Dragon Fight Club
Encounter difficulty calculatorEncounter builderCR calculatorCombat trackerMonster builderCharacter builder
Open the app →
Dragon Fight Club

Privacy Policy

Last updated 14 August 2026

Rewritten in full. Every processor is now named with its location, the transfer safeguard is stated per vendor, and the sign-in check, shelf visibility and retention periods are new.

The short version

Your account holds your email address and the work you do with it. We do not sell or share your personal data for advertising or marketing, we do not track you around the internet, and there are no ads in the app. Card numbers never reach our servers. If you never sign in, nothing you make leaves your browser unless you send it to us yourself. You can download everything we hold about you, or delete the account outright, without asking us first.

Who we are

Dragon Fight Club is a subscription tool for running D&D 5e encounters, made and run by MORG ORG in Croatia. Under the EU General Data Protection Regulation that makes MORG ORG the controller of the personal data described here. Anything on this page: support@dragonfightclub.app.

What we collect, and why

Your email address

Sign-in is passwordless, so your address is how we know you are you: a magic link goes to it, or Google or Apple confirms it on your behalf. It is the one thing an account cannot exist without, because there is nothing else to attach a library to. Sign in with Google and we also receive your basic profile and the address of your avatar image. Use Apple with Hide My Email and what we store is Apple’s private relay address, which suits us fine.

The work you do

Characters, encounters, monsters, spells, companions, your settings and the state of a running fight are saved to your account, so the same library is waiting on every device you sign in from. Signed out, all of that stays in your browser and never reaches us, unless you attach a snapshot of it to a bug report yourself.

Pictures you upload

Character portraits and player backdrops are stored in file storage that serves them by direct link, and a direct link is readable by anyone who has it. Please do not upload a picture you would mind a stranger seeing.

What you publish to the Community Shelf

Publishing is public, and that is the point of it: the item, its statblock and the creator name you chose can be read by anyone on the internet, and search engines index the page. Comments you leave on the shelf are public the same way. Nothing else in your library is, and nothing is published unless you press Share.

Your subscription

Stripe takes your card details directly and we never see them. What we store is your Stripe customer and subscription identifiers and the status they report, because that is what tells the app whether your subscription is live.

Feedback and bug reports

We keep the message you send and the contact address you choose to add. Tick the box on a bug report and we also get a snapshot of what the app was doing: the fight you had loaded, your layout, the page you were on, your browser and your account id. It is your own work, which is why it takes a deliberate tick, and your D&D Beyond credential is stripped out of it before the snapshot leaves your browser. To stop one source flooding the form we store a one-way salted hash of your IP address. The address itself is never written down.

The check on the sign-in form

Asking for a sign-in link means asking us to send email to an address, which is worth guarding, so Cloudflare runs an anti-bot check on that form. To decide you are a person, Cloudflare looks at the request and at signals from your browser. We get back a pass or a fail.

How you found us

A link carrying campaign tags, from an advert for instance, leaves those tags in your browser. They reach us only if you then sign in, and we keep them only when that sign-in creates a new account, so we can tell which adverts bring DMs here. If you never sign in, we never see them.

That you were here

While you are signed in, opening the app writes one row: your account and the date. It says nothing about what you did, what you looked at, or how long you stayed. It exists so we can answer how many DMs used the app last week without watching any of them.

Errors, and how much traffic there is

Sentry records application errors so we can fix them. It runs with personal-data collection turned off, and the only identifier we attach to an error is your account id. Vercel Web Analytics counts traffic in aggregate, sets no cookies, and does not identify a visitor.

A D&D Beyond connection, if you ask for one

Connecting D&D Beyond to import a character stores the session credential you provide, encrypted at rest. It is used for one thing: fetching that character when you ask. The credential lives on the character it fetches, so deleting the character deletes the credential with it.

Why we are allowed to hold it

Each of those has one of four reasons behind it.

  • You asked us to run your account. Sign-in, your library, sync, your subscription. Without this data there is no service to give you. The GDPR calls it performance of a contract.
  • The law requires it. Invoices and the accounting record behind them.
  • The service has to keep working. Error reports, the check on the sign-in form, the flood cap on the feedback form, the daily was-here row, and the campaign tags on a new account. These are our legitimate interests, and each one is kept as small as it can be and still answer its question.
  • You chose it. Connecting D&D Beyond, or attaching a snapshot to a bug report. Consent you can take back.

No automated decisions

Nothing here decides anything about you on its own. There is no profiling, no scoring, and no automated decision that has a legal effect or anything close to one.

