Privacy Policy - Mythframe
Last updated: September 1, 2026
1. Data controller
Mythframe is a privately developed and operated digital project.
For questions about this Policy, the use of personal data, or the exercise of your rights, write to:
Website: https://www.mythframe.it/
2. Scope of this Policy
This Privacy Policy describes how Mythframe collects, uses, stores, and protects the personal data of users who visit the website, create an account, use narrative features, make purchases, or sign in through Google or Discord.
This Policy covers data processed directly by Mythframe. External services used by the website, such as Google, Discord, Stripe, and OpenAI, also process certain data under their respective privacy policies.
3. Data provided during registration
When a user creates an account through the traditional form, Mythframe may collect:
- username;
- display name;
- email address;
- password, stored exclusively in encrypted form through the WordPress system;
- email-address verification status;
- account type and associated plan;
- account creation date;
- user preferences and settings.
Mythframe cannot view the user's original password.
4. Sign-in with Google
Mythframe allows users to register, sign in, or link an account using Google OAuth 2.0 and OpenID Connect.
When the user selects “Sign in with Google,” Mythframe requests only the following permissions:
openid;email;profile.
Through these permissions, Google may make the following available to Mythframe:
- the unique Google account identifier (
sub); - the email address associated with the account;
- the email-address verification status;
- the name or display name;
- basic profile information, such as the profile picture, if made available by Google.
Mythframe uses this data solely to:
- verify the user's identity;
- create a new Mythframe account;
- sign in to an already linked account;
- link Google to an existing Mythframe account;
- prevent duplicate accounts and fraudulent access;
- display the name selected by the user when a new account is created.
Mythframe stores the unique Google identifier needed to recognize future sign-ins in its database. When a new account is created, it also stores the email address and display name as Mythframe account data.
The Google profile picture and any other unused profile information are not currently stored by Mythframe.
Mythframe does not request or access:
- Gmail messages;
- Google Drive files;
- Google contacts;
- calendars;
- private photographs;
- browsing history;
- Google payment data;
- the Google account password.
The Google access token is used temporarily by the server to retrieve the information needed for authentication. It is not stored in the database. Mythframe does not request or store Google refresh tokens for ongoing access to user data.
Data obtained through Google is not:
- sold;
- transferred to data brokers;
- used for personalized advertising;
- used for commercial profiling;
- used to determine creditworthiness;
- included in content sent to artificial intelligence systems;
- used to train Mythframe artificial intelligence models.
Use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
5. Sign-in with Discord
Mythframe allows users to register, sign in, or link an account using Discord OAuth 2.0.
Mythframe requests only the following scopes:
identify;email.
Discord may therefore provide Mythframe with:
- the unique Discord identifier;
- the username or display name;
- the email address;
- the email-address verification status;
- basic profile information.
This data is used solely to create, recognize, or link the Mythframe account.
Mythframe does not access Discord messages, joined servers, friends lists, channels, private conversations, or user activity.
The Discord access token is used temporarily during authentication and is not stored in the database.
6. Data relating to use of Mythframe
The following may be stored while the service is used:
- created campaigns and settings;
- characters, statistics, inventories, and progress;
- messages and actions entered during play;
- generated narrative content;
- campaign memories, summaries, and state;
- uploaded or generated images, audio, and other content;
- invitations to and participation in multiplayer campaigns;
- narrative preferences and account settings;
- usage history, limits, and available credits;
- reports, support requests, and communications sent to support.
This data is necessary to provide a persistent narrative experience and allow users to resume their campaigns.
7. Use of artificial intelligence systems
To generate narratives, images, audio readings, and other content, Mythframe may send artificial intelligence providers, currently OpenAI, the information strictly necessary to process the request.
Data sent may include:
- instructions and messages written by the user;
- character information;
- campaign state;
- summaries and narrative memories;
- content required for the requested generation.
Users should not enter their own or other people's sensitive personal data into campaigns when it is not necessary.
External providers' use of data is also governed by their respective terms and privacy policies.
8. Payments and subscriptions
If a user purchases a subscription, credits, or other services, payment is handled through Stripe.
Mythframe may store:
- the Stripe customer identifier;
- the payment or subscription identifier;
- the product or plan purchased;
- the amount, currency, date, and status of the transaction;
- subscription status;
- essential purchase history.
Complete card details are neither received nor stored directly by Mythframe. They are processed by Stripe under its privacy policy and security standards.
9. Technical and security data
The following may be processed automatically while the website is used:
- IP address;
- date and time of requests;
- technical information about the browser and device;
- application errors and security logs;
- sign-in and registration attempts;
- information needed to prevent abuse, fraud, and automated access.
