Dragon Fight Club
Encounter difficulty calculatorEncounter builderCR calculatorCombat trackerMonster builderCharacter builder
Open the app →
Dragon Fight Club

Privacy Policy

Last updated 30 September 2026

Explained what the browser extension sends when you press Connect.

The short version

Your account holds your email address and the work you do with it. We do not sell or share your personal data for advertising or marketing, we do not track you around the internet, and there are no ads in the app. Card numbers never reach our servers. If you never sign in, nothing you make leaves your browser unless you send it to us yourself. You can download everything we hold about you, or delete the account outright, without asking us first.

Who we are

Dragon Fight Club is a subscription tool for running D&D 5e encounters, made and run by MORG ORG in Croatia. Under the EU General Data Protection Regulation that makes MORG ORG the controller of the personal data described here. Anything on this page: support@dragonfightclub.app.

What we collect, and why

Your email address

Sign-in is passwordless, so your address is how we know you are you: a magic link goes to it, or Google or Apple confirms it on your behalf. It is the one thing an account cannot exist without, because there is nothing else to attach a library to. Sign in with Google and we also receive your basic profile and the address of your avatar image. Use Apple with Hide My Email and what we store is Apple’s private relay address, which suits us fine.

The work you do

Characters, encounters, monsters, spells, companions, your settings and the state of a running fight are saved to your account, so the same library is waiting on every device you sign in from. Signed out, all of that stays in your browser and never reaches us, unless you attach a snapshot of it to a bug report yourself.

Pictures you upload

Character portraits and player backdrops are stored in file storage that serves them by direct link, and a direct link is readable by anyone who has it. Please do not upload a picture you would mind a stranger seeing.

What you publish to the Community Shelf

Publishing is public, and that is the point of it: the item, its statblock and the creator name you chose can be read by anyone on the internet, and search engines index the page. Comments you leave on the shelf are public the same way. Nothing else in your library is, and nothing is published unless you press Share.

Your subscription

Stripe takes your card details directly and we never see them. What we store is your Stripe customer and subscription identifiers and the status they report, because that is what tells the app whether your subscription is live.

Feedback and bug reports

We keep the message you send and the contact address you choose to add. We are normally sent a copy by email too, with that address and your account id, so we see it the day it arrives. Tick the box on a bug report and we also get a snapshot of what the app was doing: the fight you had loaded, your layout, the page you were on, your browser and your account id. It is your own work, which is why it takes a deliberate tick, and your D&D Beyond credential is stripped out of it before the snapshot leaves your browser. To stop one source flooding the form we store a one-way salted hash of your IP address. The address itself is never written down.

Reports and bans on the shelf

Reporting a shelf item or a comment records your account and the reason you gave, so we can act on it. When we delist or delete an item, or stop an account from sharing, that decision is recorded against it. A copyright notice reaches us by email, with the sender’s details in it.

The check on the sign-in form

Asking for a sign-in link means asking us to send email to an address, which is worth guarding, so Cloudflare runs an anti-bot check on that form. To decide you are a person, Cloudflare looks at the request and at signals from your browser. We get back a pass or a fail.

How you found us

A link carrying campaign tags, from an advert for instance, leaves those tags in your browser. They reach us only if you then sign in, and we keep them only when that sign-in creates a new account, so we can tell which adverts bring DMs here. If you never sign in, we never see them.

That you were here

While you are signed in, opening the app writes one row: your account and the date. It says nothing about what you did, what you looked at, or how long you stayed. It exists so we can answer how many DMs used the app last week without watching any of them.

Errors, and how much traffic there is

Sentry records application errors so we can fix them. It runs with personal-data collection turned off, and the only identifier we attach to an error is your account id. Vercel Web Analytics counts traffic in aggregate, sets no cookies, and does not identify a visitor. It also counts four moments so we can see how many people get stuck on the way to a subscription: an account created, free access starting, the payment form opening, and a subscription going live. Three of the four are a bare count with nothing attached. The account-created one records which sign-in button was used, so we can tell whether Google, Apple or an emailed link is working. None of the four carries your email, your account id, or anything else that could point back at you. Vercel Speed Insights measures how fast pages load for real visitors, and reports timings only.

