Privacy and Data Protection Policy
Your privacy and the confidentiality of your projects are absolute priorities at Dice on Top. This Policy describes clearly and transparently how we collect, process and protect your personal data, and how we guarantee you full control over it, in compliance with Brazil's General Data Protection Law (LGPD — Law No. 13,709/2018) and applicable international regulations such as the GDPR (EU Regulation 2016/679).
This is a courtesy translation of the original document, which is written in Brazilian Portuguese. In the event of any discrepancy between versions, the Portuguese version prevails for all legal purposes.
Our privacy commitments
1. Our Privacy Commitment and Principles
Dice on Top takes a Privacy by Design and Privacy by Default approach. All processing of personal data is governed by the following core principles:
- Minimisation and necessity: We collect strictly the data required for the secure operation of your account and the design tools;
- Purpose and transparency: Every piece of data has a legitimate, explicit purpose, disclosed to the user in advance;
- Security and prevention: Advanced technical and organisational measures safeguard information against unauthorised access, loss or tampering;
- Free access and quality: Data subjects are guaranteed easy access to, and accuracy of, their data;
- Non-discrimination: Data may never be processed for discriminatory, unlawful or abusive purposes.
2. Personal Data and Information Collected
We classify the data processed by the Platform into the following categories:
a) Authentication and registration data
Email address and access credentials with cryptographic hashing (handled in isolation and securely by Supabase Auth). We never store your password in plain text.
b) User profile data
Public username, optional bio (max. 280 characters), avatar selected from the inventory, and self-declared experience level in game design.
c) Interface preferences
Active theme (Dark Mode, Light Mode, Catppuccin Mocha), selected language and editor display settings.
d) Creative and project content
Project and deck titles and descriptions, data tables (imported datasets/CSV), Bento Engine block definitions, Freeform settings, game version history and the image URLs associated with your cards.
e) Technical data and operational telemetry
Request IP address (used strictly for DDoS mitigation, fraud prevention and rate limiting), system error logs, and JWT authentication session tokens with time-based expiry.
3. Legal Bases for Processing (LGPD & GDPR)
In strict alignment with Art. 7 of the LGPD and Art. 6 of the GDPR, all processing carried out by Dice on Top rests on valid legal grounds:
- Performance of a contract (LGPD Art. 7, V / GDPR Art. 6(1)(b)): Processing needed to provide the card creation infrastructure, persist your projects and run the 3D playtest agreed in the Terms of Use;
- Compliance with a legal obligation (LGPD Art. 7, II / GDPR Art. 6(1)(c)): Retention of internet application access logs in compliance with Article 15 of the Brazilian Internet Civil Framework (Federal Law No. 12,965/2014);
- Legitimate interests (LGPD Art. 7, IX / GDPR Art. 6(1)(f)): Improving software performance, protecting against cyber vulnerabilities and ensuring server stability;
- Consent (LGPD Art. 7, I / GDPR Art. 6(1)(a)): Where freely, unambiguously and knowingly given (for example, when voluntarily choosing an avatar and a public bio).
4. Purposes of Data Processing
The data we collect is used solely and exclusively for the following purposes:
- Authenticating User access and managing session security;
- Synchronising card, layout and table changes between the browser and the cloud database in real time;
- Processing the compilation and download of high-resolution files (print PDFs, spritesheets and
.doi.jsonexports); - Rendering the 3D simulation environment in the browser;
- Sending essential service notifications, such as security alerts and policy updates.
5. Information Security, Encryption and RLS
We apply rigorous technical and administrative cybersecurity measures:
Encryption in transit and at rest
All communication between your browser and the Platform is encrypted with TLS 1.3 / HTTPS using high-security certificates. Data at rest in the production databases is stored with standard AES-256 encryption.
Row Level Security (RLS) in PostgreSQL
Our database architecture uses strict PostgreSQL-native Row Level Security policies. This means that, at the database engine level, no user and no query has technical permission to read, update or delete another user's projects, decks or data.
Password management
Passwords go through modern irreversible cryptographic hashing algorithms with individual salts, so that not even the infrastructure administrators know the registered password.
6. Local Browser Storage and Cookies
6.1. Local storage technologies: Dice on Top uses browser features to improve usability and performance:
- IndexedDB: Stores a structured cache of your projects and card versions locally in your browser, so you can browse and switch between cards in milliseconds without straining your internet connection;
- localStorage: Saves your theme preference, your chosen language and the encrypted session token, so you stay conveniently logged in.
6.2. No advertising tracking cookies: We do not use third-party cookies for browsing surveillance, ad retargeting, or behavioural profiling for advertisers or social networks.
7. Cloud Infrastructure and International Transfers
7.1. Infrastructure providers: Our services are hosted on market-leading cloud infrastructure (including Supabase and AWS data centres), with ISO/IEC 27001, SOC 2 Type II and HIPAA compliance certifications.
7.2. International transfer mechanisms: Where data travels to or is stored on servers located outside Brazil or the European Union, the transfer is based on Art. 33 of the LGPD and Arts. 44 to 49 of the GDPR, through Standard Contractual Clauses and strict confidentiality and security obligations.
8. Your Rights as a Data Subject
Under Art. 18 of the LGPD and Arts. 15 to 22 of the GDPR, you have the following guaranteed rights, exercisable at any time:
Confirmation and access
Confirm that processing takes place and access all of your registered personal data.
Correction and rectification
Correct incomplete, inaccurate or outdated data directly in your profile panel.
Data portability
Export your projects and decks in full, in the open and interoperable .doi.json standard.
Erasure and right to be forgotten
Permanently delete your personal data and projects through the immediate account deletion tool.
Information about sharing
Learn which public or private entities your data may be shared with.
Withdrawal of consent
Withdraw your consent at any time, simply and free of charge.
9. Retention, Disposal and Full Account Deletion
9.1. Retention period: Personal data and project files are kept for as long as your account is active and in use.
9.2. Instant deletion via Danger Zone: In full respect of the right to erasure, we provide a direct, self-service flow in your account settings.
Effect of account deletion:
Once you confirm deletion by typing the security phrase, the database call cascades the destruction of your authentication record, profile, projects, decks and cards from our servers.
9.3. Legal retention of connection logs: Certain technical application access logs are kept confidential for a strict period of 6 (six) months, to comply with the mandatory requirement of Article 15 of Brazilian Federal Law No. 12,965/2014 (Internet Civil Framework), after which they are compulsorily erased.
10. Protection of Children and Minors
10.1. Age restriction: The Platform is not directed at, and does not knowingly collect data from, children under 13 (thirteen) years of age, in line with Art. 14 of the LGPD and with the Children's Online Privacy Protection Act (COPPA).
10.2. Immediate action: If you become aware that a child under 13 has registered personal data on the Platform without verified parental or guardian consent, contact us immediately so that we can remove that information immediately and permanently.
11. Updates and Data Protection Officer (DPO) Contact
11.1. Periodic reviews: This Privacy Policy may be reviewed from time to time to keep pace with technological innovation and regulatory updates from the Brazilian National Data Protection Authority (ANPD) or other competent international bodies.
11.2. Data Protection Officer (DPO) channel: To exercise any of your rights as a data subject, ask questions, make suggestions or submit requests relating to the processing of your personal data, contact our Data Protection Officer at help.diceontop@gmail.com.
Privacy channel & Data Protection Officer (DPO)
Response time for data subject requests: up to 15 (fifteen) business days, as required by the LGPD.