Dice and Decks Guild Hall

Privacy Policy: Wars of Ozz Army Builder

Wars of Ozz · Last updated August 27, 2026

Privacy Policy: Wars of Ozz Army Builder

Effective date: August 27, 2026 Last updated: August 27, 2026

Wars of Ozz Army Builder ("the App") is a companion army-building and community application for the Wars of Ozz miniature wargame. It is published by Tinkavu LLC, doing business as Extra Turn Games ("we", "us", "our"). This policy explains what data the App touches, where it lives, who can see it, and how you can control or remove it.

This App is not affiliated with, endorsed by, or sponsored by the publisher of the Wars of Ozz game. All game trademarks and content referenced in the App belong to their respective owners.

The short version. You can browse factions, units, rules, stores, and public events with no account at all. If you sign in (Google, Discord, or Sign in with Apple) you get an account on the D&D Guild Hall backend, our shared community backend for all Extra Turn Games apps. That account holds your email address, a display name, and, only if you switch the Player Finder on, a postal code, a country, and whatever contact handles you choose to publish. Your army lists never reach us: they stay on your device, and if you enable backup they go to your own Google Drive in a hidden app-only folder we cannot browse. There are no ads, no analytics SDKs, and no tracking of any kind. You can delete your account from inside the App.


1. What the App does, and when an account is involved

What you are doingAccount needed?Personal data involved
Browsing factions, units, stat lines, spells, rulesNoNone
Building and saving army lists on your deviceNoNone that reaches us
Browsing the store finder and public eventsNoNone
Running a league or other organized-play event on your deviceNoNone that reaches us. Participants and results stay on the device.
Backing up army lists to your own Google DriveGoogle sign-inYour Google account email, shown in the App so you can see which account is linked
Joining or creating a club, publishing an event, managing a store listingYesYour display name and whatever you type into those listings
Appearing in the Player FinderYes, and an explicit opt-inPostal code, country, and the contact handles you choose to publish
Reporting content, or blocking a playerYesYour member id, the report text, and the identity of whoever you reported or blocked

The Player Finder is off unless you turn it on. Signing in does not put you in it.


2. Data We Collect

2.1 Data you provide directly

Sign-in identity. When you sign in with Google, Discord, or Apple, we receive and store:

  • Your email address, as verified by that provider. It is the key we use to link one Guild Hall member record to you across Extra Turn Games apps.
  • A provider subject identifier (an opaque id issued by Google, Discord, or Apple), so we can recognise the same sign-in next time.
  • Your name, where the provider supplies it. Sign in with Apple hands over a name only on the very first authorization, and you may substitute Apple's private relay address and an edited name; we accept whatever you give.

We never see or store your Google, Discord, or Apple password.

Member profile. A single Guild Hall member record is created for you. It holds your display name and, optionally, a timezone used to show event times correctly.

Player Finder (opt-in, off by default). If you switch "findable" on, you may also provide:

  • A postal code / zipcode and a country, both of which you type in yourself.
  • Contact handles you choose to publish: Discord, Instagram, Telegram, Facebook, and a WhatsApp id with its own separate visibility switch.

These are shown to other signed-in players who search your postal area. Publish only what you are comfortable having seen. See Section 5.

Clubs, events, and store listings. If you create or edit these, we store what you type: club names, descriptions, websites, and Discord invite links; event names, formats, times, and locations; store names, addresses, cities, regions, postal codes, countries, coordinates, and phone numbers. Store and club addresses are business addresses, not your home address, unless you enter your home address yourself.

Organized play (leagues, open play, scenarios, conventions). Running a league or other organized-play event, including the participant names, the games recorded, and the standings, happens entirely on your device. None of it reaches us. The only thing that leaves your device is the public listing you choose to publish so other players can discover the event: its name, format, times, location, and headline counts such as the number of players and rounds.

Reports and blocks. If you report a player, listing, club, or event, we store the report: what you reported, the captured text, the reason, your member id as reporter, and the App you sent it from. If you block a player we store the pair (you, them). Both are retained as safety records. See Section 8.

Army lists. Your army compositions (name, faction, unit choices) are stored locally on your device in an on-device SQLite database. If you enable backup, one JSON file per army is written to your own Google Drive, in the hidden appDataFolder app-only space that is not visible in your normal Drive view and that no other app can read. Army data never passes through our servers, and we cannot read it.

Local export / import. Settings offers Export to File / Import from File. This writes a JSON snapshot to your device's cache directory and hands it to the OS share sheet. Nothing leaves your device in that flow beyond what you choose to do with the file.

