Legal
Privacy Policy
Effective date: 5 August 2026
This Privacy Policy explains how Elphame, LLC (“Noppera,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you use Noppera at localhost:4000 and related services (the “Service”). By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.
For our rules of use, see the Terms of Service.
1. Who we are
Noppera is operated by Elphame, LLC, a Delaware limited liability company.Noppera is a social-skills practice product that lets you configure AI characters, practice difficult conversations, receive coaching insights, and (optionally) share characters publicly in Explore.
Elphame, LLC
1111B S Governors Ave STE 34031
Dover, DE 19904
United States
Email: hello@elphame.com
Phone: (605) 702-2841
2. Information we collect
2.1 Account and identity
When you sign in (currently via Google through Firebase Authentication), we receive and store identifiers associated with your account, which may include:
- Firebase user ID
- Email address
- Display name
- Profile photo URL (if provided by your identity provider)
- Account creation and update timestamps
2.2 Content you create
To operate the Service, we store content you provide or generate while using it, including:
- Character configurations (name, relationship, scene/context, goals, appearance descriptions, difficulty, public/private setting)
- Character narrative fields such as hidden goals and secrets used to drive roleplay
- Chat sessions and messages, scores, coaching insights, debriefs, and related session metadata
- Progress and ratings (for example charisma/player stats and per-character mastery)
- Generated portrait images and related visual metadata
If you mark a character as public, other signed-in users may see its public fields and your display name in Explore. Hidden goals and secrets are not shown to non-owners.
2.3 Data stored on your device
The Service uses browser local storage (and Firebase Auth browser persistence) to keep session state, creations, visuals, player progress, and a returning-user flag so the app can load quickly and work across visits. Clearing site data in your browser removes this local copy.
2.4 Automatically collected technical data
We do not currently operate first-party advertising or product analytics cookies (such as Google Analytics or PostHog). Our hosting and authentication providers (for example Cloudflare and Google/Firebase) may process standard technical logs such as IP address, user agent, and request metadata as part of providing infrastructure and security.
2.5 Sensitive information you may type
You control what you write into chats, goals, and character setups. Do not submit information you are not comfortable sharing with our processors (listed below). The Service is not designed to collect health, biometric, payment, or precise location data, but free-text fields could contain personal or sensitive details if you enter them.
3. How we use information
We use the information above to:
- Create and authenticate your account
- Provide, sync, and improve conversation practice, scoring, insights, and debriefs
- Generate character portraits and moderate unsafe content
- Show public characters in Explore when you choose to publish them
- Maintain security, prevent abuse, and troubleshoot errors
- Comply with law and enforce our Terms
- Respond to your privacy or support requests
4. AI and automated processing
To power roleplay, coaching, moderation, and images, we send relevant prompts and content to third-party AI and media providers. This typically includes character configuration, conversation context (for example recent messages and summaries), scores, and appearance prompts. Providers currently used include:
- Anthropic — conversation replies, summaries, insights, and debriefs
- OpenAI — content moderation of character fields and chat text (when configured)
- Fal.ai — portrait image generation from appearance prompts
Those providers process data under their own terms and privacy policies. We do not use your conversations to train our own foundation models. Retention of data by AI providers is governed by their agreements with us; we retain copies in our systems as described in Section 7.
5. How we share information
We share information with:
- Service providers / processors — Google (Firebase Authentication), Cloudflare (hosting, D1 database, R2 object storage), Anthropic, OpenAI, Fal.ai, and DiceBear (fallback avatar images based on style/seed only)
- Other users — when you publish a character, public fields and your display name may appear in Explore
- Legal and safety — if required by law, regulation, legal process, or to protect rights, safety, and integrity of the Service or users
- Business transfers — if we are involved in a merger, acquisition, or asset sale, information may transfer subject to continued confidentiality protections where required
We do not sell your personal information.
6. Cookies and similar technologies
We use local storage and authentication persistence as described above. We do not set first-party marketing or analytics cookies. Third-party providers may use cookies or similar technologies as needed for authentication and infrastructure. You can clear storage or block cookies in your browser; some features (especially sign-in) may not work without them.
7. Retention
We retain account data, creations, sessions, chat logs, ratings, and related records while your account is active and as needed to provide the Service. When you delete a session or character through the product, we remove the corresponding records from our primary database according to that feature.
When you delete your account from Profile, we delete your user record and associated database data (including creations, sessions, chat logs, ratings, and visual metadata) and clear local app data on the device you use to complete deletion. Generated portrait files in object storage may not always be fully purged at the same moment; contact us if you need confirmation that associated images have been removed.
We may retain limited information where required for security, dispute resolution, legal compliance, or backups for a reasonable period.
8. Security
We use industry-standard measures appropriate to our Service, including authenticated API access for account-linked features and infrastructure security provided by our cloud hosts. No method of transmission or storage is 100% secure. Please use a strong account with your identity provider and avoid sharing highly sensitive personal data in chats.
9. Children
The Service is intended for users aged 16 and older (or the age of digital consent in your country, if higher). We do not knowingly collect personal information from children under 16. If you believe a child has provided us data, contact hello@elphame.com and we will take appropriate steps to delete it.
10. Your rights
Depending on where you live (including the EEA/UK under GDPR and certain US state laws such as the CCPA/CPRA), you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data (available in Profile)
- Object to or restrict certain processing
- Data portability (where applicable)
- Withdraw consent where processing is consent-based
- Opt out of “sale” or “sharing” for cross-context behavioral advertising (we do not sell personal information or engage in such advertising today)
- Lodge a complaint with a supervisory authority
To exercise these rights, email hello@elphame.com or use in-product account deletion. We may need to verify your identity before fulfilling a request. Authorized agents may submit requests where the law allows; we may require proof of authorization.
If you are in the EEA/UK, our legal bases for processing typically include: performance of a contract (providing the Service), legitimate interests (security, product improvement, public Explore when you publish), and consent where required (for example certain optional processing).
11. International transfers
We and our processors may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms offered by our providers.
12. Payments
The Service does not currently process payments or store payment card details. If billing is added later, this Policy will be updated and any payment processor’s terms will apply to payment data.
13. Changes
We may update this Privacy Policy from time to time. We will post the revised version with an updated effective date. Continued use of the Service after changes become effective constitutes acceptance of the updated Policy, except where additional consent is required by law.
14. Contact
Questions or privacy requests: hello@elphame.com, or write to Elphame, LLC, 1111B S Governors Ave STE 34031, Dover, DE 19904, United States. Phone: (605) 702-2841.