Hoard-Board Privacy Policy
Effective Date: October 5, 2026
Hoard-Board is a WillAI company. This Privacy Policy explains how Hoard-Board and WillAI (“Hoard-Board,” “WillAI,” “we,” “us,” or “our”) collect, use, store, disclose, and protect information when you use Hoard-Board.
Hoard-Board is an AI-assisted creative storytelling platform that allows users to create stories and characters, generate story content, connect supported outside AI services, and use optional voice and story-audio features.
Questions about this Privacy Policy or your personal information may be sent to support@hoardboardstories.com.
1. Eligibility
Hoard-Board is intended for adults age 18 or older.
You must be at least 18 years old and at least the age of legal majority where you live to create or use a Hoard-Board account.
We do not knowingly permit minors to create Hoard-Board accounts. If we learn that an account belongs to someone who does not meet our age requirement, we may suspend or delete the account and associated information.
2. Information We Collect
Account Information
When you create or use a Hoard-Board account, we may collect:
- Your email address;
- Your display name;
- Your account and authentication identifiers;
- Your account status;
- Trial, membership, referral, and entitlement information; and
- Information necessary to authenticate and secure your account.
Authentication is provided through Supabase Auth.
If you sign in using email and password, your password is handled by Supabase Auth and is not stored by Hoard-Board.
If you choose Continue with Google, Google provides information necessary to authenticate your identity, such as your Google-linked email address and authentication identifier. Hoard-Board does not receive your Google password.
Stories and Creative Content
We store content that you create, upload, generate, accept, or save through Hoard-Board. Depending on the features you use, this may include:
- Stories and projects;
- Scenes and scene descriptions;
- Story events;
- Branches and story links;
- Characters and character sheets;
- Character and scene state;
- Memories;
- Relationship observations;
- Growth and self observations;
- Dreams;
- AI-generated and accepted story responses;
- Uploaded character portraits;
- Generated character audio;
- Narrator audio; and
- Voice previews and related voice configuration information.
Your stories are private to your account unless you deliberately use a sharing feature.
Hoard-Board does not currently provide a public story-browsing system that allows other users to browse your private stories.
If we introduce public or user-to-user story sharing, we may update this Privacy Policy and provide additional controls and disclosures.
Connected API Credentials
Hoard-Board allows you to connect certain supported outside AI and voice services using API credentials.
API credentials you enter are encrypted before storage using AES-256-GCM. The encryption key is maintained separately from the stored credential data.
Saved API credentials are not displayed back to you.
Hoard-Board uses a saved credential only when necessary to perform a supported request that you initiate or authorize.
Some outside-service API keys may grant substantial access to the account associated with that service. You are responsible for protecting your outside-service credentials and should revoke or replace them directly with the applicable provider if you believe they have been compromised.
Usage Information
Hoard-Board maintains records concerning use of AI and voice services. These may include:
- The service or provider used;
- Model information where applicable;
- Call counts;
- Token or character usage;
- Request timestamps;
- Whether a request succeeded or failed;
- Usage classification; and
- Other information necessary to enforce usage limits and account entitlements.
These records are used for spending controls, service limits, billing, security, troubleshooting, and service administration.
Billing and usage records retained independently of story content are designed not to contain the story text itself.
Character Portraits and Audio
Character portraits and generated story audio may be stored in private file storage so they remain available across sessions and devices.
Hoard-Board does not offer voice cloning and does not accept voice samples for the purpose of cloning a person's voice.
Users may connect voices maintained through an outside voice provider. Hoard-Board may also offer synthetic voice design based on written voice descriptions.
Hoard-Board does not browse or expose another user's private voice library.
Information Stored on Your Device
Some playback and interface preferences may be stored locally in your browser or installed application rather than in your Hoard-Board account.
These may include settings such as volume and automatic audio playback.
Other story-audio settings may be stored with the applicable Hoard-Board project.
3. How We Use Information
We use information collected through Hoard-Board to:
- Create and maintain accounts;
- Authenticate users;
- Save and display stories and characters;
- Generate AI-assisted story content;
- Provide character and narrator audio;
- Connect outside AI and voice services at your direction;
- Maintain story continuity, memories, relationships, and other features you choose to use;
- Enforce usage and spending limits;
- Provide trials, subscriptions, referrals, and other account entitlements;
- Secure Hoard-Board and prevent fraud or abuse;
- Diagnose technical problems;
- Provide customer support;
- Maintain and improve the reliability of the service;
- Enforce our Terms of Service; and
- Comply with applicable legal obligations.
We do not sell your personal information.
Hoard-Board does not currently display advertising.
Hoard-Board does not currently use third-party behavioral advertising or analytics scripts to track users for advertising purposes.
4. AI Processing
Hoard-Board Characters
When you ask a Hoard-Board-managed AI character to generate a response, information relevant to the requested story generation is sent to OpenAI through its API.
Depending on the character and story, this information may include scene context, character information, recent story events, memories, relationships, growth information, participant state, and other information necessary to generate the requested response.
The generated response is returned to Hoard-Board for use in your story.
Connected Outside AIs
Hoard-Board may allow you to connect an AI maintained by another service.
When you choose to send a turn to a connected outside AI, Hoard-Board sends the story context necessary for that AI to participate. Story events sent through this system are identified by speaker so that the connected AI can distinguish between participants.
The outside AI remains hosted by its original provider.
