The Weaver — Privacy Policy
Effective date: 2026-09-14
The Weaver's early-access release opened on itch.io in July 2026. This is the first published version of this policy — it was not in effect before today, and we are not claiming it was. What it describes about how the app handles your data has been true of the app throughout.
Last updated: 2026-09-14
Maintained by: SUNRUNNER STUDIOS (Ontario, Canada)
The short version
The Weaver is a desktop app you install and run on your own computer. It does not have an account system. It does not phone home with your gameplay. It uses a "Bring Your Own Key" model — your AI provider keys live on your machine, and your prompts and audio go directly from your machine to the providers you've chosen, never through us.
We don't know who you are, what you played, or what your characters did, unless you opt-in to share crash reports or send us a feedback message inside the app.
What follows is the long version, written in plain English.
Who we are
The Weaver is built by SUNRUNNER STUDIOS, a sole proprietorship registered in Ontario, Canada — Business Identification Number 1001606849, registered 2026-05-12. You can reach us at al@sunrunner-studios.com for any privacy question. That address reaches a person, not a queue; we are a one-person studio and we answer it ourselves.
What "BYOK" means for your privacy
To use The Weaver, you provide your own API keys for the AI services it uses (Google Gemini for narration, Groq for voice transcription, optionally Anthropic or OpenAI as fallbacks). When you save those keys in The Weaver:
- They are stored locally on your computer, encrypted with your operating system's secure storage when available (macOS Keychain, Windows DPAPI, Linux libsecret). When secure storage is not available, keys are written to a local file in
~/.weaver-rpg/with restricted file permissions. - They are never transmitted to Sunrunner Studios. We have no servers that receive or store your keys.
- They are sent only to the provider they belong to (your Gemini key only goes to Google, your Groq key only goes to Groq, etc.) when The Weaver makes a request on your behalf.
If you use the Sign in with Google or Sign in with ChatGPT buttons in the API Keys panel, we store the resulting OAuth token bundle (access token, refresh token, expiry timestamp, and the email address the provider tells us about) the same way — encrypted at rest in the OS secure store when available, locked-down file otherwise. We treat OAuth tokens the same as API keys: never transmitted to us, sent only back to the provider that issued them. Refresh tokens can be long-lived, so if you stop using one of the sign-ins, press Clear in the API Keys panel to remove the local copy.
What data the providers receive
When you play, the relevant prompts and content go directly from your computer to the provider you've chosen, billed against your key. This is the same as if you were using each provider's website directly. Specifically:
- Google (Gemini API) receives the narration prompts, the world state, and your action text. When you use voice input and haven't configured a Groq key, Gemini also receives your microphone audio for transcription — that's the default voice-input path on a Gemini-only setup.
- Groq receives your microphone audio for voice-to-text transcription when you've configured a Groq key (the Weaver prefers Groq over Gemini for STT when both are available, because it's faster).
- Anthropic receives narration prompts when the multi-provider fallback chain hops to it (only if you've configured an Anthropic key).
- OpenAI receives narration prompts when the fallback chain hops to it (only if you've configured an OpenAI key or signed in with ChatGPT).
- Microsoft (edge-tts default) receives the Weaver's narration text for text-to-speech, unless you've switched to a different TTS provider.
- Cloudflare sees the public-invite URL you generate when you choose to host a group session over the internet. The Weaver uses Cloudflare's
trycloudflare.comquick-tunnel service. Cloudflare's terms apply to that traffic.
Each provider has its own privacy practices — they govern what data those providers store, log, or use. We do not control those practices and strongly recommend reading the privacy policy of every provider you authorize.
The one thing we do collect: the waitlist
The landing page has an email signup for release news. If you type your address into it and submit:
- Your email address is sent to a Google Apps Script endpoint we run, which appends it to a private Google Sheet in our Google account. That is the whole record — we do not capture your name, your IP address, or anything else with it.
- We use it for one thing: telling you about The Weaver's releases. We do not sell it, rent it, or share it with anyone.
- Ask and it's gone. Email us at al@sunrunner-studios.com and we will delete your row. You do not have to explain why, and you do not have to be able to prove the address is yours beyond sending the request from it.
