← OmnisGMРусский

OmnisGM Privacy Policy

Last updated: 2026-07-12

This is OmnisGM — a set of tools for tabletop role-playing games: online D&D character sheets for playing at the table (omnisgm.com), a reader for open rules (rules.omnisgm.com), and a news digest (news.omnisgm.com). This policy explains what data we collect, why, and what you can do about it. It applies to all three sites.

We try to collect as little as possible and to be honest about it. If anything is still unclear after reading, just get in touch.

Who is responsible for your data

OmnisGM is a project run by a single independent developer, a resident of the Republic of Moldova. There is no company behind the project; the data operator is the developer as an individual.

For anything about your data or your rights, contact us at [email protected]. This is the one working channel — deletion requests go there too.

What data we collect and why

Account

You only need an account in the character-sheet app (omnisgm.com). Sign-in is through Google only. When you sign in, we receive from Google and store:

  • your email;
  • your display name;
  • your avatar URL;
  • an internal user identifier (UID).

We never store or see passwords — Google handles sign-in. We use this data so you have an account, so we can tell you apart from other players, and so we can show you to the people at your table.

The rules reader (rules.omnisgm.com) and the news digest (news.omnisgm.com) work without accounts or forms.

Your game content

Everything you create in the app — games, characters and sheets, items, notes, and your participation in games — is stored so you can come back to it and play together. You own your content.

Your content is visible to the other members of the same game according to their role: the Game Master (GM) sees more than the players do. Outside your game, this content is not shown to other users.

Analytics on public pages

On our public pages — the landing page, the rules reader, and the news digest — we use Google Analytics 4 and Yandex Metrica to understand how many people visit and which pages they use. Session recording and Webvisor are turned off — we do not record your mouse movements or your screen.

Inside the app (after sign-in) there is no Yandex Metrica.

Product events inside the app (once this feature ships)

Starting with the next release, only Google Analytics 4 runs inside the app, and only with a few anonymous product events: sign-up, character creation, game creation, joining a game, and opening the app (sign_up, character_create, game_create, game_join, app_open).

We do not send page views or in-app routes to analytics, we do not pass identifiers of your games or characters, and Google Signals is turned off. The goal is to understand which features people use — not to track any specific person.

Feedback

The feedback form is built on Google Forms. Email collection in it is turned off, and the fields are optional — you decide what to share. Responses go to the project owner's Google Forms and Google Sheets.

Game invitations by email (once this feature ships)

A Game Master will be able to invite someone to their game by email — including someone who is not in the system yet. In that case we store:

  • the invitee's email (in normalized form);
  • who sent the invitation;
  • which game it is for;
  • the date and status of the invitation.

We use this data only for the invitation itself and to place the person into the game as soon as they sign up. We do not use it for marketing and do not share it with third parties. Rights of invited people who don't have an account yet are covered in a separate section below.

Transactional emails (once this feature ships)

Later, we will start sending transactional emails (for example, a game invitation) through a third-party transactional email provider. These will be service-only messages tied to a specific action — with no tracking pixels and no promotional mailings.

Bot protection (once this feature is enabled)

To make sure requests to our servers come from the real app rather than bots and scripts, we use Firebase App Check with Google reCAPTCHA v3. reCAPTCHA evaluates your interaction with the app in the background (behavioral signals, browser and device characteristics) and sends this data to Google. We never see this data — we only receive a score. Google's Privacy Policy and Terms of Service apply.

The legal basis for processing your data

In plain terms:

  • Performance of the service contract — your account, your game content, invitations, and transactional emails are needed to provide the very service you chose to use.
  • Legitimate interest — minimal analytics and basic security help us understand and maintain the project without crossing the line into your privacy.
  • Consent — where the law requires it (for example, analytics cookies in the EU), we rely on your consent. The consent mechanism is still being finalized [TODO: consent banner / Consent Mode for the EU — decision pending].

Where data is stored and transfers to the US

The app runs on Google Firebase infrastructure: sign-in through Firebase Authentication, and game content in the Firestore database in a US region (nam7). DNS, CDN, and email routing go through Cloudflare.

This means data is stored and processed in part in the United States. Transfers from the EU/Moldova to the US rely on the mechanisms Google uses (participation in the Data Privacy Framework and Standard Contractual Clauses, SCCs).

Who we share data with (processors)

We do not sell your data. We use services that process data on our behalf:

  • Google (Firebase Authentication, Firestore, Google Analytics 4, Google Forms/Sheets) — account, game content, analytics, feedback.
  • Cloudflare — DNS, CDN, and inbound email routing for the domain.
  • Yandex (Metrica) — analytics on public pages only.
  • A third-party transactional email provider — sending service emails (once this feature ships).
  • Google reCAPTCHA (App Check) — bot protection: background evaluation of app interactions (once this feature is enabled).

How long we keep data

  • Account and game content — for as long as your account exists. When the account is deleted, they are deleted with it.
  • Email invitations — an unaccepted invitation automatically expires and is deleted no later than 60 days. If the GM revokes the invitation, the record is deleted right away.
  • Analytics — for the standard retention periods of Google Analytics 4 and Yandex Metrica.

Your rights

You can:

  • access your data;
  • correct inaccurate data;
  • delete your data;
  • object to processing or restrict it.

Some of this you can do right in your account profile. Deleting your account yourself from the profile is coming later [TODO: account-deletion feature release]; when you delete it, both the sign-in record and your user data (characters, participation in games) are removed. Before deleting your account, you'll need to delete your games or transfer the Game Master role to another player (role transfer already works).

Until the self-service deletion feature ships — and for any of the rights above in general — email [email protected] and we'll take care of it.

If a Game Master gave your email and you don't have an account

It can happen that a GM invited you to a game by email while you have never signed up for OmnisGM. In that case, all we have is your email and the invitation details (see the invitations section above). You can:

  • ask us to delete your address — email [email protected];
  • do nothing — an unaccepted invitation expires and is deleted on its own (no later than 60 days). If the inviting GM revokes it, the record is deleted too.

We use this data only for the invitation and share it with no one.

Children

The service is not intended for children under 13. For users in the EU under 16, parental or guardian consent is required where national law requires it (Article 8 GDPR).

Cookies and analytics

On public pages, analytics tools (Google Analytics 4, Yandex Metrica) may use cookies and similar technologies to count visits. Session recording is off. Inside the app there is no Yandex Metrica, and Google Analytics 4 runs in a minimal mode (see the product-events section).

We are working on a mechanism to manage consent for analytics cookies for users in the EU [TODO: consent banner / Consent Mode — decision pending]. Until it is ready, we honestly describe here what is in use.

Changes to this policy

The date of the last update is shown at the top of the page. If we make material changes, we will let you know — for example, with an in-app notice. By continuing to use OmnisGM after changes take effect, you accept the updated policy.

Governing law

This policy is governed by the law of the Republic of Moldova, including Law of the Republic of Moldova No. 195/2024 on personal data protection. For users in the European Union, the General Data Protection Regulation (GDPR) also applies.

For any questions about your data or this policy: [email protected].