RuleVault iconRuleVault
FeaturesHow it worksEcosystemGuidesUpdatesJoin alpha
Join alpha
Legal

Privacy Policy

Last updated: July 25, 2026

Who we are

RuleVault is a board game rules companion app developed and operated by Dennis Essenburg, based in the Netherlands. When this policy says "we", "us", or "RuleVault", it means Dennis Essenburg.

For privacy questions or requests, contact us at [email protected].

What data we collect and why

Account data

When you create an account we collect your email address and, if you sign in via Google, Facebook, or Discord, your name and profile picture from that provider. We use this to identify you across sessions and to send you transactional emails (password reset, etc.). We never use your email for marketing without your explicit opt-in.

Usage data

We store which games you look up, which guides you open, and how many AI rules questions you ask in a given month. We use this to enforce the free-tier limit (10 AI questions per month), to improve the app, and to understand which games our users care about most.

AI questions

When you ask a rules question, your question text is sent to our backend, where two things happen. First, Cloudflare Workers AI turns it into a search embedding so we can find the most relevant passages in our rules database. Second, those passages and your question are sent to Anthropic's Claude, which generates the answer. If Anthropic is temporarily unavailable, your question falls back to OpenAI (GPT-4o-mini) so you still get a result. Each provider processes your question only to return that result; the providers that commit to it do not use API inputs to train their models — Anthropic does not train on API inputs. We log your question and its answer to your account and count it toward your monthly question allowance, so we can enforce the free-tier limit and improve answer quality over time.

Device and technical data

If you agree to analytics (see below), we collect basic technical data such as your device type, operating system, and app version, and use it for crash reporting and compatibility improvements. We do not fingerprint your device.

Theme preference

Your dark/light mode preference is stored in your browser's localStorage under the key ludo-theme. This data never leaves your device.

Analytics and session recording

We use analytics to understand which parts of RuleVault people actually use, and to find errors. This is off by default. We ask you once, and nothing is collected unless you say yes.

What we collect if you agree:

  • Screens and pages you open — recorded as a general route (for example /game/:id), not which specific game you opened.
  • Errors — when the app fails, we record the error message, where in the code it happened, your app version, and your device type.
  • Session recordings — a replay of how you moved through the interface, captured for a fraction of sessions. In the app, all text you type and all images are masked before the recording leaves your device. Network content is not captured.
  • Heatmaps (website only) — aggregated maps of where visitors click and how far they scroll on a page.

Your AI rules questions are not sent to our analytics providers. If you are signed in, analytics events are linked to your account ID so we can tell a returning user from a new one.

How to change your mind:

  • In the app — Profile → Preferences → Usage analytics. Turning it off takes effect immediately and stops any recording in progress.
  • On this website — clear this site's data in your browser, and you will be asked again on your next visit.

How we process rulebook content

RuleVault generates structured game guides by processing official rulebooks. Here is exactly how that works and what it means for your data:

  • We never store or serve rulebook PDFs. Rulebooks are downloaded privately, processed on our systems to extract structured content (setup steps, turn guides, FAQ), and then the source PDF is discarded. Users cannot download rulebooks from RuleVault.
  • We generate transformed content, not copies. What we store in our database is a structured guide derived from the rulebook — not the raw rulebook text. Each piece of content includes a reference to the page and section it came from.
  • We always link back to the official source. Every game guide includes a link to where you can read the original rulebook directly from the publisher.
  • This is your data, not ours. The rules themselves belong to each game's publisher. We are an interpretation and navigation layer, not a redistribution platform.

If you are a game publisher and have concerns about how your game is presented in RuleVault, please contact us at [email protected] and we will respond promptly.

