← Back to App

Privacy Policy

LoomMaster by TheWorldTable.ai

1. Introduction

TheWorldTable.ai ("we," "us," "our"), the trade name held by Sunisa Chaichan under Thai Department of Business Development (DBD) individual commercial registration (verify at /dbd.html), operates the LoomMaster AI tabletop role-playing game and the Mythcore:Omniveil world (together, the "Service"). This Privacy Policy explains exactly what data we store, where, why, for how long, and the rights you have over it. It is the data-protection notice for the purposes of the Thai Personal Data Protection Act (PDPA) and, for users in the EEA/UK, the GDPR. The data controller is TheWorldTable.ai (Sunisa Chaichan).

By creating an account, starting a trial, subscribing, or making a purchase, you acknowledge this Privacy Policy. Where the law requires consent for a specific use, we ask for it separately.

2. What We Store Server-Side

The following data is persisted on our servers in Thailand. We are direct about this because the prior version of this page was not.

2.1 Account data

  • Account name, email, hashed PIN, hashed sign-in tokens, signup timestamp, last-login timestamp.
  • Optional display name and avatar color you set when pledging.

2.2 Payment audit data

  • PayPal capture id, USD amount, SKU, status, timestamp. We do NOT store your PayPal credentials, card number, billing address, or any tokenized payment method - PayPal holds those.
  • Refund records linked to the original capture id (if any).

2.3 In-world ledger

  • Your Veil Essence (VE) balance and lifetime earned/spent counters.
  • An append-only chained ledger of every credit and debit (currency, direction, amount, reason, source, idempotency key, timestamp, HMAC signature). Required for accounting and refund integrity.

2.4 Gameplay and chat history (your prompts and the AI's replies)

  • Your inputs to the game/Loom and the AI's replies are stored in our database, indexed by your account/character id, so your campaign persists and you see your history when you return.
  • We use this for: gameplay continuity and persistent world/character state, providing the Service, customer support, security and abuse forensics, and debugging.
  • Usage metrics (tokens in/out, latency, and AI usage) are stored alongside for billing and accounting.
  • We do NOT use your prompts, gameplay, or chat content to train or fine-tune AI models - not our own, and we do not grant Anthropic the right to train on it. The AI is provided by Anthropic via its API (see Section 5.2). Under Anthropic's commercial terms, your inputs/outputs are not used to train Anthropic's models; Anthropic may retain them for a limited period (currently up to ~30 days) for trust & safety, after which they are deleted, except where a legal hold applies.

2.5 In-world events

  • The loom_events table records gameplay-significant events (NPC dialog, faction state, world ticks). Append-only. Tied to your account id.

2.6 What we do NOT collect

  • No third-party analytics (Google Analytics, Mixpanel, etc.).
  • No advertising network pixels or tracking cookies.
  • No browser fingerprinting beyond what your IP address inherently reveals - except that, if you send us feedback, we store the browser user-agent and viewport you submitted with that one report (see Section 2.7). We do not fingerprint you across the site.
  • No location data beyond country-level inference from IP (CloudFlare provides this for fraud screening; we do not store GPS or precise location).

2.7 Feedback you send us

LoomMaster has a small in-app feedback widget. When you choose to send a note through it, we store the following on our servers:

  • The feedback text you typed.
  • The category you picked (bug, idea, confusing, praise, or other).
  • The page you sent it from, so we can reproduce the context.
  • Your browser user-agent and viewport size at the moment of submission - only to reproduce layout and rendering bugs.
  • The submission time.
  • A best-effort client IP, used only to rate-limit submissions and curb abuse (flooding) - never for advertising, profiling, or tracking.

You can send feedback whether or not you are signed in. If you are signed in, the note is linked to your account id so we can follow up; if you are not, it is stored anonymously with no account link. The team reads and acts on feedback. Sending feedback earns you no in-app currency or reward - it is recognition only; we say thank you and read every note.

3. What We Store In Your Browser (localStorage)

The following lives only in your browser, never on our servers:

  • Your authentication bearer token (stored under the localStorage key twt_auth_token). It is sent in the Authorization header on each request to authenticate your API calls. We do not use cookies to authenticate you (see section 4).
  • UI preferences (selected theme, sidebar state, etc.).
  • Cached display copy of your account info to avoid extra API calls on page load.

