Closed-beta privacy notice · 1 August 2026
Privacy notice
Destiny Weaver stories can reveal intimate or otherwise sensitive information. Cloud storage stays locked until an invited adult explicitly consents. The beta does not sell data or use story content for advertising.
Who operates this beta
Destiny Weaver Online is a small closed test run by the individual developer who issued your invitation. Written privacy requests can be sent from the private beta feedback page; choose the “privacy” category before deleting your account.
What is stored
- Your sign-in identifier, email address and display name supplied by the hosting sign-in service.
- Your invitation label, adult attestation, consent and policy-acceptance timestamps.
- Private stories, prompts, choices, character state, relationships, inventory and generated portrait files.
- Complimentary credit activity, generation status, limited abuse-prevention counters and feedback reports.
Why it is used
Data is used only to authenticate invited testers, synchronize private saves, operate generation credits, deliver portraits, prevent abuse, troubleshoot defects, respond to requests and improve the beta. Sensitive story information is processed on the basis of the explicit consent collected at invitation activation; you can withdraw it by deleting your account.
Services that receive data
The hosted application and private storage run on OpenAI Sites and its Cloudflare infrastructure. Story or image context is sent to NovelAI or Pollinations only when you initiate generation with a provider you configured. Those providers apply their own terms and privacy notices. Provider tokens remain in this browser and are not stored in the Destiny Weaver database. No payment processor is connected.
Retention
Account content is kept until you delete the account or the beta is closed. Feedback may be retained for up to 12 months; abuse-prevention counters and operational security records for up to 90 days. A one-way invitation hash and consumed status may remain after deletion to prevent code reuse. Backups and infrastructure logs may take a short additional period to expire.
Your controls
The account page provides a machine-readable export and permanent deletion of cloud stories, media, credits, generation history, feedback and consent records. You can also delete individual stories. Deleting the account clears device saves and provider settings in that browser. You may use the private feedback form to request access, correction, restriction or other rights available under applicable law.
Security and limits
Story ownership is checked server-side, portraits use account-scoped storage paths, invitation codes are stored as one-way hashes, and sensitive responses are marked private. No internet service is perfectly secure; do not enter real names, addresses, passwords or another person's private information into a story.
Changes
If the purposes, processors or consent terms materially change, the application will require a new acceptance before restoring cloud access.