LEGAL

Privacy Policy

Last updated: May 2026

What We Collect

When you create an account we collect your email address (email/password sign-up) or your Discord username, avatar, and Discord ID (Discord OAuth sign-in). We store the characters and campaigns you create as structured data in our database. Character images you choose to upload are stored on AWS S3 and served via CloudFront. Our hosting providers (Supabase and Vercel) collect standard server logs including IP addresses and request metadata as part of normal platform operation.

We use session cookies to keep you authenticated. These are set by Supabase Auth and are necessary for the service to function. We do not use tracking or advertising cookies.

How We Use It

We use your data solely to operate Realm Codex — to authenticate you, maintain your session, and store and retrieve your characters and campaigns. We do not sell your data, share it with advertisers, or use it for any purpose beyond providing the service.

Data Storage

Your account and content data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure. Character images are stored on AWS S3 and delivered via CloudFront CDN. Row-Level Security (RLS) policies are enforced at the database level — users can only read and write their own data.

Third-Party Services

Realm Codex relies on the following third-party services to operate:

  • Supabase — authentication and database (supabase.com)
  • Discord OAuth — optional login method (discord.com)
  • AWS S3 / CloudFront — character image storage (aws.amazon.com)
  • Vercel — application hosting (vercel.com)
  • Ko-fi — optional donation link displayed in the footer (ko-fi.com). We do not share any user data with Ko-fi.

Data Retention & Deletion

Your data is retained until you request account deletion. To delete your account and all associated data, contact us at the address below. We will process deletion requests within 30 days.

Contact

Questions about this policy? Email us at jeremy.e.roberts@gmail.com.