Photo library. On iOS, the App asks for permission to add to your photo library only at the moment you choose "Save Image" while sharing an army roster or an event QR code. It never reads your library.

2.2 Data collected automatically

DataHow it is usedLeaves your device?
Network state (Wi-Fi vs cellular)Decide whether to run a cloud sync, honouring your "Wi-Fi only" preferenceNo
Session token for the Guild Hall backendKeep you signed in between launches; stored in the App's own storageOnly back to Guild Hall
Local record idsUsed as file metadata in your Drive so the App updates the right backup fileSent to the Google Drive API as metadata; not a user identifier
Server request logsStandard operational logs kept by our backend host (Supabase), including IP address and timestamp, for security and abuse investigationYes, to Supabase

The App does not collect device advertising identifiers, and it does not build a behavioural profile of you.

2.3 Data we explicitly do NOT collect

  • No device location. The App requests no location permission on either platform, and the iOS build ships with every location usage description disabled. The only "location" we hold is the postal code and country you type in yourself for the Player Finder, and the addresses on store, club, and event listings.
  • No analytics SDKs, session recording, crash reporters, or telemetry.
  • No advertising identifiers (GAID / IDFA). The App shows no ads and no App Tracking Transparency prompt, because no tracking occurs.
  • No camera, microphone, contacts, calendar, biometrics, health data, or SMS access.
  • No payment or financial data. The App is free and has no purchases.
  • No access to your army lists.

2.4 How this maps to the App Store privacy labels

The App's iOS privacy manifest declares exactly six collected data types. All six are linked to your identity and collected for App Functionality only. None is used for tracking, and the App declares NSPrivacyTracking: false with no tracking domains.

Declared typeWhat it actually is hereWhen it is collected
Email AddressThe verified email from your Google, Discord, or Apple sign-inOnly if you sign in
NameYour display name, plus any name your sign-in provider suppliesOnly if you sign in
User IDYour Guild Hall member id and your provider subject idOnly if you sign in
Other User Contact InfoPlayer Finder handles (Discord, Instagram, Telegram, Facebook, WhatsApp) and contact details on club, store, and event listingsOnly if you opt into the Player Finder or publish a listing
Coarse LocationThe postal code and country you type in, and listing addresses. Not device GPS, and never read from the deviceOnly if you opt into the Player Finder or publish a listing
Other User ContentClub names and descriptions, event details, store submissions, and the text captured in a content reportOnly if you create or report such content

2.5 Per-processor summary

ProcessorPurposeWhat they receive
Supabase (D&D Guild Hall project)Authentication, member profile, Player Finder, clubs, events, store directory, reports, blocksEverything in the table above, plus standard request logs
Google Sign-InOptional sign-in and Drive authorizationA standard OAuth flow; the access token is managed on your device
Google Drive API (drive.appdata scope)Store your army-list backups in your own DriveYour army JSON files, plus metadata fields: local id, army name, faction id, updated-at, schema version
Apple (Sign in with Apple)Optional sign-inA standard Apple identity token; you may hide your real email behind Apple's private relay
DiscordOptional sign-inA standard OAuth flow

We do not use Firebase or Firestore. Earlier versions of this App read game data from Firestore; the current App bundles all game content in the App itself, and the Firebase dependency has been removed.


3. How We Use Your Data

  • Sign you in, and keep you signed in.
  • Maintain one member profile for you across Extra Turn Games apps.
  • Show you to other players in the Player Finder, if and only if you opted in.
  • Let you create and manage clubs, events, and store listings, and show those to other users.
  • Operate the safety tools: process reports of objectionable content and abusive users, and enforce your blocks.
  • Sync your army lists to and from your own Google Drive, if you enable backup.
  • Secure the service, investigate abuse, and meet our legal obligations.

We do not sell, rent, or share your data for advertising, profiling, or any purpose not described in this policy. We do not use your data to train machine-learning models.


4. Third-Party Services and Sharing

We use only the processors listed in Section 2.5. Each operates under its own privacy policy:

ServicePrivacy policy
Supabase (backend hosting)supabase.com/privacy
Google (Sign-In, Drive)policies.google.com/privacy
Apple (Sign in with Apple, App Store)apple.com/legal/privacy
Discord (sign-in)discord.com/privacy

We do not share your data with any other third party, except where we are legally compelled to, or where it is strictly necessary to investigate a credible safety threat.