Clearing site data in your browser removes all of the above, including the bearer token - which signs you out. The server-side data in section 2 is unaffected by browser clears - to delete that, use the account-deletion process in section 9.

4. Cookies and Tracking Technologies

We do not use cookies to authenticate you or to track you. Authentication is handled by a bearer token stored in your browser's localStorage (the twt_auth_token key described in section 3), sent in the Authorization header on each request - not by a session cookie. Any cookies in use are strictly functional:

  • No authentication cookies - Sign-in uses the localStorage bearer token, not cookies.
  • Functional cookies only - If any cookie is set, it is strictly necessary for core app functionality, never for tracking or profiling.
  • Local storage - Used for your authentication token, user preferences, and game state (see section 3).
  • No tracking cookies - We do not use cookies for analytics or user tracking.
  • No third-party analytics - We do not embed tracking pixels or analytics services.

You can clear cookies and local storage from your browser settings at any time. Doing so removes the local bearer token and signs you out, but does not affect your ability to use core features once you sign in again.

5. Third-Party Services

5.1 Payment Processing (PayPal)

LoomMaster uses PayPal for processing payments. When you make a purchase:

  • Payment information is processed directly by PayPal, not stored on our servers
  • We receive only order confirmation and transaction IDs from PayPal
  • PayPal maintains industry-standard security compliance
  • Your payment method details are secured by PayPal's encryption

Please review PayPal's Privacy Policy for details on how they handle your payment information.

5.2 AI provider (Anthropic)

For play on the monthly web tier and on the Mirror Shard (founder) tier - where we run and pay for the AI - the AI narration is powered by Anthropic's Claude models, via the Anthropic API. To generate each response, your gameplay input and the relevant world state are sent to Anthropic's API for processing. Anthropic acts as our sub-processor for this purpose. Under our commercial API terms with Anthropic, your inputs and outputs are not used to train Anthropic's models; Anthropic may retain them for a limited period (currently up to ~30 days) for trust & safety and then delete them, unless a legal hold applies. Please review Anthropic's privacy policy for details on how Anthropic processes API data.

5.3 Bring Your Own AI (BYO over MCP)

If you play via the BYO (Bring Your Own AI) entitlement over MCP, the data flow is different: your inputs are processed by the AI provider or client you connect and pay for - they are not routed to Anthropic by us. Our server receives only the tool calls needed to run the deterministic engine. Your chosen AI provider's privacy practices govern that processing; please review their privacy policy.

5.4 Infrastructure and fraud screening (Cloudflare)

We use Cloudflare as a network/CDN and security layer. Cloudflare processes connection metadata (such as your IP address and request headers) to deliver the site, mitigate attacks, and provide country-level fraud screening. We do not use this for advertising or cross-site tracking.

5.5 No third-party tracking services

We do not integrate third-party analytics services, advertising networks, or user-tracking platforms. We do not sell or share user data with advertisers or data brokers.

6. How We Use Your Information

We use collected information for:

  • Providing, operating, and improving the Service (LoomMaster and Mythcore:Omniveil)
  • Processing payments and subscriptions (recurring monthly billing, one-time purchases, trials) and maintaining entitlement, drop-balance, and refund records
  • Maintaining game progress, persistent world/character state, and user accounts
  • Responding to support requests and inquiries
  • Sending service updates and support communications
  • Ensuring security and preventing fraud
  • Complying with legal obligations

We do not use your information for marketing purposes without explicit consent.

7. Data Sharing and Disclosure

We do not sell, rent, or lease your personal information to third parties. We only share information:

  • With service providers (like PayPal) who process data on our behalf under confidentiality agreements
  • When required by law or legal process
  • To protect our rights, privacy, safety, or property
  • With your explicit consent

8. Data Security

We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction:

  • Secure HTTPS connections for all data transmission
  • Encryption of sensitive information
  • Access controls and authentication mechanisms
  • Regular security assessments

While we strive to protect your information, no security system is impenetrable. Please use unique passwords and protect your account credentials.

8.1 Personal-data breach notification

If a personal-data breach affecting your information occurs, we will notify affected users and the Thai Personal Data Protection Committee (PDPC) without undue delay, as required by the PDPA (and, for users in the EEA/UK, in line with the GDPR).

