shield GDPR COMPLIANT • ZERO TRACKING COOKIES

Privacy Policy

Effective Date: January 1, 2026 • Last Updated: September 2026

lock

Privacy by Default • Belgian & EU Standards

PanicDM operates strictly under the EU General Data Protection Regulation (GDPR). We do not use third-party advertising cookies, cross-site trackers, or sell your data. Your campaign prompts are never used to train foundational AI models.

01. Data Controller Identification

This Privacy Policy explains how PanicDM (panicdm.com), operated by LazyLabs, a trade name of Kim Vereecke ("we", "us", "our"), registered in Belgium, processes and protects personal data collected through the platform.

Data Controller: Kim Vereecke (operating under the trade name LazyLabs) Enterprise / VAT Number: BE 1041.759.412 Registered Address: Beke 81, 9950 Lievegem, Belgium (European Union) 🇧🇪 Official Privacy Contact: [email protected]

02. Accurate Breakdown of Collected Data

We collect and process only the minimal information strictly required to run your account, persist your tabletop encounters, maintain billing ledgers, and secure the platform:

badge Account & Profile Data

Email address, encrypted password hash, display name, default party size, average party level, D&D 5e preferences, and live credit balances.

history_edu Encounter Generation History

Procedurally generated encounter records linked to your account in Microsoft SQL Server (title, environment, tone, difficulty, room descriptions, stat blocks, and raw JSON).

receipt_long Credit & Billing Ledger

An immutable append-only ledger tracking all credit additions, spends, and refunds with timestamps and associated Paddle transaction reference IDs.

rate_review Feedback & Diagnostics

User-submitted ratings (1–5), qualitative feedback messages, encounter diagnostic context, retention bonus credit records, and administrator resolution replies.

03. Strictly Functional Cookies & Storage

Full technical disclosure of all first-party cookies, local storage, session state, and security tokens.

PanicDM does not employ third-party advertising cookies, cross-site marketing trackers, behavioral profiling scripts, Google Analytics, or invasive digital fingerprinting.

Under the EU ePrivacy Directive (Directive 2002/58/EC Art. 5(3)) and GDPR, cookies and storage mechanisms that are strictly necessary to provide a service explicitly requested by the user are exempt from consent banner mandates. All storage items utilized across PanicDM fulfill essential security, authentication, anti-abuse, or transaction purposes:

Mechanism / Key Type & Domain Duration Strictly Necessary Purpose
.AspNetCore.Identity.Application First-Party Cookie (panicdm.com) Session / 14 Days Encrypted identity cookie (HttpOnly, Secure, SameSite=Lax) maintaining your authenticated session.
__RequestVerificationToken First-Party Cookie (panicdm.com) Session Cryptographic Cross-Site Request Forgery (CSRF) token protecting form posts and API actions.
.AspNetCore.Correlation.Google.* First-Party Cookie (panicdm.com) 15 Minutes Short-lived cryptographic state nonce preventing login session fixation and OAuth CSRF during Google Sign-In.
Identity.External First-Party Cookie (panicdm.com) Handshake (Minutes) Temporary encrypted container holding external Google claims before establishing your primary user session.
panicdm_guest_used First-Party Cookie (panicdm.com) 30 Days Anti-abuse rate limiting cookie enforcing the single free trial encounter generator policy for unauthenticated visitors.
panicdm_guest_trial_used Browser localStorage Persistent Client-side anti-abuse flag preventing automated guest generation script abuse.
panicdm_guest_encounter_* Browser sessionStorage Tab Session Preserves generated guest encounter data across the signup flow so your encounter is not lost upon registration.
__cf_bm, cf_clearance Subprocessor (Cloudflare) 30 Mins – 1 Year Cloudflare Turnstile bot detection and DDoS mitigation token protecting login and register endpoints against credential stuffing.
_paddle_cid, paddlejs_* Subprocessor (Paddle.com) Session – 1 Year Functional checkout session orchestration, local currency calculation, and transaction fraud prevention by our Merchant of Record.
info Clarification Regarding External Google Account Cookies

When you choose "Sign in with Google", your browser briefly connects to Google's authentication servers (accounts.google.com). Google operates its own cookies on its own domain to authenticate your Google account. PanicDM does not set, access, inspect, or store any cookies on Google's domains. PanicDM receives only an encrypted authorization code from Google to verify your email address, after which only PanicDM's functional session cookies listed above are maintained. PanicDM does not run Google Analytics, Google Tag Manager, or Google advertising scripts.

