Davia — Privacy Policy

Effective date: 31 July 2026 · Version: 1.0

This Privacy Policy explains how Davia Labs, Inc. ("Davia," "we," "us," or "our") collects, uses, discloses, and retains personal information when you use the Davia game, website, creator tools, and related services (the "Service").

Davia Labs, Inc. is a Delaware corporation with a registered office at c/o Resident Agents Inc., 8 The Green, Suite R, Dover, DE 19901, USA. For privacy questions or requests, email .

This Policy applies to the Davia web game. It does not describe a different Davia product where that product provides its own privacy notice.


1. Information we collect

The information we collect depends on whether you browse, use a guest session, connect an account, play, create, publish, remix, make a purchase, or contact us.

Account and profile information

We may collect:

  • an internal user identifier;
  • email address and authentication status;
  • name, display name, and profile image supplied by you or your sign-in provider;
  • authentication provider and related account metadata;
  • whether an account is a guest or connected account; and
  • interface language and other account preferences.

If you use Google sign-in, Google provides information according to the permissions shown during sign-in. Email sign-in uses a verification code. Guest accounts receive an identifier but may not include an email address.

Your display name and profile image may be visible on a public profile page associated with your user identifier. Do not use a name or image that you do not want other people to see.

Gameplay, conversations, and memory

We collect the information needed to run and preserve your game, including:

  • selected game, character, language, and in-game settings;
  • actions, free-text instructions, selected or edited suggestions, drawings, and other inputs;
  • conversations with characters and AI-generated responses;
  • playthrough state, world events, locations within the fictional map, statistics, choices, timestamps, and progress;
  • summaries, memories, recent exchanges, and other context used to maintain continuity; and
  • technical traces, staged events, errors, and diagnostic information created while a turn or conversation is processed.

An in-game location or story time zone describes the fictional world. We do not ask for your device's precise physical location to play the game. Providers may still infer an approximate location from an IP address for security, routing, or legal-compliance purposes.

Creator, publication, and remix information

When you use creator features, we may collect:

  • drafts, prompts, files, maps, map cells, world descriptions, rules, premises, characters, entities, points of interest, statistics, and related metadata;
  • uploaded or generated images, audio, music, visual references, and other assets;
  • publication state, version history, creator identifier, and timestamps; and
  • remix lineage, including the source game, source version, source creator, remixer, and resulting copy.

Drafts are not public by default. Published games and their associated content may be displayed publicly, indexed by search engines, shared, played, and remixed as explained in the . A remix is an independent copy, so deleting or unpublishing a source does not automatically delete existing remixes.

Generated media and safety information

For AI and media features, we may collect or create:

  • prompts, conversation context, world state, visual descriptions, and reference images;
  • generated text, images, music, and sound;
  • provider, model, request, and generation identifiers;
  • generation timing, quality, and error information; and
  • automated safety classifications, risk scores, moderation results, and provenance information.

Purchases, subscriptions, credits, rewards, and referrals

Stripe processes purchases and subscriptions. Davia may receive and retain:

  • Stripe customer, checkout, subscription, invoice, payment-intent, and price identifiers;
  • purchase amount, currency, product, credits granted, transaction status, and timestamps;
  • credit balance and credit-movement history;
  • subscription status and renewal information; and
  • refund, dispute, chargeback, and fraud-prevention information.

Davia does not receive or store your full payment-card number from Stripe.

For rewards and referrals, we may collect referral codes, inviter and invitee identifiers, activation and claim history, eligibility information, and anti-abuse signals. When a connected user accepts a referral, we currently create a cryptographic hash derived from the request IP address and a secret to limit multiple rewarded signups from the same network. We store the hash, not the raw address in the referral profile field, although raw IP addresses may also appear in ordinary provider or security logs.

Communications, support, and reports

We collect the content and metadata of messages you send us, including support requests, feedback, rights notices, content reports, appeals, and billing questions. This can include your contact information, the reported content, supporting evidence, and our response or decision.

After a connected user's first playthrough records its first completed turn, we may send a one-time feedback email through Loops. For that workflow, we may use and send to Loops the user's email address, internal user identifier, first name if available, language, playthrough identifier, and event name. We retain an internal delivery record, and the contact may remain available in Loops after the message is sent.

Usage, device, analytics, and diagnostic information

We and our providers may automatically collect:

  • IP address, request time, browser, device, operating system, language, referring page, and network information;
  • authentication, cookie, local-storage, session, and similar identifiers;
  • pages viewed, buttons used, games played or shared, feature events, purchase flow events, and related story or playthrough identifiers;
  • authentication state, credit balance at the time of certain events, and account identifier; and
  • errors, stack traces, performance traces, logs, and session-replay data.

