Skip to content
LegendHaven Privacy Policy
Last updated: September 28, 2026 • Contact us • Terms & Conditions
LegendHaven is the online convention venue at venue.legendhaven.com, run by LegendFiction ("we", "us"). Dominic de Souza runs LegendFiction. This page says what we collect when you use the venue, why, who else handles it, how long we keep it, and what you can ask us to do with it.
Questions and requests: legendfiction.com/contact
What we collect
Your account
  • Email address. Used to sign you in and to match you to any invite or code meant for you. It is never shown to other attendees unless you choose to share it (see "Share my email" and Cards, below).
  • How you signed in: an email link or code, an email and password, or Google. Passwords are handled and stored (hashed) by our sign-in provider, Supabase; the venue itself never stores your password. If you sign in with Google, see "Google user data" below.
  • Your role (member, Author, Knight or admin) and your access level, including any rooms a code unlocked for you.
  • Your age band, asked once as a required part of setting up your profile after you sign in (see "Age" below).
Your profile
Everyone at the venue can see your display name, the face you picked (a painted preset, or, for Authors and admins, a picture they upload), your "About you" line, and your profile link if you add one.
What you do in the venue
  • Voice. LegendHaven is voice only. There is no camera anywhere in the venue, and your mic starts off. Voice goes live, person to person, through our voice provider, LiveKit. We do not record voice.
  • Where you are on the floor. Your position is shared live with the people in the same room and is never stored. We do keep a record of which room you are in while you are there (see Visits).
  • Room chat. What you write in a room's chat is stored and shown to people in that room. The room's host and our admins can export it.
  • Direct messages between two people. Our admins cannot read them unless one of the two reports a message; then they see only the reported message.
  • "Share my email with [host]". Only if you press it in a room, your email is added to that host's list, with a record of when you agreed and which wording you agreed to. The host can download their list.
  • Cards. If two people accept each other's card request, each keeps a copy of the other's name, face, email, profile link, the first line of their "About you", their role at the venue, and the room where the cards were traded.
  • Reports, blocks and mutes. Reports you file, and people you block or mute, so the venue can act on them. Admin and moderator actions are recorded in a moderation log.
  • Visits. When you enter and leave a room, so hosts can see how many people came and for how long. Public pages show counts only, never who.
  • Uploads. Authors and admins can upload pictures (faces, room backgrounds). Members cannot upload files.
Technical data
  • IP address. Used briefly to stop abuse (for example, too many wrong codes in a row) and not stored in plain form. The one exception: when a one-time admin code is used, a one-way hashed copy of the IP address is kept with that code and deleted about a day after the code expires.
  • A sign-in cookie called lh_pass, which keeps you signed in for up to 12 hours. The page's scripts can't read it, and it is only ever sent to our own server.
  • Things kept in your browser's storage: settings (theme, sound and ambience), which hints you've seen, whether this device has signed in before, and your name, face, email and role so the venue can greet you on your next visit. These stay on your device and are only ever sent to our own server.
  • Basic page analytics from Cloudflare Web Analytics, which counts page views without cookies.
  • Server logs of errors, which can include an account ID but never passwords, sign-in tokens, cookies or email addresses.
Why we use it
To run the venue: sign you in, show you to the people you're with, carry your voice and messages, keep the venue safe (moderation and abuse limits), and let hosts see who joined their list and how their room did. We don't sell your data, and we don't use it for advertising.
Who else handles it
These services process data for us, only to run the venue:
  • Supabase: database, sign-in (including passwords and Google sign-in), and file storage
  • Cloudflare: hosting the site, security and abuse limits, page analytics
  • LiveKit: carrying live voice (not recorded) and live floor positions
  • MailerSend: sending sign-in emails
  • Google: "Continue with Google" sign-in, and web fonts
  • YouTube: only if a room shows a video, played from YouTube's privacy-enhanced player
  • jsDelivr: delivering the code libraries the page runs on
  • Onepage (onecdn.io): delivering the venue's preset faces and icons
  • Mixkit: delivering three short sound effects
  • DuckDuckGo: showing a small icon next to a profile link; it receives only that link's website name
Hosts (Authors) see their own list of people who chose "Share my email", their room's chat, and their room's visit counts. Admins see reports, reported messages only, and the moderation log.
Google user data
If you choose "Continue with Google", Google shares your name, email address and profile picture with us (the standard "email" and "profile" permissions). We ask for nothing else: not your password, contacts, files, calendar or anything else in your Google account.
  • How we use it. The venue uses only your email address: to create your LegendHaven account, sign you in, and match you to any invite or code meant for that address. Your display name and face at the venue are the ones you choose; your Google name and picture are not shown to anyone.
  • How it is stored. Our sign-in provider, Supabase, keeps the name, email and picture Google sent with your account record.
  • Sharing. We don't sell Google user data or share it with anyone except Supabase, which runs sign-in for us. We don't use it for advertising, and we don't use it to develop, improve or train generalized AI or machine-learning models. No person reads it except to keep the service secure, to comply with the law, or with your permission.
  • Keeping and deleting it. It is kept until you delete your account (You › Account › Delete my account), which removes it. You can also remove LegendHaven's access at any time from your Google Account's security settings.
LegendHaven's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect it
  • All traffic to the venue is encrypted (HTTPS, with HSTS). Our providers encrypt stored data at rest.
  • Sign-in passes are signed by our server and kept in a cookie the page's scripts can't read.
  • The database is not readable directly from the page: only our own server, holding keys that never reach your browser, can read private data such as emails, direct messages and reports.
  • Passwords are stored hashed by Supabase. IP addresses are hashed wherever one is kept.
  • Admin access is limited to a few people, and admin actions are logged.
No system is perfect. If something goes wrong that affects you, we'll tell you.
How long we keep it
  • Direct messages: 7 days (a reported message until the report is dealt with)
  • Room chat: deleted automatically 3 days after the event ends (in a room with no set end time, 3 days after each message is posted)
  • Chat mutes: 24 hours
  • Codes typed before sign-in: until they expire
  • One-time admin codes (and the hashed IP kept with a used one): about a day after they expire
  • Sign-in cookie: up to 12 hours
  • Your account, profile, visits, list sign-ups and cards: until you delete your account
  • Reports and the moderation log: kept for safety, including after an account is deleted
Your choices and rights
  • Change your profile any time, from You › Profile.
  • Sign out from You › Account.
  • Leave a host's list or remove a card, where the venue offers it.
  • Download your data any time: You › Account › Download my data.
  • Delete your account any time: You › Account › Delete my account. It removes your account and profile (including anything Google shared), your direct messages, blocks, visits, list sign-ups, access and the cards you hold. Cards other people already received from you stay with them. Reports and the moderation log are kept for safety. Admin accounts are removed on request instead.
  • To see or correct anything else, ask through legendfiction.com/contact.
Age
LegendHaven is for people aged 16 and over. People aged 14 or 15 may join with a parent or guardian's email address and phone number, which we use only to contact them about the young person's safety. We ask your age once, as a required part of setting up your profile after you sign in. People under 14 can't join.
Changes
If this policy changes in a way that matters, we'll update the date above and say so at the venue door.
Contact