Legal documents

Privacy Policy

Effective date: 2026-08-16 · Last updated: 2026-08-16 · Version: 2.1.0

1. Who handles your data

Romergo is operated by Roman Beganov as an individual under the Romergo brand, without a separately incorporated or registered business entity. Contact [email protected] for privacy matters. This policy describes current product handling and does not claim compliance with every law in every country.

2. Data we collect

Account data

Authentication identifiers, email address, display name, avatar reference, language, role, plan, account timestamps, and legal acceptance records. Authentication is provided through Clerk, which may process authentication and security data under its own terms.

Projects and user content

Quest titles, descriptions, chapters, scenes, choices, comments, reviews, access settings, uploaded files, derived media, publication snapshots, and confirmation records. Avoid uploading unnecessary personal or sensitive information.

Technical and usage data

Request timestamps, route and feature events, session and pseudonymous identifiers, browser or device class, locale, error information, rate-limit and security signals, and operational logs. Romergo does not intentionally retain full authentication tokens or email bodies in analytics logs.

Communications and requests

Messages sent to support, legal, privacy, copyright, or security addresses; account deletion requests; and the information needed to verify and resolve them.

Payments

Romergo does not currently operate paid checkout or collect payment details. A paid-plan request stores the requested plan, the optional message, the requesting account, status, and timestamps so the request can be reviewed. Before a payment provider is enabled, this policy will be updated to identify that provider and the payment data shared with Romergo. Romergo does not currently receive or store full card numbers or card security codes.

3. Why we use data

We use data to provide accounts and collaboration, store and publish quests, secure and troubleshoot the service, prevent abuse, communicate transactional events, enforce policies, process requests, maintain audit evidence, understand product performance, and comply with valid legal obligations.

Depending on the user, activity, and location, processing may be needed to provide the service requested by the user, protect accounts and the platform, apply the user’s consent choice, or respond to a valid legal obligation. This policy does not make a country-specific legal-basis determination.

5. Storage technologies and analytics

Romergo uses browser cookies or storage necessary for authentication, language, security, and application state. First-party local and session storage is also used for pseudonymous product analytics and attribution. See the Cookie Policy for the current audited categories and controls.

6. Sharing and processors

The current code and infrastructure audit identified only these service providers that process Romergo account, content, or operational data:

ProviderCurrent purpose
CloudflarePages and Workers hosting, D1 database, R2 object storage, KV, Queues, Durable Objects, analytics infrastructure, Email Routing, and transactional email delivery
ClerkAuthentication, account identity, and session security

Vercel, Neon, Cloudinary, and OpenAI were not found in the current production application path and are not listed as subprocessors. A new provider must be added here before it is enabled to process user data. We may also disclose information when required by a valid legal request or when reasonably necessary to protect users and the service.

7. International transfers

Cloudflare and Clerk may process data in countries other than the user’s location according to their own service terms and infrastructure arrangements. This statement is not a legal conclusion about an international-transfer mechanism.

8. Retention

Account and active project data is kept while needed to provide the service. The following are recommended operating targets, not claims that automated deletion already enforces them:

These are operating targets rather than legal guarantees, and some deletion steps are currently performed manually. Active disputes, security investigations, shared ownership, or valid legal obligations may require a documented exception.

9. Security

Romergo uses access controls, authenticated routes, scoped roles, encryption provided by infrastructure, rate limits, restricted secrets, and audit logging. No system is completely secure. Report suspected vulnerabilities to [email protected] and do not include unnecessary sensitive data in the first message.

10. Your choices and rights

Depending on applicable law, you may request access, correction, export, deletion, restriction, objection, or withdrawal of consent. Requests can be made from account settings where available or by following the Data Requests guide. We may verify identity and may lawfully refuse or limit a request.

11. Export and deletion

Authenticated users can download an account-data export and submit a deletion request from profile settings. Deletion is not instantaneous: ownership is verified and applicable retention, security, public-content, and backup rules are reviewed before completion.

12. Children

Romergo currently has no platform-wide age restriction. The service does not currently perform age or identity-document verification. If you believe a child’s data was submitted without appropriate authority, contact [email protected].

13. Changes

The version, effective date, and last-updated date appear above. Material changes will be communicated through an appropriate product notice or renewed acceptance where required.

14. Contact