D&D Beyond links and saved cookies

A Public D&D Beyond sheet can be read from its link without a cookie. If you save a cookie, we keep that sign-in credential encrypted in Supabase Vault, in our database in Ireland, with the name you give it and the dates it was saved and checked. It lets us read what its owner can see, including their own sheets and sheets in a campaign they run. We use it only to read sheets, never to change anything on D&D Beyond.

The Dragon Fight Club extension reads your D&D Beyond sign-in cookie from this browser. Copy cookie puts it on your clipboard without sending it to Dragon Fight Club. Connect sends the cookie and the name you choose to dragonfightclub.app over an encrypted connection, using your Dragon Fight Club sign-in in this browser, and saves it in your account as described above. Opening the popup checks whether you are signed in to Dragon Fight Club; it sends the D&D Beyond cookie only when you press Connect. The extension has no analytics or background activity and keeps no copy of the cookie in its own storage.

A cookie works like a password. Whoever it belongs to copies it from their own browser and sends it over a channel only the two of you can read. In Settings › Account › Saved cookies, removing a saved cookie deletes its encrypted value. Deleting your account deletes every saved cookie too. Removing a hero keeps its saved cookie available for your other sheets. Your data download includes saved cookie names and dates, never the cookie values or their secret references.

Why we are allowed to hold it

Each of those has one of four reasons behind it.

  • You asked us to run your account. Sign-in, your library, sync, your subscription. Without this data there is no service to give you. The GDPR calls it performance of a contract.
  • The law requires it. Invoices and the accounting record behind them, and acting on a notice of illegal content on the shelf, a copyright notice among them.
  • The service has to keep working. Error reports, the check on the sign-in form, the flood cap on the feedback form, reports and bans on the shelf, email you send us, the daily was-here row, and the campaign tags on a new account. These are our legitimate interests, and each one is kept as small as it can be and still answer its question.
  • You chose it. Connecting D&D Beyond, or attaching a snapshot to a bug report. Consent you can take back.

No automated decisions

Nothing here decides anything about you on its own. There is no profiling, no scoring, and no automated decision that has a legal effect or anything close to one.

Who else touches it

A short list of companies run parts of the service for us. Each gets only what its job needs, under a data processing agreement, and none of them gets your data for advertising or marketing.

  • Vercel (United States): hosting, the aggregate traffic counts above, and the page-speed timings.
  • Supabase (United States, running our database in Ireland): the database, sign-in, and file storage.
  • Stripe (Ireland, the European arm of a United States company): payments and subscription billing.
  • Sentry (United States, keeping our reports in Germany): error reports.
  • Resend (United States): transactional email, such as your sign-in link.
  • Cloudflare (United States): the anti-bot check on the sign-in form.
  • Google Workspace (Ireland, the European arm of a United States company): our email, which holds anything you write to us.

As sign-in providers, Google and Apple are not our processors. If you choose one of them to sign in, that step happens on their systems under their own privacy policies, and what reaches us is what the email address section above describes. D&D Beyond receives requests when you import or refresh a linked sheet, or check a cookie you choose to save. A cookie can read sheets its owner has access to; those may belong to other players in a campaign they run.

Where your data goes

Most of the companies above are in the United States, and the two in Ireland hand work to their United States parents, so using any of them can put your data outside the European Economic Area. The safeguard for that is not the same for all of them, so here it is per vendor.

  • Stripe, Vercel, Sentry, Resend, Cloudflare and Google Workspace: certified under the EU-US Data Privacy Framework, the European Commission’s adequacy decision for certified US companies. For Stripe and Google Workspace it is the United States parent that is certified, and it covers what their Irish companies send it.
  • Supabase: the European Commission’s standard contractual clauses, in the data protection terms we accepted with them. The database is in Ireland, but Supabase can reach it from the United States, and that is what the clauses cover.