Other Extra Turn Games apps. Your Guild Hall member record is shared across the Guild Hall network, which currently includes the Moonstone Companion app, the Pathfinder app, and the ddguildhall.com website. That means the display name and Player Finder details you set here are the same ones those apps see. It also means one account deletion removes you everywhere.


5. What other users can see

DataWho can see it
Your email addressUs only. It is never shown to other users.
Your display nameOther signed-in users, on your player card, in club member lists, and on events or listings you create
Player Finder postal code and countryOther signed-in users who search that area, only while you are opted in
Player Finder contact handlesThe same audience, and only the handles you filled in. WhatsApp has its own separate visibility switch.
Club, event, and store listings you createPublicly visible, including on ddguildhall.com
Your army listsNobody. Not us, not other users.
Reports you fileOur moderators only. The person you reported is not told who reported them.
People you blockNobody. Blocking is one-way and private; the blocked player is never notified.

Turning the Player Finder off removes you from those search results immediately.


6. Where Your Data Lives

DataLocationControlled by
Guild Hall account, member profile, Player Finder, clubs, events, store listings, reports, blocksSupabase, in the European Union (AWS eu-central-1, Frankfurt, Germany)Tinkavu LLC
Army lists (local)Your device (SQLite)You
Army lists (backup)Your own Google Drive appDataFolderYou
Organized-play events you run: participants, recorded games, standingsYour device onlyYou
Sign-in session tokenYour deviceYou
Game content (factions, units, rules)Bundled inside the AppTinkavu LLC

Because our backend is in the EU, data about users outside the EU is transferred into the EU, which is a transfer into a stronger privacy regime rather than out of one. Some Supabase sub-processors are located in the United States; those transfers are governed by Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.


7. Security

  • All traffic between the App and the Guild Hall backend is encrypted in transit (TLS). Data at rest is encrypted by Supabase.
  • Access to your rows is enforced in the database itself by row-level security, so a client can only read and write what its own signed-in identity is entitled to. Reading the store directory and public events requires no account and exposes no personal data.
  • Sign-in uses the PKCE flow. We never receive your password from any provider.
  • Army files in your Google Drive appDataFolder are protected by Google's own Drive security and are reachable only by apps you have explicitly authorized. The App reaches Drive only with short-lived OAuth access tokens; we hold no long-lived refresh token on any server.
  • Local data on your device is protected by your device's app sandbox.

No security system is perfect. We reduce risk by collecting as little as possible and by keeping your army data out of our hands entirely.

Breach notification. If we become aware of a breach affecting your personal data we will notify affected users and the relevant supervisory authority as required by law, in the EEA and UK within 72 hours of becoming aware where Art. 33 GDPR applies, and post a notice at https://ddguildhall.com. If you discover a security concern, please contact us at info@guillotine-life.com.


8. Data Retention

DataRetention
Guild Hall account and member profileUntil you delete your account
Player Finder details (postal code, country, contact handles)Until you clear them, switch the Player Finder off, or delete your account
Local army listsUntil you delete them in the App or uninstall
Google Drive backup filesUntil you wipe them in the App, delete your account, or revoke Drive access
Clubs, events, and store listings you createdThese are shared community records. They are not automatically deleted with your account; your authorship is anonymized instead. Ask us and we will remove a listing you created.
Blocks you madeDeleted with your account
Blocks made against youRetained. These are other users' safety settings, and erasing them would undo someone else's decision to block you.
Content reportsRetained as a safety and abuse record after the account involved is deleted. Kept for as long as needed to detect repeat abuse, then removed.
Server request logsRetained by our host for a short operational window, then rotated out

A note on how account deletion works technically. Your member row is anonymized rather than dropped: the email is replaced with a non-routable placeholder, and the display name, postal code, country, timezone, every contact handle, and the Player Finder opt-in are all cleared. The row itself is kept because other community records (a club you founded, an event you ran) point at it and would otherwise break. The result is that nothing identifying you remains, which is what erasure requires.


9. Your Rights and Choices

RightHow to exercise it
AccessAsk us at info@guillotine-life.com and we will send you everything we hold. Your army lists are yours already: read them in the App, or via Google Drive, Settings, Manage Apps.
Deletion / erasureDelete your account in the App: Settings, Account, Delete My Account. See Section 10.
CorrectionEdit your display name and Player Finder details in the App at any time.
PortabilityExport all armies to a JSON file via Settings, Export to File. For your Guild Hall record, email us and we will supply a machine-readable copy.
RestrictionSwitch the Player Finder off, disable auto-sync, or disconnect Google Drive.
ObjectionContact us at info@guillotine-life.com.
Withdraw consentDisconnect Google Drive in Settings, or revoke access at myaccount.google.com/permissions. Switch off the Player Finder. Sign out.
ComplainContact your local data protection authority. See the regional sections below.

