Privacy Policy

Rules Arbiter · Effective from the date this app is first published.

1. Who we are

Rules Arbiter (“the app”, “we”, “us”) is an independent Dungeons & Dragons 5th-edition rules-reference app. It is operated by James Hawkes, United Kingdom, who is the data controller for the information described here.

Contact: rulesarbiter@gmail.com.

Rules Arbiter is not affiliated with, endorsed by, or sponsored by Wizards of the Coast.

2. The short version

We hold the minimum needed to run the app. If you sign in, we keep your Google sign-in and a monthly question count. Our servers do not store the questions you ask or the answers you get; the app keeps your recent history on your device only so it is still there when you reopen it — we cannot see it, and you can clear it any time in Settings. We run no analytics or advertising, and we use no third-party tracking. There is one narrow exception to the “no question storage” rule: if you report an answer, that reported exchange is sent to us and kept so we can review it.

3. What we collect, and why

DataWhenWhy (lawful basis — UK/EU GDPR)
Your Google account email and Google user ID (your name and profile picture are received from Google but not used or displayed beyond your email) When you sign in To create and operate your account and enforce usage limits — performance of a contract
Your subscription tier and your question count for the current period Created automatically when you sign in; updated as you ask questions To operate the free/paid limits — performance of a contract
A one-way salted hash of your IP address (never the address itself) On every request to our server To rate-limit abuse and enforce the anonymous free trial — legitimate interests
A content report: the reported question and answer, the reason you chose, and any note you add. No account ID or IP is attached. Only if you tap “Report this answer” To review and moderate AI-generated content — legitimate interests and compliance with app-store policy

What we do not collect

4. Voice input

When you ask a question by voice, the recording is handled entirely by your device’s own speech-recognition service (on most Android phones, this is Google). The audio is never sent to us. We receive only the transcribed text, exactly as if you had typed it. That audio is subject to your device provider’s privacy policy, not this one.

Answers read aloud use your device’s built-in text-to-speech and involve no network transmission.

5. Who processes your data (sub-processors)

ProviderRoleLocation
Supabase Hosts our server, database, and the sign-in system European Union (eu-west-1, Ireland)
Google Provides Google Sign-In; also, via your device’s operating system, the speech recognition used for voice input Google infrastructure
Anthropic Generates the answer to each question. Your question text and relevant rules excerpts are sent to Anthropic’s API to produce the reply. United States

Anthropic may retain API inputs and outputs for a limited period (currently up to 30 days) for safety and abuse-prevention purposes, after which they are deleted. Anthropic does not use data submitted through its API to train its models.

We do not sell your data and we do not share it with anyone for their own purposes.

6. International transfers

Your account data is stored in the EU. Your question text is transmitted to Anthropic in the United States for the sole purpose of generating an answer, with no account identifier attached. This transfer is covered by Anthropic’s Data Processing Addendum, which incorporates the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum — the mechanism approved by the UK Information Commissioner for UK-to-US transfers.

7. How long we keep it

8. Your rights

If you are in the UK or EU, you have the right to access, correct, delete, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. To exercise any of these, email rulesarbiter@gmail.com.

You can delete your account and its data at any time from within the app (Settings → Delete account) or on the account-deletion page.

You also have the right to lodge a complaint with your data protection authority — in the UK, the Information Commissioner’s Office (ico.org.uk).

9. Children

Rules Arbiter is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Security

All traffic uses HTTPS. IP addresses are stored only as a salted one-way hash. Database access is restricted to our server. No system is perfectly secure, but we keep the amount of data we hold small on purpose.

11. Changes

If we change this policy we will update the date above and, for material changes, notify you in the app.