Privacy Policy
Last updated: June 7, 2026
This Privacy Policy explains how we, the operator of Theater of Kami (the "Service"), collect, use and protect your personal data. We are the data controller.
1. Data we collect
- Account data: your email address, a hashed (not plain-text) password, your email-verification status and account settings.
- Gameplay data: the games, characters, stories and messages you create or generate, your language-learning progress, and your in-game inventory and coin balance.
- Inputs: the text you submit to generate content.
- Technical data: log data, basic device and browser information, and a strictly necessary authentication cookie that keeps you signed in.
- Payment data: handled by Paddle. We do not collect or store your full card details. We receive limited transaction information, such as confirmation that a purchase succeeded, an order reference and your country for tax purposes.
2. How we use your data and our legal bases
- to provide the Service and operate your account (performance of a contract);
- to generate game content through AI providers (performance of a contract);
- to process purchases and prevent fraud (contract and legitimate interests);
- to send service emails such as verification codes, receipts and important notices (contract and legitimate interests);
- to secure, maintain and improve the Service (legitimate interests);
- to comply with our legal obligations.
3. AI processing
To create characters, dialogue, images and language feedback, your inputs and game content are sent to third-party AI providers that generate text and images from your inputs and return the results. Please do not submit sensitive personal data you would not want processed in this way.
4. Who we share data with
We share data only with service providers that process it on our behalf to run the Service:
- Paddle — payments and Merchant of Record;
- transactional email delivery;
- cloud hosting, database and content-delivery (CDN) providers;
- AI text and image generation providers.
We do not sell your personal data.
5. International transfers
Some of our providers are located outside your country, including in the United States. Where required, such transfers are protected by appropriate safeguards, such as the European Commission's Standard Contractual Clauses.
6. Data retention
We keep your account and gameplay data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within a reasonable period, except where we are required to retain certain records (for example, tax and accounting records held by us or by Paddle).
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to processing or withdraw consent. To exercise any of these rights, contact us using the details in the Contact section below.
8. Cookies
We use a strictly necessary authentication cookie to keep you signed in. We do not use advertising cookies.
9. Children
The Service is intended for users aged 13 and over and is not directed at younger children. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Security
We protect your data using measures such as encryption in transit, hashed passwords and access controls. No method of transmission or storage is completely secure, but we work to protect your information.
11. Changes
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email.
12. Contact
Questions about your privacy? Email [email protected].