Privacy Policy
Last updated: July 2026
Data Controller
Lazy Lands is an independent project operated by Daniel López González, who acts as the data controller for the personal data processed through the application. For any question about this policy or your personal data, contact the controller at contacto@danilopgon.com.
Data We Collect
When you use Lazy Lands, we collect:
- Email address: used for authentication and product communications.
- Campaign content: the notes, NPCs, factions, session logs, and other content you create inside the application. This data is yours and is only accessible to you.
- Authentication tokens: technical tokens (Supabase) stored in your browser to maintain your session.
Legal Basis
Processing is based on GDPR Art. 6.1.b: processing is necessary for the performance of a contract to which you are party (the Lazy Lands terms of service), or in order to take steps at your request prior to entering into a contract.
AI Processing (the Scribe)
Lazy Lands generates editable proposals with the help of a large language model. When you choose to analyze a campaign, register a session, or prepare a next session, the campaign content involved — your premise, session summaries, world state, NPCs, factions, arcs, and accepted memories — is sent to a third-party AI provider, which returns a proposal. Lazy Lands currently uses these providers on their free service tiers.
Under those free tiers, the provider processes your content to return the proposal and, according to its own terms, may also use submitted content to improve its own models and services. For that reuse the provider acts as an independent controller under its own privacy policy, not as our processor. We never use your content to train a model of our own, and we never sell or share it for marketing purposes.
The legal basis for sending your content to the AI provider to produce the proposal you requested is GDPR Art. 6.1.b (performance of the service you asked for); using the AI features is always optional. This academic release does not yet implement a separate, granular consent step or an in-app withdrawal mechanism for the provider's own reuse of content under its free tier — a known limitation. Until it does, please rely on the caution below and keep your entries free of personal or confidential data.
Because free-tier providers may reuse submitted content, do not include real personal data about yourself or other people, or confidential third-party information, in your campaign content. Keep entries to fictional campaign material.
Private notes are never sent to the AI provider, and dismissed suggestions never re-enter the model context.
Depending on availability, the AI provider that processes your content may be one of the following:
- Google (Gemini) — United States.
- Groq — United States.
- Mistral AI — European Union (France).
- Cerebras — United States.
International Data Transfers
Some of the providers we use are based in, or transfer data to, the United States (Google, Groq, and Cerebras for AI generation; Vercel and Railway for hosting). For hosting and for delivering AI proposals, these transfers rely on the safeguards required by Chapter V of the GDPR, principally the European Commission's Standard Contractual Clauses. Where a free-tier AI provider reuses submitted content for its own purposes, that processing is governed by the provider's own terms and privacy policy rather than by our processing agreement. Mistral AI processes data within the European Union.
Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate data.
- Right to erasure: request deletion of your personal data ("right to be forgotten").
- Right to restriction: request that we limit the processing of your data in certain circumstances.
- Right to portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right to lodge a complaint: if you believe your data is not being handled lawfully, lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es).
To exercise any of these rights, contact the data controller at contacto@danilopgon.com. We respond within the time limits set by the GDPR.
Data Retention
We retain your data for as long as your account is active. Deleting your account removes all campaign data. Authentication logs are retained for up to 90 days for security purposes.
No Third-Party Sharing
We do not sell, rent, or share your personal data with third parties for marketing purposes. Beyond the AI provider described above, we rely on infrastructure processors that act on our instructions: Supabase for database and authentication, Vercel for frontend hosting, and Railway for backend hosting. Each acts under a data processing agreement.