Valdris
Terms Privacy ← Back

Privacy Policy

Valdris is operated by Eynhallo LLC.  ·  Last updated: August 6, 2026

This Privacy Policy explains how Eynhallo LLC (“Eynhallo,” “we,” “us,” “our”), a limited liability company organized under the laws of the State of Tennessee, United States, collects, uses, shares, and protects personal information when you use Valdris — our subscription, browser-based, AI-narrated role-playing game and the related website, application, and services (together, the “Service”), available at playvaldris.com, play.eynhallo.com, and related domains.

This Policy is part of, and should be read together with, our Terms of Service. Capitalised terms not defined here have the meaning given in the Terms. By using the Service, you acknowledge the practices described in this Policy.

In short: we collect what we need to run the game, keep your saves, sign you in, and take payment. To generate the story, your inputs and game context are sent to our AI provider to produce the next passage. We do not sell your personal information, we do not show you third-party advertising, and we do not use your Player Inputs or game content to train our own AI models.

Contents

  1. Who we are & scope
  2. Age — the Service is for adults (18+)
  3. Information we collect
  4. How we use your information
  5. Your inputs and the AI provider
  6. How we share information (service providers)
  7. No sale of data, no ad tracking, no model training
  8. Cookies & similar technologies
  9. Data retention
  10. Deleting your data & your choices
  11. Security
  12. International data transfers
  13. Your rights (EEA, UK & Switzerland / GDPR)
  14. Your rights (California / CCPA & CPRA)
  15. Children’s privacy
  16. Changes to this Policy
  17. Contact us

1. Who we are & scope

Eynhallo LLC is the controller responsible for personal information processed through the Service. This Policy covers information we handle when you visit playvaldris.com or play.eynhallo.com, create an account, and play Valdris. It does not cover the independent practices of the third-party providers we rely on (our AI provider, Clerk, and Stripe), each of which processes some information under its own privacy policy; we identify those providers in Section 6.

2. Age — the Service is for adults (18+)

The Service is intended for adults aged 18 or older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you are under 18, please do not use the Service or provide us with any information. If you believe a person under 18 has given us personal information, contact us at hello@eynhallo.com and we will delete it. See also Section 15.

3. Information we collect

3.1 Account & identity information (via Clerk)

Sign-in and account management are handled by our authentication provider, Clerk. When you register or sign in, Clerk collects and holds your email address, any name you provide, your sign-in method, and authentication credentials, and issues your session. Our own systems receive and store a Clerk-issued user identifier (an opaque account ID) and use it to create a profile that links your saved games and activity to your account. We do not receive or store your password.

3.2 Payment information (via Stripe)

If you purchase a subscription, payments are processed by Stripe. Stripe collects and processes your payment-card or other payment details and related billing information directly. We do not receive or store full payment-card numbers. Our systems store only limited billing state needed to run your subscription — for example, a Stripe customer identifier, your current plan/tier, and the date your paid period ends.

3.3 Game data (your Player Inputs and the generated story)

To let you play and resume your adventures, we store your game data in our database, including:

  • your Player Inputs — the text and choices you submit during play and during character creation;
  • the AI-generated story (narration, scene text, and NPC dialogue) returned in response;
  • your saved games and checkpoints, including character details you create (such as your character’s name, class, level, and in-game location), world state, and session history; and
  • your exportable Chronicle of your adventure.

This game data is stored keyed to your account so you can save, resume, and revisit your adventures.

3.4 Usage & telemetry

We record technical event data about how the Service is used, so we can operate it, enforce plan limits, and improve it. For each turn you take, we log an event that may include: the input mode (button, typed text, or command); whether the turn involved a dice roll or combat; the number of sentences in the narration; how long the turn took to generate (latency); how long you spent before responding (dwell time); and the number of characters in your input. These per-turn events record the length of your input, not the text of it. We also log events for starting and ending sessions (including session duration and turn counts) and for progressing through character creation. We use some of these events as an internal ledger to enforce plan limits (for example, the number of exchanges included in your plan each month, and reasonable limits on how many new adventures may be started in a month to prevent abuse).

When you send us feedback through the in-app feedback tool, we store the text of your message, the screen you were on, the app version, your account identifier, your browser’s user-agent string, and — if the report is tied to one of your games — your character’s name and current in-game location.

3.5 Technical information

When you use the Service, we and our providers receive standard technical information, including your IP address and your browser user-agent. Your IP address is transmitted with every request and is processed to deliver, route, and secure the Service (including by our hosting, authentication, and payment providers). We capture your user-agent string when you submit feedback (see Section 3.4). We also use cookies and local browser storage as described in Section 8.

