Privacy Policy
Last updated: 17 giugno 2026 — v1.3
This notice describes how Narrantium SRLS processes the personal data of users of narrantium.com, in compliance with EU Regulation 2016/679 (GDPR), Italian Legislative Decree 196/2003 (Italian Privacy Code) and the rulings of the Italian Data Protection Authority (Garante).
1. Data Controller
Playgrown S.r.l.s. (marchio commerciale: Narrantium)
Sede legale: Via Volturno 5, 20900 Monza (MB) — Italia
C.F. e P.IVA: 14762340967 — REA: MB-2805883
PEC: narrantium@legalmail.it
Email contatto privacy: info@narrantium.com
No formal DPO has been appointed: for any request concerning personal data please write to the privacy contact email indicated above.
2. What data we collect
- Account data: email, nickname, nome, cognome, paese, telefono (opzionale), data di nascita, avatar, bio.
- Billing data: ragione sociale, codice fiscale, P.IVA, indirizzo, PEC, SDI. Richiesti solo per l'acquisto di Quest a pagamento.
- User content: Quest, scene, mappe, personaggi e media che crei o carichi sulla piattaforma.
- Game session data: nickname, lanci di dadi, note, schede personaggio — esclusivamente all'interno delle tue sessioni private.
- Payment data: elaborati da Stripe (vedi sezione Destinatari). Narrantium non memorizza in alcun modo i dati della carta.
- Technical data: indirizzo IP (anonimizzato per analytics), tipo di browser e dispositivo, pagine visitate. Solo previo consenso per finalità di analisi.
- Consent log: registriamo le tue scelte sui cookie e l'accettazione di Privacy/Termini come prova legale (GDPR Art. 7).
- Subscription plan: codice del piano attivo (free, basic, pro, ecc.), stato (attivo/sospeso/annullato), data di inizio e di scadenza. Necessari per erogare le funzionalità incluse nel tuo piano.
- AI credits wallet (NC): saldo dei crediti narrativi (NC) e storico transazioni (top-up, addebiti per generazioni AI, bonus, rimborsi). I crediti NC sono un credito interno alla piattaforma, non rimborsabile e non convertibile in denaro.
- AI prompts and generated content: testi e parametri inviati alle funzionalità di generazione AI (es. Auto-Eroe, Auto-Nemico, traduzioni). I prompt vengono trasmessi a sub-processor AI (vedi sezione Destinatari) per il tempo strettamente necessario alla generazione e non vengono utilizzati per addestrare modelli.
3. Why we process your data (legal bases)
- Performance of a contract (Art. 6.1.b): creazione e gestione account, accesso ai contenuti, sessioni di gioco, acquisti.
- Legal obligation (Art. 6.1.c): fatturazione, registri fiscali, conservazione documenti contabili.
- Consent (Art. 6.1.a): cookie di analisi, cookie di marketing, comunicazioni commerciali via email.
- Legitimate interest (Art. 6.1.f): sicurezza della piattaforma, prevenzione frodi, miglioramento del servizio.
4. Recipients and data processors
Your data may be processed by the following parties acting as data processors (Art. 28 GDPR), each bound by contract and DPA:
- Lovable / Supabase — hosting, database, autenticazione, storage. Server in UE.
- Stripe Payments Europe Ltd. (Irlanda) e Stripe Inc. (USA) — elaborazione pagamenti per abbonamenti, acquisto Quest, top-up del wallet NC e payout creator (Stripe Connect). Trasferimento extra-UE garantito da Standard Contractual Clauses.
- Lovable AI Gateway — instradamento delle richieste di generazione AI verso i modelli sottostanti: modelli di testo (Google Gemini) e modelli di generazione immagini (Google Gemini Image / Imagen, OpenAI GPT-Image, Flux). I prompt sono trasmessi per il tempo strettamente necessario alla generazione e non vengono usati per addestrare modelli. Trasferimento extra-UE garantito da SCC.
- Google Ireland Ltd. — Google Analytics 4, Google Search Console, Google Tag Manager, Google Fonts. Solo con consenso analytics. Trasferimento extra-UE garantito da SCC.
- Meta Platforms Ireland Ltd. — Meta Pixel (Facebook/Instagram). Solo con consenso marketing.
- Provider email transazionali (Resend / Supabase Auth) — invio email di conferma e recupero password.
We do not sell or transfer your personal data to third parties for commercial purposes.
5. Transfers outside the EU
Some providers (Stripe, Google, Meta) may process data in the United States. Such transfers are protected by Standard Contractual Clauses (SCC) approved by the European Commission and, where applicable, by adherence to the EU-US Data Privacy Framework.
6. Retention
- Account data: for the entire duration of the account, plus 24 months after deletion (to handle potential disputes).
- Billing and tax data: 10 years (legal obligation — art. 2220 Italian Civil Code).
- NC wallet transactions (top-ups, charges, bonuses, refunds): 10 years for tax obligations; the remaining balance is zeroed when the account is deleted and is non-refundable.
- AI generation prompts and outputs: they are not kept beyond the time needed for generation and any saving to your account (created heroes/enemies). They are not used to train models.
- Game sessions and Quests: until deletion by the user.
- Cookie consent log: 24 months.
- Technical and security logs: 12 months.
7. Minors
The service is intended for users aged 14 or over (threshold set by art. 2-quinquies of the Italian Privacy Code for information society services). Minors between 14 and 18 years of age must obtain consent from the person exercising parental responsibility before registering. Registration of persons under 14 is prohibited: if we become aware of accounts held by minors under 14, we will delete them immediately.
8. Your rights (GDPR Art. 15–22)
You have the right to access your data, rectify it, erase it, restrict its processing, object to processing and receive your data in a structured format (portability). To exercise these rights write to: info@narrantium.com. We will respond within 30 days.
You can delete your account directly from the profile settings or request its deletion by email. Deletion entails the removal of personal data; publicly published content (public Quests) is anonymised to preserve the experience of other users.
You also have the right to lodge a complaint with the Italian Data Protection Authority: garanteprivacy.it.
9. Cookies
For the full list of cookies used and to manage preferences, see the Cookie Policy.
10. Security
Data is encrypted in transit (HTTPS/TLS 1.2+) and at rest. Database access is governed by Row-Level Security policies that prevent any user from accessing other users' data. We perform periodic backups and follow incident management procedures consistent with Art. 33 GDPR.
11. Changes
We may update this notice: any material change will be notified by email to registered users and via in-app notice. The last update date at the top always reflects the current version.