Who we are
Caplan Studio LLC ("Caplan Studio", "we", "us") is an independent software studio registered in Arizona, United States. We build our own products and we operate them ourselves, which means this policy is written by the studio that runs the servers.
For anything in this policy, including data requests, write to [email protected].
What this covers
This policy applies to caplanstudio.com and to every product we operate:
- Gamenight (pvpers.us), community hubs for gaming groups
- PantryTrack (pantrytrack.app), pantry and grocery tracking
- Tales & Fables (talesnfables.com), collaborative writing
- BookLocally (booklocally.net), booking storefronts for local businesses
- CrewTempo (crewtempo.com), staff scheduling and timesheets
- RecallRally (recallrally.com), spaced-repetition flashcards
- ServerPack (mc.pvpers.us), Minecraft community sites and plugins
Products differ in what they need, so a few sections below single out the product they apply to. If a product is not named, the section applies to it generally.
What we collect
Account information
Most products ask for an email address and a password. We never store the password itself: it is hashed with a one-way algorithm, so nobody at the studio can read it or recover it for you.
Gamenight is different. It signs you in through Discord and requests only
Discord's identify scope, which returns your Discord username, user ID, and
avatar. We do not receive your email address, your password, your DMs, your friends list,
or the servers you belong to.
Content you create
Whatever you put into a product, we store so we can give it back to you: profiles, gamertags, availability, event and tournament records, pantry items, stories and drafts, flashcard decks and review history, bookings, schedules, timesheets, and comments. You decide what goes in. We do not go looking for more.
Connected game accounts (Gamenight)
If you link a League of Legends or Valorant account, we store the in-game name you provide and the public match and rank data returned by Riot Games' API and by third-party Valorant stat services. That data is already public on your game profile. Unlink the account and we stop refreshing it.
Location (CrewTempo only)
CrewTempo supports geofenced clock-ins. Where an employer turns that on, we record your device's coordinates at the moment you clock in or out so the employer can confirm you were on site. We do not track location between clock-ins, and no other product asks for location at all.
Technical logs
Our servers keep ordinary request logs: IP address, timestamp, page or endpoint, browser user agent, and error traces. We use them to keep the service running and to investigate abuse and outages. They are not built into user profiles.
What we do not do
- No analytics or tracking scripts. There is no Google Analytics, no Meta pixel, no session recorder, and no behavioral profiling anywhere in our products.
- No advertising. We run no ads and we share nothing with ad networks or data brokers.
- No selling or renting data. Not now, and if that ever changed it would require your explicit opt-in first.
- No reading your private content for training. We do not use your content to train machine learning models, ours or anyone else's.
Cookies
We set cookies for one reason: to keep you signed in and to protect sign-in forms against cross-site request forgery. They are strictly necessary cookies. We set no advertising, analytics, or cross-site tracking cookies, which is why you will not find a cookie consent banner on our sites. Clearing them signs you out.
How we use what we collect
- To operate the product: authenticate you, render your data, and send the features you asked for.
- To send transactional email such as sign-in links, invitations, booking confirmations, and password resets. We do not send marketing email.
- To deliver notifications you or your community configured, such as a Gamenight event announcement posted to a Discord channel.
- To keep things secure and working: rate limiting, abuse investigation, backups, and debugging.
- To comply with the law where we are legally required to.
Where the GDPR or similar laws apply, our legal bases are performance of a contract (running the product you signed up for), legitimate interests (security, abuse prevention, and keeping the service alive), consent (optional integrations you choose to connect), and legal obligation.
Who else touches your data
We keep the list of third parties short, and each one is a processor doing a specific job:
- Cloudflare, network delivery and protection in front of our servers.
- Discord, sign-in for Gamenight, and delivery of the notifications a community configures.
- Riot Games and third-party Valorant stat providers, public game and rank data for Gamenight.
- Resend, transactional email delivery.
- Sentry, error monitoring for CrewTempo, which receives crash traces and may incidentally include the user ID attached to a failing request.
- Anthropic, which powers optional AI writing assistance in Tales & Fables. Text you send to that feature is processed to generate a response and is not used to train models. If you do not use the feature, nothing is sent.
- Stripe, payment processing. See the next section.
Beyond those, we disclose data only when the law requires it, or when it is necessary to investigate abuse or protect someone's safety. If we are ever acquired or merged, your data would transfer with the product, and we would say so here before it happened.
Payments
Our products are free today. Some of them have Stripe wired up for paid plans we have not turned on yet. When we do launch a paid plan, Stripe processes the payment: card details go to Stripe directly and never touch our servers, and we receive only the billing status and the last four digits of the card. We will update this policy before charging anyone.
What other people can see
Several of our products are shared spaces, so some of your data is visible to the people you share them with. This is by design and worth knowing:
- In Gamenight, other members of a club see your profile, gamertag, availability, event attendance, badges, and ladder standing. Club owners, admins, and moderators additionally see roster and moderation tools for their own club and no other.
- In CrewTempo, your employer's administrators see your schedule, timesheets, and clock-in records, including geofence results where enabled.
- In BookLocally, the business you book with sees the booking details you submit.
- In Tales & Fables, collaborators you invite to a story see that story and its edit history.
Organizations on our multi-tenant products are isolated from each other. A club or company administrator can see only their own organization's data.
Where data lives, and how long
Our services run on infrastructure we operate in the United States, including self-hosted hardware. If you use our products from outside the US, your data is transferred to and stored in the US.
We keep your data for as long as your account is active. Delete your account and we remove your personal data within 30 days, except where we have to keep something to meet a legal obligation. Encrypted backups may hold residual copies for up to 90 days before rotating out. Request logs are kept for a short operational window and then discarded.
Content you contributed to a shared space may remain visible after you leave, in the same way a message stays in a conversation. Ask us and we will remove or anonymize it.
Your rights
You can ask us to:
- Show you what we hold about you, and give you a copy in a portable format.
- Correct anything that is wrong, most of which you can edit yourself in your profile.
- Delete your account and the data attached to it.
- Restrict or object to a particular use of your data.
- Withdraw consent for an optional integration, by unlinking it.
Email [email protected] and we will respond within 30 days. We will not charge you for it, and we will not degrade your service for asking. Residents of California, the EU, the UK, and other regions with equivalent laws have these rights by statute; we extend them to everyone regardless of where you live.
Security
Traffic is encrypted in transit with TLS. Passwords are hashed with modern one-way algorithms. Access to production systems is limited to the people who operate them. Multi-tenant products enforce organization isolation at the query layer, and we test that isolation automatically.
No system is perfectly secure, and we would rather say so plainly than imply otherwise. If a breach ever affects your personal data, we will notify affected users and the relevant authorities without undue delay. If you find a vulnerability, please report it to [email protected] and we will work with you in good faith.
Children
Our products are not directed at children under 13, and we do not knowingly collect data from them. Gamenight relies on Discord sign-in, and Discord requires its users to be at least 13. If you believe a child under 13 has given us personal data, email us and we will delete it.
Changes to this policy
When we change this policy we update the date at the top of the page. If a change meaningfully affects how we handle your data, we will give notice in the product before it takes effect, rather than quietly editing the page.
Contact
Caplan Studio LLC, Arizona, United States.
[email protected]