Who else touches it

A short list of companies run parts of the service for us. Each gets only what its job needs, under a data processing agreement, and none of them gets your data for advertising or marketing.

  • Vercel (United States): hosting, and the aggregate traffic counts above.
  • Supabase (United States): the database, sign-in, and file storage.
  • Stripe (United States): payments and subscription billing.
  • Sentry (United States): error reports.
  • Resend (United States): transactional email, such as your sign-in link.
  • Cloudflare (United States): the anti-bot check on the sign-in form.

Google and Apple are not our processors. If you choose one of them to sign in, that step happens on their systems under their own privacy policies, and what reaches us is what the email address section above describes. D&D Beyond receives a request only when you connect it, and only for your own characters.

Where your data goes

Every company above is a United States company, so using them can put your data outside the European Economic Area. The safeguard for that is not the same for all of them, so here it is per vendor.

  • Stripe, Vercel, Sentry, Resend and Cloudflare: certified under the EU-US Data Privacy Framework, the European Commission’s adequacy decision for certified US companies.
  • Supabase: the European Commission’s standard contractual clauses, in the data protection terms we accepted with them.

How long we keep it

  • Your account and everything in it: for as long as the account exists. Delete the account and the wipe starts the same minute.
  • Invoices: 11 years. Croatian accounting law requires it of us, and Stripe holds the billing record that long on our behalf, whatever either of us would prefer.
  • Feedback and bug reports: kept indefinitely, because they are the record of what has gone wrong. The message survives the account that sent it, with the contact address and any snapshot cleared out, so what is left is an unattributed note about a bug.
  • Anything you published to the shelf: the copies other DMs already took stay in their libraries, credited to nobody. The public listing does not survive you: deleting the account takes your creator name with it and leaves the item with no owner, the shelf lists only items that have one, and the item stops being publicly readable.
  • Comments you left on the shelf: the comment stays on the thread it is part of, because pulling one line out of a conversation rewrites the replies around it. Your name comes off it and it reads as a departed creator’s.
  • Error reports: held by Sentry, which ages them out on its own schedule. We keep no copy, and the only thing in one that points at you is your account id.

Your rights

You can ask us for a copy of the personal data we hold about you, for a correction, for deletion, for a portable copy, and you can object to or restrict some of the processing above. Two of those need nothing from us: in Settings, then General, Download your data hands you the lot as a file, with Delete account directly beneath it. For anything else, write to support@dragonfightclub.app and we will answer.

You can also complain to a supervisory authority. Ours is the Croatian Personal Data Protection Agency, AZOP, in Zagreb, and you may instead go to the authority where you live.

Deleting your account

Settings, then General, then Delete account. It runs while you wait: any live subscription is cancelled, your uploaded pictures are removed, and your library, your settings and your sign-in are deleted. Four things outlive it, all described above: the billing record accounting law makes us keep, the copies of shelf items other DMs already took, anything you said on someone else’s shelf page, and the message of any feedback or bug report you sent. Only the billing record keeps your name; the rest lose it, the feedback its contact address and snapshot too. Now and then a deletion cannot reach every uploaded file in one pass. When that happens we are told which files were left and we finish the job by hand.

Security

Traffic is encrypted in transit. Sensitive credentials are encrypted at rest. The database enforces per-account rules, so one account cannot read another’s rows even if the app asks it to. No online service can promise perfect security. We can promise the unglamorous measures are in place and that we treat a mistake here as the most serious kind.

Cookies, and why there is no banner

A session cookie keeps you signed in, and the Stripe code that draws the payment form sets a few of its own while you are on the checkout page. That is the whole list. There is no advertising cookie and no analytics cookie, because the analytics we use counts visits without one. Storage that is strictly necessary does not need consent under the ePrivacy rules, so there is no cookie banner on this site: it would be theatre, and this section is the disclosure instead. If we ever start tracking visitors, that changes, and you will get a real choice rather than a wall to click past.

The app also uses your browser’s own storage rather than cookies for your layout, your settings, the work of a signed-out session, and the campaign tags described above. None of it is shared with an advertising network, and clearing your browser data clears all of it.

Children

You must be at least 16 years old to have an account. The service is not directed at children, and we do not knowingly hold a child’s data.

Changes to this policy

When the service changes, this page changes with it. The date at the top moves and the line under it says what moved, so you never have to read the whole thing twice to find out.

Contact

Questions about this policy, or about your data: support@dragonfightclub.app.

Adapted from the Basecamp open-source policies, used under CC BY 4.0.

Dragon Fight Club
support@dragonfightclub.appCommunity ShelfPrivacyTermsUpload rules

Run 5e encounters at the table.

Made at the table by MORG ORG