaign’s Director.
8. How long we keep it
- Account data— while your account exists, plus up to 30 days after deletion to handle reversals and audit requests.
- Game content— while your campaigns exist. If you delete a campaign, content is removed from active systems within 30 days and from backups within 90 days.
- Payment and tax records— up to 7 years as required by Australian tax law.
- Logs and diagnostic data— typically 30 days, longer for security-relevant events.
9. Security
We protect personal information with TLS in transit, encryption at rest (AES-256 for database storage), Supabase Row-Level Security policies that enforce per-user data isolation, secrets management for API keys, principle-of-least-privilege service roles, and routine dependency updates. No system is perfectly secure; if we become aware of a personal-data breach affecting you we will notify you in accordance with applicable law (within 72 hours where GDPR applies, in line with the Notifiable Data Breaches scheme under Australian law).
10. Your rights
Subject to your jurisdiction, you have the right to:
- access the personal information we hold about you;
- correct inaccurate or incomplete information;
- delete your account and associated personal information (subject to retention obligations above);
- request a portable copy of your data;
- object to or restrict certain processing, including direct marketing;
- withdraw consent at any time for any processing based on consent;
- lodge a complaint with your local data-protection authority (in Australia, the Office of the Australian Information Commissioner at oaic.gov.au).
To exercise any of these rights, email gamemaster@evolve-rpg.com. We will verify your identity (typically by replying to the email registered to your account) and respond within 30 days, or earlier where required by law.
11. California residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect (described above), the right to delete it, the right to correct inaccuracies, and the right to opt out of any “sale” or “sharing” of personal information as defined in the CCPA. We do not sell or share personal information for cross-context behavioural advertising. We do not process sensitive personal information for purposes that require an opt-out under California Civil Code §1798.121.
California residents may exercise these rights by emailing gamemaster@evolve-rpg.com. We will not discriminate against you for exercising these rights.
12. Children
The Service is not directed at children under 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children below those ages. If you believe a child has provided personal information to us, contact us and we will delete the relevant data.
14. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page shows when. Material changes will be flagged to logged-in users via an in-app notice or email before they take effect.
15. Contact
Privacy enquiries: gamemaster@evolve-rpg.com
Postal: Evolve Simulations Pty Ltd, Sydney, New South Wales, Australia.