Privacy Policy
Dungeon Grimoire is operated by CroCode BV (info@dungeongrimoire.com), a private limited company registered in the Netherlands.
Last updated: August 2026
1. Who we are
Grimoire is a campaign management tool for tabletop role-playing games, available at dungeongrimoire.com. When this policy says “we”, “us”, or “our”, it refers to CroCode BV.
2. What data we collect
Account data
When you create an account we collect your email address and an optional display name (username). Your password is hashed by our authentication provider and is never stored in plain text.
Campaign content
Everything you create inside Grimoire (campaigns, NPCs, monsters, notes, encounters, calendar events, locations, items, spells, and other content) is stored and associated with your account.
AI feature data
If you use the AI generation features (which features use AI, and how AI output is marked, is explained on About AI in Grimoire):
- Bring Your Own Key (BYOK), server-stored: Your API key (OpenAI, Anthropic, or Google) is stored encrypted at rest (AES-256-GCM) in our database. The key is decrypted server-side only at the moment of a generation request and is never sent to your browser in plain text.
- Platform-key mode: If you do not supply your own key, AI generations use Grimoire’s own provider keys and are charged against your account’s credit balance. Your prompts (and any reference images you provide) are sent to the relevant AI provider listed below to fulfil the request.
- Bring Your Own Key (BYOK), local-only mode: If you opt into local-only key storage in Campaign Settings, your API key is stored only in your browser (the encryption key is a non-extractable key held in IndexedDB and the encrypted API key is held in local storage) and is never transmitted to or stored by CroCode BV. In this mode all AI generation happens directly between your browser and the AI provider. Our servers are not involved. You can verify this via your browser’s network inspector.
- Reference images and likenesses: Some features work from images you provide: turning a character portrait into a stylized mini (Simulacrum), group portraits, scene art that includes party members, and NPC disguises. The portrait or reference images you supply are sent to the campaign’s configured image provider (OpenAI or Google) to fulfil that request; for 3D minis, the resulting stylized image (not your original upload) is then sent to Meshy to produce the model. These features require an explicit in-app likeness acknowledgement before anything is sent, and you must have the permission of any real person whose photo you use.
- Usage logs: Each AI generation is logged with the model name, provider, approximate token counts, and estimated cost. These logs are used solely for service improvement and pricing calibration. No AI-generated content is sent to third parties beyond the AI provider used for the request.
Payment data
If you purchase AI credits, payments are processed by Stripe. We receive a payment confirmation and a customer reference; we never see or store your full card number or bank details.
Bug and feature reports
If you file a bug report or a feature request from inside the app, we collect what you wrote, the part of the app you pointed at, an optional screenshot, and which account submitted it. The text you write is published as an issue in Grimoire’s public GitHub repository. Your identity and your screenshot are deliberately kept out of that issue and stay in our own database; section 4 explains exactly where the line falls.
Error reports
When something goes wrong in the app, an automatic error report is sent to Sentry (EU region) so we can find and fix it. The report contains the error message, the stack trace, which page or feature it happened in, your browser and version, and your account’s internal ID. Never your email address, your username, or your IP address.
It also deliberately excludes your campaign content. Anything you have written or generated, and any prompt you send to an AI feature, is removed from the report before it leaves your device: request bodies are never attached, URLs are reduced to their shape (no search terms, no file identifiers, no sign-in tokens), and anything shaped like an email address or an API key is masked out of the remaining text. We do not use session recording, so no error report ever contains a picture or a copy of what was on your screen.
Your account ID is included so we can tell whether a fault hit one person or everyone. It is an internal identifier that means nothing without our database, and it is not shared with anyone else.
Technical data
Standard server and client logs may include your IP address, browser type, and timestamps for security and diagnostic purposes. We use a session cookie to keep you logged in; no advertising or tracking cookies are used. If you connect optional integrations, the relevant tokens are stored in your browser’s local storage: Spotify access/refresh tokens (if you link Spotify for music playback) and your encrypted local-only API key (if you enable that mode).
Visitor statistics
We use Vercel Web Analytics to count how the app is used: how many people arrive, which screens they open, roughly where in the world they are, and whether they are on a phone or a computer. We look at this to find where the app is confusing or broken, which on a small team is otherwise mostly guesswork.