Google processes and stores that sheet on our behalf, under Google's own terms. If you would rather not be on a list in a Google Sheet, do not use the signup — nothing else on the site collects anything, and the app itself never asks.
Service providers we use
PIPEDA requires us to disclose the third parties that touch any data on our behalf. Sunrunner Studios uses very few of these because the desktop app is local-first; here is the complete list:
| Provider | Purpose | What they may see |
|---|---|---|
| Cloudflare | DNS and web hosting for sunrunner-studios.com; the trycloudflare.com quick-tunnel for group play; email routing for our contact addresses |
Standard web traffic (IP, user-agent) on the marketing site; relayed traffic for hosted group sessions; emails sent to or from our contact addresses |
| Google Workspace (Apps Script + Sheets) | Storing the landing-page waitlist email list | The email address you typed into the signup form, and nothing else |
| itch.io | Distribution and payment processing for The Weaver's early-access release, including pay-what-you-want contributions | Your itch.io account activity for the purchase or download, and payment information, both handled by itch.io under its own privacy policy and payment terms. We see only what itch.io reports to us as the seller: the amount, the date, and the buyer's itch.io display name. We never see card data. |
| Sentry (opt-in only — off by default) | Crash reporting if you've enabled it in Settings | Error message, stack trace, app version, OS — never your prompts, your campaign content, your API keys, or anything you typed |
| GitHub | Source hosting and continuous integration for the project | No end-user data. The Weaver is distributed through itch.io, not from GitHub. |
| AI providers (Google Gemini, Anthropic, OpenAI, Groq) | Generate narration, transcribe voice — using your own API key or sign-in | Whatever you send through your account. These are your direct relationships with each provider, not Sunrunner Studios'. Each provider's privacy policy applies; we encourage you to read the policy of every provider you authorize. |
| Microsoft (edge-tts) | Text-to-speech narration when edge-tts is the active TTS provider | The narration text the Weaver speaks aloud |
We do not share data between these providers, nor do we operate any backend that aggregates data about you across them. If you have a question about how we work with any of these providers, contact the privacy officer at the address below.
What stays on your computer
Your campaign content — adventure notes, transcripts, character sheets, character knowledge, world state, audio recordings before transcription, session backups — is stored locally in ~/.weaver-rpg/. Sunrunner Studios does not see or copy this content. Daily database backups are written to that same folder; they do not leave your machine.
If you delete your local data (delete the ~/.weaver-rpg/ folder), it is gone.
What we collect, and only with your consent
The Weaver has two narrow channels where data can reach Sunrunner Studios. Both are off by default and require you to take an action.
1. Crash reporting (opt-in). If you enable crash reporting in Settings, The Weaver may send error reports to our crash-reporting provider (Sentry). These reports include the error message, a stack trace, the app version, and the OS — they do not include your prompts, your campaign content, your API keys, or any text you typed. You can turn this off at any time in Settings.
2. Feedback messages (you-initiated). When you press the in-app Send Feedback button, your message — and your email if you provide one — is sent to a Sunrunner Studios feedback channel (currently a Discord channel via webhook). Alongside the message we also send a small set of diagnostic fields that help us reproduce bugs: the app version, the OS platform identifier your browser reports, the browser-engine user-agent string, and a submission timestamp. We never include your prompts, your campaign content, or your API keys in this payload. Nothing is sent unless you press the button.
We do not use analytics, fingerprinting, or background telemetry of any kind in the desktop app. There is no advertising. We do not sell or share data, because we do not have your data to sell or share.
Group play (Cloudflare Tunnel)
When you, as a host, generate a public invite link for a group session, The Weaver starts a Cloudflare quick-tunnel that exposes your local server to the internet at a temporary trycloudflare.com URL. While that tunnel is running:
- Players who have the URL can connect to your machine to play.
- Cloudflare relays the traffic. Cloudflare's terms apply.
- Sunrunner Studios is not involved in the connection — we do not see the URL, the traffic, or who joined.
- When you stop the public invite or quit the app, the tunnel closes.
