Privacy

Plain-language privacy notes

Effective July 22, 2026. Everlore is built for RPG campaign data, which often includes private table conversations. This page explains what the beta stores and why.

What Everlore stores

Everlore stores waitlist email addresses and referral attribution before signup. For beta accounts, Everlore stores account identifiers, worlds, campaign names, pasted transcripts, generated recaps, analyst output, wiki drafts, shared and campaign-only wiki notes, exports, invite usage, subscription state, and generation logs.

Transcripts can contain player conversations, table jokes, character choices, and other campaign context. They are retained until you delete the campaign.

Audio uploads are stored only while Everlore creates the text transcript. Depending on file length and track layout, audio may be sent to Soniox, ElevenLabs, or Groq for transcription. After successful transcription, the original audio files are deleted from Everlore storage; the generated transcript text remains with the campaign until deletion.

If an audio transcription fails or is still pending, the temporary audio may remain available for retry or cleanup until you delete the campaign source or contact support.

Managed AI

Managed recap and wiki generation sends the transcript and relevant campaign or world lore to configured AI providers so they can produce the requested output. Provider credentials remain on the server and are not exposed to the browser.

Payments and authentication

Google OAuth is used for beta sign-in. When subscriptions are enabled, Stripe handles checkout and payment details; Everlore stores Stripe customer/subscription identifiers and subscription status, not card numbers. Private beta entry currently requires an invite.

Private invitations are bound to the recipient email. Everlore stores a one-way digest and short display hint for the invitation token, its status, cohort/source labels, and the terms and privacy versions accepted at claim time. The original token is not retained.

Exports and deletion

Obsidian vault exports are stored so you can download them again until you delete the export or campaign.

Campaign deletion removes the campaign rows and stored artifacts managed by Everlore. A campaign that owns world-shared lore must first return those pages to campaign scope so shared history is not deleted accidentally.

You can request account deletion from the account menu. Submitting the request pauses workspace access immediately; during closed beta, an operator inventories the account, removes stored exports, audio, wiki images, application data, and the authentication identity, and verifies completion.

Minimal deletion and security evidence may be retained without campaign content. Encrypted backups may retain deleted data until normal backup expiration; restored backups are subject to the completed-deletion suppression record so the account is not silently reactivated. Legal or security obligations may require longer retention in exceptional cases.

Security and access

Application data is accessed through the Everlore API rather than directly from the browser database client. Access is restricted to the signed-in beta account and service operators who need it to run or troubleshoot the service.

No internet service can guarantee absolute security. Report suspected account or data exposure promptly.

Contact

Email support@everlore.app for deletion, export, security, or privacy questions.