A short list of named actions is counted the same way, so that we can see which parts of Grimoire people actually reach: that a campaign was created, or that an AI generator was run and which kind. What is recorded is the fact and the kind, never the campaign, never the character, and never a word of what you typed.
It is deliberately the least invasive tool we could pick, and it is worth being specific about what that means:
- It stores nothing on your device. No analytics cookie, no identifier in local storage, nothing to consent to and nothing to refuse, which is why Grimoire has no cookie banner.
- It cannot follow you between visits or to other sites. There is no profile, no persistent visitor ID, and no advertising network involved.
- Addresses are reduced to their shape before they are sent. Grimoire’s addresses contain the IDs of your own campaigns, characters and notes, and searches contain whatever you typed. All of that is stripped in your browser first, so what is recorded is the kind of page you opened, never which of your things you opened or what you searched for.
There is no way to switch this off from inside the app, because there is nothing switched on to begin with: what is collected is already anonymous. If you would rather not be counted at all, any browser-level tracker blocker will stop the script loading, and the app works exactly the same without it.
Emails we send you
Most of our email is unavoidable plumbing: confirming your address, resetting a password, receipts, and security notices. Those come with having an account, and we cannot switch them off without breaking the service.
Two other kinds exist, and both are deliberately narrow.
When something broke for you. If we find a fault that affected your account specifically (you were shown an error, or worse, you were quietly shown nothing at all), we may write and tell you what happened and what we fixed. We would rather you heard it from us than concluded the app simply did not work.
Asking how it went. We may occasionally write and ask what your experience was like, particularly if you tried Grimoire and stopped. This is a genuine question from a person, not a survey funnel: Grimoire is built by a very small team, and honest criticism from someone who walked away is worth more than any amount of guessing.
Neither of these is marketing. They carry no offers, no promotions and no pitch to upgrade, and we do not put tracking pixels in them. If you would rather not receive either, say so in a reply. One sentence is plenty. We will note it and stop. We keep a record of that request, and only that, so that the answer sticks.
Pro launch waitlist
On dungeongrimoire.com you can leave your email address to be told when Pro checkout opens. We store the address, which page you submitted it from, and the date. It is used for exactly one thing: a single email when Pro opens. You are not added to a newsletter, and the list is never used for other marketing or shared with anyone. The list lives in our own database (Supabase, EU), is readable only by us, and is deleted once that launch email has gone out, or after 365 days if for some reason it never does.
You can leave the list at any time, and you never have to ask us to do it for you. Every email we send to this list carries an unsubscribe link. Following it opens a page with a single button, and pressing that button deletes your address there and then: no account, no sign-in, and nothing to wait for us to do. If your mail app shows its own unsubscribe button, that works too and skips the page entirely. (The reason there is a button at all rather than deletion on the click itself: some mail systems automatically open every link in a message to scan it, and we would rather that not quietly take you off a list you meant to stay on.) If the link does not work for you, or you would rather not wait for an email to arrive, write to info@dungeongrimoire.com and we will remove your address by hand. Deleting your Grimoire account also removes a waitlist entry matching the address on the account.
3. Why we process your data
| Purpose | Legal basis |
|---|---|
| Providing and operating the service | Contract performance |
| Sending email confirmations and security notices | Contract performance |
| Preventing abuse and ensuring security | Legitimate interest |
| Automatic error reporting, to keep the app working | Legitimate interest |
| AI usage logging for pricing calibration | Legitimate interest |
| Processing payments | Contract performance |
| Acting on bug reports and feature requests | Legitimate interest |
| Telling you about a fault that affected your account | Legitimate interest |
| Asking about your experience of the service | Legitimate interest |
| Understanding how the app is used, without cookies | Legitimate interest |
| Emailing you when Pro checkout opens (waitlist) | Consent |
We do not use your data for advertising, sell it to third parties, or use it to train AI models. Our AI sub-processors operate under API terms that exclude training on your data, with one disclosed exception (Meshy; see section 4).
