Privacy Policy
Last updated: 2026-10-03 · v1.9
Privacy at a glance
Audio removed promptly
Shared by link or Discord
Delete live data
No ad tracking
Your privacy rights
Looking for our copyright policy? Read our Copyright Policy
This Privacy Policy explains what personal data Recap Raven collects, how we use it, and your rights. It forms part of our Terms of Service.
1. Who we are
Recap Raven is a service operated by Agile Outpost (“Agile Outpost”, “we”). We are the controller when we decide how personal data is used for accounts, licensing and billing, website analytics, security, support and improving the Service. For session content submitted and controlled by a game master or account holder, they normally act as controller and instruct us to process that content to provide the Service. We act as controller for our own limited security, administration and non-identifying service-insight purposes. You can reach us through our Discord.
2. What we collect
- Account data: your name, email address and authentication data.
- Session content you provide: the session audio, plus campaign notes, names and spelling-dictionary entries. Audio reaches us in one of two ways — our Discord bot records the session’s voice channel directly (our recommended path), or you give us a recording link or pasted transcript. Audio is processed for transcription and the related Service outputs described here (see Retention below).
- Discord data (when you use our bot): the Discord user IDs and usernames of participants present in the recorded voice channel, the channel/server identifiers, and the in-channel consent announcement record. You may also map a participant’s Discord identity to their player character so the recap reads naturally.
- Discord billing and licence data: minimised entitlement, subscription, product, application, user and server identifiers, subscription periods, status and processing records supplied by Discord. We do not retain the raw Discord billing payload.
- Website billing and payment records: when you choose website billing, Creem collects the buyer, billing and payment details needed to act as merchant of record. Recap Raven receives and retains only protected provider references, the selected product and tier, amount and currency, subscription and licence periods, payment, refund or dispute status, and minimised webhook and request records. We do not receive or store card details or raw webhook payloads.
- Optional character portraits: artwork you choose to attach to a Cast member, plus a player-safe visual description and minimal safety-check metadata derived from it. We do not keep the original upload or its filename: we keep a metadata-stripped, re-encoded copy after it passes the safety check.
- Generated outputs: transcripts, recaps, GM notes, engagement stats and, only when you separately enable the feature, one session illustration for an eligible recap.
- Usage & technical data: limited logs, security events and operational telemetry needed to run, debug and secure the Service. We avoid storing transcript content or secrets in logs.
- Website analytics: our self-hosted, cookie-free Umami service records page paths, the referring domain, approximate location, browser, operating system, device type, screen size and language so we can understand and improve use of the Service. We also collect Core Web Vitals (page loading, responsiveness and visual-stability measurements) and a small set of named interactions: starting Discord sign-up or sign-in and selecting a public pricing tier to install the Discord bot. We do not record general clicks, form contents, keystrokes, the page’s visual contents or session replays. We discard URL fragments and query parameters except for a bounded allow-list of standard UTM campaign attribution fields; advertising click identifiers and other query data are discarded. Password-reset, email-verification, email-change, OAuth and account-link routes are excluded. An unlisted player recap is intended to be viewed by anyone its link is shared with, so its complete
/share/<token>path is recorded and visible to our authorised analytics administrator.
3. How we use it
We use your data to provide and operate the Service — authenticating you, downloading and transcribing your recording, generating recaps and notes, metering fair-use credits, and keeping the Service secure. We also use website analytics solely to understand how the Service is used and improve it. We do not use analytics for advertising, profiling or decisions about individual users. We do not sell your data, and we never use your content to train AI models.
Authorised administrator access. We do not routinely read your session content. An authorised administrator may access your account data and session content, including transcripts, GM notes and recaps, where reasonably necessary to respond to a support request, diagnose or fix a technical issue, investigate suspected abuse or a security incident, or review a specific output to improve Service reliability and quality. We limit access to the purpose and people who need it, and content accessed in this way is never used to train AI models.
