Privacy Policy
Last updated: 22 juin 2026
This policy describes the personal data processed by TaleSmith as part of the TaleSmithRP service (Discord bot and dashboard). It addresses two audiences: server owners who install the service, and members who talk to the characters. We comply with the General Data Protection Regulation (GDPR).
Who is responsible for what
The service involves two distinct processing operations, with different roles:
- Your members' data (messages exchanged with characters, memory and relationships): by installing TaleSmith on your server and configuring it, you decide on this processing. You are its controller; TaleSmith acts as a processor, on your instructions and within the limits described here. It is your responsibility to inform your server's members and to have a legal basis for this processing. The terms of this arrangement are set out in our Terms (section “Data processing”).
- Your account data (Discord ID, subscription, billing, service security): TaleSmith is the controller.
Contact us : TaleSmith — contact@talesmith.fr.
Data processed
Depending on how you use the service, the following data is processed. This list aims to be exhaustive: if you notice any discrepancy with the service's actual behaviour, please tell us.
- At sign-in (dashboard): your Discord ID, your username and the list of servers you administer — through the authorization you grant to Discord. No Discord access token is stored.
- When using the bot: the Discord ID (or the proxy character's identity) and display name of members who talk to a character, the content of the messages exchanged, and a relational state per member — affinity, trust, a summary of the relationship, and “remembered facts” extracted automatically by the AI (what the member said about themselves: first name, tastes, life events they share).
- Scene context: when a character is tied to a channel, the latest messages in that channel are passed to it so it can react to what is happening — including messages from members who are not talking to it. The name of a member the character doesn't know is not passed on (it is replaced by an anonymous label); the message content is. A character can be set to react only to proxy characters.
- Gossip (off by default): if the server owner enables this option, a character may mention to a member the names of other members it knows and the public nature of the tie (“your friend dropped by yesterday”). Never the content of what was confided to it.
- Chronicle and events: public facts about a character (injury, death, server event), written by the owner or generated automatically from the roleplay, and known to all players. They are not tied to an account.
- Configuration: the servers, characters, Lore, Bot and images you create.
- Payment: a Stripe customer ID and the status of your subscription. We never store your card details: they are handled directly by Stripe.
- Technical: usage counters (message counts, aggregated per day and per server) and operational logs. These logs contain the server and channel ID, the character's name and the display name of a message's author — never message content. In demo mode, a per-player trial counter.
Purposes and legal basis
For the processing for which TaleSmith is the controller (account, subscription, security):
- Manage your account, subscription and billing — performance of the contract / legal obligation.
- Ensure the security of the service and prevent abuse — legitimate interest.
For a server's member data, the purpose (bringing to life characters that remember) and the legal basis rest with the server owner, who is the controller of that processing. TaleSmith only uses this data to provide the service: it is never sold, used for any other purpose, or used to train an artificial intelligence model.
Processors and recipients
To operate the service, certain data is shared with providers, only to the extent necessary:
- Anthropic (Claude API): the content of messages exchanged with a character and the associated context (the character's personality, the server's setting, relational state, scene context) are sent to Anthropic to generate the character's reply. Anthropic is located in the United States.
- Discord: the platform on which the service operates (authentication and message delivery).
- PluralKit: when a message comes from a proxy, that message's ID is sent to PluralKit's public API to find out which character it belongs to. In return we receive the character's ID and that of the Discord account that triggered it. No message content is transmitted.
- Sentry: technical monitoring. If the service errors, the incident report may contain elements of the message being processed.
- Stripe: payment processing (United States / EU).
- OVH: hosting of the servers and the database (European Union).
- Backblaze: storage of encrypted database backups, in a private space located in the European Union (Amsterdam region). Backblaze Inc. is a company established in the United States.
For the avoidance of doubt: the service is compatible with Tupperbox, but sends it no data. Messages proxied by Tupperbox are simply read within Discord, like any other message.
Transfers that may involve a country outside the European Union (Anthropic, Stripe, Sentry, Backblaze) are covered by the appropriate safeguards provided for by the GDPR (standard contractual clauses).
Retention period
Message history is automatically erased after 30 days on a rolling basis. Each relationship's most recent exchanges are kept beyond that period, so a character doesn't lose the thread of a conversation with a player who returns after a break. A character's memory (affinity, trust, facts, summary) is kept until it is erased.
Deleting a character deletes the associated messages and relationships. Removing the bot from a server deletes all of that server's data. Billing data is kept for the period required by accounting and tax obligations.
Encrypted database backups are taken daily and kept for 14 days on a rolling basis before automatic deletion. After exercising a right to erasure, your data may therefore remain in these encrypted backups for a maximum of 14 days, until they are rotated out.
Cookies
The dashboard uses a single session cookie, strictly necessary for your authentication, and a cookie storing your language choice. No advertising or third-party tracking cookies are placed.
Your rights
You have the right to access, rectify, erase, restrict, object to and port your data. To exercise these rights, write to contact@talesmith.fr. Regarding data processed on a Discord server, please contact that server's owner first, as the controller of that processing; we assist them in responding. You may also lodge a complaint with the CNIL (cnil.fr).
Self-service erasure: any member can erase their own data on a server by typing the command /tsrp_oubliemoi there. After confirmation, the memories, relational state and message history concerning them on that server are erased immediately and permanently — including those of their proxy characters (PluralKit, Tupperbox), where the link to their account could be established.
This command does not erase public facts already written into a character's chronicle or the server's events: they are tied to no account and belong to the collective story. A server administrator can remove them, or you can write to us.