Privacy Policy: Wars of Ozz Army Builder
Wars of Ozz · Last updated August 27, 2026
Privacy Policy: Wars of Ozz Army Builder
Effective date: August 27, 2026 Last updated: August 27, 2026
Wars of Ozz Army Builder ("the App") is a companion army-building and community application for the Wars of Ozz miniature wargame. It is published by Tinkavu LLC, doing business as Extra Turn Games ("we", "us", "our"). This policy explains what data the App touches, where it lives, who can see it, and how you can control or remove it.
This App is not affiliated with, endorsed by, or sponsored by the publisher of the Wars of Ozz game. All game trademarks and content referenced in the App belong to their respective owners.
The short version. You can browse factions, units, rules, stores, and public events with no account at all. If you sign in (Google, Discord, or Sign in with Apple) you get an account on the D&D Guild Hall backend, our shared community backend for all Extra Turn Games apps. That account holds your email address, a display name, and, only if you switch the Player Finder on, a postal code, a country, and whatever contact handles you choose to publish. Your army lists never reach us: they stay on your device, and if you enable backup they go to your own Google Drive in a hidden app-only folder we cannot browse. There are no ads, no analytics SDKs, and no tracking of any kind. You can delete your account from inside the App.
1. What the App does, and when an account is involved
| What you are doing | Account needed? | Personal data involved |
|---|---|---|
| Browsing factions, units, stat lines, spells, rules | No | None |
| Building and saving army lists on your device | No | None that reaches us |
| Browsing the store finder and public events | No | None |
| Running a league or other organized-play event on your device | No | None that reaches us. Participants and results stay on the device. |
| Backing up army lists to your own Google Drive | Google sign-in | Your Google account email, shown in the App so you can see which account is linked |
| Joining or creating a club, publishing an event, managing a store listing | Yes | Your display name and whatever you type into those listings |
| Appearing in the Player Finder | Yes, and an explicit opt-in | Postal code, country, and the contact handles you choose to publish |
| Reporting content, or blocking a player | Yes | Your member id, the report text, and the identity of whoever you reported or blocked |
The Player Finder is off unless you turn it on. Signing in does not put you in it.
2. Data We Collect
2.1 Data you provide directly
Sign-in identity. When you sign in with Google, Discord, or Apple, we receive and store:
- Your email address, as verified by that provider. It is the key we use to link one Guild Hall member record to you across Extra Turn Games apps.
- A provider subject identifier (an opaque id issued by Google, Discord, or Apple), so we can recognise the same sign-in next time.
- Your name, where the provider supplies it. Sign in with Apple hands over a name only on the very first authorization, and you may substitute Apple's private relay address and an edited name; we accept whatever you give.
We never see or store your Google, Discord, or Apple password.
Member profile. A single Guild Hall member record is created for you. It holds your display name and, optionally, a timezone used to show event times correctly.
Player Finder (opt-in, off by default). If you switch "findable" on, you may also provide:
- A postal code / zipcode and a country, both of which you type in yourself.
- Contact handles you choose to publish: Discord, Instagram, Telegram, Facebook, and a WhatsApp id with its own separate visibility switch.
These are shown to other signed-in players who search your postal area. Publish only what you are comfortable having seen. See Section 5.
Clubs, events, and store listings. If you create or edit these, we store what you type: club names, descriptions, websites, and Discord invite links; event names, formats, times, and locations; store names, addresses, cities, regions, postal codes, countries, coordinates, and phone numbers. Store and club addresses are business addresses, not your home address, unless you enter your home address yourself.
Organized play (leagues, open play, scenarios, conventions). Running a league or other organized-play event, including the participant names, the games recorded, and the standings, happens entirely on your device. None of it reaches us. The only thing that leaves your device is the public listing you choose to publish so other players can discover the event: its name, format, times, location, and headline counts such as the number of players and rounds.
Reports and blocks. If you report a player, listing, club, or event, we store the report: what you reported, the captured text, the reason, your member id as reporter, and the App you sent it from. If you block a player we store the pair (you, them). Both are retained as safety records. See Section 8.
Army lists. Your army compositions (name, faction, unit choices) are stored locally on your device in an on-device SQLite database. If you enable backup, one JSON file per army is written to your own Google Drive, in the hidden appDataFolder app-only space that is not visible in your normal Drive view and that no other app can read. Army data never passes through our servers, and we cannot read it.
Local export / import. Settings offers Export to File / Import from File. This writes a JSON snapshot to your device's cache directory and hands it to the OS share sheet. Nothing leaves your device in that flow beyond what you choose to do with the file.
