Language

Privacy Policy

Last updated: 2026-10-10

We are Three Kingdoms Odyssey, an independent project mapping the Three Kingdoms era. This policy explains, in plain language, what data we handle when you use the service and what choices you have. Email us if anything below is unclear.

Who we are

Three Kingdoms Odyssey is a public, AI-enhanced atlas of the Three Kingdoms period, run by an independent maker. In this policy, 'we' means the operator of the service.

Information we collect

Account: when you sign up or sign in via Supabase Auth we store your email address, a generated user ID, sign-in timestamps, and your subscription tier (free or premium). Your password is hashed by Supabase; we never see it in cleartext.

Usage: we keep server-side records of the URLs you visit, query parameters, the messages you exchange with historical personas, and basic interaction events. This is how features like 'revisit a past conversation' work, and how we improve quality and fix bugs.

Payments: card details are handled and stored by Stripe. We receive only subscription metadata from Stripe — status, billing period, invoice IDs — and never see your full card number.

Network metadata: browser user-agent, referring page, and IP address. We hash IPs and use the hash for per-visitor rate-limiting. We do not deliberately store raw IPs, though Fly.io's access logs may retain them briefly (typically <= 30 days) per platform policy.

How we use it

To provide and maintain the service, identify users and apply rate limits, process subscriptions and billing, improve content quality and fix bugs, compile aggregate product metrics, and respond to legitimate legal requests.

Third-party processors

We use the following third parties to operate the service, and their privacy policies apply alongside this one: Supabase (authentication and database), Stripe (payments and subscriptions), Cloudflare R2 (image and generated-content storage), Google Vertex AI / Gemini (AI inference), and Fly.io (application hosting and logs).

We do not sell personal information to advertisers and do not integrate any third-party tracking or ad networks.

AI conversations

When you chat with a historical persona, your message and the context required to generate a reply (persona profile, relevant source passages) are sent to Google Vertex AI for inference. Per Google's current enterprise-API policy, this data is not used to train Google's general models. We do not use your conversations to train any models of our own.

Cookies and local storage

We use only functionally-essential cookies: NEXT_LOCALE to remember your language, and a session cookie set by Supabase to keep you signed in. We do not use advertising cookies and do not integrate Google Analytics or any equivalent third-party analytics.

Storage and international transfers

Structured data is stored in Supabase Postgres in the ap-northeast-1 (Tokyo) region. Images and generated content are stored in Cloudflare R2 across its global network. If you use the service from outside Asia-Pacific, your data is transferred to those locations over the public internet; by using the service you consent to that transfer.

Retention

Account information: retained while your account exists, cleared on deletion.

Conversations: retained indefinitely so you can revisit them, and can be deleted individually or in bulk from settings.

Billing and invoices: retained for 7 years for tax and accounting purposes.

Access logs: Fly.io and Supabase roll over per platform defaults, typically 7-30 days.

Your rights

Wherever you live, you can access, correct, export, and delete the data we hold about you. Account and conversation management are available in settings; export requests can be made by email.

Residents of stricter jurisdictions (EU, UK, California, Brazil, etc.) have additional rights under GDPR, UK GDPR, CCPA, and LGPD — including objection and restriction of processing. Email us to exercise them.

Minors

The service is intended for users 13 and older. If you are under 13, please do not create an account or submit personal information. If we learn we have collected data from a child under 13, we will delete it.

Security

We use HTTPS for transport, Supabase's hashed password storage, and role-scoped database access. No online service is 100% secure; we recommend you use a unique strong password here and enable multi-factor authentication on your email account. If you suspect your account has been compromised, please tell us right away.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the 'last updated' date at the top of this page, and we will notify registered users by email or in-app. Continued use of the service constitutes acceptance of the updated policy.

Contact

Privacy questions, requests, or complaints: privacy@example.com. We aim to respond within 30 days.