How long we keep it

  • Your account and everything in it: for as long as the account exists. Delete the account and the wipe starts the same minute.
  • Invoices: 11 years. Croatian accounting law requires it of us, and Stripe holds the billing record that long on our behalf, whatever either of us would prefer.
  • Feedback and bug reports: kept indefinitely, because they are the record of what has gone wrong. The message survives the account that sent it, with the contact address and any snapshot cleared out, so what is left is an unattributed note about a bug. The copy emailed to our inbox is kept like any other email, below.
  • Email you send us: kept in our inbox until we delete it, and that includes the emailed copy of feedback, with its contact address and account id. It is how we look back at what we told whom. Ask and we will delete yours.
  • Reports you made on the shelf: a report on an item stays, with its reason, as the record that somebody objected. A report on a comment goes when the comment does. Deleting your account takes your account id off both.
  • A ban from sharing: until we lift it, or until the account it applies to is deleted.
  • Anything you published to the shelf: the copies other DMs already took stay in their libraries, credited to nobody. The public listing does not survive you: deleting the account takes your creator name with it and leaves the item with no owner, the shelf lists only items that have one, and the item stops being publicly readable.
  • Comments you left on the shelf: the comment stays on the thread it is part of, because pulling one line out of a conversation rewrites the replies around it. Your name comes off it and it reads as a departed creator’s.
  • Error reports: held by Sentry, which ages them out on its own schedule. We keep no copy, and the only thing in one that points at you is your account id.

Your rights

You can ask us for a copy of the personal data we hold about you, for a correction, for deletion, for a portable copy, and you can object to or restrict some of the processing above. Two of those need nothing from us: in Settings, then Account, Download your data hands you the lot as a file, with Delete account directly beneath it. For anything else, write to support@dragonfightclub.app and we will answer.

You can also complain to a supervisory authority. Ours is the Croatian Personal Data Protection Agency, AZOP, in Zagreb, and you may instead go to the authority where you live.

Deleting your account

Settings, then Account, then Delete account. It runs while you wait: any live subscription is cancelled, your uploaded pictures are removed, and your library, your settings and your sign-in are deleted. A few things outlive it, all described above: the billing record accounting law makes us keep, the copies of shelf items other DMs already took, anything you said on someone else’s shelf page, reports you made, the message of any feedback or bug report you sent, and email in our inbox. The billing record keeps your name. Our inbox keeps what you sent it: your email, and the emailed copy of any feedback with its contact address and account id. Everything else is cut loose from you, and the feedback we keep loses its contact address and snapshot. Now and then a deletion cannot reach every uploaded file in one pass. When that happens we are told which files were left and we finish the job by hand.

Security

Traffic is encrypted in transit. Sensitive credentials are encrypted at rest. The database enforces per-account rules, so one account cannot read another’s rows even if the app asks it to. No online service can promise perfect security. We can promise the unglamorous measures are in place and that we treat a mistake here as the most serious kind.

Cookies, and why there is no banner

A session cookie keeps you signed in, and the Stripe code that draws the payment form sets a few of its own while you are on the checkout page. That is the whole list. There is no advertising cookie and no analytics cookie, because the analytics we use counts visits without one. Storage that is strictly necessary does not need consent under the ePrivacy rules, so there is no cookie banner on this site: it would be theatre, and this section is the disclosure instead. If we ever start tracking visitors, that changes, and you will get a real choice rather than a wall to click past.

The app also uses your browser’s own storage rather than cookies for your layout, your settings, the work of a signed-out session, the campaign tags described above, and a note of which of the four counts above this browser has already sent, so it is not sent twice. None of it is shared with an advertising network, and clearing your browser data clears all of it.

Children

You must be at least 16 years old to have an account. The service is not directed at children, and we do not knowingly hold a child’s data.

Changes to this policy

When the service changes, this page changes with it. The date at the top moves and the line under it says what moved, so you never have to read the whole thing twice to find out.

Contact

Questions about this policy, or about your data: support@dragonfightclub.app.

Adapted from the Basecamp open-source policies, used under CC BY 4.0.

Dragon Fight Club
support@dragonfightclub.appCommunity ShelfDesktop appPrivacyTermsUpload rules

Run 5e encounters at the table.

Made at the table by MORG ORG