Photo library. On iOS, the App asks for permission to add to your photo library only at the moment you choose "Save Image" while sharing an army roster or an event QR code. It never reads your library.
2.2 Data collected automatically
| Data | How it is used | Leaves your device? |
|---|---|---|
| Network state (Wi-Fi vs cellular) | Decide whether to run a cloud sync, honouring your "Wi-Fi only" preference | No |
| Session token for the Guild Hall backend | Keep you signed in between launches; stored in the App's own storage | Only back to Guild Hall |
| Local record ids | Used as file metadata in your Drive so the App updates the right backup file | Sent to the Google Drive API as metadata; not a user identifier |
| Server request logs | Standard operational logs kept by our backend host (Supabase), including IP address and timestamp, for security and abuse investigation | Yes, to Supabase |
The App does not collect device advertising identifiers, and it does not build a behavioural profile of you.
2.3 Data we explicitly do NOT collect
- No device location. The App requests no location permission on either platform, and the iOS build ships with every location usage description disabled. The only "location" we hold is the postal code and country you type in yourself for the Player Finder, and the addresses on store, club, and event listings.
- No analytics SDKs, session recording, crash reporters, or telemetry.
- No advertising identifiers (GAID / IDFA). The App shows no ads and no App Tracking Transparency prompt, because no tracking occurs.
- No camera, microphone, contacts, calendar, biometrics, health data, or SMS access.
- No payment or financial data. The App is free and has no purchases.
- No access to your army lists.
2.4 How this maps to the App Store privacy labels
The App's iOS privacy manifest declares exactly six collected data types. All six are linked to your identity and collected for App Functionality only. None is used for tracking, and the App declares NSPrivacyTracking: false with no tracking domains.
| Declared type | What it actually is here | When it is collected |
|---|---|---|
| Email Address | The verified email from your Google, Discord, or Apple sign-in | Only if you sign in |
| Name | Your display name, plus any name your sign-in provider supplies | Only if you sign in |
| User ID | Your Guild Hall member id and your provider subject id | Only if you sign in |
| Other User Contact Info | Player Finder handles (Discord, Instagram, Telegram, Facebook, WhatsApp) and contact details on club, store, and event listings | Only if you opt into the Player Finder or publish a listing |
| Coarse Location | The postal code and country you type in, and listing addresses. Not device GPS, and never read from the device | Only if you opt into the Player Finder or publish a listing |
| Other User Content | Club names and descriptions, event details, store submissions, and the text captured in a content report | Only if you create or report such content |
2.5 Per-processor summary
| Processor | Purpose | What they receive |
|---|---|---|
| Supabase (D&D Guild Hall project) | Authentication, member profile, Player Finder, clubs, events, store directory, reports, blocks | Everything in the table above, plus standard request logs |
| Google Sign-In | Optional sign-in and Drive authorization | A standard OAuth flow; the access token is managed on your device |
Google Drive API (drive.appdata scope) | Store your army-list backups in your own Drive | Your army JSON files, plus metadata fields: local id, army name, faction id, updated-at, schema version |
| Apple (Sign in with Apple) | Optional sign-in | A standard Apple identity token; you may hide your real email behind Apple's private relay |
| Discord | Optional sign-in | A standard OAuth flow |
We do not use Firebase or Firestore. Earlier versions of this App read game data from Firestore; the current App bundles all game content in the App itself, and the Firebase dependency has been removed.
3. How We Use Your Data
- Sign you in, and keep you signed in.
- Maintain one member profile for you across Extra Turn Games apps.
- Show you to other players in the Player Finder, if and only if you opted in.
- Let you create and manage clubs, events, and store listings, and show those to other users.
- Operate the safety tools: process reports of objectionable content and abusive users, and enforce your blocks.
- Sync your army lists to and from your own Google Drive, if you enable backup.
- Secure the service, investigate abuse, and meet our legal obligations.
We do not sell, rent, or share your data for advertising, profiling, or any purpose not described in this policy. We do not use your data to train machine-learning models.
4. Third-Party Services and Sharing
We use only the processors listed in Section 2.5. Each operates under its own privacy policy:
| Service | Privacy policy |
|---|---|
| Supabase (backend hosting) | supabase.com/privacy |
| Google (Sign-In, Drive) | policies.google.com/privacy |
| Apple (Sign in with Apple, App Store) | apple.com/legal/privacy |
| Discord (sign-in) | discord.com/privacy |
We do not share your data with any other third party, except where we are legally compelled to, or where it is strictly necessary to investigate a credible safety threat.
