This Privacy Policy explains how Eynhallo LLC (“Eynhallo,” “we,” “us,” “our”), a limited liability company organized under the laws of the State of Tennessee, United States, collects, uses, shares, and protects personal information when you use Valdris — our subscription, browser-based, AI-narrated role-playing game and the related website, application, and services (together, the “Service”), available at playvaldris.com, play.eynhallo.com, and related domains.
This Policy is part of, and should be read together with, our Terms of Service. Capitalised terms not defined here have the meaning given in the Terms. By using the Service, you acknowledge the practices described in this Policy.
Eynhallo LLC is the controller responsible for personal information processed through the Service. This Policy covers information we handle when you visit playvaldris.com or play.eynhallo.com, create an account, and play Valdris. It does not cover the independent practices of the third-party providers we rely on (our AI provider, Clerk, and Stripe), each of which processes some information under its own privacy policy; we identify those providers in Section 6.
The Service is intended for adults aged 18 or older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you are under 18, please do not use the Service or provide us with any information. If you believe a person under 18 has given us personal information, contact us at hello@eynhallo.com and we will delete it. See also Section 15.
Sign-in and account management are handled by our authentication provider, Clerk. When you register or sign in, Clerk collects and holds your email address, any name you provide, your sign-in method, and authentication credentials, and issues your session. Our own systems receive and store a Clerk-issued user identifier (an opaque account ID) and use it to create a profile that links your saved games and activity to your account. We do not receive or store your password.
If you purchase a subscription, payments are processed by Stripe. Stripe collects and processes your payment-card or other payment details and related billing information directly. We do not receive or store full payment-card numbers. Our systems store only limited billing state needed to run your subscription — for example, a Stripe customer identifier, your current plan/tier, and the date your paid period ends.
To let you play and resume your adventures, we store your game data in our database, including:
This game data is stored keyed to your account so you can save, resume, and revisit your adventures.
We record technical event data about how the Service is used, so we can operate it, enforce plan limits, and improve it. For each turn you take, we log an event that may include: the input mode (button, typed text, or command); whether the turn involved a dice roll or combat; the number of sentences in the narration; how long the turn took to generate (latency); how long you spent before responding (dwell time); and the number of characters in your input. These per-turn events record the length of your input, not the text of it. We also log events for starting and ending sessions (including session duration and turn counts) and for progressing through character creation. We use some of these events as an internal ledger to enforce plan limits (for example, the number of exchanges included in your plan each month, and reasonable limits on how many new adventures may be started in a month to prevent abuse).
When you send us feedback through the in-app feedback tool, we store the text of your message, the screen you were on, the app version, your account identifier, your browser’s user-agent string, and — if the report is tied to one of your games — your character’s name and current in-game location.
When you use the Service, we and our providers receive standard technical information, including your IP address and your browser user-agent. Your IP address is transmitted with every request and is processed to deliver, route, and secure the Service (including by our hosting, authentication, and payment providers). We capture your user-agent string when you submit feedback (see Section 3.4). We also use cookies and local browser storage as described in Section 8.
While Valdris is invite-only, you can ask to be invited by adding your address to the waitlist form on our home page. If you do, we collect your email address and the date you joined, and nothing else. You do not need an account to join, and joining does not create one.
We use it for exactly one thing: to send you an invitation when a place is available, and occasional messages about that invitation. We do not use waitlist addresses for advertising, we do not sell or share them, and we do not add you to a marketing list. Waitlist entries are held by our authentication provider, Clerk (see Section 6), on our behalf.
You can ask us to remove your address at any time by emailing us at the address in Section 17, and we will delete the entry. If you accept an invitation and create an account, your waitlist entry is superseded by your account and is handled under the rest of this Policy.
We use the information above to:
Legal bases (EEA/UK). Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service and process your subscription); legitimate interests (to secure, debug, analyse, and improve the Service, and to prevent abuse), balanced against your rights; consent (where we ask for it, such as for any non-essential cookies); and compliance with a legal obligation (such as tax and record-keeping duties).
Valdris generates its story with a third-party AI model. To produce the next passage, your Player Inputs and relevant game context are transmitted to our AI provider, which processes them to return generated narration. That provider processes this data as our service provider, under its applicable API and privacy terms. We may use more than one AI provider — for different features, or in place of another — and the provider or model may change over time. Whichever we use, the commitments below apply to all of them.