When a user is signed in, PostHog and Sentry currently receive the user's internal identifier and email address. Our current Sentry replay configuration may record text displayed on screen, text entered into fields, images and other media, and canvas or map activity. This can include gameplay, conversation, and creator content visible during the recorded session. See Section 7 for choices and important limitations.

2. Where information comes from

We obtain personal information:

  • from you, when you sign in, play, create, upload, purchase, publish, report, or contact us;
  • automatically, from your browser, device, use of the Service, cookies, logs, analytics, and security systems;
  • from service providers, such as Google, Supabase, Stripe, AI providers, and communications providers;
  • from other users, for example when someone refers you, remixes a game, reports content, or submits information involving you; and
  • from public or licensed sources, when creator content, maps, assets, or reports include public information.

3. Why we use information and our legal bases

We use personal information for the following purposes. Where European or UK data-protection law applies, the table also describes the legal bases on which we rely.

PurposeExamplesLegal basis where required
Provide the ServiceAuthenticate users; run gameplay; generate content; preserve conversations, memory, drafts, and progress; publish and remix gamesPerformance of our contract with you; steps requested before entering a contract
Process commerceCreate checkout and portal sessions; fulfill credits; manage subscriptions, refunds, disputes, and accountingPerformance of a contract; compliance with legal obligations
Operate rewards and referralsDetermine eligibility, grant credits, prevent duplicate or abusive claimsPerformance of the program terms; our legitimate interests in operating offers and preventing abuse
Keep the Service secureDetect fraud, abuse, prohibited content, prompt injection, account compromise, and technical attacks; investigate reportsOur legitimate interests in protecting users, Davia, and the Service; compliance with legal obligations
Maintain and improve the ServiceDebug errors; measure reliability and feature use; evaluate outputs; improve interfaces, models, prompts, and safety systemsOur legitimate interests in maintaining and improving the Service; consent where required for a particular tracker or technology
CommunicateSend authentication, billing, policy, safety, support, creator-review, and feedback messagesPerformance of a contract; legal obligations; our legitimate interests; consent where required
Publish content chosen for publicationDisplay, index, distribute, attribute, and enable in-Service remixing of public contentPerformance of our contract with you; our legitimate interests in operating public creator features
Enforce rights and obligationsApply our Terms, handle intellectual-property notices, preserve evidence, resolve disputes, and respond to lawful requestsLegal obligations; our legitimate interests in establishing, exercising, or defending legal claims

When we rely on legitimate interests, we consider the purpose, necessity, and effects of the processing. You may object as described in Section 10.

We do not use personal information for advertising based on activity across unrelated websites or services.

Some information is necessary to provide a feature. For example, an account identifier and gameplay input are needed to preserve a playthrough, an email is needed for a connected email account, and Stripe must receive payment information if you make a purchase. If you do not provide required information, the relevant feature may be unavailable. Publishing, adding optional profile details, accepting a referral, and sending non-essential feedback are optional.

4. AI processing and model improvement

The Service sends inputs and relevant context to AI and media providers to generate text, images, music, sound, suggestions, safety classifications, and other requested features. Depending on the feature, that context can include conversation history, actions, world state, character descriptions, public or private creator content, prompts, and reference images.

Davia does not currently use private conversations or creator content to train a general-purpose Davia AI model. We may still process that information to provide the requested output, maintain game memory, evaluate quality and safety, debug failures, prevent abuse, and improve the Service's prompts, workflows, and product behavior.

AI providers may retain inputs and outputs for limited periods or process them for security, abuse prevention, service operation, or other purposes permitted by the applicable provider terms, configurations, and contracts. These practices can vary by provider and feature. Do not submit highly sensitive personal information that is not needed for the experience.

5. When we disclose information

We do not sell or rent personal information for money. We disclose information in the following circumstances.

Service providers

Provider selection can vary by feature, availability, and fallback path. Current provider categories include:

CategoryCurrent providers may includeInformation and purpose
Authentication, database, and storageSupabase; Google sign-inAccount, profile, sessions, gameplay, creator content, and application data
Web hosting and deliveryVercel; Google Cloud Storage; CloudflareRequests, network data, logs, public and private assets, and content delivery
Text and reasoning AIGoogle Gemini; DeepSeek; OpenRouter and models accessed through itPrompts, actions, conversations, world context, memory, outputs, and safety requests
Image generationxAI; Fal; Google services where usedImage prompts, story and character context, reference images, outputs, and safety data
Music and soundGoogle Lyria or related Google services; ElevenLabsAudio prompts, story context, generated audio, and request metadata
PaymentsStripeContact, customer, checkout, subscription, payment, fraud, refund, and dispute information
Analytics and diagnosticsPostHog; SentryAccount identifiers, email, usage events, device/network data, errors, traces, and session replays
CommunicationsLoops; ResendEmail, name, language, message or event details, delivery status, and related identifiers

These providers process information under their agreements with us and their applicable policies. Some providers act as independent controllers for parts of their service, such as Stripe or Google when you interact directly with their checkout or sign-in interfaces.