3.6 Waitlist (before you have an account)

While Valdris is invite-only, you can ask to be invited by adding your address to the waitlist form on our home page. If you do, we collect your email address and the date you joined, and nothing else. You do not need an account to join, and joining does not create one.

We use it for exactly one thing: to send you an invitation when a place is available, and occasional messages about that invitation. We do not use waitlist addresses for advertising, we do not sell or share them, and we do not add you to a marketing list. Waitlist entries are held by our authentication provider, Clerk (see Section 6), on our behalf.

You can ask us to remove your address at any time by emailing us at the address in Section 17, and we will delete the entry. If you accept an invitation and create an account, your waitlist entry is superseded by your account and is handled under the rest of this Policy.

Please don’t submit sensitive information. Player Inputs and feedback are free-text fields. Please do not enter special-category or sensitive personal information (such as health, precise location, government-ID, or financial details) into the game or the feedback tool. We do not ask for it and do not intend to collect it.

4. How we use your information

We use the information above to:

  • Provide the Service — run the game, generate the story, and save, load, and let you resume your adventures and Chronicle;
  • Authenticate you and maintain your account and sign-in;
  • Process payments, manage your subscription, and enforce plan allowances and limits;
  • Secure the Service and prevent abuse — including verifying account ownership, guarding against fraud and unauthorised or runaway usage, and protecting our users and systems;
  • Provide support and respond to your feedback and requests;
  • Analyse and improve the Service — understand how the game is played and improve gameplay, content, reliability, and performance, generally using aggregated or de-identified data; and
  • Comply with law and enforce our Terms, including responding to lawful requests and establishing, exercising, or defending legal claims.

Legal bases (EEA/UK). Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service and process your subscription); legitimate interests (to secure, debug, analyse, and improve the Service, and to prevent abuse), balanced against your rights; consent (where we ask for it, such as for any non-essential cookies); and compliance with a legal obligation (such as tax and record-keeping duties).

5. Your inputs and the AI provider

Valdris generates its story with a third-party AI model. To produce the next passage, your Player Inputs and relevant game context are transmitted to our AI provider, which processes them to return generated narration. That provider processes this data as our service provider, under its applicable API and privacy terms. We may use more than one AI provider — for different features, or in place of another — and the provider or model may change over time. Whichever we use, the commitments below apply to all of them.

Consistent with our Terms, we do not use the content of your Player Inputs or your game content to train our own generative AI models. AI-generated content is fiction and may be inaccurate or unexpected; how that content is treated is described in the Terms.

Our AI providers do not train on your content either. This is a standing commitment, not a description of one vendor: we only use AI providers on paid terms that contractually prohibit training on customer content, and we will not move to a provider or plan that permits it. Free and consumer tiers of these services generally do allow the provider to train on what you submit; we do not use them, and we pay for the tier that forbids it.

To be precise about what does still happen: providers typically retain prompts and responses for a short period solely to detect and prevent abuse of their service. That is the extent of it. Your stories are not training data — not for us, and not for whoever’s model writes them.

We do not name our AI providers here, because we may use more than one and may change them. The commitment above is what binds us: paid terms that prohibit training on your content, on every provider we use. If you want to know which providers are in use at a given time, ask us at the address in Section 17 and we will tell you.

6. How we share information (service providers)

We do not sell your personal information (see Section 7). We share information only as described here:

Service providers / sub-processors. We rely on a small set of trusted providers who process personal information on our behalf, under contract and only to provide their service to us:

ProviderRoleInformation it processes
AI provider(s) Generates the AI narration Your Player Inputs and relevant game context, sent to produce the next passage
Clerk Authentication & account management Email, name, sign-in method, credentials, session data, IP address
Stripe Payment processing Payment-card / payment details, billing information, IP address
Railway Cloud hosting & database Data processed and stored to run the Service (in transit and at rest)

Legal, safety & business transfers. We may disclose information if we reasonably believe it is necessary to comply with a law, legal process, or lawful government request; to enforce our Terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Eynhallo, our users, or the public. If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

Each provider processes personal information under its own privacy policy. We do not authorise our service providers to use your personal information for their own independent marketing.

7. No sale of data, no ad tracking, no model training

  • We do not sell your personal information, and we do not “share” it for cross-context behavioural advertising, as those terms are used under California law.
  • We do not display third-party advertising in the Service, and we do not use third-party advertising or analytics trackers. Our usage telemetry (Section 3.4) is recorded in our own database for our own operational and product analytics — it is not sent to any third-party advertising or analytics network.
  • We do not use your Player Inputs or game content to train our own AI models (see Section 5).