Aggregate service insights. We may combine session and Service data to calculate aggregate statistics including, for example, average session length, play-pillar patterns and speaker distribution, and use those statistics to understand, improve, explain and market the Service. We use or publish them only in an aggregated form that is not reasonably capable of identifying or singling out an account, campaign, session, character or participant. We do not use recordings, transcripts, recaps, quotes, individual-session statistics or small-cohort breakdowns in marketing.
When you provide campaign notes (lore) to build your campaign spelling dictionary, those notes are processed by our AI gateway to extract the names, places and terms to spell consistently. They are held only transiently for that purpose and are not stored as campaign content; we keep only the resulting spelling-dictionary entries, which you can edit or delete.
When you upload an optional character portrait, we canonicalise it, check it for prohibited content and ask a visual AI model for a bounded description of visible character appearance. If you later enable automatic session artwork, we may send player-safe recap excerpts and relevant approved portraits to the named AI processors to create one illustration. The artwork feature remains off by default and has its own just-in-time notice.
Automatic attendee delivery. We may automatically deliver session materials, including recaps, transcripts, images and share links, to session attendees through Discord. Depending on campaign settings and Discord capabilities, delivery may use a private thread, the recording channel or another disclosed Discord destination. Content posted in a channel is visible to people with access to that destination and can be copied or forwarded. Anyone who receives an unlisted share link can open it; marking a link as not for search indexing is not access control. You and recipients are responsible for keeping share links within the intended audience and not forwarding them more widely. A campaign owner should revoke a link if it is exposed beyond the intended audience. GM-only notes and reports are not included in attendee delivery.
Recap Raven depends heavily on Discord’s server, channel, role and membership privacy controls. Those controls can change, be misconfigured, or give a wider audience access than you expect, and players or other recipients may copy or distribute content and share links in ways you do not expect. Before recording or using the Service, the account holder must explain and discuss the privacy implications with the table and relevant Discord server, obtain every participant’s permission, and make sure the chosen destinations and audiences are appropriate.
Optional public Discord forums. A campaign owner can explicitly switch on publication of player recaps to a forum in a linked Discord server. When enabled, we send the player-facing recap, its unlisted share link, any recap image and the full normalised session transcript to a forum thread visible to everyone who can access that forum in Discord. We may add session participants as thread members, which can make their association with that session visible in Discord; adding them does not make the thread private. The post content does not include an attendee list or participant IDs. GM-only reports are not posted to the public forum and remain available only through their owner-only delivery paths.
4. Legal bases (UK/EU GDPR)
Where we act as controller, we process data to perform our contract with you, including optional Service features you choose to activate; on the basis of consent where we expressly ask for GDPR consent; and for our legitimate interests in securing and improving the Service, administering licences and billing, understanding website payment operations, and producing non-identifying aggregate statistics that help us explain and market it. Where we act as processor for session content, the account holder is responsible for identifying and communicating the lawful basis for that processing. A feature switch or rights confirmation is not described as GDPR consent unless its notice expressly says that it is.
Optional public Campaign Showcase
Campaign artwork before publication. The first time the owner opens Campaign Showcase settings after completing a player-safe recap, we automatically request one campaign illustration. This happens before the owner decides whether to publish. We select a limited sample of player-safe recap titles and scenes, use our text-processing AI provider to prepare an illustration prompt, and send that prompt to our image-generation provider. Our visual AI provider also processes the generated image for a safety check. These providers fall within the processor categories described below. We do not use GM-only notes, raw transcripts, account details or the public GM profile for this artwork. Player-safe scenes may still contain personal information supplied in the original session.
Approved campaign artwork is stored on our image delivery service at an unlisted link. Anyone who obtains that image link can view or forward the image, even while the campaign itself is private. Opening settings does not publish the campaign or its recaps. We keep the same image when sharing is turned off or on, or when new recaps are added. Generation is best-effort; an unsuccessful attempt leaves the default image in place.