For any request that the in-App controls cannot satisfy, contact info@guillotine-life.com. We respond within 30 days.


10. Deleting your account

You can delete your account from inside the App, with no email and no form: Settings, Account, Delete My Account.

Deletion does three things, in this order:

  1. Wipes your cloud army backups from your linked Drive storage.
  2. Erases your Guild Hall personal data: display name, postal code, country, timezone, every contact handle, your WhatsApp id, your Discord user id, your Player Finder opt-in, the blocks you made, and your provider identity records. Your member row is anonymized as described in Section 8.
  3. Removes the sign-in account itself, including the email address held against it.

If step 1 or step 3 fails (for example, because you are offline), the App tells you exactly which steps completed rather than claiming a clean deletion, and step 2, the erasure of your personal data, has already happened. You can retry, or email info@guillotine-life.com and we will finish it.

Uninstalling the App alone does not delete your account. There is also a web route at ddguildhall.com/remove-my-information if you no longer have the App installed.


11. EEA, UK, and Switzerland (GDPR)

Data controller: Tinkavu LLC, 2865 Apaloosa Trl, Deltona, FL 32738, USA. Contact: info@guillotine-life.com.

Lawful bases under GDPR Art. 6:

Processing activityLawful basis
Creating and maintaining your account and member profileArt. 6(1)(b): performance of a contract you asked us to enter
Clubs, events, store listings you createArt. 6(1)(b)
Player Finder listing (postal code, country, contact handles)Art. 6(1)(a): consent, given by the explicit opt-in, withdrawable at any time
Syncing army lists to your own Google DriveArt. 6(1)(a): consent, given by connecting Drive
Content reports, blocks, and enforcement recordsArt. 6(1)(f): legitimate interest in keeping the community safe, and Art. 6(1)(c) where a legal obligation applies
Security and operational loggingArt. 6(1)(f): legitimate interest in securing the service

Data-subject rights (Arts. 15 to 22): access, rectification, erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21), exercisable as described in Section 9. We respond within one month (Art. 12(3)).

Automated decision-making (Art. 22): none. We do not profile you, and no decision with legal or similarly significant effects is made about you automatically. Moderation decisions are made by a human reviewing a report.

International transfers: our backend is in the EU (Frankfurt), so EEA and UK personal data stays in the EEA at rest. Where a Supabase sub-processor, or Google or Apple in connection with sign-in, is located outside the EEA, those transfers rely on Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.

EU/UK representative (Art. 27): Tinkavu LLC is a very small operator whose processing of EU/UK personal data is occasional, is not large-scale, and involves no special-category data. We rely on the Art. 27(2)(a) exemption and have not designated a representative. We will review this if our processing changes materially.

DPO: none designated. We do not meet the Art. 37 thresholds. Privacy contact: info@guillotine-life.com.

Supervisory authority: you may lodge a complaint with your local EEA, UK, or Swiss data protection authority.


12. California (CCPA / CPRA)

Do we "sell" or "share" personal information? No. We do not sell personal information and we do not share it for cross-context behavioural advertising. We have never done so, including for consumers under 16.

Categories of personal information collected (Cal. Civ. Code § 1798.140):

CategoryCollected?Notes
Identifiers (email, account id)Yes, if you sign inUsed to operate your account; not disclosed for commercial purposes
Customer records (name, contact details)Yes, if you sign in or opt into the Player FinderDisplay name and the handles you publish
Geolocation dataCoarse only, and only what you typePostal code and country you enter yourself. No device location is ever read.
Internet / network activityLimitedStandard server request logs
Commercial informationNoThe App is free with no purchases
Sensory dataNo
Biometric informationNo
Professional / employment infoNo
Education informationNo
Sensitive personal informationNo
Inferences / profilesNo

Your CCPA/CPRA rights: to know, to delete, to correct, to opt out of sale or sharing (not applicable, we do neither), to limit use of sensitive personal information (not applicable, we collect none), and to non-discrimination. Exercise them via Section 9 or at info@guillotine-life.com. Authorized agents may submit requests with written authorization from you. We will not discriminate against you for exercising any right.


