Privacy

Last updated 30 September 2026.

Session Chronicle is a small, invite-only app for tabletop groups. It turns recordings of your game sessions into summaries, a campaign log and pictures. This page explains what it keeps, who else sees it, and how to delete it.

What's stored

  • Your account: your name, your email address and your password. The password is stored only as a hash, never as you typed it.
  • Signing in: while you're signed in, your IP address and browser are stored with your sign-in, to keep you signed in and to spot abuse. Sign-in and password-reset attempts are counted per IP address, to stop password guessing.
  • Your campaigns: the story so far, the DM's notes, names to listen for, characters and their portraits, and the people in each campaign.
  • Each session: the recording (for a short time, see below), the transcript, the summary, the campaign log and the moments picked from it, with their pictures.
  • Credits: a record of each piece of AI work that ran for the campaign, and what it cost.
  • Server logs: Cloudflare keeps the app's logs for a few days, to find problems. They show what the app did (for example "the summary was written"). When an AI reply can't be read, its first few lines are logged too, which can include a little of what was said.

Where it's kept

Everything is kept with Cloudflare, which runs the app. The database and files are stored in the Oceania region.

Emails (confirming your address, resetting your password, and telling you a session is ready) are sent through Resend, which sees your email address and the message. The "session is ready" email includes the first lines of the summary and a link to one of its pictures. You can turn it off on your account page, or from the link in the email.

Who else sees your sessions

The AI work is done by these companies:

  • AssemblyAI turns the recording into a transcript. It fetches the recording through a private link that stops working after a few hours. Once the transcript is saved, the app asks AssemblyAI to delete its copy.
  • Cloudflare Workers AI writes the summary and the campaign log and picks the moments, from the transcript, the story so far, the characters and the DM's notes. It also paints the pictures, from a description of each moment and the characters' portraits.

The host can keep the DM's notes away from the AI entirely: untick Let the AI read the DM notes on the campaign's Story & notes page.

If the app starts using a different AI company, this page will be updated first. Each company has its own privacy policy.

Recordings are deleted

A recording is only needed until the transcript is made and the speakers are named. As soon as the host has named them (or straight away, if the transcript already has names), the recording is deleted.

If a session fails before there's a transcript, the recording is kept so the session can be tried again. It's deleted along with the session.

Who in your campaign sees what

  • Everyone in the campaign sees the story so far, the characters, the sessions' transcripts, summaries and pictures, and the campaign log.
  • Only the host and co-DMs see the DM's notes and can play the recordings.
  • Only the host sees everyone's email addresses and the credits.
  • The app's admin can see each campaign's name, its host's email address and its credits, and can reach the database to fix problems.

Your choices and deleting everything

  • Before recording, check everyone at the table is happy to be recorded. The app asks whoever adds a session to confirm this.
  • Delete a session from its page. Its transcript, summary and pictures are deleted with it.
  • Export a campaign (the host): Export & delete in the campaign's menu downloads everything written about it, with its pictures.
  • Delete a campaign (the host): also on Export & delete. Everything in it is deleted, for everyone in it.
  • Delete your account: click your name at the top, then Delete my account. Campaigns you host are deleted with it. Characters you played in other people's campaigns stay there, and your name may still appear in those campaigns' summaries and logs, as they belong to those campaigns.

Deleted data is gone from the app straight away. Backups of the database keep it for up to 8 weeks more, and then it's gone for good.

If you have a question about your data, ask your host, or email the app's admin.

Back to Session Chronicle · Terms