Privacy policy
Last updated: 8 October 2026. This page covers the Polymancer waitlist on polymancer.app and its mirror go.polymancer.app and, from “The table” on, the table itself on play.polymancer.app.
Who we are
Polymancer is a browser-based 3D virtual tabletop developed by Andrei Chernomurov, Serbia, a private individual. He is the controller of your data, that is, the person responsible for it. Contact: hello@polymancer.app.
What we store
- your email address;
- the language of the page you signed up from (to write to you in it);
- whether you reserved a founder licence (the signup form does not offer this at the moment);
- a short label of where you came from, if the link had one (for example,
reddit); - when you signed up and confirmed;
- how many confirmation emails we sent you and when the last one went out.
We do not store your IP address with the waitlist. The signup form talks to our own server (play.polymancer.app), which, like any web server, keeps access logs with IP addresses for up to 14 days to fend off abuse, then deletes them. We do not use cookies. If you switch the language with the EN/RU buttons, the page remembers your choice in your browser’s storage; that stays on your device. On polymancer.app, page visits are counted with Cloudflare Web Analytics, which does not use cookies and does not track you across sites; like any request, it sees your IP address.
The waitlist is not for children: sign up only if you are 16 or older.
What we send
- right after you sign up, an email asking you to confirm your address;
- an email when the Polymancer alpha opens;
- an offer of the founder licence, a one-off way to back the project: what it includes and its price. It may come in the alpha email or on its own. It asks whether you want to reserve one; nothing is charged;
- an email when the beta opens. If you reserved a founder licence, it reminds you of that; buying is up to you;
- now and then, news about Polymancer and offers for people on the list, such as early access or bonuses in Polymancer.
Only about Polymancer: no advertising for anyone else. We never sell the list and share it only with the providers listed below, who run the service for us.
Legal basis
- The waitlist and the emails: your consent (GDPR Art. 6(1)(a)), which you give by confirming your email. You can withdraw it at any time.
- Before you confirm — keeping your address for up to 7 days and sending the email that asks you to confirm it (up to three times in total if you resubmit the form): our legitimate interest in answering the request you made by submitting the form and making sure the address is really yours (GDPR Art. 6(1)(f)).
- Access logs with IP addresses, rate limits on the form and backups: our legitimate interest in keeping the service secure and protecting it from abuse (GDPR Art. 6(1)(f)).
How long
- If you do not confirm your email, it is deleted after 7 days.
- If you confirm, we keep it until six months after the Polymancer beta opens and then delete it. We delete it earlier if you unsubscribe or if Polymancer stops before that. The beta email tells you the exact date.
- The database with the waitlist is backed up daily and each copy is kept for up to 15 days. The copy stored outside our server (Cloudflare R2) is encrypted; copies on the server itself are accessible only to its administrator. Whenever an address is deleted — automatically after the periods above, when you unsubscribe or when you ask — it is removed from the list itself at once; we do not edit backups, so it stays in them until they expire — no longer than 15 days.
Where and who helps us
- Hetzner, in Finland (EU): our own server that stores the waitlist and the access logs.
- polymancer.app is hosted on Cloudflare Pages. Cloudflare delivers its pages and, like any host, sees the IP address of your request, but it does not receive your email — the form sends it straight to our server.
- Cloudflare Web Analytics: counts page visits, as described above.
- polymancer.app is also available from our own server at go.polymancer.app (Hetzner, Finland), for visitors who cannot reach Cloudflare. It keeps the same access log for up to 14 days and has no Cloudflare Web Analytics; if you sign up there, the links in the confirmation email lead back to it.
- Cloudflare R2: stores the encrypted backups of our database for up to 15 days. Cloudflare cannot read them.
- Zoho Mail, in its EU data centre: the mailbox for hello@polymancer.app. It receives the emails you send us and keeps our replies.
- Emails are sent through Resend, from its EU region (Ireland); it receives only your address and the message.
Cloudflare and Resend are companies based in the United States, so your data may be accessed from outside the EU. Such transfers are covered by the EU Standard Contractual Clauses in their data processing agreements.
Your rights
Every email has a link to a page where one button deletes your address from the list — not marks it, deletes it. That also withdraws your consent and removes a founder reservation. You can also write to hello@polymancer.app to:
- see what we store about you and get a copy of it;
- correct or delete it;
- withdraw your consent;
- object to processing based on our legitimate interest;
- restrict processing while a request is being sorted out;
- get your data in a machine-readable form to take elsewhere (portability).