Public disclosures

Information you publish is disclosed to the public. This may include a profile name and image, games, worlds, characters, maps, assets, creator attribution, version history, and remix lineage. Public content can be copied or indexed by other people and search engines outside our control.

Private playthroughs and drafts are not publicly displayed by default. They are still disclosed to the providers needed to operate, secure, and support the Service.

Legal, safety, and business disclosures

We may disclose information:

  • to comply with law, court orders, or valid governmental requests;
  • to protect a person's safety or the rights and security of users, Davia, or others;
  • to investigate fraud, abuse, security incidents, or violations;
  • to establish, exercise, or defend legal claims;
  • with professional advisers, auditors, insurers, and corporate service providers under appropriate duties; or
  • as part of a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law.

If you submit a copyright notice or counter-notice, we may share it, including contact information, with the person who published the reported content or the original claimant as described in our .

6. Public content, deletion, and remixes

You decide whether to publish a creator game. Once published, the content is public and other authenticated users may create independent remixes under the Terms of Use.

If you delete or unpublish a source game:

  • the source may become unavailable after a reasonable propagation period;
  • search engines, caches, recipients, or backups may retain copies for a time;
  • remixes already created do not automatically disappear; and
  • we may preserve limited source, version, creator, remix-lineage, moderation, and rights-enforcement records.

A legal or safety report may lead us to review and restrict a source, related remixes, or both, depending on what each version contains.

7. Cookies, analytics, and session replay

The Service uses cookies, local storage, and similar technologies for:

  • authentication and session security;
  • language and interface preferences;
  • fraud prevention and referral handling;
  • remembering purchase-flow context;
  • analytics and product measurement; and
  • error monitoring, performance tracing, and session replay.

Essential technologies are needed for sign-in, security, and requested features. PostHog analytics and Sentry diagnostics may start when the Service loads. As explained in Section 1, current replay settings may capture visible and entered content, media, and canvas activity.

You can use browser controls to delete or block cookies and local storage, but blocking essential technologies may prevent sign-in or other features from working. Applicable law may require prior consent for non-essential analytics or replay technologies. The Service does not yet offer a complete in-product consent-management interface; this is an operational limitation, and browser blocking is not equivalent to a full consent control.

8. Email and communications

We may send messages needed to authenticate your account, process payments, respond to requests, enforce our policies, or provide important Service or legal updates. We may also send the one-time feedback message described in Section 1.

To stop non-essential email, use an unsubscribe control included in the message when available or email . We may retain limited suppression information so that we can respect the request. You cannot opt out of messages strictly necessary for an active account, transaction, safety matter, or legal obligation.

Emails may contain delivery or interaction technologies supplied by our communications providers. Applicable law may require consent or another valid basis for those technologies. The Service does not yet expose a separate in-product control for email tracking; you may object by contacting us.

9. How long we retain information

We retain information for no longer than reasonably necessary for the purposes described in this Policy. Because the Service is persistent, some categories are kept for the life of an account or content unless you request deletion.

We use the following criteria:

  • Account, private gameplay, conversations, memory, and drafts: while your account or the relevant content remains active, and afterward for a reasonable deletion, backup, security, or dispute period.
  • Public content and profile information: while published or needed to operate the public feature; copies outside our control and existing remixes may remain. Limited attribution and lineage may be retained as described above.
  • AI requests, outputs, traces, and safety records: for the time needed to deliver the feature, preserve game continuity, debug, evaluate safety, prevent abuse, and resolve disputes. Provider retention may differ.
  • Purchases, subscriptions, credit ledgers, and rewards: for transaction, accounting, tax, fraud, chargeback, and legal-retention requirements.
  • Referral anti-abuse hash: while needed to enforce referral limits and investigate abuse, or until the associated record is deleted when no longer needed.
  • Support, reports, and rights notices: for the time needed to handle the matter, document the decision, prevent abuse, and establish or defend claims.
  • Feedback email and delivery records: while needed to send and evaluate the message, honor suppression requests, and maintain an auditable delivery record. The Loops contact may remain until deletion or suppression is applied.
  • Analytics, security logs, diagnostics, and replays: according to the configured provider retention period and for as long as needed for analytics, reliability, security, and incident response.

