Privacy notice
Curse of Strahd — Tarokka Randomizer · last updated 28 September 2026
In short: the randomizer runs entirely in your browser. The cards you draw and what they mean for your campaign are never sent to any server — they stay on your device. We do not profile you, there is no account to create, and there is nothing we could hand back or delete on request, because we hold nothing of yours. The one cookie we set exists only if you connect Google Drive, and it holds nothing but the permission you granted.
Who is responsible
The data controller is TirateIniziativa, which runs this project as non-commercial fan content. Contact: [email protected].
What stays in your browser
The app saves three entries in the browser's local storage. These are not cookies and are never transmitted.
| entry | what it holds | why |
|---|---|---|
tarokka.state.v1 |
the reading on the table: which cards came up in which position, the name you gave it, your language, and your weighting settings | so the reading is still there after you close the tab — it is the very service you asked for by using the app |
tarokka.lastVisitDay |
a date, e.g. 2026-09-28 |
so the same visit is not counted twice on the same day |
tarokka.drive.v1 |
only if you connect Google Drive: the fact that you said yes, and the identifiers of the two folders | so the folders are not created again at every visit. It never holds the access token, which lives in memory only |
You can clear everything at any time, from New reading inside the app or by clearing the site data in your browser. Neither requires telling us, because we know nothing about it.
If you export a Markdown or JSON file, your browser produces it and it goes wherever you send it.
Sharing a reading with your players
When you open a session, the five cards of the reading travel through a Cloudflare Worker so that the people you gave the code to can watch the same table. What travels is only the reading itself: which card is in which position, and the name you gave it. No account, no identity, no address book — whoever holds the six-character code is whoever is at the table. The session is kept for the length of the game and its storage is erased one hour after the last person disconnects.
What reaches us: the visit counter
At the bottom of the page there is a public visit counter. When you open the app, your browser
sends our server a request that says only "one more visit". The server keeps
monthly totals only — for example 2026-09: 412 — plus the
running total. No IP addresses, identifiers, cookies, device or referrer information are stored,
and there is no way, not even for us, to trace those numbers back to a person or to know how many
pages anyone viewed. The "once a day" de-duplication happens in your browser, using the date
described above, and is never sent.
Hosting
The site, the sessions and the counter run on Cloudflare infrastructure (Cloudflare, Inc., United States), acting as data processor. Like any hosting provider, Cloudflare transiently processes the technical data needed to deliver pages and protect the service from abuse, including the request's IP address. See Cloudflare's privacy policy.
Typefaces
The pages load two typefaces (Cinzel and EB Garamond) from Google Fonts. To
deliver them, your browser contacts Google's servers (fonts.googleapis.com and
fonts.gstatic.com), which at that moment receive the request's IP address and your
browser's technical information. See
Google's privacy policy.
Google Drive, if you connect it
Connecting Google Drive is optional and never automatic: it starts only when you press “Sign in with Google”, and until you do, the site does not contact Google at all — not even the sign-in script is loaded. Once you have connected it, the script does load when you open the page, so that the permission can be renewed without asking you again; disconnect and it stops loading.
If you do connect it:
-
one permission is requested, the
drive.filescope, which grants access solely to files this app created and to nothing else in your Drive: the rest of your files stay invisible to us; - no name, email address or other profile data is requested. Writing a file into the Drive of whoever authorised it does not require knowing who they are;
- readings travel straight from your browser to Google, never through us: we keep no copy and never see them;
- the name you give a save is stored in the file description on Drive, next to the file itself, so that the list of your saves can show it without opening any of them;
-
the access token is kept in the
ti_drivecookie described below, so that a single sign-in serves every TirateIniziativa tool. It expires within an hour, together with the permission itself, and is deleted as soon as Google turns it down. Besides it, all that stays in the browser is the fact that you said yes, plus the folder identifiers, which open nothing on their own; -
files are created in the
TirateIniziativa_AppDataStoragefolder of your Drive. They are yours: move, rename or delete them whenever you like, and “Disconnect” revokes the permission without touching them.
Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Transfers, retention, minors
The monthly visit totals contain no personal data and are kept indefinitely, since their purpose is to show how often the tool has been used. The data in your browser is kept by you, for as long as you like. The service is not specifically directed at children and does not knowingly collect data about them — it does not knowingly collect data about anyone.
Your rights
Regulation (EU) 2016/679 gives you rights of access, rectification, erasure, restriction, objection and portability. In practice there is no personal data here to exercise them against: what you write is on your device and you delete it yourself. If you think something is wrong you can write to the address above, or lodge a complaint with the Italian Data Protection Authority.
Cookies
One cookie, and only if you connect Google Drive. Until you do, this site sets none at all — neither technical nor profiling, neither first- nor third-party. The local-storage entries described above are not cookies and never leave your device.
| cookie | what it holds | why | how long |
|---|---|---|---|
ti_drive |
the access permission Google issued for the drive.file scope — no name, no email address, no profile |
so that one sign-in covers every TirateIniziativa tool: it is set on tirateiniziativa.com, so the home page and each tool find the permission already granted instead of asking you again |
exactly as long as the permission itself, one hour at most. It is also deleted the moment Google turns it down, and when you press “Disconnect” |
It is a strictly necessary cookie: it exists only to deliver the function you asked for by pressing “Sign in with Google”, it is not used to profile you and it is never shared with anyone. That is why no consent banner is shown — connecting Drive is itself the consent, and it can be withdrawn at any time with “Disconnect”.
What it costs, said plainly. Unlike the local-storage entries above, a cookie
travels: the browser attaches it to every request to tirateiniziativa.com. We do not
read it on the server and we do not record it — no server-side code of ours looks at
cookies at all — but it does leave your device, which those entries never do. We accepted
that because it is the only way a single sign-in can serve every tool. If you would rather it did
not exist, do not connect Drive, or press “Disconnect”: it is deleted immediately and
the app goes on working exactly as before.