For now we handle these requests by hand: write from the address in question, and we will answer within one month. We answer in English and Russian. The copy is a small machine-readable file (JSON) with everything the list holds about your address.
You can complain to the Serbian data protection authority, the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs), or to the data protection authority of your EU country.
The table: play.polymancer.app
This part covers the table itself — where game masters build scenes and players join them. The controller and the contact are the same as above.
The table: what we store
- Game master account: your email address and when the account was created. Sign-in links (valid for 30 minutes, single use) and sessions (30 days) are stored only as hashes. We also store which tables are yours and, during the closed alpha, the list of invited addresses.
- Players have no account. Our server issues a random guest ID that your browser keeps, and stores the name you type when you join a table (up to 32 characters), your role at that table and whether a game master removed you from it.
- What happens at a table: scenes, the chat and roll log (the last 400 entries), handouts, character sheets, personal notes, and the pictures and music uploaded to the table. An uploaded file can be opened by anyone who has its link; the link cannot be guessed.
- Table diary: for each play session — when it started, how many minutes it lasted, the peak number of players and how often each feature was used. No names, no participant IDs, no content, but each entry is linked to its table, and so to the game master’s account. It tells us whether the tool is actually used.
- Error reports from your browser: the error text, where in our code it happened, the table ID and your browser’s user agent. No names, chat or page address. Together with our server’s own error messages they go to the service log.
- IP addresses are used to limit request rates and are kept only in memory; they are not stored with anything above. The server’s access log keeps the IP address, time, requested address, browser user agent and other request headers (such as the page you came from) of each request for up to 14 days.
- In your browser: the session or guest token, your name, language, theme, table settings, the websites you allowed music from and, for a moment while you sign in, the table you came from — in its local storage. The table link of a game master contains their key, so it stays in the browser history. We do not use cookies.
The table: who sees what
- Everyone at a table sees the names of those at it, the chat and the open rolls. Secret rolls are seen only by game masters.
- A character sheet is seen by its player and by the game masters of the table; a personal note only by its author — not even by the game masters.
- The game masters of a campaign see each other’s email addresses, so that the owner knows whom they gave the role to. The invitation says so before you accept it.
- The game master who created a table controls it: deleting the table deletes everything at it, including players’ sheets, notes and pictures. Game masters can also edit or delete players’ character sheets with their portraits, but cannot read or change personal notes. What you add stays yours (see the terms of use).
- If a game master plays music from a link to another website, every browser at the table downloads it directly from that website, which sees your IP address. Players are asked before a new website is used for the first time; the browsers of game masters do not ask.
The table: legal basis
- Game master accounts and the tables they own: providing the service under our terms of use (GDPR Art. 6(1)(b)).
- Players without an account, and everything at a table while the terms are not in force: our legitimate interest, and the game master’s, in running the game the player joined (GDPR Art. 6(1)(f)).
- Error reports, the service and access logs, rate limits, the table diary and backups: our legitimate interest in keeping the service working, secure and worth developing (GDPR Art. 6(1)(f)). You can object, see “Your rights”.
The table: how long
- An account — until you ask us to delete it; we then delete it together with all tables it owns and its place on the alpha invite list.
- The alpha invite list — until the closed alpha ends, then deleted.
- A table — until its game master deletes it in My tables; it is removed from our server at once with everything at it. Pictures may stay in the browser cache of those who sat at it. A table started without an account is deleted 7 days after its game master last opened it.
- A file nobody uses any more — about 24 hours, then it is deleted.
- The table diary — 400 days, or less if the table is deleted earlier.
- The service log with error reports — up to 30 days; the access log — up to 14 days.
- Backups — up to 15 days, as in the waitlist part. If we ever have to restore the database from a backup, tables and accounts deleted after that backup are deleted again automatically.
- If Polymancer shuts down, we tell game masters by email in advance, so they can download their scenes, and then delete accounts and tables.
The table: where and who helps us
- Hetzner, in Finland (EU): the server that runs the table and stores everything above.
- Resend, from its EU region (Ireland): sends sign-in links; it receives only your address and the message.
- Cloudflare R2: the encrypted backups, which Cloudflare cannot read.
- Zoho Mail, in its EU data centre: the mailbox for hello@polymancer.app.
Service alerts go to our own Discord channel: counts and error texts with addresses, links and table IDs removed. The table page loads nothing from other websites except music from a link, described above. Transfers outside the EU are covered as in the waitlist part.
