Thimpat Storyteller is a desktop application (Windows, built with Electron) made up of a story-building tool ("Builder") and a role-playing story viewer ("Viewer"). An Android version of the Viewer is planned for later. This policy explains what the app stores on your own computer, what it sends over the network, and to whom — and it only describes what the app actually does, feature by feature.
Thimpat Storyteller is published by an individual developer trading as Thimpat, not a company. If you have questions about this policy or your data, contact: thimpat@gmail.com.
By default, Thimpat Storyteller is a local-first app. Your projects, stories and conversations live as files on your own computer, in the project folder you choose. Nothing about them is sent anywhere unless you use one of the network features described in Section 3.
In addition, the app keeps a small amount of its own data in your operating system's
per-user application-data folder (on Windows, %APPDATA%\storyteller):
storyteller.db) that
holds the app's own local sign-in accounts: a username, a bcrypt-hashed password (never the
plain password), a role, and per-user app preferences. This is separate from any online
account — it exists so more than one person can use the same installed copy of the app (for
example, a builder account and a player account), and it never leaves your device unless you
deliberately enable LAN sharing (Section 3).cloud-session.json), created
only if you sign in to the optional Cloud Credits feature described below. It holds a
security token that lets the app act as you when talking to our Cloud Gateway service; it is
never sent anywhere except back to the gateway that issued it.logs/storybuilder.log, logs/python-server.log). These stay on your
machine; the app does not upload them anywhere.None of the above is transmitted to us or anyone else just by having the app installed or running it locally. It only leaves your device through one of the features below, and only when you use that feature.
Every item below is a feature you have to actively use or turn on — none of it runs by default.
If you use locally-installed AI models (for image generation, text/dialogue generation, text-to-speech, lip-sync, etc.) nothing about your story, prompts or generated content leaves your computer. All processing happens on your own machine.
When you choose to install an AI model through the in-app Model Manager, the app downloads the model files directly from Hugging Face (huggingface.co) to your computer. Only the request needed to fetch that file is made; no story content is involved. This only happens when you explicitly start a download.
Thimpat Storyteller offers an optional "Cloud" feature where you sign in with an account (email + password, or "Sign in with Google") and spend Credits on AI generation instead of running models locally or supplying your own API key. This talks to our own service, the Cloud Gateway, and only when you are signed in and choose a Cloud/Credits option.
If you choose "Sign in with Google" for the Cloud feature above, your browser is sent to Google's own sign-in page. We receive back only what is needed to create or verify your Cloud account (such as your Google-verified email address); we do not receive your Google password. Google's own privacy policy governs that part of the exchange.
Instead of, or alongside, the Cloud Credits feature, you can enter your own API key for a third-party AI provider in Settings. If you do, and you choose that provider for a generation, your prompt (and, for image-based calls, the image) is sent directly from your computer to that provider, using your own key — not through us. Providers you can currently configure this way:
These are each governed by that provider's own privacy policy, since the request goes directly from your machine to them, not through us. We only store the API key you enter, locally on your device, so the app can use it.
Two settings, both off by default, let you expose parts of the app to other devices on your own local network:
Both are entirely local: nothing goes over the internet because of these settings, only to other devices already on your own network, and only while the setting is turned on. An optional access token can be set to require authentication from other devices on the network.
Only the services above, and only when you use the corresponding feature:
| Third party | When | What they receive |
|---|---|---|
| Our own Cloud Gateway | You sign in and use a Cloud/Credits feature | Account email, authentication tokens, and the prompt/image/text you submit for that generation |
| You choose "Sign in with Google" | Standard OAuth sign-in exchange; we receive your verified email back | |
| Hugging Face | You download a model via Model Manager | The download request for the model file(s) you chose |
| Pollinations, Groq, OpenRouter | You configure your own API key for one of these and use it | Your prompt (and image, where applicable), sent directly with your key |
Thimpat Storyteller is an authoring and story-playing tool. Because stories, dialogue and images in it are written or AI-generated by you (or by whoever authored the story you're playing), the app can be used to create or display content unsuitable for children, including mature themes. The app currently has no age verification, content rating, or parental control feature. It is not directed at children, and we do not knowingly collect personal information from children through the app itself (its local accounts do not ask for age, name, or other identifying details beyond a username). If you are a parent or guardian and believe a child has used the app's Cloud sign-in feature, contact us at the address in Section 9 and we will assist with deleting that account.
%APPDATA%\storyteller on Windows).Wherever you are, you can ask us at any time to: tell you what account data we hold about you, correct it, or delete it. If you are in the EU, UK, or another jurisdiction with similar data protection law, this corresponds to your rights of access, rectification, erasure, and to object to processing. Since almost all of the app's data stays on your own device under your own control, most of these rights are already exercised simply by managing your local files; for anything held by the Cloud Gateway (Section 4), write to the contact address below.
We may update this policy as the app changes — for example, when the Android Viewer or the in-app Credits purchase flow ships. We'll update the effective date above when we do. Continued use of the app after a change means you accept the revised policy.
Questions, requests, or concerns about this policy or your data: thimpat@gmail.com.