Backups, caches, and provider systems may take additional time to purge. We may retain information longer when required by law, necessary for safety or fraud prevention, or needed to establish, exercise, or defend legal claims. We may also aggregate or de-identify information so it can no longer reasonably be linked to you.

10. Your privacy rights and choices

Depending on where you live, you may have the right to:

  • know whether we process your personal information and obtain access to it;
  • receive information about categories, sources, purposes, and recipients;
  • correct inaccurate information;
  • delete information, subject to legal and operational exceptions;
  • receive a portable copy of certain information;
  • restrict or object to certain processing, including processing based on legitimate interests or direct marketing;
  • withdraw consent without affecting earlier lawful processing;
  • opt out of a sale, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling where applicable;
  • limit certain uses of sensitive personal information where applicable;
  • appeal a denial of a privacy request; and
  • complain to your local data-protection or privacy regulator.

Davia does not currently sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising, so we do not offer an opt-out for those activities.

To exercise a right, email and describe your request. We may need to verify your identity and authority to protect your account and other people. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct verification. We will respond within the period required by applicable law.

You may request deletion of an account or specific content by email. The Service does not currently provide a complete self-service export or deletion control. Deletion may not remove public copies outside our control, independent remixes, transaction records, suppression records, or evidence we are legally permitted or required to retain.

We will not unlawfully discriminate against you for exercising a privacy right. If we deny a request, you may reply to our decision to appeal where applicable.

European Economic Area and United Kingdom

You may object to processing based on legitimate interests. You also have the right to lodge a complaint with the supervisory authority where you live, work, or believe an infringement occurred. You may contact us first so we have an opportunity to address the concern.

United States

Residents of California and other states with applicable comprehensive privacy laws may have rights to know, access, correct, delete, and obtain a copy of personal information, as well as rights concerning sale, targeted advertising, sensitive information, profiling, and appeals. The categories collected, sources, purposes, and recipients are described throughout Sections 1 through 5. We do not knowingly use or disclose sensitive personal information for the purpose of inferring characteristics for advertising.

For purposes of U.S. state privacy-law categories, the information described in Section 1 may include identifiers and customer records; commercial information; internet or other electronic-network activity; audio, visual, and creative content; approximate location inferred from network information; inferences and safety classifications; and sensitive information such as account credentials or private communications. During the preceding 12 months, we may have disclosed these categories for the operational purposes described in Section 5 to the corresponding provider categories. We have not sold them or shared them for cross-context behavioral advertising.

Credits offered through rewards or referrals are based on eligible activity and program rules. They are not offered in exchange for permission to sell personal information or use it for targeted advertising.

11. International data transfers

Davia is based in the United States. We and our providers may process information in the United States and other countries whose laws may differ from those where you live.

Where applicable law restricts a transfer, the transfer must use an available legal mechanism and appropriate safeguards. Depending on the recipient and country, these may include an adequacy decision, standard contractual clauses, the UK international data transfer addendum or agreement, or another lawful mechanism. Contact to request information about safeguards applicable to a particular transfer.

12. Security

We use administrative, technical, and organizational measures designed to protect information, including authentication controls, role-based database access, row-level security, restricted service credentials, and encrypted network transport where supported. No system is perfectly secure, and we cannot guarantee that information will never be lost, accessed, or disclosed without authorization.

You are responsible for protecting access to your email and sign-in provider. Contact if you believe your account or information has been compromised.

13. Automated safety systems

We use automated systems to classify content, detect prompt injection, identify fraud or referral abuse, evaluate generated media, and enforce some feature limits. These systems may block, rewrite, flag, or restrict a request and can make mistakes.

Automated signals may also support content or account enforcement. To contest a restriction or decision, email with the account and content or request involved. Where applicable law gives you a right concerning solely automated decisions with legal or similarly significant effects, you may request information and human review.

14. Children

The Service is intended only for people who are at least 18 years old. We do not knowingly allow children to use the Service. The Service does not currently operate a complete age-verification system, so the contractual age requirement is not by itself proof that every user is an adult.

If you believe a person under 18 has provided personal information, contact . If we learn that a child has provided information in circumstances where processing is not permitted, we will take appropriate steps to restrict the account and delete the information, subject to legal obligations and safety needs.

15. Changes to this Policy

We may update this Policy as the Service, providers, or law changes. We will change the version and effective date and provide additional notice when a change is material or applicable law requires it. We will not treat continued use as consent where the law requires an affirmative choice.

16. Contact

Privacy questions and rights requests:

  • Email:
  • Company: Davia Labs, Inc.
  • Address: c/o Resident Agents Inc., 8 The Green, Suite R, Dover, DE 19901, USA

Please do not send passwords, full payment-card details, government identifiers, or unnecessary sensitive information in an email request.