Privacy Policy

Version of 13 August 2026. Effective from the date of publication.

1. General provisions

1.1. This policy governs the processing of personal data of users of the Banshee service (the "Service") and forms an integral part of the terms of use.

1.2. The controller of personal data within the meaning of the General Data Protection Regulation (GDPR) is Anton Shvets, a natural person, Vietnam. The full postal address is provided upon written request.

1.3. Address for enquiries concerning the processing of data: support@banshee.quest.

1.4. Data is processed in accordance with the Law of Vietnam "On the Protection of Personal Data" and, in respect of users in the European Economic Area, in accordance with the GDPR.

1.5. A data protection officer has not been designated: the processing does not meet the conditions of Article 37 GDPR. Enquiries are handled by the Operator.

1.6. Personal data is not sold and is not disclosed for advertising purposes. No advertising is placed within the Service.

2. Data processed and legal bases

2.1. Account data

Email address, password stored as an irreversible hash, selected interface language, confirmation status of the email address, date of registration, records of acceptance of the terms of use and of this policy, subscription tier and the date on which it began.

Legal basis — performance of a contract (Article 6(1)(b) GDPR).

2.2. User content

The texts of the user's actions, characters, worlds and their rules, the chronicle, campaign memory, images of scenes and portraits, and campaign settings.

Legal basis — performance of a contract.

2.3. Technical records

Records of requests to language models: the type of generation, its cost, its status, the time of the request and information about errors. The text of the request sent to the model is stored as part of such a record.

Legal basis — performance of a contract as regards the accounting of subscription limits, and the legitimate interests of the Operator (Article 6(1)(f) GDPR) as regards the detection of failures and the prevention of abuse.

2.4. Payment data

From the seller the Operator receives and stores: the fact of the payment, its date and amount, the subscription identifier on the seller's side, the date of the next charge, and the last four digits and type of the payment card.

The card number, its expiry date and the CVC code are not disclosed to the Operator. Those details are entered on the seller's side and processed by it in accordance with the PCI DSS standard.

Legal basis — performance of a contract and compliance with a legal obligation (Article 6(1)(c) GDPR) as regards the retention of records of payments.

2.5. Protection against automated access

Google reCAPTCHA is used at sign-in and registration. Google receives the user's IP address, information about the browser and about the interaction with the form, and sets its own cookies.

Legal basis — the legitimate interests of the Operator in protecting accounts against unauthorised access.

2.6. Service messages

The email address and the content of service messages: confirmation codes, password recovery, notice of an upcoming charge, and notices of material changes to the terms.

Legal basis — performance of a contract. No marketing communications are sent.

2.7. Browser notifications

Where notifications are enabled, the browser provides the Operator with a push subscription endpoint.

Legal basis — the user's consent (Article 6(1)(a) GDPR). Consent is withdrawn by disabling notifications in the browser.

2.8. Data in the user's browser

The Service sets no cookies of its own. The session token, the selected language and display settings are stored in the browser's local storage. That data is held on the user's device and is erased together with the site data.

Cookies are set by reCAPTCHA (clause 2.5) and, on the payment page, by the seller. No analytics or advertising tools are used.

3. Purposes of processing

3.1. Personal data is processed solely for the following purposes: providing access to the Service and operating it, authenticating the user, storing and reproducing user content, accounting for subscription limits, processing payments, sending service messages, detecting failures and preventing abuse.

3.2. User content is not used to train language models, either by the Operator or by the providers of the models.

4. Recipients of data

4.1. Providers of language models. The text of the user's action, the state of the scene and the related fragments of memory are transmitted to OpenRouter and, through it, to the providers of the models used: Anthropic, OpenAI, Google. The transfer is necessary for the operation of the Service. The terms of the application programming interfaces of those providers prohibit the use of requests for training models.

4.2. The seller — upon payment for a subscription, the email address, country and amount of the payment are transmitted. The seller processes the data as an independent controller in accordance with its own privacy policy.

4.3. Google — upon completion of the check referred to in clause 2.5.

4.4. Purelymail (United States) — for the sending of service messages.

4.5. Fornex (data centre in the Netherlands) — hosting of the application and of the database.

4.6. Data is not disclosed to any other party. Disclosure is possible only pursuant to a lawful request by a competent public authority.

4.7. Data processing agreements have been concluded with those who process data on the Operator's instructions.

5. International transfers

5.1. Some of the recipients listed in section 4 are established outside the European Economic Area, principally in the United States. The Operator is established in Vietnam.

5.2. Transfers of data outside the European Economic Area are made on the basis of the standard contractual clauses of the European Commission or of an adequacy decision, where such a decision applies to the recipient concerned. A copy of the applicable clauses is provided upon written request.

6. Retention periods

6.1. Account data and user content — for as long as the account exists. Upon deletion of the account the data is deleted; it remains in backups for up to 30 days.

6.2. Technical records of requests to language models — up to 12 months.

6.3. Payment records — three years, in accordance with the statutory requirements for the retention of records of payments. Those records cannot be deleted at the user's request before that period expires.

6.4. Correspondence with support — 12 months from the closure of the enquiry.

6.5. Records of the termination of access for a breach of the rules of use (the email address in hashed form and the ground for termination) — three years. Retention is necessary to prevent re-registration.

7. Rights of the user

7.1. The user has the right to:

  • obtain information about the data processed and a copy of it in a machine-readable format (access and portability);
  • request rectification of inaccurate data;
  • delete the account together with the user content within the Service (erasure);
  • request restriction of processing or object to processing carried out on the basis of legitimate interests;
  • withdraw consent previously given; withdrawal does not affect the lawfulness of processing carried out before it;
  • lodge a complaint with a supervisory authority: in Vietnam, the Vietnam Parliament Commissioner for Human Rights; in the European Union, the supervisory authority of the place of residence, place of work or place of the alleged infringement.

7.2. Requests, other than actions available within the interface of the Service, are sent to support@banshee.quest from the email address given at registration. The response period is 30 days. No fee is charged.

7.3. It is not technically possible to withdraw data from a request already sent to a language model. The Operator's record of such a request is deleted together with the account.

8. Automated decision-making

8.1. No decisions producing legal effects for the user are taken by automated means. No profiling is carried out.

8.2. The restriction of access upon exhaustion of a subscription limit is an arithmetical comparison of the cost of requests within the accounting period against the size of the limit, and is lifted automatically upon expiry of that period.

8.3. A decision to terminate access for a breach of the rules of use is taken by the Operator and may be appealed in the manner set out in the terms of use.

9. Security

9.1. The Operator applies the following protective measures: encryption of connections (TLS), storage of passwords as irreversible hashes, restriction of access to the database, access to servers by cryptographic keys, and encryption of backups.

9.2. Those measures do not entirely exclude the risk of unauthorised access.

9.3. The Operator notifies the supervisory authority of a personal data breach within 72 hours of becoming aware of it, and the user without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

10. Data of minors

10.1. The Service is intended for persons who have reached the age of 18 and is not designed to collect the data of minors.

10.2. Where an account is found to have been registered by a minor, the account and its content are deleted and the amounts paid for the unexpired paid period are refunded. A parent or legal guardian may request this by writing to the support address.

11. Changes to this policy

11.1. The current version of this policy is published on this page with the date stated.

11.2. The Operator notifies users of material changes, including the addition of new recipients of data, new purposes of processing or new retention periods, by email and within the interface of the Service no later than 30 days before the changes take effect.

12. Details

Operator: Anton Shvets, a natural person, Vietnam.

Email: support@banshee.quest.

Related documents: terms of use, refund policy.