The table: your rights
- While the table exists and you are at it, a player can download their character as a file from the sheet menu (without the portrait). Personal notes cannot be downloaded yet — copy them yourself. When a game master deletes the table, your character and notes are deleted too.
- A game master can download any scene with its files from the scene menu and delete their tables in My tables.
- To delete an account, get a copy of what we store about you, correct it, or object to processing, write to hello@polymancer.app from the address you sign in with. We do it by hand for now and answer within one month. A player without an account can ask through the game master of the table, or tell us the table and the name they used; we may check with the game master.
- Your other rights and where to complain are as in “Your rights” above.
The table is not for children: use it only if you are 16 or older.
Политика конфиденциальности
Обновлено 8 октября 2026 года. Здесь описан лист ожидания Polymancer на polymancer.app и его зеркале go.polymancer.app, а начиная с «Стола» — сам стол на play.polymancer.app.
Кто мы
Polymancer — 3D-стол для настольных ролевых игр в браузере. Разработчик — Андрей Черномуров, Сербия, физическое лицо. Он же контролёр ваших данных, то есть тот, кто за них отвечает. Связь: hello@polymancer.app.
Что храним
- адрес вашей почты;
- язык страницы, с которой вы записались, — чтобы писать на нём;
- отметку, забронировали ли вы лицензию основателя (форма записи сейчас этого не предлагает);
- короткую метку, откуда вы пришли, если она была в ссылке (например,
reddit); - когда вы записались и подтвердили почту;
- сколько писем с просьбой подтвердить адрес мы отправили и когда ушло последнее.
IP-адрес вместе с листом не храним. Форма записи обращается к нашему серверу (play.polymancer.app), и у него, как у любого веб-сервера, есть журнал запросов с IP-адресами — он нужен против злоупотреблений, хранится до 14 дней и удаляется. Cookies не используем. Если вы переключили язык кнопками EN/RU, страница запоминает выбор в хранилище вашего браузера — он остаётся на вашем устройстве. На polymancer.app посещения считает Cloudflare Web Analytics — без cookies и без слежки между сайтами; как и при любом запросе, он видит IP-адрес.
Лист ожидания не для детей: записывайтесь, только если вам 16 лет или больше.
Что присылаем
- сразу после записи — письмо с просьбой подтвердить адрес;
- письмо, когда откроется альфа Polymancer;
- предложение лицензии основателя — разового способа поддержать проект: что в неё входит и сколько она стоит. Оно может прийти в письме об альфе или отдельно. Оно спрашивает, хотите ли вы её забронировать; денег не берёт;
- письмо, когда откроется бета. Если вы бронировали лицензию основателя, оно напомнит о брони; покупать или нет — решаете вы;
- время от времени — новости Polymancer и предложения для тех, кто в листе, например ранний доступ или бонусы в Polymancer.
Только о Polymancer: чужой рекламы не шлём. Список не продаём и передаём только тем, кто держит сервис для нас, — они перечислены ниже.
Основания
- Лист и письма — ваше согласие (GDPR, ст. 6(1)(a)), которое вы даёте, подтверждая почту. Отозвать его можно в любой момент.
- До подтверждения — хранить адрес до 7 дней и отправить письмо с просьбой его подтвердить (всего не больше трёх, если отправить форму ещё раз): наш законный интерес — ответить на просьбу, которую вы отправили формой, и убедиться, что адрес ваш (GDPR, ст. 6(1)(f)).
- Журнал запросов с IP-адресами, ограничение частоты запросов формы и резервные копии — наш законный интерес: безопасность сервиса и защита от злоупотреблений (GDPR, ст. 6(1)(f)).
Как долго
- Неподтверждённая почта удаляется через 7 дней.
- Подтверждённая хранится до шести месяцев после открытия беты Polymancer, потом удаляется. Раньше — если вы отпишетесь или если Polymancer закроется до этого. Точную дату назовёт письмо об открытии беты.
- База с листом каждый день копируется, каждая копия хранится до 15 дней. Копия вне нашего сервера (Cloudflare R2) зашифрована; к копиям на самом сервере есть доступ только у его администратора. Когда адрес удаляется — сам по истечении сроков выше, по отписке или по вашей просьбе, — из самого листа он исчезает сразу; копии мы не правим, поэтому в них он остаётся, пока не истечёт их срок, — не дольше 15 дней.