Consistent with our Terms, we do not use the content of your Player Inputs or your game content to train our own generative AI models. AI-generated content is fiction and may be inaccurate or unexpected; how that content is treated is described in the Terms.
Our AI providers do not train on your content either. This is a standing commitment, not a description of one vendor: we only use AI providers on paid terms that contractually prohibit training on customer content, and we will not move to a provider or plan that permits it. Free and consumer tiers of these services generally do allow the provider to train on what you submit; we do not use them, and we pay for the tier that forbids it.
To be precise about what does still happen: providers typically retain prompts and responses for a short period solely to detect and prevent abuse of their service. That is the extent of it. Your stories are not training data — not for us, and not for whoever’s model writes them.
We do not name our AI providers here, because we may use more than one and may change them. The commitment above is what binds us: paid terms that prohibit training on your content, on every provider we use. If you want to know which providers are in use at a given time, ask us at the address in Section 17 and we will tell you.
We do not sell your personal information (see Section 7). We share information only as described here:
Service providers / sub-processors. We rely on a small set of trusted providers who process personal information on our behalf, under contract and only to provide their service to us:
| Provider | Role | Information it processes |
|---|---|---|
| AI provider(s) | Generates the AI narration | Your Player Inputs and relevant game context, sent to produce the next passage |
| Clerk | Authentication & account management | Email, name, sign-in method, credentials, session data, IP address |
| Stripe | Payment processing | Payment-card / payment details, billing information, IP address |
| Railway | Cloud hosting & database | Data processed and stored to run the Service (in transit and at rest) |
Legal, safety & business transfers. We may disclose information if we reasonably believe it is necessary to comply with a law, legal process, or lawful government request; to enforce our Terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Eynhallo, our users, or the public. If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
Each provider processes personal information under its own privacy policy. We do not authorise our service providers to use your personal information for their own independent marketing.
We use only the cookies and browser storage needed to make the Service work:
No advertising or cross-site tracking cookies. We do not use advertising cookies or third-party tracking cookies. We also self-host our web fonts rather than loading them from a font CDN, so simply viewing a page does not transmit your IP address to a font provider.
We keep personal information for as long as we need it for the purposes in this Policy:
Our service providers (our AI provider, Clerk, Stripe, Railway) retain data under their own policies and retention schedules.
You are in control of your game data:
Deleting your account here removes your data from our systems. Information held by Clerk (your login) and Stripe (billing) is governed by their retention obligations; you can also contact us at hello@eynhallo.com for help with a deletion request across providers.
We use reasonable technical and organisational measures designed to protect personal information, including:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your sign-in credentials confidential.
Eynhallo is based in the United States, and our service providers process personal information in the United States and potentially other countries. If you access the Service from the European Economic Area (EEA), the United Kingdom, Switzerland, or elsewhere outside the United States, your personal information will be transferred to and processed in the United States, which may not provide the same level of data-protection law as your home country. Where required, we rely on appropriate safeguards for such transfers — such as the European Commission’s Standard Contractual Clauses (and the UK Addendum / IDTA) — and you may contact us for more information.
If the GDPR or UK GDPR applies to you, you have the right to:
To exercise these rights, email hello@eynhallo.com. We may need to verify your identity before acting on a request. We will not discriminate against you for exercising your rights.
If you are a California resident, you have the right to:
In the preceding 12 months we have collected the categories of personal information described in Section 3 (identifiers, account and payment-related information, internet/usage activity, and the content you create in the game), for the purposes in Section 4, and disclosed it to the service providers in Section 6. We have not sold or shared personal information. To exercise your rights, email hello@eynhallo.com; you may use an authorised agent, and we will verify requests as permitted by law.
The Service is for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete it. If you are a parent or guardian and believe a minor has provided us with information, contact us at hello@eynhallo.com.
We may update this Policy from time to time. If we make material changes, we will update the “Last updated” date above and provide reasonable notice (for example, by email or in-app notice) before the changes take effect, where required. Your continued use of the Service after the effective date constitutes acknowledgement of the updated Policy.
If you have questions about this Policy or how we handle your personal information, or to exercise your rights, contact us:
Eynhallo LLC
Contact: hello@eynhallo.com