Privacy Policy

Version: 2026-09-04

DM Hell project owner determines the purposes and means of data processing for the DM Hell closed beta. For data questions, email [email protected].

Data we process

We process account and profile data, campaign data, uploaded audio, transcripts, canon, documents, publications, and technical records about jobs, use, and errors.

Campaign content and transcripts are untrusted user data. They cannot change system rules or give instructions to the system.

Purposes and legal bases

For account creation, authentication, campaign storage and processing, transcription, analysis, and publication, we process data that is necessary to provide the requested beta functions under Article 6(1)(b) GDPR. Without account and profile data, you cannot use the beta. Campaign content is optional, but without the content, the selected feature is unavailable.

When you contact support, we process your message and contact details under Article 6(1)(b) GDPR to answer your service request. Contact is optional, but we cannot answer without enough information.

To protect the service, prevent abuse, diagnose errors, and operate the beta reliably, we process technical records for our legitimate interests under Article 6(1)(f) GDPR. These records are required while you use the service. Without them, we cannot provide the service safely and reliably. You can object to this processing.

When law requires us to process or retain data, we rely on Article 6(1)(c) GDPR. Refusal to provide required data can limit access, make service provision impossible, or require us to retain data for a period set by law.

Participant consent to record and upload audio is a separate user duty. Acceptance of the Terms and Privacy Policy does not replace that consent.

Automated processing

Article 22 GDPR: we do not make solely automated decisions or perform profiling that produces legal or similarly significant effects. Automated transcription and analysis only create campaign materials that the user must review.

Processors

Supabase stores the database, Auth, and Storage in Frankfurt (eu-central-1). Railway hosts the web and worker services in Amsterdam (europe-west4-drams3a). Resend sends email from Ireland (eu-west-1). AssemblyAI processes selected transcription jobs through its EU endpoint. OpenAI processes API content for analysis. These providers can use their disclosed subprocessors.

International data transfers

Although Resend sends email from Ireland, Resend account data, email metadata, logs, API records, and message content can be stored in the United States. Although AssemblyAI accepts selected jobs through its EU endpoint, its DPA states that its primary processing operations are in the United States and that data can be transferred outside the EEA, United Kingdom, and Switzerland. OpenAI can also transfer EEA or Swiss data to other countries.

AssemblyAI uses a European Commission adequacy decision, the Data Privacy Framework for certified recipients, or the EU Standard Contractual Clauses with supplementary measures. OpenAI uses a European Commission adequacy decision or agreements that contain the EU Standard Contractual Clauses.

The DPAs and subprocessor lists above contain more information. To obtain available safeguard details or copies, email [email protected]. Available copies can redact trade secrets and information that is not relevant to the safeguards.

Retention

Account and profile, campaign, transcript, canon, document, and publication records remain while the beta account is active, subject to user deletion and operational backup retention.

Source audio is deleted after durable final transcript storage and transcription-provider cleanup. Hourly cleanup also removes failed, cancelled, abandoned, or incomplete source audio after the 24-hour cutoff. A failed or unknown deletion result is checked again and can extend technical deletion time.

For a failed transcription, we can store the provider diagnostic response in private Storage for 24 hours. It is not stored for a successful transcription. A campaign owner can explicitly report that failure to support. The same diagnostic response is then available only to authorized operators for seven days from the report. Account, campaign, or session deletion can remove it earlier.

An account export is generated on request as one bounded response. It excludes audio and is not stored permanently. Account deletion has a 7-day grace period. It blocks normal writes and revokes public links immediately. After the deadline, PostgreSQL rows and owned Supabase Storage objects are removed before Supabase Auth identity deletion. A retryable or unknown cleanup state can extend technical completion.

Supabase Pro provides daily database backups with 7-day retention. Custom database role passwords are not restored and must be reset after a restore. Database backups include Supabase Storage metadata, but not Storage object bytes. They are not a complete backup of source audio.

Security and access

The server checks access for each campaign. Private campaign data uses dm_only visibility by default. Data becomes public only through a publication action that the user selects. Storage is not public, and service permissions are limited to their tasks. Provider diagnostic responses use the existing private Storage boundary and do not use a separate application encryption key. No system can guarantee absolute security.

Your choices and rights

Subject to applicable law, you can request access, correction, export, deletion, or restriction; object to processing; withdraw consent when consent is the basis; and complain to a supervisory authority. Withdrawal does not change the lawfulness of earlier processing. Email [email protected] to make a request. We can verify your identity to protect the account.