Who we share data with

We use a small number of third-party services to operate RuleVault:

  • Supabase — our database and authentication provider. Your account data and usage data are stored on Supabase infrastructure. Supabase is SOC 2 Type II certified. Supabase privacy policy →
  • Google / Meta / Discord — only if you choose to sign in via these providers. We receive only the data they pass to us during authentication.
  • Anthropic — when you ask an AI rules question, your question is processed by Anthropic's Claude API to generate an answer. Anthropic does not use API inputs to train their models. Anthropic privacy policy →
  • Cloudflare — when you ask an AI rules question, your question text is sent to Cloudflare Workers AI to generate the search embedding we use to find the most relevant rulebook passages. Cloudflare privacy policy →
  • OpenAI — used only as a fallback answer provider. If Anthropic is unavailable, your question is sent to OpenAI (GPT-4o-mini) to generate the answer. OpenAI does not use API inputs to train their models. OpenAI privacy policy →
  • Firebase Hosting (Google) — our marketing website is hosted on Google's Firebase Hosting. Firebase privacy policy →
  • PostHog — our product analytics, session replay, and error tracking provider, used in the app and on this website. Only active if you agree to analytics. Our PostHog project is hosted in the European Union. PostHog acts as our data processor. PostHog privacy policy →
  • Microsoft Clarity — provides heatmaps and session recordings on this website only; it is not used in the app. Only active if you agree to analytics. Microsoft acts as an independent data controller for Clarity, not as our processor, which means Microsoft uses this data for its own purposes, including advertising, under its own privacy statement. You can opt out of Microsoft's advertising use directly at optout.aboutads.info. Microsoft privacy statement →

We do not sell your data. Aside from Microsoft Clarity's own advertising use described above, which applies only on this website and only if you agree to analytics, we do not share your data for advertising purposes.

Where your data is processed

Your account and usage data are stored in the European Union (Supabase, hosted on AWS eu-central-1 in Frankfurt).

When you ask an AI rules question, the question text is transferred to service providers located in the United States — Anthropic and Cloudflare, and OpenAI when it is used as a fallback. These transfers are made under the EU Standard Contractual Clauses (SCCs). The specific SCC and data-processing-agreement basis applies per each provider's own terms.

Analytics data, if you agree to it, is stored with PostHog in the European Union (Amazon Web Services eu-central-1 in Frankfurt) — we deliberately chose their European region so this data does not leave the EEA.

Microsoft Clarity is the exception. On this website, your contract is with Microsoft Ireland Operations Limited, but Microsoft may transfer the data to the United States under Standard Contractual Clauses between its own entities.

How long we keep your data

  • Account data — kept for as long as your account is active. Deleted within 30 days of account deletion.
  • AI question logs — kept for 12 months for quality improvement, then deleted.
  • Usage data — kept for 24 months, then aggregated and anonymised.
  • Analytics events and error reports (PostHog) — kept for 12 months.
  • Session recordings (Microsoft Clarity, website only) — kept for 30 days; heatmap data and a small sample of recordings for up to 9 months. These periods are set by Microsoft, not by us.

Your rights (GDPR)

As we operate from the Netherlands, EU General Data Protection Regulation (GDPR) applies. You have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your account and associated data.
  • Portability — request your data in a machine-readable format.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interest.

To exercise any of these rights, email [email protected]. We will respond within 30 days. If you are unsatisfied, you may lodge a complaint with the Dutch data protection authority: Autoriteit Persoonsgegevens .

Cookies and local storage

The data we keep on your device falls into two groups.

Strictly necessary — always present, no consent required:

  • Your theme preference, under the localStorage key ludo-theme.
  • Your authentication session token, so you stay signed in.
  • Your analytics choice, so we do not ask you again.

These never leave your device, apart from the session token used to authenticate you.

Analytics — only if you agree:

  • PostHog — stores an identifier in localStorage and a first-party cookie so repeat visits can be recognised as the same person.
  • Microsoft Clarity (website only) — sets its own first-party cookies to link a visitor's page views into one session. Microsoft may also set cookies associated with its advertising services.

Nothing in the second group is loaded, and no analytics cookie is set, until you agree. If you decline, those scripts are never downloaded at all.

Children

RuleVault is not directed at children under 16, the minimum age of consent for data processing in the Netherlands under GDPR Article 8. We do not knowingly collect personal data from children under this age. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

Changes to this policy

We may update this policy as the product evolves. When we make material changes, we will update the date at the top of this page and, for significant changes, notify you by email.

RuleVault iconRuleVault

Know the rules. Rule the game.

Early accessJoin the alpha waitlist
ProductUpdates & changelog
EcosystemBoard Games Tracker
LegalPrivacy PolicyTerms of Service
© 2026 RuleVault. Made for board gamers. Board Games Tracker