# Privacy Notice — Draft

**Legal review required. Last updated: 22 August 2026.**

Hexcrawl Studio performs core map creation in the browser without requiring an
account. A user may choose to create a passkey account and explicitly upload a
project for cloud backup, revision history, or a revocable hosted player link.
Projects remain only in browser storage unless the user performs that upload.
Application analytics and production purchasing are not enabled.

Complete project files can contain author information, private GM notes,
undiscovered locations, encounter material, and other campaign data. Player
exports are designed to omit private and undiscovered information, but users
should inspect them before sharing. Downloaded files are outside the
application's control.

The public application and optional API use Cloudflare Pages and D1. Cloudflare
necessarily processes connection, authentication, storage, and security
information under its own policies and the site's account configuration. The
separate education portal uses Cloudflare Access and its configured identity
provider.
Ordinary infrastructure logs may process IP address, user agent, timestamps,
and request metadata; application code must not log project bodies or GM notes.

Users can delete individual local or cloud projects, export cloud account data,
revoke player links, and delete a cloud account through application controls.
Browser site-data controls can remove local data. Deletion may be irreversible,
so export a backup first. Data-controller identity, contact details,
jurisdiction-specific rights, children/guardian terms, and cloud-subprocessor
wording require owner/legal review before commercial launch.