Где и кто нам помогает
- Hetzner, Финляндия (ЕС) — наш сервер, где лежат лист и журнал запросов.
- polymancer.app размещён на Cloudflare Pages. Cloudflare отдаёт его страницы и, как любой хостинг, видит IP-адрес запроса, но почту не получает — форма отправляет её прямо на наш сервер.
- Cloudflare Web Analytics — считает посещения, как сказано выше.
- polymancer.app доступен и с нашего сервера — go.polymancer.app (Hetzner, Финляндия), для тех, у кого не открывается Cloudflare. У него тот же журнал запросов до 14 дней и нет Cloudflare Web Analytics; если записаться там, ссылки в письме подтверждения ведут туда же.
- Cloudflare R2 — хранит зашифрованные копии нашей базы до 15 дней. Прочесть их Cloudflare не может.
- Zoho Mail, дата-центр в ЕС, — ящик hello@polymancer.app: принимает письма, которые вы нам шлёте, и хранит наши ответы.
- Письма уходят через Resend, из его региона в ЕС (Ирландия), — он получает только адрес и текст письма.
Cloudflare и Resend — компании из США, поэтому доступ к данным возможен из-за пределов ЕС. Такая передача идёт на основании стандартных договорных условий ЕС (SCC) в их соглашениях об обработке данных.
Ваши права
В каждом письме есть ссылка на страницу, где одна кнопка удаляет ваш адрес из листа — не помечает, а удаляет. Она же отзывает согласие и снимает бронь лицензии основателя. Ещё можно написать на hello@polymancer.app, чтобы:
- узнать, что мы о вас храним, и получить копию;
- исправить или удалить данные;
- отозвать согласие;
- возразить против обработки на основании нашего законного интереса;
- ограничить обработку, пока разбирается ваш запрос;
- получить данные в машиночитаемом виде, чтобы унести их (переносимость).
Пока такие запросы мы исполняем вручную: напишите с того адреса, о котором речь, и мы ответим в течение месяца. Отвечаем на английском и русском. Копия — небольшой машиночитаемый файл (JSON) со всем, что лист хранит о вашем адресе.
Пожаловаться можно в сербский орган по защите данных — Повереник за информације од јавног значаја и заштиту података о личности (poverenik.rs) — или в орган по защите данных своей страны ЕС.
Стол: play.polymancer.app
Эта часть — о самом столе: где мастера собирают сцены, а игроки садятся играть. Контролёр и связь те же, что выше.
Стол: что храним
- Аккаунт мастера: адрес почты и когда аккаунт заведён. Ссылки для входа (живут 30 минут, одноразовые) и сессии (30 дней) хранятся только в виде хешей. Ещё — какие столы ваши и, пока идёт закрытая альфа, список приглашённых адресов.
- У игроков аккаунта нет. Сервер выдаёт случайный пропуск гостя, который хранит ваш браузер, и запоминает имя, которое вы ввели, садясь за стол (до 32 знаков), вашу роль за этим столом и отметку, если мастер вас выгнал.
- Что происходит за столом: сцены, журнал чата и бросков (последние 400 записей), раздатки, листы персонажей, личные заметки, загруженные за стол картинки и музыка. Загруженный файл может открыть любой, у кого есть его ссылка; подобрать ссылку нельзя.
- Дневник столов: для каждой игровой встречи — когда началась, сколько минут шла, сколько игроков было за столом на пике и как часто пользовались каждой функцией. Ни имён, ни id участников, ни содержимого, но каждая запись привязана к столу, а значит, и к аккаунту его мастера. По нему мы понимаем, пользуются ли столом на самом деле.
- Отчёты об ошибках из вашего браузера: текст ошибки, место в нашем коде, id стола и user agent браузера. Ни имён, ни чата, ни адреса страницы. Вместе с сообщениями об ошибках самого сервера они попадают в журнал службы.
- IP-адреса нужны, чтобы ограничивать частоту запросов, и живут только в памяти сервера; ни с чем из перечисленного выше они не хранятся. Журнал запросов сервера хранит IP-адрес, время, запрошенный адрес, user agent браузера и другие заголовки запроса (например, адрес страницы, с которой вы пришли) каждого запроса до 14 дней.
- В вашем браузере: пропуск сессии или гостя, ваше имя, язык, тема, настройки стола, сайты, с которых вы разрешили музыку, и на время входа — стол, с которого вы пришли, — в локальном хранилище. В ссылке мастера на стол есть его ключ, поэтому она остаётся в истории браузера. Cookies не используем.