4. Who we share data with
We use the following sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, Edge Functions | EU (AWS eu-west-1) |
| Vercel | Hosting for this website and for the app, and cookieless visitor statistics | US |
| Cloudflare | Object storage and CDN delivery for uploaded and generated assets, including portraits | EU / US |
| Resend | Sending notification emails (receives the recipient address and the message content) | US |
| Stripe | Payment processing | EU / US |
| OpenAI | AI text, image, and search-embedding generation (BYOK or Grimoire platform key) | US |
| Anthropic | AI text generation (BYOK or Grimoire platform key) | US |
| AI text, image, music, and search-embedding generation (BYOK or Grimoire platform key) | US | |
| Meshy | Image-to-3D mini generation (Grimoire platform key only) | US |
| Freesound | Sound-effect search and previews (your search terms are sent to find matching sounds) | EU |
| Spotify | Optional music-playback integration you connect via your own Spotify account (OAuth) | EU / US |
| GitHub | Public issue tracker that receives the text of bug reports and feature requests | US |
| Sentry | Automatic error reporting (error message, stack trace, browser, account ID) | EU |
AI providers receive the prompts you generate (and any reference images you provide); in BYOK mode they also receive the API key you supplied. They are subject to their own privacy policies.
How long AI providers keep request data: under the API terms we use, OpenAI and Anthropic delete API inputs and outputs within about 30 days (abuse-monitoring window) and do not use them to train models; Google’s paid Gemini API keeps abuse-monitoring logs for 55 days and does not use paid-tier prompts or outputs to improve its products.
Meshy and your minis: Meshy automatically deletes generated models about 3 days after generation; Grimoire downloads your mini within that window and hosts it ourselves. Be aware that Meshy’s standard (non-Enterprise) terms permit it to use submitted images and generated models to improve its services. We only ever send Meshy the stylized, AI-drawn source image, never your original photo upload; if that trade-off is not acceptable to you, skip the 3D mini step and keep the stylized portrait. The app repeats this warning at the sculpt step itself.
Bug reports and GitHub: Grimoire’s issue tracker is a public repository, so whatever you type into the in-app reporter is published to the open internet the moment you submit it. Write it with that in mind, and leave other people’s details out of it. What does not go into the issue is you: your account and any screenshot you attach are stored on your report record in our own database, readable only by you and by us, and the issue links to them by number rather than by name. Screenshots are deleted after 90 days, and everything attached to your report is deleted along with your account.
Local-only key mode: If you use local-only key storage, your API key and generation requests go directly from your browser to the AI provider. CroCode BV never sees your key or acts as an intermediary for the request itself. Only anonymised usage metadata (model name, token counts) is logged.
International transfers
Several of our sub-processors process data in the United States. GDPR requires a legal safeguard for each such transfer, and this is the safeguard per provider (as verified in August 2026):
| Provider | Transfer safeguard |
|---|---|
| Vercel | Vercel Inc. is certified under the EU-U.S. Data Privacy Framework, including the UK Extension and the Swiss-U.S. framework; its Data Processing Addendum also provides for the EU Standard Contractual Clauses. |
| Cloudflare | Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (with the Swiss-U.S. framework and the UK extension); its standard Data Processing Addendum additionally incorporates the EU Standard Contractual Clauses, which it relies on should a certification lapse. |
| Resend | Resend is certified under the EU-U.S. Data Privacy Framework and its UK Extension; its public Data Processing Addendum additionally incorporates the EU Standard Contractual Clauses. Resend stores customer data in the United States. |
| OpenAI | Data Processing Addendum with OpenAI Ireland Ltd (the EEA contracting entity); onward transfers under the EU Standard Contractual Clauses or an EU adequacy decision. Not certified under the EU-U.S. Data Privacy Framework. |
| Anthropic | Data Processing Addendum incorporating the EU Standard Contractual Clauses (controller-to-processor and processor-to-processor modules). Not certified under the EU-U.S. Data Privacy Framework. |
| Google LLC is certified under the EU-U.S. Data Privacy Framework; paid Gemini API processing is additionally governed by Google’s data-processing terms with Google Ireland Ltd as the EEA contracting entity. | |
| Meshy | Not certified under the EU-U.S. Data Privacy Framework and offers no standard-tier Data Processing Addendum; its privacy policy commits to the EU Standard Contractual Clauses or equivalent safeguards for transfers from the EU. See the Meshy note in the table above before using the 3D mini feature. |
| Stripe | Stripe’s own Data Processing Agreement, which incorporates the applicable transfer safeguards for the portion of payment processing that happens in the US. |
| GitHub | GitHub, Inc. is certified under the EU-U.S. Data Privacy Framework (with the UK Extension and the Swiss-U.S. framework) as a separately listed Microsoft entity, and its Data Protection Agreement also incorporates the EU Standard Contractual Clauses. |
| Sentry | Error reports are stored in Sentry’s EU region, so the data itself stays in the EU. Its operator, Functional Software, Inc. d/b/a Sentry, is a US company certified under the EU-U.S. Data Privacy Framework (with the UK Extension and the Swiss-U.S. framework); its Data Processing Addendum additionally incorporates the EU Standard Contractual Clauses as a fallback. |
You can request a copy of the relevant safeguards by emailing us at info@dungeongrimoire.com. In local-only key mode, AI generation requests go directly from your browser to the provider and are not routed through our servers; no transfer by CroCode BV takes place.
