Privacy Policy for Central Nexus

Last Updated: January 2, 2025
Effective Date: January 2, 2025

1. Introduction

Central Nexus ("we", "our", "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our virtual tabletop platform.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email, username, password (encrypted)
  • Profile Information: Avatar, bio, gaming preferences, timezone
  • Content: Posts, comments, messages, VTT session data

2.2 Automatically Collected Information

  • Usage Data: Pages visited, features used, session duration
  • Device Data: Browser type, OS, IP address (anonymized)
  • Cookies: Authentication, preferences, analytics (with consent)

3. How We Use Your Information

  • Provide and maintain VTT services
  • Authenticate and secure your account
  • Personalize your experience (matching, recommendations)
  • Communicate updates, support, and notifications
  • Analyze usage to improve platform performance
  • Comply with legal obligations

4. How We Share Your Information

We do not sell your personal data. We share data only in these situations:

  • Service Providers: Supabase (database, auth), Render (hosting), PayPal (donations)
  • Legal Compliance: When required by law or to protect rights/safety
  • Public Content: Posts, profiles set to "Public" are visible to all users

4.1 Third-Party Service Providers

We use the following third-party services to operate Central Nexus. Your data may be shared with these providers as necessary:

5. Data Retention

  • Active Accounts: Data retained while account is active
  • Deleted Accounts: Data anonymized or deleted within 30 days
  • Legal Retention: Some data (logs, abuse reports) retained for security/legal purposes (up to 1 year)

6. Your Rights (GDPR/CCPA)

You have the right to:

  • Access: Request a copy of your data (use "Export My Data" in Settings)
  • Correction: Update your profile information
  • Deletion: Delete your account (use "Delete My Account" in Settings)
  • Portability: Receive data in machine-readable format (JSON)
  • Opt-Out: Disable analytics cookies in Cookie Settings
  • Withdraw Consent: Change cookie preferences anytime

To exercise rights, contact: dnddevhelper@gmail.com

7. Children's Privacy (COPPA)

Central Nexus is intended for users 13 years and older. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, please contact us immediately at dnddevhelper@gmail.com.

8. International Data Transfers

Your data may be processed in the United States or EU (Supabase servers). We use Standard Contractual Clauses (SCCs) and other safeguards to protect data transferred outside your region.

9. Security

We use industry-standard security measures: HTTPS, encrypted passwords (bcrypt), secure cookies (HttpOnly, Secure, SameSite), and access controls. However, no method is 100% secure.

Our platform may link to third-party services. We are not responsible for their privacy practices. Review their policies:

11. Changes to This Policy

We may update this Privacy Policy. Changes will be posted here with a new "Last Updated" date. Continued use after changes constitutes acceptance.

12. Contact Us

For privacy questions or to exercise your rights:

Note: This Privacy Policy is provided as a template and has not been reviewed by a qualified attorney. Before relying on this document for legal compliance, please consult with legal counsel to ensure it meets all applicable laws and regulations for your jurisdiction.