9. Your Rights as a Data Subject (Thai PDPA / EU GDPR)

As an operator established in Thailand and accessible from any jurisdiction, we honor the data-subject rights granted by the Thai Personal Data Protection Act B.E. 2562 (PDPA) for users located in Thailand, and the EU General Data Protection Regulation (GDPR) for users located in the European Economic Area or the United Kingdom. The substantive rights overlap substantially; we describe them once below and honor them for all users regardless of location.

9.1 Right of access

You may request a copy of all personal data we hold about you, including account data, payment audit data, Veil Essence ledger entries, gameplay and chat history (your prompts and the AI replies), and in-world event records. We provide the export within 30 days at no charge.

9.2 Right to rectification

You may correct any inaccurate personal data we hold about you (e.g. email, display name, country of residence). Self-service updates are available in your account settings; for fields not exposed in the UI, contact us.

9.3 Right to erasure ("right to be forgotten")

You may request deletion of your account and all associated personal data. We will remove your account and personal data within 30 days. Exceptions: (i) the append-only chained ledger retains a redacted record (account id hash + amount + capture id only, with name / email scrubbed) because deleting ledger rows would break the cryptographic chain that protects all other users' audit integrity; (ii) data we are required to retain by Thai tax or accounting law (typically 5 years for VAT records, though we do not currently collect VAT).

9.4 Right to restriction of processing

You may request that we suspend processing of your personal data while a dispute or correction request is being resolved, instead of erasing it outright.

9.5 Right to data portability

You may request a machine-readable export (JSON) of the personal data you have provided to us (account profile, gameplay and chat history (your prompts and the AI replies), ledger entries). Provided within 30 days.

9.6 Right to object to processing

You may object to processing of your personal data carried out on the basis of our legitimate interests. (Note: we do not use your prompts, gameplay, or chat content to train or fine-tune AI models - see sections 2.4 and 5.2 - so there is no training use to object to.) Where you object, we will stop the relevant processing unless we have compelling legitimate grounds that override your interests or we need it to establish, exercise, or defend legal claims.

9.7 Right to withdraw consent

Where we rely on your consent as the lawful basis for processing (e.g. public Founders' Wall display, marketing communications), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

9.8 Right to lodge a complaint

If you believe our processing of your personal data infringes the PDPA or the GDPR, you may lodge a complaint with the relevant supervisory authority - for Thailand, the Office of the Personal Data Protection Committee; for the EU/EEA, your national data protection authority. We strongly encourage you to contact us first so we can resolve the issue directly, but you are not required to do so before approaching a regulator.

9.9 How to exercise these rights

Email [email protected] from the email address associated with your account, stating which right you wish to exercise. We respond within 30 days (often much sooner). We may ask for additional verification if the request would expose personal data and the request did not come from the registered account email.

9.10 Communications preferences

You may opt out of receiving non-essential communications from us by contacting us directly. Transactional communications related to your account, purchases, or refunds cannot be opted out of while your account is active.

10. Children's Privacy (18+)

The Service is intended for adults and requires users to be at least 18 years of age (or the age of majority in their jurisdiction, if higher). It is not directed to children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have collected data from a person under 18, we will delete it promptly. A parent or guardian who believes a minor has provided us data should contact [email protected] immediately.

11. International Data Transfers

TheWorldTable.ai (Sunisa Chaichan, DBD-registered) is based in Krabi, Thailand. Your information is processed and stored in Thailand. By using the Service, you consent to the transfer of your information to Thailand for processing and storage in accordance with this Privacy Policy.

12. Data Retention

We retain your information for as long as necessary to provide our services and fulfill the purposes outlined in this policy. You can request deletion of your account and associated data at any time. After account deletion, we retain only information required by law or for legitimate business purposes.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be effective when posted to our application. We will notify you of material changes via email or through the application. Your continued use of the Service following changes constitutes your acceptance of the updated Privacy Policy.

14. Contact and Legal Entity

If you have questions about this Privacy Policy, your personal information, or our practices, please contact us:

  • Email: [email protected]
  • Trade name: TheWorldTable.ai
  • Registered owner: Sunisa Chaichan
  • Registration: Thai Department of Business Development (DBD) individual commercial registration - verify at /dbd.html
  • Address: 31 Moo 6, Tumbon Ao Luek Tai, Ampur Ao Luek, Krabi, Thailand

We will respond within 7 business days.

Last Updated: June 29, 2026

LoomMaster by TheWorldTable.ai - Privacy Policy