We don't store your invite URL or anything that travels through the tunnel.
Group-play participant consent
When you host a multi-player session, the Weaver captures input from every player at the table — what they type, what they say, what their characters do — and stores it locally as part of your campaign transcript. If you choose to share that transcript or recording outside the session (with us via feedback, on a podcast, in a YouTube video, with friends, on social media), that share now includes content authored by other people at your table.
As the host, you are responsible for getting your players' consent before sharing any session content that includes their input. Specifically:
- Sharing transcripts, recordings, or screenshots that include other players' text, dialogue, or character actions — get their permission first.
- Including third-party content (a player's character name, their words, their voice) in feedback messages you send Sunrunner Studios — get their permission first.
- Publishing any session content publicly — get the players' permission first, and consider whether it identifies them in ways they didn't anticipate.
The Weaver itself doesn't broadcast or store session recordings centrally — they live on your machine. Once you share something off your machine, the consent question is between you and the players at your table. We can't enforce this for you; we can only ask, in writing here, that you treat your players' contributions the way you'd want yours treated.
If you receive a request from another player (one of your guests, not the host) asking us to remove their content from anything we hold, we'll honor that to the extent we can — which, given our local-first architecture, mostly means: if you've sent us a feedback message containing their words, we'll delete that message. Anything still on the host's local machine is the host's responsibility.
The landing page (sunrunner-studios.com)
The marketing site at sunrunner-studios.com runs no analytics or tracking scripts at all — no Google Analytics, no Cloudflare Web Analytics beacon, no advertising pixels, no cookies set by us. The site is served through Cloudflare, so Cloudflare processes standard request data (IP address, user-agent) as our hosting provider in the ordinary course of serving the page, and reports it to us only in aggregate. The desktop app does not load the landing page or share anything with it.
Children
The Weaver is not directed at children under 13. AI-generated content can be unpredictable; we don't recommend unsupervised use by young children. We do not knowingly collect data from children under 13, in part because we collect very little data from anyone.
Your rights
Because Sunrunner Studios does not store personal data about you in the normal course of running The Weaver, most rights-of-access requests have a simple answer: we don't have anything about you to access, correct, or delete.
If you live somewhere with specific privacy rights (such as the EU, UK, or California) and want to confirm this — or if you've sent us a feedback message and want it deleted — contact us at the email above.
Personal information breach response
PIPEDA requires us to take reasonable steps if a breach occurs that creates a real risk of significant harm to anyone whose personal information we hold. Because The Weaver is local-first and Sunrunner Studios collects very little, the realistic scope of what could ever be breached on our side is small — limited to feedback messages you've sent us and (opt-in) crash reports.
What counts as a breach: unauthorized access to, disclosure of, or loss of personal information held by Sunrunner Studios. Examples that would trigger this procedure: someone gaining unauthorized access to the inbox where feedback messages arrive, or a misconfiguration exposing stored crash reports.
Our response procedure if we become aware of a breach:
- Within 24 hours of becoming aware: the privacy officer (currently Al Morrish, contact below) confirms the scope, contains the breach, and stops the source.
- Within 72 hours: if the breach creates a real risk of significant harm, we will notify the affected individuals directly — by email at the address you used to contact us, or via an in-app notice on next launch. We will also notify the Office of the Privacy Commissioner of Canada (OPC) when PIPEDA requires it.
- Within 7 days: we will publish a brief summary of what happened and what we did, in the project's release notes and any community channel that's been established by then.
- Records retained for 24 months minimum, as PIPEDA requires.
You do not need to do anything to be eligible for breach notification — if you've sent us a feedback message or opted into crash reports, and we therefore have a way to reach you, we will reach you.
If you believe a breach has affected you and we haven't yet reached out, please contact the privacy officer at the address below.
Changes to this policy
If we change how this works, we'll update this page with a new "Last updated" date and post a note in the project's release notes and Discord. For changes that materially affect your privacy (for example, if we ever add a new place data could go), we'll surface a notice in the app on next launch and require you to acknowledge it.
Contact
al@sunrunner-studios.com