Privacy Policy
Last updated: June 17, 2026 — v1.3
This notice describes how Playgrown S.r.l.s. (owner of the Narrantium brand and service) processes the personal data of users of narrantium.com, in compliance with EU Regulation 2016/679 (GDPR), Italian Legislative Decree 196/2003 (Italian Privacy Code) and the rulings of the Italian Data Protection Authority (Garante).
1. Data Controller
Playgrown S.r.l.s. (trade name: Narrantium)
Registered office: Via Volturno 5, 20900 Monza (MB) — Italy
Tax code and VAT no.: 14762340967 — REA: MB-2805883
Certified email (PEC): narrantium@legalmail.it
Privacy contact email: info@narrantium.com
No formal DPO has been appointed: for any request concerning personal data please write to the privacy contact email indicated above.
2. What data we collect
- Account data: email, nickname, first name, last name, country, phone (optional), date of birth, avatar, bio.
- Billing data: company name, tax code, VAT number, address, PEC, SDI code. Required only to purchase paid Quests.
- User content: Quests, scenes, maps, characters and media you create or upload to the platform.
- Game session data: nickname, dice rolls, notes, character sheets — only within your private sessions.
- Payment data: processed by Stripe (see the Recipients section). Narrantium never stores card details.
- Technical data: IP address (anonymised for analytics), browser and device type, pages visited. Only with your consent, for analytics purposes.
- Consent log: we record your cookie choices and your acceptance of the Privacy Policy/Terms as legal proof (GDPR Art. 7).
- Subscription plan: code of the active plan (free, basic, pro, etc.), status (active/suspended/cancelled), start and expiry dates. Needed to deliver the features included in your plan.
- AI credits wallet (NC): balance of narrative credits (NC) and transaction history (top-ups, charges for AI generations, bonuses, refunds). NC are an internal platform credit, non-refundable and not convertible into money.
- AI prompts and generated content: texts and parameters sent to the AI generation features (e.g. Auto-Hero, Auto-Enemy, translations). Prompts are transmitted to AI sub-processors (see the Recipients section) only for the time strictly needed for generation and are not used to train models.
3. Why we process your data (legal bases)
- Performance of a contract (Art. 6.1.b): account creation and management, access to content, game sessions, purchases.
- Legal obligation (Art. 6.1.c): invoicing, tax records, retention of accounting documents.
- Consent (Art. 6.1.a): analytics cookies, marketing cookies, commercial emails.
- Legitimate interest (Art. 6.1.f): platform security, fraud prevention, service improvement.
4. Recipients and data processors
Your data may be processed by the following parties acting as data processors (Art. 28 GDPR), each bound by contract and DPA:
- Lovable / Supabase — hosting, database, authentication, storage. Servers in the EU.
- Stripe Payments Europe Ltd. (Ireland) and Stripe Inc. (USA) — payment processing for subscriptions, Quest purchases, NC wallet top-ups and creator payouts (Stripe Connect). Transfers outside the EU are covered by Standard Contractual Clauses.
- Lovable AI Gateway — routing of AI generation requests to the underlying models: text models (Google Gemini) and image generation models (Google Gemini Image / Imagen, OpenAI GPT-Image, Flux). Prompts are transmitted only for the time strictly needed for generation and are not used to train models. Transfers outside the EU are covered by SCC.
- Google Ireland Ltd. — Google Analytics 4, Google Search Console, Google Tag Manager, Google Fonts. Only with analytics consent. Transfers outside the EU are covered by SCC.
- Meta Platforms Ireland Ltd. — Meta Pixel (Facebook/Instagram). Only with marketing consent.
- Transactional email providers (Resend / Supabase Auth) — sending confirmation and password-recovery emails.
We do not sell or transfer your personal data to third parties for commercial purposes.
5. Transfers outside the EU
Some providers (Stripe, Google, Meta) may process data in the United States. Such transfers are protected by Standard Contractual Clauses (SCC) approved by the European Commission and, where applicable, by adherence to the EU-US Data Privacy Framework.
6. Retention
- Account data: for the entire duration of the account, plus 24 months after deletion (to handle potential disputes).
- Billing and tax data: 10 years (legal obligation, art. 2220 Italian Civil Code).
- NC wallet transactions (top-ups, charges, bonuses, refunds): 10 years for tax obligations; the remaining balance is zeroed when the account is deleted and is non-refundable.
- AI generation prompts and outputs: they are not kept beyond the time needed for generation and any saving to your account (created heroes/enemies). They are not used to train models.
- Game sessions and Quests: until deletion by the user.
- Cookie consent log: 24 months.
- Technical and security logs: 12 months.
7. Minors
The service is intended for users aged 14 or over (threshold set by art. 2-quinquies of the Italian Privacy Code for information society services). Minors between 14 and 18 years of age must obtain consent from the person exercising parental responsibility before registering. Registration of persons under 14 is prohibited: if we become aware of accounts held by minors under 14, we will delete them immediately.
8. Your rights (GDPR Art. 15-22)
You have the right to access your data, rectify it, erase it, restrict its processing, object to processing and receive your data in a structured format (portability). To exercise these rights write to: info@narrantium.com. We will respond within 30 days.
You can delete your account directly from the profile settings or request its deletion by email. Deletion entails the removal of personal data; publicly published content (public Quests) is anonymised to preserve the experience of other users.
You also have the right to lodge a complaint with the Italian Data Protection Authority: garanteprivacy.it.
9. Cookies
For the full list of cookies used and to manage preferences, see the Cookie Policy.
10. Security
Data is encrypted in transit (HTTPS/TLS 1.2+) and at rest. Database access is governed by Row-Level Security policies that prevent any user from accessing other users' data. We perform periodic backups and follow incident management procedures consistent with Art. 33 GDPR.
11. Changes
We may update this notice: any material change will be notified by email to registered users and via in-app notice. The last update date at the top always reflects the current version.