Ink & Echo ("we", "us") is an online collaborative storytelling game. This policy explains what personal data we collect, why, how long we keep it, and the rights you have over it under the EU/UK General Data Protection Regulation (GDPR).
Questions or requests about your data can be sent to support@inkecho.world.
You can create an account with an email address and password, or by signing in with Google or Apple. If you use Google or Apple sign-in, the provider confirms who you are and shares a limited set of profile information with us — typically your name and email address (Apple can relay a private forwarding address if you choose to hide your email).
We store your email address, display name, an optional avatar, and your preferences such as theme and language. If you set a password, we store it only as a salted hash — we never see it. We use this data to provide your account and sign you in. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)). It is kept until you delete your account.
We also keep a record of when you sign in — the date and time, and which method you used (password, Google or Apple). We use it to keep accounts secure, to investigate suspicious activity, and to understand how much the game is being used. These records are kept for 365 days and are deleted with your account. Legal basis: our legitimate interest in running a secure service and in knowing how our own service is used (Art. 6(1)(f)). This is basic account activity rather than the optional analytics described in section 4, so it is not covered by the analytics tick box.
Playing as a guest (“Play now”): you can try a story without creating an account. To do that we create a temporary, anonymous sign-in that holds no email address, name or password — only a random identifier — and lives in your browser tab; it ends when you close the tab. The story you play is held under that identifier so that you can keep it by creating an account, in which case it becomes your account data as described above. A guest sign-in that is not kept is deleted, with its story, within seven days. Legal basis: performance of the service you asked for (Art. 6(1)(b)).
Playing the game necessarily creates records: your campaigns, characters, the actions and messages you submit during play, AI-generated story responses to your inputs, image-generation requests, and credit transactions. We process this data because the game cannot function without it. Legal basis: performance of our contract with you (Art. 6(1)(b)). Operational logs used for debugging and abuse prevention (such as AI request logs and game event records, which may include your IP address and browser user agent) are processed under our legitimate interest in running a secure, working service (Art. 6(1)(f)).
Retention of AI request logs: we keep logs of the requests sent to our AI generation providers for debugging, cost control, abuse prevention, and to establish or defend legal claims. Their content (the submitted text and generated output) is automatically redacted after 180 days, and the log records are deleted in full after 365 days. Because we rely on these logs for the reasons above, they are retained — in redacted form — even after you delete your account. Legal basis: our legitimate interest in running a secure service and establishing or defending legal claims (Art. 6(1)(f)).
Safety retention of messages: if you delete an adventure, or delete your account, the messages written during play (including chats with characters) are not immediately erased. We keep them — unlinked from the deleted adventure or account — for up to 12 months from when they were written, solely so we can investigate reports of abuse or unlawful content and comply with legal obligations, after which they are permanently deleted. For the same reason, when you delete your account we keep a minimal record of your account identity (user id and email address) so retained messages can still be attributed if an investigation requires it. Legal basis: our legitimate interest in keeping the service safe and establishing or defending legal claims (Art. 6(1)(f)), and compliance with legal obligations (Art. 6(1)(c)).
Shared adventures continue without you: adventures are collaborative, so deleting your account does not delete adventures that other players are still part of — your seat is marked as away and your ownership link is removed. An adventure with no remaining players is deleted automatically.
We collect a small amount of usage data to understand how the game performs and where it breaks. There are two tiers:
Anonymous (always on): a random session identifier not linked to your account, device type (desktop/mobile/tablet), operating system and browser family, app version, language, viewport size, the page you were on, country (derived from your IP address at our edge server — the IP itself is never stored or shared), page-load performance timings, and error reports (message and stack trace).
Linked to your account (only with your consent): the same data, plus your account identifier, which lets us connect your device, browser, location and performance data to your account. You give or refuse this consent with the optional tick box at sign-up, and you can change it at any time in App Settings → Privacy. It is off by default.
To be clear about what this tick box does and does not cover: it governs the analytics data described above. It does not switch off the basic records the game needs to run and to stay secure — your sign-in history (section 2) and your gameplay records (section 3), which include how many rounds you have played and when. Those are kept for every account. Declining analytics means we cannot see your device, browser, location or performance data, and we do not load any third-party analytics for you.
When we advertise Ink & Echo (for example on Reddit), we want to know whether those adverts actually work. To do this we record, on our own servers, how visitors arrive:
the page you landed on and the site that referred you (the referring site’s address only, never the full page you came from);
campaign labels in the link you clicked (the industry-standard “utm” parameters) and, if you arrived from an advert, the click identifier the advertising platform added to the link;
a random identifier we create and keep in your browser’s local storage — it is not a cookie, contains nothing about you, and is never shared with anyone else. If you later create an account, we link that identifier’s landing records to your account so we know which channel brought you to us;
your browser and device type, and a one-way code made from your network address combined with the type of device you are using. The code changes every day and cannot be turned back into the address, which we do not store. It lets us tell one visit from the next when the same person arrives twice in quick succession (for example from an app’s built-in browser and then their normal browser) and keep automated traffic out of our figures.