Optional artwork regeneration. You can request a replacement using an editable scene description and an art style. We retain the safe visual brief to let you edit it, and send your description to our text-processing provider for a safety rewrite before image generation. A smaller copy of the resulting image is sent for a safety check; it is not published separately. Do not include private notes or personal information in your description. A successful replacement uses a small amount of your GM Ask allowance. Your current image remains in place if generation fails. Replaced images are removed through our image cleanup process, although copies held elsewhere may remain.
Campaign Showcase is off by default. When the campaign owner enables it, we make the designated player-safe campaign content available to anyone without an account, including through our discovery pages and search engines. This can include recap text, character names, chronicles, quest and thread information, party highlights, and the optional public GM profile, social links and recruiting links supplied by the owner. GM-only notes and raw transcripts are not published through Showcase. Player-safe content can still contain personal information; the owner should review it and discuss public sharing with participants before publishing. Manual publication and the recommended one-day delay offer time to review. Delayed recaps publish after 24 hours unless held; immediate automatic publication may publish before the owner has read the recap. Both automatic modes make content public without a separate approval for each recap.
We process the publication choice and public content to provide this optional feature at the owner’s request. We record publication changes and process reports to operate and protect the Service. Enabling Showcase does not provide consent on behalf of everyone mentioned in the content or remove their data-protection rights. The lawful-basis explanation above continues to apply.
Turning Showcase off stops public access through our Showcase pages and removes the campaign from our discovery listings. It does not delete the private campaign or necessarily remove copies already saved, shared or cached by visitors, search engines, internet archives or other third parties. We cannot guarantee deletion from systems we do not control. You can still exercise your data-protection rights using the contact details below. Where applicable law requires us to erase personal data we made public, we will also take reasonable steps to inform other controllers processing it of the request to erase links, copies or replications. Switching Showcase off and requesting erasure of personal data are separate actions.
5. Processors and third parties
We use a small number of providers to deliver the Service. We select and review providers with regard to their role, location, security and available contractual safeguards. Provider routes and suppliers can change; we will provide the identities, roles and current available transfer information on request. Our AI and speech-processing providers may briefly retain a request to operate and protect their service. We do not authorise providers to use your content to train AI models, we do not use it for that purpose, and we do not sell your data.
- AI and speech-processing services — voiced segments are sent over an encrypted connection for speech-to-text. Transcript text and prompts are processed to generate recaps, notes and chat answers. Relevant text or images may also be processed to rank campaign-search results and to safety-check and describe an optional character portrait. Our text and visual AI providers prepare campaign illustration prompts, generate images and safety-check the resulting artwork, as explained above. Before automatic session artwork is made available, this notice will describe any additional image-generation processing. We aim to remove audio promptly after transcription, subject to the operational qualifications in Retention below.
- Communications and account services — transactional email providers send verification and account/job notifications. Discord supplies the independent platform on which the recording bot operates, may be used to sign you in, and supplies entitlement and subscription information used to grant, reconcile and revoke licences; its own terms apply to your use of Discord.
- Website payment services — Creem provides the hosted checkout and acts as merchant of record for website purchases, including payment processing, invoicing, tax, subscriptions, refunds and disputes. Creem processes buyer and transaction information under its own buyer terms and privacy notice, and processes limited integration data for us under its published data-processing agreement.
- Hosting, delivery, security and backup services — EU hosting providers run the Service and may hold access-restricted infrastructure snapshots of data stored on those systems, network-security and content-delivery providers protect and deliver it, and encrypted off-site backup providers hold protected database recovery copies.
Discord’s platform and policies
Discord operates its platform independently. Your use of Discord, including its voice transport and its collection and handling of account, voice and platform metadata, is governed by Discord’s Terms of Service and Privacy Policy. Recap Raven relies on the audio and participant data that Discord makes available to our bot. We do not control Discord’s operation, availability, security or separate data practices and are not responsible for those activities. This does not reduce our responsibility for personal data after Recap Raven receives and processes it.
Creem website payments
Creem (Armitage Labs OÜ, Estonia) is the merchant of record and contractual seller for a website purchase. Its Buyer Terms and Privacy Notice apply to the buyer and payment information it collects at checkout. Creem also publishes a Data Processing Agreement for processing it performs on a merchant’s instructions. Recap Raven does not receive your card details.
