01. Data Controller Identification
This Privacy Policy explains how PanicDM (panicdm.com), operated by LazyLabs, a trade name of Kim Vereecke ("we", "us", "our"), registered in Belgium, processes and protects personal data collected through the platform.
02. Accurate Breakdown of Collected Data
We collect and process only the minimal information strictly required to run your account, persist your tabletop encounters, maintain billing ledgers, and secure the platform:
Email address, encrypted password hash, display name, default party size, average party level, D&D 5e preferences, and live credit balances.
Procedurally generated encounter records linked to your account in Microsoft SQL Server (title, environment, tone, difficulty, room descriptions, stat blocks, and raw JSON).
An immutable append-only ledger tracking all credit additions, spends, and refunds with timestamps and associated Paddle transaction reference IDs.
User-submitted ratings (1–5), qualitative feedback messages, encounter diagnostic context, retention bonus credit records, and administrator resolution replies.
03. Strictly Functional Cookies & Storage
Full technical disclosure of all first-party cookies, local storage, session state, and security tokens.
PanicDM does not employ third-party advertising cookies, cross-site marketing trackers, behavioral profiling scripts, Google Analytics, or invasive digital fingerprinting.
Under the EU ePrivacy Directive (Directive 2002/58/EC Art. 5(3)) and GDPR, cookies and storage mechanisms that are strictly necessary to provide a service explicitly requested by the user are exempt from consent banner mandates. All storage items utilized across PanicDM fulfill essential security, authentication, anti-abuse, or transaction purposes:
| Mechanism / Key | Type & Domain | Duration | Strictly Necessary Purpose |
|---|---|---|---|
| .AspNetCore.Identity.Application | First-Party Cookie (panicdm.com) | Session / 14 Days | Encrypted identity cookie (HttpOnly, Secure, SameSite=Lax) maintaining your authenticated session. |
| __RequestVerificationToken | First-Party Cookie (panicdm.com) | Session | Cryptographic Cross-Site Request Forgery (CSRF) token protecting form posts and API actions. |
| .AspNetCore.Correlation.Google.* | First-Party Cookie (panicdm.com) | 15 Minutes | Short-lived cryptographic state nonce preventing login session fixation and OAuth CSRF during Google Sign-In. |
| Identity.External | First-Party Cookie (panicdm.com) | Handshake (Minutes) | Temporary encrypted container holding external Google claims before establishing your primary user session. |
| panicdm_guest_used | First-Party Cookie (panicdm.com) | 30 Days | Anti-abuse rate limiting cookie enforcing the single free trial encounter generator policy for unauthenticated visitors. |
| panicdm_guest_trial_used | Browser localStorage | Persistent | Client-side anti-abuse flag preventing automated guest generation script abuse. |
| panicdm_guest_encounter_* | Browser sessionStorage | Tab Session | Preserves generated guest encounter data across the signup flow so your encounter is not lost upon registration. |
| __cf_bm, cf_clearance | Subprocessor (Cloudflare) | 30 Mins – 1 Year | Cloudflare Turnstile bot detection and DDoS mitigation token protecting login and register endpoints against credential stuffing. |
| _paddle_cid, paddlejs_* | Subprocessor (Paddle.com) | Session – 1 Year | Functional checkout session orchestration, local currency calculation, and transaction fraud prevention by our Merchant of Record. |
When you choose "Sign in with Google", your browser briefly connects to Google's authentication servers (accounts.google.com). Google operates its own cookies on its own domain to authenticate your Google account.
PanicDM does not set, access, inspect, or store any cookies on Google's domains. PanicDM receives only an encrypted authorization code from Google to verify your email address, after which only PanicDM's functional session cookies listed above are maintained. PanicDM does not run Google Analytics, Google Tag Manager, or Google advertising scripts.
04. AI Procedural Generation & Privacy (Groq Cloud API)
When you trigger an encounter generation, your tactical parameters (party level, player count, environment, and user prompt text) are transmitted via secure TLS 1.3 to Groq, Inc. for sub-second structured inference.
- Ephemeral In-Memory Processing: Groq processes generation prompts in volatile memory to construct the tactical response.
- Zero AI Training: Your prompt text, campaign ideas, and generated stat blocks are never used to train foundational AI models.
- No Broker Sales: We never sell, monetize, or transmit your prompt parameters to advertisers or data brokers.
05. Verified Third-Party Subprocessors
We engage only vetted service providers operating under strict confidentiality, data protection agreements, and EU Standard Contractual Clauses (SCCs):
| Subprocessor | Role / Purpose | Location | Data Shared |
|---|---|---|---|
| Paddle.com Market Ltd | Merchant of Record, Payment Processing & VAT | United Kingdom / Ireland (EU) | Transaction amounts, user ID, payment tokens |
| Groq, Inc. | High-Speed AI Inference Engine | United States (Standard Contractual Clauses) | Ephemeral prompt context (party level, prompt text) |
| MailerSend / MailerLite | Transactional Email Dispatch | European Union | Recipient email, account confirmation & support replies |
| Cloudflare, Inc. | Turnstile Bot Mitigation & CDN/DDoS | United States / Global Edge | Client IP, browser headers for threat verification |
| Google LLC (Optional) | OAuth Identity Provider (Login with Google) | United States / Global | Google Account ID, verified email (only if chosen by user) |
06. Data Retention & Automated GDPR Account Purge
We maintain data only as long as necessary to provide your active service and fulfill statutory accounting obligations:
- General Logs: Daily rolling server logs are retained for 30 days before automatic deletion.
- Billing & Webhook Logs: Financial webhook audit logs are retained for 90 days to resolve transaction disputes.
- Automated Self-Service Deletion: You can permanently delete your PanicDM account at any time in your Profile Settings. When you initiate deletion, our system immediately executes an automated purge:
- Permanently deletes all your saved encounters and generation outputs.
- Anonymizes credit ledger records (stripping your user identity while preserving transaction hashes for tax accounting).
- Anonymizes user feedback and security logs.
- Permanently destroys your identity account credentials.
07. Your Rights Under the GDPR
Under the General Data Protection Regulation (EU) 2016/679, you hold the following statutory rights:
- Right to Access (Art. 15): Request a copy of the personal data held about you.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete account preferences.
- Right to Erasure (Art. 17): Request the permanent deletion of your personal data via Settings or support.
- Right to Restriction of Processing (Art. 18): Restrict processing under contested circumstances.
- Right to Data Portability (Art. 20): Receive your encounter histories in a structured, machine-readable format.
- Right to Object (Art. 21): Object to data processing based on legitimate interest.
To exercise any of these rights, contact our Data Protection Officer at [email protected]. We respond to all verified requests within 30 days without charge.
Supervisory Authority Contact:
You have the right to lodge a complaint with the Belgian Data Protection Authority:
Gegevensbeschermingsautoriteit (GBA) / Autorité de protection des données (APD)
Drukpersstraat 35, 1000 Brussels, Belgium • Website: gegevensbeschermingsautoriteit.be