13. Brazil (LGPD)

Legal bases (Art. 7 LGPD):

  • Execution of a contract (Art. 7(V)): operating your account and the community features you use.
  • Consent (Art. 7(I)): the Player Finder opt-in, and Google Drive backup.
  • Legitimate interest (Art. 7(IX)): safety, moderation, and security logging.

Your LGPD rights: confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, deletion of data processed on consent, information about sharing, and revocation of consent. Exercise them as described in Section 9 or at info@guillotine-life.com. We respond within 30 days.

Encarregado: given our size and processing footprint we have not appointed an Encarregado. Privacy contact: info@guillotine-life.com.

ANPD: you may lodge a complaint with Brazil's Autoridade Nacional de Proteção de Dados at gov.br/anpd.


14. Canada (PIPEDA and provincial laws)

We collect personal information only with your knowledge and consent, for the purposes described in this policy. You may withdraw consent at any time by switching the Player Finder off, disconnecting Google Drive, or deleting your account.

Under PIPEDA you have the right to access and correct the personal information we hold about you, and to challenge our compliance. Requests go to info@guillotine-life.com; we respond within 30 days.

Accountability: Tinkavu LLC is responsible for personal information under its control, including information transferred to processors for processing.

OPC: you may escalate to the Office of the Privacy Commissioner of Canada at priv.gc.ca.


15. Japan (APPI)

Under Japan's Act on the Protection of Personal Information, where we provide personal information to third parties located outside Japan we must inform you about the protection system in the recipient country.

  • Supabase (European Union, Germany): our backend. The EU has been recognised by Japan's Personal Information Protection Commission as providing an equivalent level of protection under the Japan-EU mutual adequacy arrangement.
  • Google (United States): Google Sign-In and, if you enable it, Google Drive backup. The United States has no adequacy finding equivalent to the EU's; Google maintains its own data-protection commitments and Standard Contractual Clauses. See Google's Privacy Policy.
  • Apple (United States) and Discord (United States): optional sign-in only, under those companies' own commitments.

You have the right to request disclosure, correction, addition, deletion, or cessation of use of your personal information. Contact info@guillotine-life.com.

PPC: guidance is available from Japan's Personal Information Protection Commission at ppc.go.jp.


16. Australia (Privacy Act / APPs)

We handle personal information in accordance with the Australian Privacy Principles.

  • We collect personal information only for the purposes disclosed in this policy, and only what those purposes need.
  • We do not use or disclose it for secondary purposes without your consent.
  • We store it on servers in the European Union, and we take reasonable steps to protect it (see Section 7).
  • You may access and correct your information via Section 9.
  • We do not send direct marketing.

For Australian privacy inquiries or complaints, contact info@guillotine-life.com. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.


17. Children's Privacy

This App is intended for users 13 years of age and older, and it is not directed at children. We do not knowingly collect personal data from anyone under 13, and we run no interest-based advertising, so we hold no children's data under COPPA.

If you believe a child under 13 has created an account, contact us at info@guillotine-life.com and we will delete it promptly. If the child connected Google Drive, also revoke the App's access at myaccount.google.com/permissions.

Because the App includes user-to-user contact features, we ask parents and guardians of users between 13 and the age of majority to review the Player Finder settings with them, and to read the community standards in our Terms of Use.


18. Cookies and Advertising Identifiers

This App does not use cookies, web tracking technologies, or advertising identifiers (Google Advertising ID, Apple IDFA, or any equivalent). The App displays no ads. No App Tracking Transparency prompt is shown, because no cross-app tracking occurs.


19. Changes to This Policy

If we make material changes to this policy, we will:

  1. Update the "Last updated" date at the top of this page.
  2. Post a notice at https://ddguildhall.com.

For changes we consider significant (new data collection, new sharing, or changes to your rights), we will seek to provide at least 30 days' advance notice before the change takes effect, and where the change requires your consent we will ask for it rather than assume it. Continued use of the App after a material change constitutes acceptance of the revised policy.


20. Contact

For privacy questions, rights requests, or concerns:

Tinkavu LLC / Extra Turn Games Email: info@guillotine-life.com Mailing address: TINKAVU LLC, 2865 Apaloosa Trl, Deltona, FL 32738 Website: https://ddguildhall.com

We respond to all privacy inquiries within 30 days.


Wars of Ozz is a trademark of its respective owner. This App is an unofficial, fan-made companion tool and is not affiliated with, endorsed by, or sponsored by the Wars of Ozz game publisher.