Стол: кто что видит
- Все за столом видят имена сидящих, чат и открытые броски. Тайные броски видят только мастера.
- Лист персонажа видят его игрок и мастера стола; личную заметку — только её автор, мастера тоже нет.
- Мастера одной кампании видят адреса почты друг друга — чтобы владелец знал, кому дал роль. Приглашение говорит об этом до того, как вы его примете.
- Стол в распоряжении мастера, который его завёл: удаляя стол, он удаляет всё, что за ним, в том числе листы, заметки и картинки игроков. Ещё мастера могут править и удалять листы персонажей игроков вместе с портретами, но не могут ни прочесть, ни изменить личные заметки. Добавленное вами остаётся вашим (см. условия использования).
- Если мастер включает музыку по ссылке на чужой сайт, каждый браузер за столом скачивает её прямо с этого сайта, и он видит ваш IP-адрес. Игрока спрашивают, прежде чем впервые обратиться к новому сайту; браузеры мастеров не спрашивают.
Стол: основания
- Аккаунт мастера и его столы — оказание услуги по условиям использования (GDPR, ст. 6(1)(b)).
- Игроки без аккаунта и всё, что за столом, пока условия не вступили в силу, — наш законный интерес и интерес мастера в том, чтобы шла игра, за которую игрок сел (GDPR, ст. 6(1)(f)).
- Отчёты об ошибках, журналы службы и запросов, ограничение частоты запросов, дневник столов и резервные копии — наш законный интерес: чтобы сервис работал, был защищён и его стоило развивать (GDPR, ст. 6(1)(f)). Возразить можно — см. «Ваши права».
Стол: как долго
- Аккаунт — пока вы не попросите его удалить; тогда мы удаляем его вместе со всеми его столами и с записью в списке приглашённых на альфу.
- Список приглашённых на альфу — до конца закрытой альфы, затем удаляется.
- Стол — пока мастер не удалит его в «Моих столах»; с нашего сервера он удаляется сразу вместе со всем, что за ним. Картинки могут остаться в кеше браузеров тех, кто за ним сидел. Стол, заведённый без аккаунта, удаляется через 7 дней после того, как мастер заходил в него последний раз.
- Файл, которым больше никто не пользуется, — около 24 часов, потом удаляется.
- Дневник столов — 400 дней или меньше, если стол удалят раньше.
- Журнал службы с отчётами об ошибках — до 30 дней; журнал запросов — до 14 дней.
- Резервные копии — до 15 дней, как в части о листе ожидания. Если базу придётся восстановить из копии, столы и аккаунты, удалённые после неё, удалятся снова сами.
- Если Polymancer закроется, мы заранее напишем мастерам, чтобы они успели скачать свои сцены, а потом удалим аккаунты и столы.
Стол: где и кто нам помогает
- Hetzner, Финляндия (ЕС), — сервер, на котором работает стол и лежит всё перечисленное.
- Resend, регион в ЕС (Ирландия), — отправляет ссылки для входа; получает только адрес и текст письма.
- Cloudflare R2 — зашифрованные резервные копии, прочесть их Cloudflare не может.
- Zoho Mail, дата-центр в ЕС, — ящик hello@polymancer.app.
Оповещения о работе сервиса уходят в наш закрытый канал Discord: числа и тексты ошибок без адресов, ссылок и id столов. Страница стола ничего не загружает с чужих сайтов, кроме музыки по ссылке, о которой сказано выше. Передача за пределы ЕС — на тех же основаниях, что в части о листе ожидания.
Стол: ваши права
- Пока стол есть и вы за ним, игрок может скачать своего персонажа файлом из меню листа (без портрета). Личные заметки скачать пока нельзя — скопируйте их сами. Удаляя стол, мастер удаляет и вашего персонажа, и заметки.
- Мастер может скачать любую сцену вместе с файлами из меню сцены и удалить свои столы в «Моих столах».
- Чтобы удалить аккаунт, получить копию того, что мы о вас храним, исправить это или возразить против обработки, напишите на hello@polymancer.app с того адреса, которым входите. Пока мы делаем это вручную и отвечаем в течение месяца. Игрок без аккаунта может обратиться через мастера стола или назвать стол и имя, под которым сидел; мы можем уточнить у мастера.
- Остальные права и куда жаловаться — как в «Ваших правах» выше.
Стол не для детей: пользуйтесь им, только если вам 16 лет или больше.