echory

Privacy policy

Controller and scope

{full legal name / company}, {full postal address}, is responsible for personal data processed through echory. Contact: {privacy email}. Data protection officer, if appointed: {name and contact details or not applicable}. EU representative, where required: {name, address and email or not applicable}.

This policy covers our website, accounts and interactive AI stories. Swiss data protection law applies; the GDPR also applies where its territorial requirements are met.

Website access and security

When you access echory, technical data may be processed, including IP address, request time, requested URL, browser/device information and error or security logs. Purpose: delivery of the website, troubleshooting and protection against misuse. Hosting/CDN/security providers and processing countries: {legal names, services and countries}. Log retention: {period}. Under the GDPR, the basis is our legitimate interest in a stable, secure service (Article 6(1)(f)); statutory duties, where applicable, rely on Article 6(1)(c).

Account and support

Registration requires a display name, email address and password. We process account details, authentication information and support messages to create and secure your account, communicate with you and provide the requested service. GDPR basis: Article 6(1)(b), or Article 6(1)(f) for security and general enquiries. Account and support retention: {periods and deletion criteria}. Without required account information, account-based features cannot be provided.

Stories, inputs and AI providers

We process your story inputs, generated responses, character choices, saved progress and {other actual session data} to generate and continue your adventures. GDPR basis: Article 6(1)(b) insofar as necessary to provide the service.

AI provider(s): {legal name, model/service and privacy-policy URL}. Data transmitted: {exact fields, including whether account identifiers are sent}. Processing countries: {all relevant countries}. Provider retention: {period}. Use of inputs or outputs for model training: {actual policy, provider settings and any opt-in/opt-out}. Internal review or moderation: {whether performed, purpose, access and retention}. Any optional processing beyond what is necessary requires its own valid basis, stated here: {purpose and legal basis, or not applicable}.

Avoid entering sensitive personal data or information about others into stories. Fictional responses are generated automatically; any automated decisions producing legal or similarly significant effects: {none, if verified; otherwise describe logic, significance, consequences and safeguards}.

Cookies and optional services

See our Cookie policy for device storage, providers, purposes and lifetimes. Optional analytics, marketing or external integrations: {actual services, data, recipients, retention and consent mechanism, or none}. Where consent is required, GDPR processing relies on Article 6(1)(a); withdrawal is possible at any time with effect for the future via {privacy settings URL or other available mechanism}.

Recipients and international transfers

Recipients include the service providers identified above, {email/support providers and countries}, authorised staff and authorities where legally required. Other recipients: {list or none}. Providers acting on our instructions are subject to appropriate data-processing arrangements.

For each foreign recipient: {recipient, country and applicable adequacy decision or transfer safeguard; where needed, standard contractual clauses, Swiss adaptations and supplementary measures}. Where no adequate protection exists, transfers require valid safeguards or a statutory exception. You may request information or a copy of relevant safeguards, subject to lawful redactions, at {privacy email}.

Retention and security

Data is retained for the stated purposes and periods, then deleted or anonymised unless a legal duty or justified need requires retention. Backups: {retention and deletion cycle}. Records subject to legal retention: {categories, law and period}. Security measures: {verified access controls, encryption and other measures}. No Internet service can guarantee absolute security.

Your rights

Subject to applicable law and its conditions, you may request access, correction, deletion, data portability or release of data, restriction of processing, and object to processing, particularly processing based on legitimate interests and direct marketing. You may withdraw consent at any time; this does not affect prior lawful processing. Send requests to {privacy email}. We may request proportionate verification of identity.

You may contact the Swiss Federal Data Protection and Information Commissioner (www.edoeb.admin.ch) and, where the GDPR applies, lodge a complaint with the competent supervisory authority, particularly in your habitual residence, workplace or the place of the alleged infringement.

Children and changes

Minimum age and any parental authorisation requirements: {actual age policy and lawful implementation for supported countries}. We update this policy when our processing changes. Last updated: 6 October 2026.