Other Extra Turn Games apps. Your Guild Hall member record is shared across the Guild Hall network, which currently includes the Moonstone Companion app, the Pathfinder app, and the ddguildhall.com website. That means the display name and Player Finder details you set here are the same ones those apps see. It also means one account deletion removes you everywhere.
5. What other users can see
| Data | Who can see it |
|---|---|
| Your email address | Us only. It is never shown to other users. |
| Your display name | Other signed-in users, on your player card, in club member lists, and on events or listings you create |
| Player Finder postal code and country | Other signed-in users who search that area, only while you are opted in |
| Player Finder contact handles | The same audience, and only the handles you filled in. WhatsApp has its own separate visibility switch. |
| Club, event, and store listings you create | Publicly visible, including on ddguildhall.com |
| Your army lists | Nobody. Not us, not other users. |
| Reports you file | Our moderators only. The person you reported is not told who reported them. |
| People you block | Nobody. Blocking is one-way and private; the blocked player is never notified. |
Turning the Player Finder off removes you from those search results immediately.
6. Where Your Data Lives
| Data | Location | Controlled by |
|---|---|---|
| Guild Hall account, member profile, Player Finder, clubs, events, store listings, reports, blocks | Supabase, in the European Union (AWS eu-central-1, Frankfurt, Germany) | Tinkavu LLC |
| Army lists (local) | Your device (SQLite) | You |
| Army lists (backup) | Your own Google Drive appDataFolder | You |
| Organized-play events you run: participants, recorded games, standings | Your device only | You |
| Sign-in session token | Your device | You |
| Game content (factions, units, rules) | Bundled inside the App | Tinkavu LLC |
Because our backend is in the EU, data about users outside the EU is transferred into the EU, which is a transfer into a stronger privacy regime rather than out of one. Some Supabase sub-processors are located in the United States; those transfers are governed by Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
7. Security
- All traffic between the App and the Guild Hall backend is encrypted in transit (TLS). Data at rest is encrypted by Supabase.
- Access to your rows is enforced in the database itself by row-level security, so a client can only read and write what its own signed-in identity is entitled to. Reading the store directory and public events requires no account and exposes no personal data.
- Sign-in uses the PKCE flow. We never receive your password from any provider.
- Army files in your Google Drive
appDataFolderare protected by Google's own Drive security and are reachable only by apps you have explicitly authorized. The App reaches Drive only with short-lived OAuth access tokens; we hold no long-lived refresh token on any server. - Local data on your device is protected by your device's app sandbox.
No security system is perfect. We reduce risk by collecting as little as possible and by keeping your army data out of our hands entirely.
Breach notification. If we become aware of a breach affecting your personal data we will notify affected users and the relevant supervisory authority as required by law, in the EEA and UK within 72 hours of becoming aware where Art. 33 GDPR applies, and post a notice at https://ddguildhall.com. If you discover a security concern, please contact us at info@guillotine-life.com.
8. Data Retention
| Data | Retention |
|---|---|
| Guild Hall account and member profile | Until you delete your account |
| Player Finder details (postal code, country, contact handles) | Until you clear them, switch the Player Finder off, or delete your account |
| Local army lists | Until you delete them in the App or uninstall |
| Google Drive backup files | Until you wipe them in the App, delete your account, or revoke Drive access |
| Clubs, events, and store listings you created | These are shared community records. They are not automatically deleted with your account; your authorship is anonymized instead. Ask us and we will remove a listing you created. |
| Blocks you made | Deleted with your account |
| Blocks made against you | Retained. These are other users' safety settings, and erasing them would undo someone else's decision to block you. |
| Content reports | Retained as a safety and abuse record after the account involved is deleted. Kept for as long as needed to detect repeat abuse, then removed. |
| Server request logs | Retained by our host for a short operational window, then rotated out |
A note on how account deletion works technically. Your member row is anonymized rather than dropped: the email is replaced with a non-routable placeholder, and the display name, postal code, country, timezone, every contact handle, and the Player Finder opt-in are all cleared. The row itself is kept because other community records (a club you founded, an event you ran) point at it and would otherwise break. The result is that nothing identifying you remains, which is what erasure requires.