Creem’s data-processing agreement identifies buyer name, email address and IP address as processed to generate AI-based transaction statistics for merchants, and lists OpenAI as an AI API subprocessor. Creem may use OpenAI or another disclosed AI provider for that processing. Where this processing is carried out on our behalf, we rely on our legitimate interest in understanding and improving website payment operations. We do not combine those statistics with session content or use them to decide access, eligibility or pricing, and we do not use them for advertising. You can avoid this Creem processing by purchasing through the Discord Store instead of choosing website checkout. If you have already used Creem, you can also object by contacting us using the details below; objection cannot undo processing already required for a completed payment or Creem’s legal retention obligations.
Craig is not our processor
Craig (craig.chat) is a separate, independent recording tool that some game masters choose to use. If you record with Craig, you do so under Craig’s own terms and privacy policy — we are not involved in that recording and Craig is not our processor or sub-processor. We offer Craig support only as a convenience for GMs who already use Craig and want to keep their own copy of the audio: when you give us a Craig download link, we simply download that recording to process it, which saves you downloading and re-uploading it yourself. Our own Discord bot is built independently of Craig and hosted by us.
6. Where we process your data (international transfers)
We are based in the UK and host the core Service in the EU (France). Some provider routes, including transcription and AI processing, may process data in the United States or other disclosed locations. Depending on the provider and route, relevant transfer mechanisms may include adequacy arrangements, the EU Standard Contractual Clauses and the UK Addendum. Contact us for the current providers, processing locations and available safeguards before submitting session content if location matters to your table.
Creem is established in Estonia and publishes an EU GDPR data-processing agreement. Its service uses sub-processors in the EU and United States; its published terms describe contractual safeguards, including Standard Contractual Clauses where required, for transfers outside the EU/EEA.
7. Retention
- Recordings (raw audio / extracted tracks): kept only long enough to transcribe them, then deleted as soon as reasonably possible. Queueing, retries or system failures may delay deletion; we investigate and remediate cleanup failures. There is no way to download audio back out of the Service.
- Live account and session data (account data, transcripts, recaps, GM notes, spelling-dictionary entries and campaign data): retained in the live Service until you delete it or delete your account, subject to the limited records and external copies below.
- Website analytics: detailed pageviews, selected events, performance measurements and cookieless, pseudonymous sessions are scheduled for automatic deletion after 180 days. We investigate and remediate cleanup failures.
- Character portraits and descriptions: retained until you remove or replace the portrait, remove the Cast member, delete the campaign, or delete your account. Removal deletes our serving copy. Copies may remain temporarily in access-restricted hosting-provider infrastructure snapshots until those snapshots expire under the provider and account retention settings; they are not live or publicly accessible.
- Campaign Showcase artwork: retained until the campaign or account is deleted, including when public sharing is switched off. Deletion removes our serving copy through our image cleanup process. Copies already downloaded, forwarded or held by browsers and other third-party caches may remain outside our control. A failed generation attempt is recorded to prevent repeated paid generation; that record contains operational status and usage information, not the source recap text or image bytes. For optional regeneration, we also retain the submitted scene description, selected style and credit transaction record to process the request and prevent duplicate charges.
- Generated session artwork: retained until you remove it or delete the related recap, campaign, or account. Artwork is delivered through an unlisted link. Anyone who obtains that link can view or forward it, and copies held by recipients, browsers, Discord, or third-party caches may remain after we remove our copy.
- Artwork-setting evidence: while your account exists, we retain a content-minimal record of who enabled or disabled the feature, when, and which legal and availability versions applied. Campaign or account deletion removes the live setting and relational links. A separate content-minimal security/legal audit record may retain pseudonymous user and campaign identifiers, timestamps and version facts for up to six years, solely to demonstrate compliance and establish, exercise or defend legal claims; it contains no campaign text, portrait, generated image or asset link.