04. AI Procedural Generation & Privacy (Groq Cloud API)

When you trigger an encounter generation, your tactical parameters (party level, player count, environment, and user prompt text) are transmitted via secure TLS 1.3 to Groq, Inc. for sub-second structured inference.

  • Ephemeral In-Memory Processing: Groq processes generation prompts in volatile memory to construct the tactical response.
  • Zero AI Training: Your prompt text, campaign ideas, and generated stat blocks are never used to train foundational AI models.
  • No Broker Sales: We never sell, monetize, or transmit your prompt parameters to advertisers or data brokers.

05. Verified Third-Party Subprocessors

We engage only vetted service providers operating under strict confidentiality, data protection agreements, and EU Standard Contractual Clauses (SCCs):

Subprocessor Role / Purpose Location Data Shared
Paddle.com Market Ltd Merchant of Record, Payment Processing & VAT United Kingdom / Ireland (EU) Transaction amounts, user ID, payment tokens
Groq, Inc. High-Speed AI Inference Engine United States (Standard Contractual Clauses) Ephemeral prompt context (party level, prompt text)
MailerSend / MailerLite Transactional Email Dispatch European Union Recipient email, account confirmation & support replies
Cloudflare, Inc. Turnstile Bot Mitigation & CDN/DDoS United States / Global Edge Client IP, browser headers for threat verification
Google LLC (Optional) OAuth Identity Provider (Login with Google) United States / Global Google Account ID, verified email (only if chosen by user)

06. Data Retention & Automated GDPR Account Purge

We maintain data only as long as necessary to provide your active service and fulfill statutory accounting obligations:

  • General Logs: Daily rolling server logs are retained for 30 days before automatic deletion.
  • Billing & Webhook Logs: Financial webhook audit logs are retained for 90 days to resolve transaction disputes.
  • Automated Self-Service Deletion: You can permanently delete your PanicDM account at any time in your Profile Settings. When you initiate deletion, our system immediately executes an automated purge:
    1. Permanently deletes all your saved encounters and generation outputs.
    2. Anonymizes credit ledger records (stripping your user identity while preserving transaction hashes for tax accounting).
    3. Anonymizes user feedback and security logs.
    4. Permanently destroys your identity account credentials.

07. Your Rights Under the GDPR

Under the General Data Protection Regulation (EU) 2016/679, you hold the following statutory rights:

  • Right to Access (Art. 15): Request a copy of the personal data held about you.
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete account preferences.
  • Right to Erasure (Art. 17): Request the permanent deletion of your personal data via Settings or support.
  • Right to Restriction of Processing (Art. 18): Restrict processing under contested circumstances.
  • Right to Data Portability (Art. 20): Receive your encounter histories in a structured, machine-readable format.
  • Right to Object (Art. 21): Object to data processing based on legitimate interest.

To exercise any of these rights, contact our Data Protection Officer at [email protected]. We respond to all verified requests within 30 days without charge.

Supervisory Authority Contact:

You have the right to lodge a complaint with the Belgian Data Protection Authority:

Gegevensbeschermingsautoriteit (GBA) / Autorité de protection des données (APD)

Drukpersstraat 35, 1000 Brussels, Belgium • Website: gegevensbeschermingsautoriteit.be

An unhandled error has occurred. Reload 🗙

Reconnecting to the Weave...

The arcane channel to the dungeon server wavered. This is (hopefully) just a temporary timeout — holding your table's place while we reconnect you shortly.

Re-Attuning Astral Link...

Temporary connection lull detected. Don't worry, your encounter session is preserved. We should be back soon — retrying in s...

The Weave Has Gone Silent

The connection timed out and could not be restored automatically. The servers should be back momentarily. Please re-cast or reload your grimoire.

Tavern Rest: Session Paused

The dungeon server has temporarily paused this live session. Your room layouts and campaign data remain safely preserved in the vault.

Failed to Resume Session

Could not resume the active session. This temporary timeout might require refreshing your browser to return to your table.