Legal
Privacy Policy
Last updated: 2026-07-18
This Privacy Policy explains how larper (the “Service”), operated by [Company legal name](“we”, “us”, “our”), collects, uses and protects your personal data. We are the data controller for the personal data described here. You can contact us about privacy at [contact email]. This policy is written to reflect the UK GDPR and the Data Protection Act 2018.
1. Who we are
larper is operated by [Company legal name], a company registered in England & Wales (company number [company number]), registered office [registered address]. For privacy queries or to exercise your rights, contact [contact email].
2. The data we collect
We collect and process the following categories of personal data:
- Account data — your email address and a securely hashed password (handled by our authentication provider).
- Order content — the briefs, instructions, notes and files you upload, and the documents we generate for you. These may contain personal data if you include it.
- Payment data — order amount, status and payment references. Your card details are entered with and held by Stripe; we do not receive or store your full card number.
- Technical & usage data — IP address, device/browser information, and aggregated analytics about how the Service is used.
3. How and why we use your data
We use your personal data on the following legal bases:
- To perform our contract with you — creating your account, processing your order, generating and delivering your document, and providing support.
- Our legitimate interests — securing the Service, preventing abuse and fraud, and understanding and improving how the Service performs (in a way that does not override your rights).
- Legal obligations — keeping records (for example, for tax and accounting).
- Consent — where we ask for it, such as any non-essential cookies. You can withdraw consent at any time.
We do not sell your personal data, and we do not use your order content to train our own models.
4. Who we share your data with
We share personal data with the service providers (sub-processors) below, only as needed to run the Service, under contracts that require them to protect it:
- Supabase — Database, authentication and file storage (your account, briefs, uploaded files and generated documents). (EU / UK region.)
- Vercel — Website and application hosting, and privacy-friendly usage analytics. (Global CDN; US.)
- Railway — Background document processing, job queue and diagram rendering. (EU / US.)
- Anthropic — AI text generation (Claude). Receives your brief, instructions and uploaded content to produce your document. (US.)
- WriteHuman — AI text refinement. Receives generated prose to make it read naturally. (US.)
- Stripe — Payment processing. Card details are entered with, and held by, Stripe — we do not store your card number. (US / global.)
- Resend — Sending transactional email (account and order notifications). (US.)
We may also disclose data where required by law, to establish or defend legal claims, or in connection with a merger or sale of our business.
5. International transfers
Some of our providers process data outside the UK/EEA (including in the United States). Where they do, we rely on appropriate safeguards — such as UK adequacy regulations, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum — so your data receives an equivalent level of protection.
6. How long we keep it
We keep your account and order data for as long as your account is active and for a reasonable period afterwards to meet legal, accounting and dispute-resolution needs. Payment and transaction records are kept for [6] years as required by law. You can ask us to delete your account and associated content at any time (subject to records we must retain).
7. Your rights
Under UK data protection law you have the right to:
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, or its processing restricted, in certain circumstances;
- data portability (receive your data in a portable format);
- object to processing based on our legitimate interests; and
- withdraw consent where we rely on it.
To exercise any of these, contact [contact email]. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk, though we ask that you contact us first so we can help.
8. Cookies
We use essential cookies to keep you signed in and to operate the Service securely. We use privacy-friendly analytics to understand usage. Where any non-essential cookies are used, we will ask for your consent.
9. Security
We protect your data with encryption in transit, access controls, and reputable infrastructure providers. No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the risk.
10. Children
The Service is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and, for material changes, notify you by email or an in-product notice. The “last updated” date above shows when it last changed.
12. Contact
For any privacy question or to exercise your rights, contact us at [contact email]. [If you appoint a Data Protection Officer, add their contact details here.]