The IP address may be used to apply temporary limits to login, registration, email-resending, and social-authentication attempts.
10. Cookies and local data
Mythframe uses technical cookies and equivalent tools needed to:
- maintain the WordPress session;
- recognize the authenticated user;
- protect OAuth sign-in through a temporary security value;
- store technical preferences;
- manage invitations and game sessions;
- prevent abuse and forged requests.
The temporary cookie used to protect Google or Discord sign-in is HttpOnly, has a short lifetime, and is not used for advertising or profiling.
Data obtained through Google or Discord is not used for advertising purposes.
11. Push notifications
If the user voluntarily enables push notifications, Mythframe may store the browser push service's technical address and the associated keys needed for delivery.
Notifications can be disabled in browser or device settings. Push services may be operated by providers such as Apple, Google, Mozilla, or the maker of the browser being used.
12. Purposes and legal bases
Data is processed to:
- create and manage the account;
- authenticate the user;
- provide narrative and multiplayer features;
- store campaigns and progress;
- manage payments and subscriptions;
- respond to support requests;
- protect users and infrastructure;
- prevent fraud and abusive use;
- comply with any legal obligations;
- improve the stability, security, and operation of the service.
The legal bases may include:
- performance of the service requested by the user;
- compliance with legal obligations;
- legitimate interests in the security and proper operation of the service;
- user consent, where required for optional features.
13. Recipients and service providers
To the extent necessary, data may be processed by:
- hosting and technical-infrastructure providers;
- email providers;
- Google and Discord for the authentication selected by the user;
- Stripe for payments and subscriptions;
- OpenAI for artificial intelligence features;
- browser push-service providers;
- technical or professional consultants subject to confidentiality obligations;
- public authorities, where required by law.
Mythframe does not sell personal data or provide user lists to third parties for commercial purposes.
14. International transfers
Some providers, including Google, Discord, Stripe, and OpenAI, may process data outside the European Economic Area.
In such cases, processing takes place subject to safeguards required by applicable law and the instruments adopted by the relevant providers, such as adequacy decisions or standard contractual clauses.
15. Data retention
Account and campaign data is retained while the account remains active or for as long as necessary to provide the service.
In particular:
- the Google or Discord identifier is retained while the provider remains linked or until the account is deleted;
- Google and Discord access tokens are not retained after authentication;
- the OAuth security state normally expires within ten minutes;
- campaigns and game content are retained until they or the account are deleted;
- payment and transaction data may be retained for periods required by accounting, tax, or legal-protection rules;
- technical logs and security data are retained for as long as needed to diagnose problems and prevent abuse;
- residual copies may remain temporarily in technical backups until their normal rotation.
When data is no longer needed, it is deleted or anonymized unless legal retention obligations apply.
16. Security
Mythframe adopts reasonable technical and organizational measures to protect data, including:
- HTTPS connections;
- passwords stored in encrypted form by WordPress;
- email-verification tokens stored in a form that is not directly readable;
- protections against forged requests;
- rate limiting for sign-in attempts;
- protected authentication cookies;
- Client Secrets stored in server configuration rather than public code;
- restricted access to administrative data.
No system can, however, guarantee absolute security.
17. User rights
Where provided for by applicable law, users may request:
- access to their data;
- rectification of inaccurate data;
- deletion;
- restriction of processing;
- data portability;
- objection to processing;
- withdrawal of consent, without affecting processing already carried out;
- information about recipients and processing methods.
Requests may be sent to assistenza@mythframe.it.
Data subjects may also lodge a complaint with the Italian Data Protection Authority: https://www.garanteprivacy.it/.
18. Revoking Google or Discord authorization
Users can revoke the authorization granted to Mythframe through their Google account security settings or Discord's authorized applications section.
Revocation prevents future sign-ins through that provider but does not automatically delete the Mythframe account or data already stored.
To request deletion of the account and associated data, follow the instructions at:
https://www.mythframe.it/eliminazione-dati/
or write to assistenza@mythframe.it, stating the email address associated with the account.
19. Minors
Mythframe is not specifically designed for or directed at children under the age of 14.
Users who are minors must use the service in compliance with applicable law and, where necessary, with the authorization and supervision of a person exercising parental responsibility.
20. Changes to this Policy
This Privacy Policy may be updated to reflect technical, regulatory, or functional changes.
The updated version will be published on this page with the date of the latest revision. Users may receive additional notice in the event of material changes.

