Privacy Policy
Last updated: 2026-05-14
This Privacy Policy explains how charactertraits.co (the “Site”) collects, uses, stores, and shares information when you visit or use our fiction trait generator and related pages. It is intended to meet common expectations for transparency on professional websites and to align, where applicable, with principles reflected in the GDPR, UK GDPR, and U.S. state privacy laws. It does not constitute legal advice; you should consult qualified counsel for your jurisdiction and use case.
1. Data controller / operator
The Operator identified on the Site (the “Controller” or “we”) determines how personal data is processed in connection with the Site. For privacy questions and requests, email hi@charactertraits.co. Additional legal name or postal details may appear in the footer or an About page when published.
2. Scope
This Policy applies to information processed through the public pages of the Site, including when you submit inputs to generate character behavior sheets when you click Generate. It does not describe third-party websites you reach through links we do not control.
3. Summary of what we process
- Inputs you provide: selected trait identifiers, backdrop and scenario selections, and optional custom trait tags you type.
- Technical identifiers: your network address may be used as part of a short-lived counter stored at our hosting edge (for example with Cloudflare) to enforce per-day limits, with a bounded lifetime on the order of roughly two days. Separately, we store salted cryptographic hashes of your IP address and browser fingerprint string in longer-lived request logs to reduce direct identifiability in those records while still supporting abuse analysis.
- Device storage: your browser may store a local list of recent successful input combinations so you can reopen them; this stays on your device until you clear stored data for this site in your browser.
- Model provider: when you run the generator, prompts are sent to our AI agent to produce the structured text that appears in your browser.
- Usage analytics: public pages load Microsoft Clarity so we can see how people move through the Site . Microsoft processes this information under its own policies.
We do not sell your personal information as “sale” is commonly defined in U.S. state privacy statutes.
4. Categories of personal data
4.1 Content and creative inputs
Trait selections, backdrop and scenario identifiers, and any custom trait phrases you submit. These may reveal creative preferences and, depending on what you type, could incidentally include personal information about you or third parties. Please avoid entering sensitive personal data unless necessary and lawful.
4.2 Request and generation metadata
Timestamps, request identifiers, approximate sizes, success or error codes, latency, usage statistics from the model host (where available), cache indicators, model identifier, prompt version, and similar diagnostics used to operate and improve reliability. Where database logging is enabled, this can include the full assembled prompt text sent to the model and a machine-readable record of your preset selections.
4.3 Security and anti-abuse data
Salted hashes of IP address and browser fingerprint in application logs; short-lived counters keyed in part on client IP for per-origin rate limiting; and signals needed to detect automated abuse or attacks. Edge infrastructure providers may also process connection details under their own policies.
4.4 Local storage on your device
A bounded history (up to a fixed number of entries) of successful input snapshots (trait ids, backdrop, scenario, custom tags) in your browser’s storage for this site under a versioned key. Generated long-form text is not required to be stored in that history by the Site’s default behavior described in this Policy.
5. Purposes of processing
- provide the trait generator and return results to your browser;
- enforce rate limits and protect the service from abuse, fraud, and denial-of-service patterns;
- maintain security, audit trails, and incident response;
- troubleshoot problems, monitor performance, and improve prompts and product quality;
- measure how visitors use public pages to improve layout, stability, and discoverability;
- comply with legal obligations and respond to lawful requests from public authorities.
6. Legal bases (EEA / UK visitors)
Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases: (i) performance of a contract or pre-contractual steps at your request when we provide the generation you initiate; (ii) legitimate interests in securing the Site, preventing abuse, improving the service, and understanding aggregate usage, balanced against your rights; (iii) legal obligation where processing is required by law; and (iv) consent where required for non-essential cookies or similar technologies if we introduce them with a consent banner.
7. Cookies and similar technologies
Your browser may store essential cookies or similar data from our hosting provider for security, load balancing, or bot management.
Where local law requires opt-in consent for this kind of analysis, we may add controls or change our setup; substantive changes will be reflected on this page.
8. Recipients and subprocessors
We use service providers who process data on our instructions. Depending on configuration, categories of providers may include:
- Hosting / edge compute: for example Cloudflare or comparable infrastructure that secures connections, runs the application, and may log security events.
We may also disclose information if required by law, court order, or governmental request, or to protect the rights, safety, and security of users and the public.
9. International transfers
Our operators and subprocessors may process data in countries other than your own, including countries that may not be deemed to provide an adequate level of protection by your local supervisory authority. Where required, we will implement appropriate safeguards (such as Standard Contractual Clauses) and perform transfer impact assessments. You may request more information about safeguards at hi@charactertraits.co, subject to confidentiality and security constraints.
10. Retention
Server-side logs and request records are intended for short-term operational and security use and are retained only as long as needed for those purposes unless a longer period is required by law or to establish, exercise, or defend legal claims. Exact retention windows may evolve with infrastructure; material changes will be reflected by updating this Policy or an internal retention schedule published on request where appropriate.
Local input history on your device persists until you delete it via browser controls (for example “clear stored data” for this website).
11. Security
We implement administrative, technical, and organizational measures appropriate to the risk, including TLS in transit, access controls on production secrets, rate limiting, and minimization of raw identifiers in logs where feasible. No method of transmission or storage is completely secure; you use the Site at your own risk.
12. Automated decision-making
We do not use your personal data for automated decisions that produce legal or similarly significant effects under the GDPR. Model outputs are creative suggestions only.
13. Children
The Site is not directed to children under 13 (or the higher age required by local law), and we do not knowingly collect personal information from children. If you believe a child has provided personal information, email hi@charactertraits.co and we will take appropriate steps to delete it, subject to applicable law.
14. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict processing, object to processing, data portability, and withdraw consent where processing is consent-based. You may also lodge a complaint with a supervisory authority. To exercise rights regarding data we control, email hi@charactertraits.co. Some requests must be verified to prevent fraud.
For data held only on your device (such as local input history), we cannot delete it remotely; use your browser’s settings to clear stored data for this Site.
15. Notice to California residents
If the California Consumer Privacy Act (CCPA) as amended by the CPRA applies, we provide this supplemental notice. In the preceding twelve months, we may have collected identifiers (such as IP address used in rate-limit storage, and hashed IP / hashed browser fingerprint in logs), Internet or other electronic network activity information (use of the Site and the generator) . We use this information for the purposes described above. We do not “sell” or “share” personal information for cross-context behavioral advertising as defined by the CPRA based on the practices described in this Policy; if that changes, we will update this Policy and offer any legally required opt-out mechanisms.
California residents may have the right to request access to specific pieces of personal information, deletion, and correction, and to limit use of sensitive personal information where applicable. We will not discriminate against you for exercising these rights. Authorized agents may submit requests where permitted by law.
16. Other U.S. states
Residents of Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws may have similar rights, including appeal rights if we deny a request. We will respond within the timeframes required by applicable law once we confirm your identity.
17. Changes to this Policy
We may update this Policy to reflect changes in practices, subprocessors, or legal requirements. We will post the revised version on this page and revise the “Last updated” date. Where required, we will provide additional notice or seek consent.
18. Contact and privacy requests
For privacy-related requests (including access, deletion, or questions about international transfers), write to hi@charactertraits.co. We aim to respond within a reasonable time and may ask for limited information to verify your request.
Not medical / legal advice: the Site is a creative writing aid and does not provide clinical, legal, or professional counseling.