5. Data retention
Most of what Grimoire holds lives exactly as long as your account does: your profile, your settings, your campaigns, and everything you have written or generated inside them. Delete your account and it goes with it, within 30 days. Search index entries are deleted along with the note, monster, or location they were built from.
Some categories are cleared on a shorter fixed schedule whether or not you ask, because there is no good reason to hold them longer:
| What | How long we keep it |
|---|---|
| The prompt text you type into an AI feature | 90 days, then wiped. What it produced stays in your Gallery until you delete it |
| Records of AI generations that produced nothing | 90 days |
| Records of AI generations that worked (the receipt, not the artwork) | 365 days |
| Screenshots attached to a bug report | 90 days |
| The bug report itself | 365 days |
| Spending-protection records (why an unusual charge was held back) | 180 days |
| Automatic error reports | 90 days (Sentry’s standard retention), then deleted by Sentry |
| Rate-limit counters | 25 hours |
| Invite links, including the first name written on one | 90 days after the link expires or is used up |
| “Notify me when this ships” clicks | 365 days |
| Pro launch waitlist addresses | Until you unsubscribe, or the launch email is sent, and 365 days at the outside |
Two things are kept longer than your account, because the law requires it:
Payment and consent records are kept for seven years and then deleted. Dutch tax law runs that clock from the end of the financial year a payment fell in rather than from the payment itself, so a purchase made in March 2026 is held until the end of 2033. If you delete your account before then, these records are anonymised rather than kept under your name: what survives is the transaction, not you. The end of that period is a rule in its own right, not just a minimum. We do not keep them indefinitely.
The administrative action log records privileged actions taken on an account, such as a plan change, a refund, an account freeze, or an erasure, so that there is an honest account of who did what. It holds internal identifiers only, never your email address or your name, and runs on the same seven-year clock.
6. Your rights (GDPR)
As a resident of the EU/EEA you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data (“right to be forgotten”)
- Restrict processing in certain circumstances
- Receive a portable copy of your data in a machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent at any time, where our processing is based on your consent. This does not affect the lawfulness of processing carried out before withdrawal
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl
To exercise any of these rights, contact us at info@dungeongrimoire.com.
7. Security
We use industry-standard measures including encrypted data at rest, TLS in transit, row-level security policies on all database tables, and AES-256-GCM encryption for stored API keys. No method of transmission or storage is 100% secure; in the event of a breach we will notify you as required by GDPR.
8. Children
Grimoire is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided personal data, contact us and we will delete it.
9. Changes to this policy
We may update this policy as the service evolves. We will notify you of material changes by email or in-app notice. The date at the top of this page reflects the last revision.
10. Contact
CroCode BV (data controller)
Koraalrood 54F, 2718 SC Zoetermeer, Netherlands
Chamber of Commerce (KvK) no. 76933067 · VAT (BTW) no. NL860845011B01
info@dungeongrimoire.com
For privacy enquiries or to exercise your data rights, email us with the subject line “Privacy Request”.