This Policy explains what TheMarketBug LLC ("we," "us") collects, why we collect it, who else sees it, and the choices you have. We've written it in plain English because roleplay content is personal, and you deserve to know exactly what happens to it.
1. What we collect
Account information
- Your email address — used for login, account recovery, billing notices, and essential service communications.
- A username (visible to you; may be visible to other users if you participate in the marketplace or party sessions).
- An encrypted password hash. We do not store your password in plaintext.
Content you create
- Characters, personas, worlds, scenes, and the messages you exchange with them.
- This content is stored so your memory system works — without it, the platform cannot do the thing it exists to do.
- Structured memory data: entities, relationships, and facts that the system extracts from your conversations. This is visible to you in the Memory page and editable/deletable.
Billing information
- Payment data is handled by Stripe, our payment processor. We do not store your full card number, CVV, or banking details — Stripe handles all of that.
- We store: your Stripe customer ID, subscription tier, subscription status, and billing period dates. This lets us provide the service you paid for and display your subscription status.
- Stripe's privacy practices are governed by their own privacy policy, available at stripe.com/privacy.
Operational data
- Usage data: message counts, feature use, API calls, error logs. Used for capacity planning, abuse prevention, and product improvement.
- Server logs: timestamps, request sizes, IP addresses, error traces. Retained for up to 90 days for debugging and security.
- Subscription history: records of your plan changes, payments, and cancellations. Retained for accounting and legal compliance.
2. The important part: who processes your roleplay content
When you send a message in a scene, that message — and the surrounding context needed to generate a reply — is sent to a third-party language model provider. This is fundamental to how the Service works. You should assume your roleplay content is processed by these providers.
- Default (Free and Pro tiers): we route requests to our configured model provider (currently MiMo, operated by Xiaomi). Their handling of your prompts is governed by their privacy policy and terms, in addition to ours.
- BYO Key tier: you connect your own model API key. Your prompts go directly to the provider you selected. We do not see your API key in plaintext (it is stored encrypted) and we are not a party to your relationship with that provider.
We do not currently use your roleplay content to train our own models, and we do not grant our model providers a license to train on your content beyond what their own terms allow for inputs they receive. If we ever change this, we will update this Policy and notify active users before doing so.
3. Memory extraction
The Service automatically extracts structured memory from your conversations — entities (characters, places, objects), relationships (who trusts whom), and facts. This is the core differentiator of the platform. This extracted memory:
- Is stored in your account's database, scoped to your sessions and worlds.
- Is visible to you in the Memory page, where you can review, edit, or delete individual entries.
- Is generated by an AI model call (MiMo) that processes your recent messages to produce the extraction. The same data-processing caveats from Section 2 apply.
- Is never shared with other users unless you explicitly publish a character or world to the marketplace.
4. How we use your information
- To operate the Service — generating replies, maintaining your memory graph, syncing your sessions, processing payments.
- To communicate with you about your account, billing, security, and major policy changes.
- To prevent abuse, fraud, and violations of our Terms.
- To improve the Service — fixing bugs, planning capacity, deciding what features to build next. Aggregated and de-identified data may be used for this; it is not tied back to your identity.
- To comply with legal obligations and respond to lawful requests.
We do not sell your personal information or your roleplay content.
5. Cookies and local storage
The Service uses minimal client-side storage. Your authentication token is stored in your browser's localStorage so you stay signed in. We do not use third-party advertising or cross-site tracking cookies. If we add analytics, it will be configured to respect Do Not Track and will be limited to first-party, privacy-respecting measurement.
6. Data retention
- Your roleplay content is retained for as long as your account is active, so your memory system keeps working.
- When you delete specific content (a scene, a character, a memory entry), it is removed from the active system promptly and from backups within 90 days.
- When you delete your account, your content is deleted within 30 days, except for billing records retained for accounting/tax compliance and limited server-log fragments retained for security.
- Server logs are retained for up to 90 days.
- Billing records (subscription history, payment references) are retained for 7 years as required for tax and accounting compliance.
7. Your choices and rights
Depending on your jurisdiction (e.g. GDPR, CCPA), you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and associated content.
- Export a copy of your data (the platform supports exporting characters and scenes).
- Object to or restrict certain processing.
- Withdraw consent for any processing based on consent.
- Cancel your subscription at any time via the billing settings or Stripe Customer Portal.
To exercise any of these, contact us at support@themarketbug.com. We will respond within the timeframe required by applicable law (typically 30 days).
8. Security
- Encrypted password storage (bcrypt).
- Encrypted API key storage (Fernet encryption at rest).
- Reset tokens stored as SHA-256 hashes, not plaintext.
- TLS encryption in transit for all API and web traffic.
- Payment processing handled by Stripe (PCI-DSS compliant).
- Access controls on production systems; database backups with integrity verification.
No service is perfectly secure. If a breach occurs that materially affects you, we will notify affected users as required by law.
9. Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from minors. If you believe a minor has provided us personal information, contact us and we will delete it.
10. International users
The Service is operated from the United States by TheMarketBug LLC. Your data may be processed in the United States or by model providers in other jurisdictions. By using the Service you consent to this cross-border transfer as described in this Policy.
11. Changes to this Policy
We may update this Policy to reflect changes in our practices, our model providers, or the law. If we make material changes, we will update the "Last updated" date above and notify active users where appropriate. We encourage you to review this page periodically.
12. Contact
Privacy questions can be directed to support@themarketbug.com. If you have a concern that we have not resolved, you have the right to lodge a complaint with your local data protection authority.