Privacy Policy
Effective date: 31 May 2026 · Operated by Leonardo Freccero · leonardofreccero@gmail.com
branchtale is a non-profit experiment — no advertising, no data brokerage, no venture funding. This policy explains honestly what data the site collects, why, and what you can do about it.
1. Who we are
branchtale is a non-profit, non-commercial platform for collaborative branching stories. It is operated by a single individual (Leonardo Freccero) as a personal project. The site is open to the public and runs entirely on free-tier infrastructure.
For GDPR purposes, Leonardo Freccero is the data controller. Contact: leonardofreccero@gmail.com.
2. Data we collect and why
We only collect data that is necessary to make the site work or to understand how it is used at an aggregate level.
Account data (signed-in users only)
- Email address — received from Google when you sign in. Displayed back to you in the site header; not shown to other users.
- User identifier — an opaque UUID assigned by Supabase. Used as a foreign key to associate your contributions with your account. Publicly visible in profile URLs (e.g.
/profile/abc123…) but not linked to your name or email. - Google may also send your display name and profile picture URL. These are stored by Supabase in your auth record but are not currently used or displayed by the site.
Legal basis (GDPR): performance of a contract — this data is required to provide you with an account and to attribute your contributions.
Content you create
- Chapters and branch proposals — text you write or prompt an AI to generate, linked to your account. Publicly readable by all visitors.
- Abuse reports — the reason text you enter and the chapter you flag. Visible to site administrators only.
Legal basis: performance of a contract; legitimate interest in maintaining a safe platform for moderation purposes.
Reading history
When you read a story, we record the ordered sequence of chapters you visit (a list of chapter IDs) in a reading session row server-side. This is linked to the opaque rsid cookie — not to your name or email. If you are signed in, the session is also associated with your user ID so objective and quest state survives across devices.
Legal basis: legitimate interest — this data is the mechanism that tracks which story objectives are open on your specific path through a branching narrative. It is not used for advertising or profiling.
Anonymous usage analytics
We use Umami to collect aggregate page-view statistics. Umami is designed to be privacy-first:
- It sets no cookies.
- It collects no personally identifiable information — no IP address, no user ID, no email.
- It records: the page URL, your browser language, approximate device type, and referring URL. All data is aggregated and anonymised before storage.
- We also track a handful of named interaction events — e.g. “Start reading” clicks, signing in and out, which path you pick in a chapter, proposing a branch, creating a story, requesting an image regeneration, reporting a chapter, and editing a chapter.
- These are counts, occasionally tagged with a small non-identifying label — for example the story mode (linear / free-form / quest), the position of the option you chose (1st, 2nd…), or whether a proposal came from a suggestion chip or was typed. We never attach your identity, and we never send the text you type (story titles, proposed options, report messages).
Legal basis: legitimate interest — anonymous aggregate statistics help us understand which features are useful and which stories people enjoy. No consent is required for cookieless, non-identifying analytics under GDPR and the ePrivacy Directive.
AI-generated content
When you propose a new story branch, the text of the parent chapter (written by another user or by a previous AI pass) is sent to a locally-running AI model to generate the next chapter. Your branch proposal label is included as context. This processing happens on hardware we control; no data is sent to an external AI API. We log a hash of each prompt and its token count for cost-tracking purposes — the plaintext of the prompt is not stored in our logs.
3. Cookies
branchtale uses only strictly necessary cookies — cookies that are required for the site to function. We do not use advertising cookies, tracking cookies, or third-party analytics cookies. Because all cookies we set are strictly necessary, no cookie consent banner is required under the ePrivacy Directive or GDPR.
| Cookie | Purpose | Duration | Essential? |
|---|
| sb-* | Supabase authentication — stores your signed-in session so you stay logged in across page loads. Two tokens: a short-lived access token and a long-lived refresh token. | Access token: ~1 hour. Refresh token: up to 1 year. | Yes |
| theme | Remembers whether you chose dark or light mode. Read server-side so the correct theme renders before the page paints (avoids a flash). | 1 year. | Yes |
| rsid | Reading session — a random opaque ID that links the chapters you visit within a story into an ordered path. Used to show you the correct objectives and quest state as you navigate branching stories. No name, email, or device fingerprint is stored in this cookie. | 1 year. | Yes |
You can delete these cookies at any time in your browser settings. Deleting the auth cookies will sign you out. Deleting rsid will reset your reading progress tracking for branching stories.
4. Third-party services
The following sub-processors handle data on our behalf. Each operates under its own privacy policy.
- Supabase (privacy policy) — authentication, database, and real-time updates. Data is stored in the EU. Supabase manages the
auth.users table including your email and OAuth tokens. - Cloudflare R2 (privacy policy) — stores generated chapter background images and character sprites. Images are publicly accessible via URL; no user identity is embedded in image URLs. Cloudflare may log access requests as part of its standard infrastructure operations.
- Umami Cloud (privacy policy) — anonymous page-view analytics. No cookies, no personal data. See §2 above.
- Google OAuth (privacy policy) — used only as a sign-in provider. When you click “Sign in”, your browser connects to Google and you go through Google's consent flow. We receive your email address and an opaque user token; we do not receive your Google password or full Google account data.
- Vercel (privacy policy) — hosts the web application. Vercel may log request metadata (IP address, timestamp, URL) as part of standard server operation. We do not access or export these logs.
5. Data retention
We do not have automated data-deletion schedules at this time. Practically:
- Account and auth data — retained for as long as your Supabase account exists. You can request deletion (see §6).
- Chapters and contributions — retained indefinitely as public content of the platform. If you delete your account, the
created_by field on your contributions is set to null; the content itself remains unless you also request its removal. - Reading history — retained until you request deletion or reset the
rsid cookie in your browser. - Abuse reports — retained for moderation purposes until reviewed and closed.
- Anonymous analytics — retained by Umami per their own policy; we do not control this.
6. Your rights (GDPR)
If you are in the European Economic Area, you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — request deletion of your account and associated personal data. We will delete your Supabase auth record and, on request, your contributions.
- Restriction / objection — ask us to stop processing your data in specific ways.
- Portability — request an export of your data in a machine-readable format.
- Lodge a complaint — you have the right to complain to your national data protection authority.
To exercise any of these rights, email leonardofreccero@gmail.com. We will respond within 30 days. Because this is a solo-operated non-profit, there is no DPO; all requests go directly to the operator.
7. Children
branchtale is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has created an account, please contact us and we will delete it promptly.
8. Changes to this policy
We may update this policy when the site's data practices change — for example, if we add new features that collect new types of data. Material changes will be noted with a new effective date at the top of this page. Continued use of the site after a change constitutes acceptance of the updated policy.
← Back to branchtaleLast updated 31 May 2026