- Security, operational and billing records: Discord entitlement and licence records, and Recap Raven’s protected Creem subscription and transaction records, are retained while your account and the related licence or billing issue remain active. Account deletion removes the live account-linked Creem records once no current or unknown billing relationship remains. Minimized webhook receipts and checkout/cancellation request records are removed after 13 months. Content-minimal audit records may be retained for up to six years where reasonably needed for security, fraud prevention, billing reconciliation, compliance or legal claims. Raw billing payloads and card details are not retained by Recap Raven.
- Discord trial and claim records: expired, single-use server claim links are removed by our recurring cleanup. We retain a minimal Discord server identifier and trial date while reasonably needed to prevent repeated use of a one-time server trial; its link to an account is removed when that account is deleted.
- Encrypted database backups and hosting snapshots: deletion removes data from the live Service, but a copy may remain in encrypted, access-restricted database recovery backups or access-restricted hosting-provider infrastructure snapshots. Our database recovery schedule is intended to expire database backup copies within 180 days. Hosting snapshots expire under the provider and account retention settings. Provider or operational failures may delay expiry and will be investigated and remediated. Backups and snapshots are used for disaster recovery, not ordinary access; if a recovery copy is restored, we aim to reapply completed deletion requests as soon as reasonably possible.
- Discord deliveries and recipient copies: materials delivered to private threads, channels, forums or other Discord destinations become copies held on Discord. Ordinary attendee or channel deliveries, forwarded messages, downloaded files and copied share links may remain after the source is deleted, subject to Discord’s and the server owner’s controls. Contact the server owner or Discord about copies they control.
- Optional Discord forum posts: switching the campaign setting off stops future public forum posts but does not remove posts already sent to Discord. When you edit a player recap, revoke its share link, delete its session or campaign, or delete your account, we queue the corresponding forum post for update or deletion. That operation can be delayed while Discord is unavailable, and Discord controls any copies retained under its own terms.
8. Your rights
Subject to applicable law, you can access, correct, export or delete your data, object to or restrict certain processing, and withdraw consent. You can delete jobs and your account in the app, or contact us through our Discord or email privacy@recapraven.com. The website-analytics control below applies only to website analytics; contact us to object to other processing, including Creem’s AI-based buyer statistics or our use of service data to create aggregate insights. You may also complain to your local data-protection authority.
9. Security
We use measures including encrypted transport, HttpOnly cookie sessions, CSRF protection and access controls. No system is completely secure, but we work to protect your data. You are responsible for participant permissions, Discord audience settings and how you or recipients distribute outputs and share links. The indemnity in section 6 and the limitation of liability in section 9 of our Terms apply to your use of the Service. Nothing in this Policy or the Terms excludes liability that cannot lawfully be excluded or transfers our own data-protection duties to you.
10. Cookies and website analytics
We use strictly necessary cookies for authentication and security, such as the HttpOnly session cookie and the CSRF cookie. We do not use advertising cookies, Google Analytics or Microsoft Clarity. Our self-hosted Umami analytics does not set analytics cookies, does not receive your Recap Raven account identifier, does not use session recording, and respects your browser’s Do Not Track and Global Privacy Control settings.
You can object to website analytics on this device at any time. Your choice is stored only in this browser and does not affect your ability to use the Service.
11. Children
The Service is strictly for adults and for adult TTRPG games. It is not directed to children, and we do not knowingly collect or process the personal data of anyone under 18. You must not upload, submit or process any recording or content that includes the voice or personal data of a minor. Doing so is a serious breach of our Terms: offending accounts may be suspended or permanently banned, and we may cooperate with law enforcement and relevant authorities in connection with child-safety matters. Ensuring that every recorded participant is a consenting adult is entirely the responsibility of the account holder (the GM). If you believe a minor’s data has been provided to us, contact us through our Discord or email privacy@recapraven.com so we can remove it.
12. Changes
We may update this policy; material changes update the version and date above. Continued use means you accept the updated policy.
13. Contact
Privacy questions? Get in touch through our Discord.