8. Cookies & similar technologies

We use only the cookies and browser storage needed to make the Service work:

  • Authentication cookies (Clerk). Our authentication provider sets strictly necessary cookies to keep you signed in and to secure your session. Without these you cannot stay logged in.
  • Local browser storage (first-party). We store small interface preferences in your browser’s local storage — such as your chosen theme (light/dark) and text size — so the reading surface remembers your settings. This stays on your device and is not used to track you.

No advertising or cross-site tracking cookies. We do not use advertising cookies or third-party tracking cookies. We also self-host our web fonts rather than loading them from a font CDN, so simply viewing a page does not transmit your IP address to a font provider.

9. Data retention

We keep personal information for as long as we need it for the purposes in this Policy:

  • Account, game saves, Chronicle, and telemetry are retained while your account is active, so you can resume your adventures, and are deleted when you delete your account or the relevant game (see Section 10), except where we must keep limited records to comply with legal, tax, accounting, or security obligations or to resolve disputes.
  • Billing records may be retained by us and by Stripe for the periods required by law.
  • Waitlist entries are kept until you are invited and create an account, until you ask us to remove yours, or until we close the waitlist — whichever comes first. If we close it without inviting you, we delete the remaining entries.

Our service providers (our AI provider, Clerk, Stripe, Railway) retain data under their own policies and retention schedules.

10. Deleting your data & your choices

You are in control of your game data:

  • Delete a single game. You can delete an individual adventure/save from within the Service.
  • Delete your account. You can delete your account and all associated data at any time from the account menu. Deleting your account permanently removes your profile, all of your saved games and checkpoints, and your associated usage/telemetry and feedback events from our database. This action cannot be undone.

Deleting your account here removes your data from our systems. Information held by Clerk (your login) and Stripe (billing) is governed by their retention obligations; you can also contact us at hello@eynhallo.com for help with a deletion request across providers.

11. Security

We use reasonable technical and organisational measures designed to protect personal information, including:

  • Encryption in transit (HTTPS/TLS) for data moving between your browser, our Service, and our providers;
  • Access controls — every non-public request must be authenticated, and access to your saved games, telemetry, and feedback is restricted to your own account through per-record ownership checks;
  • Verified sessions and payments — sign-in tokens are cryptographically verified, and payment webhooks are signature-verified; and
  • Data minimisation — for example, we do not store full payment-card numbers.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your sign-in credentials confidential.

12. International data transfers

Eynhallo is based in the United States, and our service providers process personal information in the United States and potentially other countries. If you access the Service from the European Economic Area (EEA), the United Kingdom, Switzerland, or elsewhere outside the United States, your personal information will be transferred to and processed in the United States, which may not provide the same level of data-protection law as your home country. Where required, we rely on appropriate safeguards for such transfers — such as the European Commission’s Standard Contractual Clauses (and the UK Addendum / IDTA) — and you may contact us for more information.

13. Your rights (EEA, UK & Switzerland / GDPR)

If the GDPR or UK GDPR applies to you, you have the right to:

  • Access the personal information we hold about you;
  • Rectify inaccurate or incomplete information;
  • Erase your information (“right to be forgotten”);
  • Restrict or object to certain processing, including processing based on our legitimate interests;
  • Data portability — receive your information in a portable format;
  • Withdraw consent at any time, where we rely on consent (without affecting processing already carried out); and
  • Lodge a complaint with your local data-protection supervisory authority.

To exercise these rights, email hello@eynhallo.com. We may need to verify your identity before acting on a request. We will not discriminate against you for exercising your rights.

14. Your rights (California / CCPA & CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose;
  • Delete personal information we hold about you;
  • Correct inaccurate personal information;
  • Opt out of the sale or sharing of personal information — note that we do not sell or share your personal information, so there is nothing to opt out of;
  • Limit the use of sensitive personal information — we do not intend to collect sensitive personal information or use it for purposes that require this option; and
  • Non-discrimination — we will not discriminate against you for exercising your rights.

In the preceding 12 months we have collected the categories of personal information described in Section 3 (identifiers, account and payment-related information, internet/usage activity, and the content you create in the game), for the purposes in Section 4, and disclosed it to the service providers in Section 6. We have not sold or shared personal information. To exercise your rights, email hello@eynhallo.com; you may use an authorised agent, and we will verify requests as permitted by law.

15. Children’s privacy

The Service is for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete it. If you are a parent or guardian and believe a minor has provided us with information, contact us at hello@eynhallo.com.

16. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will update the “Last updated” date above and provide reasonable notice (for example, by email or in-app notice) before the changes take effect, where required. Your continued use of the Service after the effective date constitutes acknowledgement of the updated Policy.

17. Contact us

If you have questions about this Policy or how we handle your personal information, or to exercise your rights, contact us:

Eynhallo LLC
Contact: hello@eynhallo.com

← Back to Valdris