9. Your Rights and Choices
| Right | How to exercise it |
|---|---|
| Access | Ask us at info@guillotine-life.com and we will send you everything we hold. Your army lists are yours already: read them in the App, or via Google Drive, Settings, Manage Apps. |
| Deletion / erasure | Delete your account in the App: Settings, Account, Delete My Account. See Section 10. |
| Correction | Edit your display name and Player Finder details in the App at any time. |
| Portability | Export all armies to a JSON file via Settings, Export to File. For your Guild Hall record, email us and we will supply a machine-readable copy. |
| Restriction | Switch the Player Finder off, disable auto-sync, or disconnect Google Drive. |
| Objection | Contact us at info@guillotine-life.com. |
| Withdraw consent | Disconnect Google Drive in Settings, or revoke access at myaccount.google.com/permissions. Switch off the Player Finder. Sign out. |
| Complain | Contact your local data protection authority. See the regional sections below. |
For any request that the in-App controls cannot satisfy, contact info@guillotine-life.com. We respond within 30 days.
10. Deleting your account
You can delete your account from inside the App, with no email and no form: Settings, Account, Delete My Account.
Deletion does three things, in this order:
- Wipes your cloud army backups from your linked Drive storage.
- Erases your Guild Hall personal data: display name, postal code, country, timezone, every contact handle, your WhatsApp id, your Discord user id, your Player Finder opt-in, the blocks you made, and your provider identity records. Your member row is anonymized as described in Section 8.
- Removes the sign-in account itself, including the email address held against it.
If step 1 or step 3 fails (for example, because you are offline), the App tells you exactly which steps completed rather than claiming a clean deletion, and step 2, the erasure of your personal data, has already happened. You can retry, or email info@guillotine-life.com and we will finish it.
Uninstalling the App alone does not delete your account. There is also a web route at ddguildhall.com/remove-my-information if you no longer have the App installed.
11. EEA, UK, and Switzerland (GDPR)
Data controller: Tinkavu LLC, 2865 Apaloosa Trl, Deltona, FL 32738, USA. Contact: info@guillotine-life.com.
Lawful bases under GDPR Art. 6:
| Processing activity | Lawful basis |
|---|---|
| Creating and maintaining your account and member profile | Art. 6(1)(b): performance of a contract you asked us to enter |
| Clubs, events, store listings you create | Art. 6(1)(b) |
| Player Finder listing (postal code, country, contact handles) | Art. 6(1)(a): consent, given by the explicit opt-in, withdrawable at any time |
| Syncing army lists to your own Google Drive | Art. 6(1)(a): consent, given by connecting Drive |
| Content reports, blocks, and enforcement records | Art. 6(1)(f): legitimate interest in keeping the community safe, and Art. 6(1)(c) where a legal obligation applies |
| Security and operational logging | Art. 6(1)(f): legitimate interest in securing the service |
Data-subject rights (Arts. 15 to 22): access, rectification, erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21), exercisable as described in Section 9. We respond within one month (Art. 12(3)).
Automated decision-making (Art. 22): none. We do not profile you, and no decision with legal or similarly significant effects is made about you automatically. Moderation decisions are made by a human reviewing a report.
International transfers: our backend is in the EU (Frankfurt), so EEA and UK personal data stays in the EEA at rest. Where a Supabase sub-processor, or Google or Apple in connection with sign-in, is located outside the EEA, those transfers rely on Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
EU/UK representative (Art. 27): Tinkavu LLC is a very small operator whose processing of EU/UK personal data is occasional, is not large-scale, and involves no special-category data. We rely on the Art. 27(2)(a) exemption and have not designated a representative. We will review this if our processing changes materially.
DPO: none designated. We do not meet the Art. 37 thresholds. Privacy contact: info@guillotine-life.com.
Supervisory authority: you may lodge a complaint with your local EEA, UK, or Swiss data protection authority.
12. California (CCPA / CPRA)
Do we "sell" or "share" personal information? No. We do not sell personal information and we do not share it for cross-context behavioural advertising. We have never done so, including for consumers under 16.
Categories of personal information collected (Cal. Civ. Code § 1798.140):
| Category | Collected? | Notes |
|---|---|---|
| Identifiers (email, account id) | Yes, if you sign in | Used to operate your account; not disclosed for commercial purposes |
| Customer records (name, contact details) | Yes, if you sign in or opt into the Player Finder | Display name and the handles you publish |
| Geolocation data | Coarse only, and only what you type | Postal code and country you enter yourself. No device location is ever read. |
| Internet / network activity | Limited | Standard server request logs |
| Commercial information | No | The App is free with no purchases |
| Sensory data | No | |
| Biometric information | No | |
| Professional / employment info | No | |
| Education information | No | |
| Sensitive personal information | No | |
| Inferences / profiles | No |
Your CCPA/CPRA rights: to know, to delete, to correct, to opt out of sale or sharing (not applicable, we do neither), to limit use of sensitive personal information (not applicable, we collect none), and to non-discrimination. Exercise them via Section 9 or at info@guillotine-life.com. Authorized agents may submit requests with written authorization from you. We will not discriminate against you for exercising any right.
