Privacy policy
What RPG Lab collects, why, and who else handles it.
Last updated Sep 17, 2026
Who's responsible
RPG Lab (rpglab.io) is a trade name of Sunset Mesa Ventures LLC, a Colorado limited liability company. For anything about your data, email hello [at] rpglab [dot] io.
What RPG Lab collects
- Account. Your email address, handle, display name, and whatever you add to your profile (bio, links, an avatar). If you sign in with Discord or Google, the provider tells RPG Lab five things: the email address on that account, whether you've verified it there, your display name there, your profile picture, and an account id. The name pre-fills your display name here, and a copy of the picture becomes your avatar until you change it. The id and the provider's sign-in tokens are kept so that way of signing in keeps working.
- Sign-ins. Sign-in link tokens, which expire within minutes or on use. Each signed-in session records the IP address and browser it was started from, so sessions can be told apart.
- What you post. Projects, updates, posts, comments, versions, playtest calls, applications, feedback, messages in playtest threads, the images you upload, and the files you attach to a version. Uploaded images and files are stored as you sent them. The copies of images shown to other people are re-encoded with camera metadata, including location, removed.
- Playtest records. Your applications and the message on them, the rosters you're on, session records, your feedback responses, the messages in a call's roster thread and in follow-ups on your feedback, and any private notes a designer writes about a playtester. Versions with a hosted file count how often the file is downloaded, without recording who.
- Following, access, and settings. Who and what you follow, your notifications, the projects and studios you've been invited to and the role you hold on them, and your settings, like the adult-content opt-in and which notifications reach you by email.
- People you invite. When you invite someone onto a project or a studio, RPG Lab stores the handle or email address you gave, who sent the invitation, and what became of it. An address invited this way is used for that invitation only and never added to any list.
- Waitlist and mailing list. Your email, what you said you're here for, and, if you ticked the box, a record of that consent: when, from which form, and which wording. Confirmation clicks are recorded too.
- Technical logs. Requests are logged with a request id, the signed-in account id, and what happened (an update was posted, a form was saved). Errors are reported with the page, the browser, and the account involved so they can be fixed. Rate limiting counts requests per IP address for about a minute at a time.
- Analytics. Page views are counted with Cloudflare Web Analytics, which uses no cookies, doesn't fingerprint browsers, and reports totals only.
RPG Lab doesn't buy data about you from anyone, doesn't run ads, and doesn't track you across other sites.
What it's used for
- Running the site: showing your work to the people you chose, signing you in, keeping your feed and notifications working.
- Sending you the email described below.
- Keeping the site working and safe: fixing errors, stopping spam and abuse, enforcing the terms.
Your data is never sold and never used for advertising.
- Sign-in links, when you ask for one.
- Notifications, to your account email: someone replied to your comment or commented on your post; a project, designer, or studio you follow posted an update, made a new project public, or opened a playtest call; someone wrote a post about a project you follow; playtest events you're part of (an application came in, you were approved, a session was scheduled, a form is ready); a message in a playtest thread you're in; and an invitation onto a project or a studio. Each kind except invitations can be turned off in settings. Milestone updates (a release, a campaign launch, a playtest opening) are sent even when plain updates are turned off.
- Waitlist mail: one email to confirm your address, and one when your invite is ready.
- The mailing list: occasional notes on how RPG Lab is coming along. Only to people who ticked the box, and only after their address was confirmed by a click. Every send has an unsubscribe link. You can also withdraw by emailing hello [at] rpglab [dot] io.
Following someone, joining a playtest, or being on the waitlist never puts you on the mailing list.
Who else handles your data
RPG Lab runs on services other companies operate. Each one handles data only to provide its service:
- Cloudflare hosts the site, stores uploaded images and files, serves and resizes images, counts page views, enforces rate limits, and stores server logs.
- PlanetScale hosts the database, including its backups.
- Resend delivers email.
- Sentry receives error reports.
- Discord and Google, only if you sign in with them. They learn that you signed in to RPG Lab.
Nobody else gets your personal data, except when the law requires it (a valid legal request) or to deal with an emergency. These services run in the United States and elsewhere, so your data may be stored outside your country.
What other people can see
- Your profile (handle, display name, bio, links, avatar), your public projects, your published updates and posts, and your comments are visible to anyone on the internet, signed in or not. Unlisted projects are visible to anyone with the link. Private projects are visible only to you, the studio's owners for a studio project, and the people invited onto the project as editors or viewers.
- The people listed on a project as editors or viewers are visible to the project's owners and editors. Studio owners and members are listed on the studio's page.
- Follower and following lists are visible to anyone.
- Playtest applications, rosters, and feedback responses are visible to the people who manage that project, and your own responses to you. Session dates show on the call page to anyone who can see the call; the location, notes, and who's at the table show only to the roster. A call's roster thread is visible to the project's managers and the approved roster; a follow-up on your feedback, to the managers and you. Files hosted on a version go only to the people the version is open to. Private notes a designer writes about you are visible only to that project's managers.
How long it's kept
- Your account and what you posted stay as long as your account exists.
- A project, post, or comment you delete disappears from the site at once. Its record stays in the database, marked deleted, so abuse can still be investigated, and it's removed for good when your account is deleted.
- Sign-in link tokens expire within minutes. Sessions end when you sign out or after a while without use.
- Server logs and error reports are kept for a limited period, weeks to a few months, then discarded.
- Database backups expire on their own schedule. Deleted data can persist in a backup until that backup expires.
- Waitlist entries stay until the invite is used or you ask for removal.
Your choices and rights
- To delete your account, open settings and type your handle. That removes your profile, projects, posts, comments, messages, and playtest records, signs you out everywhere, and releases your email address and handle. Feedback you gave in someone's playtest stays with their project, with your name removed. A studio you're the only owner of has to get another owner or be deleted first. To get a copy of your data, correct something you can't change yourself, or delete an account you can't sign in to, email hello [at] rpglab [dot] io from the address on your account.
- To stop mailing-list email, use the unsubscribe link in any send, or email the address above.
- If you're in the EU or the UK, you also have the right to complain to your data protection authority. Your local law may give you more rights.
Age
RPG Lab is for people 16 and older and doesn't knowingly collect data from anyone younger. An account that turns out to belong to someone younger is closed and its data deleted.
Changes
When this policy changes in a way that matters, the date at the top changes and the site says so. The terms of service are a separate page.