Outside AI services may maintain their own conversation histories or memories independently of Hoard-Board. Information transmitted to an outside provider is processed under that provider's own privacy policy, terms, and data-retention practices.
Hoard-Board story branches separate Hoard-Board's own story canon. They cannot guarantee separation of memory maintained independently by an outside AI provider. Information sent from one Hoard-Board branch may therefore influence an outside AI's response in another branch.
Voice and Story Audio
When you request speech generation, the dialogue or narration needed to create that audio is sent to ElevenLabs.
If you connect your own supported voice and API credential, requests involving that voice use your connected service account.
If you use a voice created and hosted by Hoard-Board or a Hoard-Board narrator preset, Hoard-Board may use its own service account.
Hoard-Board does not provide voice cloning.
5. Third-Party Service Providers
Hoard-Board uses third-party providers to operate portions of the service.
These currently include:
- Supabase — database hosting, authentication, and private file storage. Hoard-Board's primary Supabase infrastructure is currently hosted in Canada.
- Fly.io — application hosting. Hoard-Board's application server is currently hosted in Toronto, Canada.
- Cloudflare — domain and DNS services.
- Resend — transactional account emails such as confirmation and account-recovery messages.
- Google — optional Google account authentication and, where applicable, Google Play services.
- OpenAI — AI generation for Hoard-Board-managed characters and related AI functionality.
- ElevenLabs — supported speech and voice-generation functionality.
- Connected outside AI services — when you deliberately connect and use a supported outside service, information necessary to perform the request is transmitted to that service.
These companies process information under their own applicable agreements, privacy policies, and legal obligations.
6. Data Security
We use technical and organizational safeguards intended to protect Hoard-Board data.
These safeguards include authenticated access, HTTPS encryption in transit, private media storage, database-level ownership controls, application-level authorization, and encrypted storage of user-provided API credentials.
User-provided API credentials are encrypted using AES-256-GCM before storage. The encryption key is maintained separately from the database.
Passwords used for email/password authentication are handled by Supabase Auth rather than stored by Hoard-Board.
No system can guarantee absolute security. You are responsible for maintaining the security of your Hoard-Board account and any outside-service credentials you choose to connect.
If you believe your account or a connected API credential has been compromised, contact us and revoke affected third-party credentials directly with the applicable provider where appropriate.
7. Data Retention
We generally retain account and story information for as long as necessary to provide your Hoard-Board account and the features you use.
Connected API credentials are retained until you remove the connection, delete your account, or the credential is otherwise removed as part of service administration.
Certain operational records may be retained for legitimate purposes such as:
- Billing and accounting;
- Fraud prevention;
- Security;
- Usage enforcement;
- Dispute resolution;
- Compliance with legal obligations; and
- Enforcement of our Terms.
Where story content is deleted, retained billing or operational records are separated from that story content to the extent reasonably possible.
Backups
Hoard-Board maintains rolling backups for disaster recovery.
Our current backup schedule retains up to:
- 14 daily backups;
- 8 weekly backups; and
- 6 monthly backups.
Information deleted from the active service may remain temporarily in a disaster-recovery backup until that backup expires according to the applicable backup schedule.
Backups are maintained for disaster recovery and are not intended to function as user-accessible archives.
8. Account and Data Deletion
You may request deletion of your Hoard-Board account through Hoard-Board's account controls or through the public account-deletion page available on our website.
Deleting your account removes the active account and associated Hoard-Board data, including your stories, characters, story memories and observations, media, connected API credentials, and sign-in relationship.
Some minimal records may be retained when reasonably necessary for security, fraud prevention, accounting, legal compliance, dispute resolution, or another legitimate retention requirement.
Any retained information will be limited to what is reasonably necessary for those purposes and will not be used to preserve your deleted stories for ordinary use.
Deleted information may remain temporarily in disaster-recovery backups until those backups expire according to the backup schedule described above.
9. Your Choices and Rights
You may:
- Edit supported account information;
- Remove connected API credentials;
- Delete individual story content where the feature permits;
- Request deletion of your account; and
- Contact us concerning your personal information.
Depending on where you live, applicable privacy law may provide additional rights concerning access, correction, deletion, restriction, objection, or portability of personal information.
To submit a privacy request, contact support@hoardboardstories.com.
We may need to verify your identity before fulfilling a request concerning an account or personal information.
10. Adults Only
Hoard-Board is designed for adults.
We do not knowingly collect personal information from children or knowingly permit users under 18 to maintain Hoard-Board accounts.
If you believe a person under 18 is using Hoard-Board, contact support@hoardboardstories.com.
11. Legal Requirements and Safety
We may access, preserve, or disclose information when reasonably necessary to:
- Comply with applicable law or valid legal process;
- Respond to lawful governmental requests;
- Protect the rights or safety of users or others;
- Investigate fraud, abuse, or security incidents;
- Protect Hoard-Board or WillAI; or
- Enforce our Terms of Service.
12. Business Transfers
If Hoard-Board or WillAI is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, information may be transferred as part of that transaction subject to applicable law.
13. Changes to This Privacy Policy
We may update this Privacy Policy as Hoard-Board develops or as our legal, technical, or business requirements change.
When a change materially affects how we handle personal information, we will provide notice where required by law.
The effective date at the top of this page identifies the current version.
14. Contact Us
Questions, privacy requests, or concerns may be sent to:
Hoard-Board — a WillAI company