PRIVACY POLICY

LAST UPDATED: JUNE 11, 2026 // STRAND GTM LLC

This Privacy Policy describes how Strand GTM LLC ("OSR.RUN," "we," "us") collects, uses, and shares information when you use the website and service at osr.run (the "Service"). By using the Service, you agree to the collection and use of information as described here. Capitalized terms not defined here have the meanings given in our Terms of Service.

The short version: we collect what's needed to run a game-table service and nothing else. No advertising, no analytics trackers, no selling data, no training AI models on your content.

1. Information We Collect

Account information

When you create an account, our authentication provider (Clerk) collects your email address, name, and — if you sign in with a third-party provider such as Google — basic profile information from that provider. Passwords are handled entirely by Clerk; we never see or store them. Our own database stores your Clerk user ID to link your campaigns, characters, and subscription status to you.

Payment information

GM subscriptions are processed by Stripe. Your card number and full billing details go directly to Stripe and never touch our servers; we receive and store only your subscription status and what is needed to manage your plan. Stripe's handling of your data is governed by its own privacy policy.

Game content

Using the Service inherently involves storing the things you make in it:

This is content data rather than personal data in the usual sense, but note that character names and free-text notes contain whatever you put in them — don't put sensitive personal information in game notes.

Technical data

Like every web service, our infrastructure providers log basic request data — IP address, browser type, pages requested, timestamps — for operations and security. Real-time play uses WebSocket connections that carry your session's game state.

Stored on your device only

Per-device preferences — theme override, text size, reduced motion, haptics, and the GM's session token — are stored in your browser's local storage. They stay on your device and are not synced to our servers.

2. Cookies and Tracking

We use no advertising cookies, no analytics, and no third-party trackers. The only cookies set are essential authentication cookies from Clerk that keep you signed in. Because these are strictly necessary for the Service to function, the Service does not work without them.

3. How We Use Information

We use the information we collect to:

We do not use your information or content for advertising, sell or rent it to anyone, or use it to train machine-learning models.

4. How Information Is Shared

With other users, at your direction

Sharing inside a game table is the point of the Service: your GM can see your character data; players and the table display in a session you join can see the game state the GM chooses to show (HP, conditions, names, deaths); GM-only notes are visible only to the GM. Joining a session is your consent to this table-level visibility, as described in our Terms.

With service providers

We share data with the infrastructure providers that run the Service, each only to the extent needed to do their job:

ProviderRoleWhat they process
ClerkAuthenticationEmail, name, sign-in credentials, auth cookies
StripePaymentsBilling details, payment method, subscription status
TursoDatabaseAccount links, campaigns, characters, rulesets
Fly.ioHostingAll Service data in transit and at rest; request logs

These providers act as processors under our instructions and their own privacy policies. We may update this list as infrastructure changes; the current policy always reflects the providers in use.

Legal and safety

We may disclose information if required by law or valid legal process, or where reasonably necessary to protect the rights, safety, or property of OSR.RUN, our users, or the public.

Business transfers

If OSR.RUN is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your personal information becomes subject to a different privacy policy.

5. Data Retention

When you delete your account, we delete the personal information and content associated with it, except where retention is required by law (for example, payment records) and residual backup copies pending their normal purge.

6. Your Rights

You can access and update most of your information directly in the Service. For anything else — including requesting a copy of your data, correcting it, or deleting your account and data — contact us at support@osr.run. We respond to all legitimate requests and may need to verify your identity first.

If you are in the European Economic Area or United Kingdom, you have rights under data-protection law including access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. If you are a California resident, you have rights under the CCPA/CPRA including to know, delete, and correct your personal information and to be free from discrimination for exercising those rights — and note that we do not sell or share personal information as those terms are defined in California law.

7. Security

We protect your information with industry-standard measures: encrypted connections (TLS), token-based authentication on all GM operations, per-session permission enforcement, and isolation of each campaign's data. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security — but we treat your data's security as a design requirement, not an afterthought.

8. Children

The Service is not directed to children under 13 (or under 16 where local law sets a higher age of digital consent), and we do not knowingly collect personal information from them. Children below that age may participate at a physical table under an adult's account without an account of their own, in which case any character data entered belongs to the adult account holder. If you believe a child has provided us personal information, contact us at support@osr.run and we will delete it.

9. International Transfers

The Service is operated from the United States and our providers store data in the United States (and, for our edge database, in regional replicas). If you use the Service from outside the US, your information will be transferred to and processed in the US, where data-protection laws may differ from your jurisdiction's. We take steps to ensure your data is treated in accordance with this policy wherever it is processed.

10. Links to Other Sites

The Service may link to third-party sites (for example, publisher sites for bundled-content attribution). We have no control over and assume no responsibility for their content or privacy practices; review their policies separately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy here with a new "Last updated" date and, for material changes, make reasonable efforts to notify you (for example, by email or an in-app notice) before the change takes effect.

12. Contact

Questions or requests about this policy or your data: