This Privacy Policy explains how PocketTavern (“we”, “us”) collects, uses, stores, and shares information about you, and how you can exercise your rights. It applies together with the Terms of Use. Using the Web client (including app.pockettavern.com), the iOS / Android apps, or this website means you are informed of the processing described here.
Core promises: chats and card packs stay on your device by default; official-model requests leave your device only when you send a message; Custom API keys and bodies never pass through our official-model pipe; we do not sell personal information, we do not use advertising identifiers, and we do not train our own models on your chats.
1. Who we are and scope
This Policy covers the PocketTavern website, Web client, iOS / Android apps, and processing tied to accounts, subscriptions, and points. It does not cover third-party model vendors you connect to (they have their own policies) or the SillyTavern desktop app — we never read your SillyTavern install folder.
For the purpose of China’s Personal Information Protection Law (PIPL), the PocketTavern operator is the “personal information processor” (个人信息处理者). For the EU / UK GDPR we are the “controller” of information about you.
Privacy contact: privacy@pockettavern.com.
2. Information we process
2.1 Account data
When you sign in with an email one-time code, Apple, or Google, we process: email address or the identifier those providers share, display name if any, sign-in time, and coarse region. IP addresses are used only for sign-in, abuse prevention, and security; inferred region is country / macro-region level (not street level), and raw IP is normally dropped or truncated from searchable logs after 30 days. We do not store a password. Email sign-in uses a one-time code only.
2.2 Subscriptions and payments
If you subscribe to Pro, the app store handles payment instruments. We receive only what the store sends back: transaction id, product type (subscription), price tier, and expiry or renewal state. We do not store full card numbers or CVC.
2.3 Point ledger
We keep your point balance, daily-grant claim records, and a ledger of grants and spends for reconciliation and the in-app history. Ledger entries contain only metadata (timestamp, model id, magnitude spent, source of the grant) — never prompt text or conversation bodies.
2.4 Operations data
To keep the Service stable and safe we may process crash logs (with conversation bodies stripped by default), app version, device and OS type, coarse network type, launch counts, and taps on key controls (for example opening pricing, or an import error code). This is aggregated and de-identified where possible. You can turn off non-essential anonymous analytics in settings. Security logs we need to stop abuse may still be kept for the shortest period required.
2.5 Website visits
When you visit the website we process language preference, strictly necessary session data, and any support email you send us (see Section 2.7). We do not collect a waitlist or marketing subscription from the site.
2.6 API access logs
For security audit and abuse prevention we log API request metadata (endpoint, status code, timestamp, coarse region, request headers with secrets stripped). Retention is typically no more than 30 days, then aggregated or deleted. Logs do not capture request bodies or keys.
2.7 Information you send us
If you email a question, complaint, or rights request, we process the contact details and content you send, only to reply and to keep a compliance record.
3. What we do not collect
Unless you turn on a cloud feature we provide and describe at the time, we do not collect the following onto our account servers:
- chat bodies or per-session author notes;
- the full contents of character cards, World Info, Personas, or presets;
- Custom API keys, base URLs, or request bodies;
- the on-device app-lock PIN;
- files you picked from disk or photos but did not finish importing;
- advertising identifiers (IDFA / AAID), precise location, contacts, microphone, camera, calendar, or health data.
We do not sell personal information, do not use chats or cards for advertising profiles, and do not train our own models on that content.
4. Purposes and legal bases
- Contract: creating the account, running the client, metering points, enabling Pro, sending sign-in codes, handling deletion.
- Legitimate interests: stopping abuse and fraud, crash reports to fix defects, and coarse product analytics on de-identified events. You may object to legitimate-interest processing (see Section 12).
- Consent: optional analytics, and sync you switch on. You may withdraw consent at any time without affecting processing done before withdrawal.
- Legal obligation: tax and accounting records, valid demands from competent authorities, and support for investigations of unlawful content.
5. Official models and Custom API
5.1 Official models
When you send a message to an official model, the prompt, injected character and World Info context, Persona, and recent turns needed for that call go to the model vendor. The vendor processes that data under its own terms. We send only what the call needs and keep usage metadata required to debit points (such as token magnitude). We do not add full chats to a training corpus of our own. We select API channels that default to “not used for training” where possible; the vendor list is published in Section 10.
5.2 Custom API
Custom API requests go from your device or browser to the endpoint you set. We do not proxy that traffic, so we do not see the key or the body. Reaching local Ollama from the Web client may require CORS on your machine. That is your environment; it does not change our “keys stay on device” rule.
5.3 AI character generation
When a Pro user generates a character, the description you type is sent to the model used for generation. The result is stored on your device (and in sync if you use it). Do not put personal data in the prompt if you do not want the model vendor to see it.
6. Local storage, lock and export
Creative assets and chats use on-device storage (SQLite / IndexedDB / secure enclave) by default. An optional 4-digit PIN is checked only on the device and is never uploaded. We cannot reset a forgotten PIN. You would reinstall or restore from an export you made earlier.
You may export local data at any time (JSON or SillyTavern-compatible files for cards, World Info, Personas, presets, and chats). Exports are plain files; use a trusted channel and encrypt them or protect them with a passphrase yourself. You are responsible for exported files.
7. Account sync and cloud features
When you sign in, account profile, subscription state, and point balance are the same on each surface. Creative assets (characters, World Info, Personas, presets) can sync across Web, iOS, and Android so one card pack follows the account.
Cross-device chat-history sync is not a generally available feature yet. Until it ships, chats remain local to each device. If we later offer optional chat sync, we will say so in the app — including where it is stored, how it is protected, and how to turn it off — and we will update this Policy. We will not upload your full chat history without that notice.
8. Cookies and local storage
We group cookies, localStorage, and similar tools into three categories:
- Strictly necessary (always on, cannot be disabled): sign-in session, CSRF, language preference, content security. Session cookies expire after 30 days of inactivity or as soon as you sign out.
- Preferences (on by default): theme and last page.
- Analytics (off by default, consent required): de-identified crash and usage stats. You can withdraw consent in settings or the browser at any time.
We do not use advertising cookies and do not share cookie identifiers with ad networks. Clearing site data in the browser signs you out and resets language. If your browser sends a Do Not Track (DNT) or Global Privacy Control (GPC) signal we treat it as a refusal of analytics cookies.
9. Sharing and processors
We share or appoint processors only for:
- Model vendors, when you use official models or AI character generation (Section 5);
- Identity providers — Apple and Google — to complete sign-in;
- App stores and payment rails — to settle Pro subscriptions;
- Hosting and email vendors — to run accounts and send codes or system mail;
- Legal demands — a valid order from a court or regulator;
- Corporate events — a merger or acquisition, with equivalent protection and notice to you.
Processors may use the data only on our instructions, not for their own marketing.
10. Sub-processors
The table below lists the main sub-processors we currently rely on. The actual configuration may change by feature, region, or your own choices; the list on this page controls.
| Category | Vendor | Purpose | Region | Mechanism |
|---|---|---|---|---|
| Infrastructure | AWS / Alibaba Cloud | Account database, logs, static assets | Nearest region | DPA / SCC / PIPL outbound assessment |
| CDN & DDoS | Cloudflare | Website and Web-client delivery | Global | SCC / DPA |
| Official models | OpenAI · Anthropic · Google · xAI, etc. | Official-model calls and AI character generation | Vendor’s stated region | Vendor DPA; default to “not used for training” channels |
| Identity & stores | Apple · Google | Sign-in, subscription, payment | Global | Vendor terms |
| Amazon SES or equivalent | One-time codes, system mail | US / EU | SCC / DPA | |
| Crash monitoring | Sentry or equivalent | Crash reports (bodies stripped) | EU / US | SCC / DPA |
We do not share your account or usage data with any advertising network, data broker, or behavioural marketing platform.
11. Retention
- Account profile: until deletion completes, or until a long-inactive account may be closed under law;
- Subscription and payment metadata: as long as accounting and store reconciliation require, and not longer than the law allows (typically up to 10 years for tax records in mainland China);
- Point ledger: with the account; deleted or anonymised after deletion completes;
- API access logs: normally up to 30 days, longer only if a compliance investigation requires it;
- Crashes and analytics: aggregates may be kept; device-level raw logs are dropped after the shortest fix cycle (usually within 90 days);
- System backups: database snapshots retained up to 30 days; deletion of your account propagates in the next backup cycle;
- On-device data: under your control; uninstalling the app or clearing site data deletes it if you have not exported.
12. Your rights
Subject to applicable law, you may:
- access the account data and point ledger we hold;
- correct an inaccurate email or display name (limits depend on the sign-in method);
- export local creative assets and chats;
- turn off non-essential anonymous analytics;
- request account deletion (30-day cooling-off; see the Terms of Use);
- object to processing based on legitimate interests;
- request a portable copy of structured account-side data (JSON).
Email privacy@pockettavern.com. We may need to verify you control the account via the registered email. We usually respond within 15 business days and always within 30 days (a single extension is possible for complex requests, and we will tell you). You may also complain to your local data-protection authority.
13. Children and sensitive data
Children: the Service is not directed at children under 13 (or a higher age where you live). We do not knowingly collect their personal data. If you believe we have, or your child created an account without your consent, contact privacy@pockettavern.com and we will delete the account-side record and close the account.
Sensitive data: we do not knowingly collect sensitive personal information (religious or political views, health, race, biometric identifiers, sexual orientation, precise location, financial account numbers, national ID numbers, etc.). If you volunteer such information inside a card, Persona, or message, it travels to the model vendor when you call an official model (Section 5) and stays in your local storage. Use your judgement about what you type.
14. International transfers
Official models, Apple, Google, and some infrastructure may sit outside your country. When we transfer data we protect it through one of these means:
- a Data Processing Agreement with the vendor, together with the EU Standard Contractual Clauses, the UK IDTA, or an equivalent instrument;
- for personal information leaving mainland China, one of the PIPL routes — the Standard Contract, a security assessment, or PIPL certification — depending on the volume and sensitivity involved;
- a framework the vendor has joined (for example the EU-U.S. Data Privacy Framework).
Using an official model means you understand completions are processed where that vendor states. If you want to stay in a particular region, pick a local or regional model in the app’s model selector.
15. Region-specific rights
15.1 Mainland China
If you are in mainland China, PIPL gives you the right to access, copy, correct, delete, close your account, and ask us to explain how we process your data. You may complain to your local Cyberspace Administration or take the matter to court. Processing of children’s personal information also follows the Rules on Online Protection of Children’s Personal Information.
15.2 EU / UK / Switzerland (GDPR, UK GDPR)
You have the rights of access, rectification, erasure, restriction, objection, portability, and to withdraw consent for consent-based processing at any time. You may complain to your Member State authority (for example the Irish DPC or the UK ICO). If we have not designated an Article 27 representative in the EU, contact privacy@pockettavern.com and we will handle the request under GDPR.
15.3 California (CCPA / CPRA)
You have the right to know, access, delete, correct, and limit the use of your personal information, and to opt out of “sale” and “sharing”. We do not sell your personal information and do not share it for cross-context behavioural advertising. Categories, sources, and purposes for the past 12 months are described in Sections 2 and 4. Non-discrimination rights under CCPA apply.
15.4 Brazil, Japan, South Korea and other regions
Under LGPD, APPI, PIPA, and similar laws, you have equivalent rights of access, correction, deletion, and objection. Please use the address in Section 20.
16. Security and breach notice
We use technical and organisational measures matched to the Service: TLS in transit, encryption and access control for data at rest, secrets separated from production data, least-privilege access, multi-factor authentication for staff, anomaly detection, and Custom API keys that never leave the device. No online service is perfectly secure.
If a security incident may affect your personal information, we will notify the relevant authority within the time the law requires (typically within 72 hours under GDPR; immediately under PIPL) and, where reasonable, notify affected users in-app or by email with a description of the incident, likely impact, and recommended steps.
Practical tips: use a trusted device, do not show one-time codes in public, export important card packs regularly, and keep Custom API keys and exports safe.
17. Advertising identifiers and push
Advertising identifiers: the Service does not use IDFA, AAID, cookie IDs, or similar identifiers for cross-site or cross-app behavioural tracking. We do not send attribution postbacks or conversion pixels.
Push notifications: on iOS / Android, and only if you grant OS-level permission, we send notifications about your account, subscription, and security (for example unusual sign-in, subscription expiry, or a claimable daily point grant). We do not send marketing push. You may revoke push at any time in system settings.
18. Automated decision-making
We apply automated risk controls to obvious abuse patterns (mass sign-ups from one IP, farming daily grants, model-vendor flags for misuse). These support human review. You may request human review of any decision that affects you by writing to abuse@pockettavern.com; we normally respond within 10 business days. We do not carry out solely automated decisions that produce legal or similarly significant effects on you.
19. Changes
When we update this Policy we change the date and version at the top of this page. If the purposes, scope of collection, or the sub-processor list change in a material way, we will notify you at least 7 days in advance in-app or by email. Continued use means you are informed of the updated Policy. If you do not accept it, stop using the Service and request deletion. Prior versions are available on request.
20. Contact
- Privacy and data rights: privacy@pockettavern.com
- Data protection officer / EU representative queries: dpo@pockettavern.com
- Complaints and account appeals: abuse@pockettavern.com
- General: hello@pockettavern.com
- Web app: https://app.pockettavern.com
This Policy is issued in Chinese and English. If they conflict and you primarily use the Service in mainland China, the Chinese text controls. Otherwise the English text controls, subject to mandatory local law.