13. Brazil (LGPD)
Legal bases (Art. 7 LGPD):
- Execution of a contract (Art. 7(V)): operating your account and the community features you use.
- Consent (Art. 7(I)): the Player Finder opt-in, and Google Drive backup.
- Legitimate interest (Art. 7(IX)): safety, moderation, and security logging.
Your LGPD rights: confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, deletion of data processed on consent, information about sharing, and revocation of consent. Exercise them as described in Section 9 or at info@guillotine-life.com. We respond within 30 days.
Encarregado: given our size and processing footprint we have not appointed an Encarregado. Privacy contact: info@guillotine-life.com.
ANPD: you may lodge a complaint with Brazil's Autoridade Nacional de Proteção de Dados at gov.br/anpd.
14. Canada (PIPEDA and provincial laws)
We collect personal information only with your knowledge and consent, for the purposes described in this policy. You may withdraw consent at any time by switching the Player Finder off, disconnecting Google Drive, or deleting your account.
Under PIPEDA you have the right to access and correct the personal information we hold about you, and to challenge our compliance. Requests go to info@guillotine-life.com; we respond within 30 days.
Accountability: Tinkavu LLC is responsible for personal information under its control, including information transferred to processors for processing.
OPC: you may escalate to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
15. Japan (APPI)
Under Japan's Act on the Protection of Personal Information, where we provide personal information to third parties located outside Japan we must inform you about the protection system in the recipient country.
- Supabase (European Union, Germany): our backend. The EU has been recognised by Japan's Personal Information Protection Commission as providing an equivalent level of protection under the Japan-EU mutual adequacy arrangement.
- Google (United States): Google Sign-In and, if you enable it, Google Drive backup. The United States has no adequacy finding equivalent to the EU's; Google maintains its own data-protection commitments and Standard Contractual Clauses. See Google's Privacy Policy.
- Apple (United States) and Discord (United States): optional sign-in only, under those companies' own commitments.
You have the right to request disclosure, correction, addition, deletion, or cessation of use of your personal information. Contact info@guillotine-life.com.
PPC: guidance is available from Japan's Personal Information Protection Commission at ppc.go.jp.
16. Australia (Privacy Act / APPs)
We handle personal information in accordance with the Australian Privacy Principles.
- We collect personal information only for the purposes disclosed in this policy, and only what those purposes need.
- We do not use or disclose it for secondary purposes without your consent.
- We store it on servers in the European Union, and we take reasonable steps to protect it (see Section 7).
- You may access and correct your information via Section 9.
- We do not send direct marketing.
For Australian privacy inquiries or complaints, contact info@guillotine-life.com. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
17. Children's Privacy
This App is intended for users 13 years of age and older, and it is not directed at children. We do not knowingly collect personal data from anyone under 13, and we run no interest-based advertising, so we hold no children's data under COPPA.
If you believe a child under 13 has created an account, contact us at info@guillotine-life.com and we will delete it promptly. If the child connected Google Drive, also revoke the App's access at myaccount.google.com/permissions.
Because the App includes user-to-user contact features, we ask parents and guardians of users between 13 and the age of majority to review the Player Finder settings with them, and to read the community standards in our Terms of Use.
18. Cookies and Advertising Identifiers
This App does not use cookies, web tracking technologies, or advertising identifiers (Google Advertising ID, Apple IDFA, or any equivalent). The App displays no ads. No App Tracking Transparency prompt is shown, because no cross-app tracking occurs.
19. Changes to This Policy
If we make material changes to this policy, we will:
- Update the "Last updated" date at the top of this page.
- Post a notice at https://ddguildhall.com.
For changes we consider significant (new data collection, new sharing, or changes to your rights), we will seek to provide at least 30 days' advance notice before the change takes effect, and where the change requires your consent we will ask for it rather than assume it. Continued use of the App after a material change constitutes acceptance of the revised policy.
20. Contact
For privacy questions, rights requests, or concerns:
Tinkavu LLC / Extra Turn Games Email: info@guillotine-life.com Mailing address: TINKAVU LLC, 2865 Apaloosa Trl, Deltona, FL 32738 Website: https://ddguildhall.com
We respond to all privacy inquiries within 30 days.
Wars of Ozz is a trademark of its respective owner. This App is an unofficial, fan-made companion tool and is not affiliated with, endorsed by, or sponsored by the Wars of Ozz game publisher.