Legal basis: our legitimate interest in measuring our own marketing (Art. 6(1)(f)). You can object at any time: turning the analytics toggle off in App Settings → Privacy stops this recording on your device, or contact us (section 1). Landing records linked to your account are unlinked when you delete your account.
Separately — and only if you gave consent with the tick box at sign-up (Art. 6(1)(a)) — we confirm a completed sign-up to the advertising platform whose advert brought you here, so it knows the advert worked. That confirmation contains the platform’s own click identifier and a one-way scrambled (SHA-256 hashed) version of your email address; we never send your actual email address, and we send nothing at all without your consent, which you can withdraw at any time in App Settings → Privacy.
Raw telemetry (sessions, events, performance samples, error reports) is automatically deleted after 90 days. We may keep aggregate statistics (for example, daily session counts per country) indefinitely; these contain no identifiers and cannot be traced back to you.
We keep cookies to a minimum. Essential cookies set by our authentication provider keep you signed in and secure. We also store a few preferences and short-lived caches in your browser to make the app work and feel faster. We do not use advertising or third-party cross-site tracking cookies. Our Cookie & Storage Policy explains this in full, including how to manage cookies in your browser.
We use a small number of trusted service providers to run Ink & Echo, and share with each only the data it needs. We describe them here by the function they perform for us:
Cloud hosting, database & storage (European Economic Area) — stores your account and game data.
Application hosting & content delivery — serves the website and app to your device.
Payment processing — handles credit and membership purchases; your card details go directly to the payment provider, and we receive only a customer reference and your purchase history.
Transactional email — sends account emails such as sign-up confirmation and password resets (receives your email address).
Sign-in providers (Google, Apple) — only if you choose them, to confirm your identity.
AI generation providers — turn the text you submit during play into story text, images, music, and spoken audio; they receive that gameplay text (in live in-character chats this includes your display name) but not your password or payment details.
Product analytics & error monitoring — only if you opt in (see "Usage analytics" above).
Advertising platforms (conversion measurement) — only with your consent, and only to confirm that a sign-up followed one of their adverts (see "How we measure our marketing" above); they receive their own click identifier and a hashed version of your email address, never the raw address.
We will name the specific recipients of your data, and tell you their purpose and location, on request.
Our core hosting, database, and storage are located in the European Economic Area (EEA). Some of the other providers above — including AI generation, payment processing, transactional email, sign-in, and application hosting/analytics providers — process data in the United States or in other countries outside the UK and the EEA.
Where the destination country is covered by a UK "adequacy" decision, we rely on that decision. Where it is not, we put appropriate safeguards in place — the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU standard contractual clauses — so that your data receives an equivalent level of protection. You can ask us for a copy of the safeguard that applies to a particular transfer.
We do not sell your data, and we do not embed third-party advertising or tracking services in the app. If you arrived from one of our adverts and gave consent, we confirm your sign-up to that advertising platform server-to-server (section 5) — never with your raw email address. No IP address is sent to any third-party lookup service, and we do not use your geolocation beyond country level.
Under the GDPR you can ask us at any time to:
Access a copy of the personal data we hold about you (Art. 15)
Correct inaccurate data (Art. 16)
Delete your data ("right to be forgotten", Art. 17) — deleting your account erases your account data and all telemetry linked to it. In-game messages are retained unlinked for up to 12 months for safety and legal reasons, AI request logs are retained in redacted form (both explained in section 3), and financial transaction records are kept as required by law
Restrict or object to processing based on legitimate interest (Arts. 18, 21)
Receive your data in a portable format (Art. 20)
Withdraw telemetry and marketing-measurement consent at any time in App Settings → Privacy, with effect from that moment (Art. 7(3))
If you are in the United States, including California, you have the right to know what personal information we collect and why, to access or delete it, and to opt out of any sale or sharing of your personal information. We do not sell your personal information, and we do not use it for cross-context behavioural advertising. The only disclosure to an advertising platform is the consent-gated sign-up confirmation described in section 5, which you can switch off at any time in App Settings → Privacy. To exercise any of these rights, contact us at the address in section 1, and we will not discriminate against you for doing so.
Ink & Echo is intended for adults. You must be at least 18 to use it, as set out in our Terms of Service. We do not knowingly collect personal data from anyone under 18; if you believe someone under 18 has given us their data, contact us and we will delete it.
If you believe we have mishandled your data, please contact us first at support@inkecho.world. You also have the right to lodge a complaint with your local data protection supervisory authority.
If we materially change what we collect or why, we will update this page and the "last updated" date above, and — where the change requires it — ask for your consent again.