Privacy Policy
Effective August 3, 2026
This policy explains what The Dungeon Trainer LLC, a Colorado limited liability company doing business as The Dungeon Trainer ("we", "us"), collects, how we use it, and who we share it with. It applies to the The Dungeon Trainer website and app (the "Service"). The Dungeon Trainer LLC is the business responsible for the information described here.
What we collect
- Account data: your email address and authentication details, managed by our auth provider.
- Profile: an optional username you choose.
- Play content: the campaigns, characters, NPCs, prompts, and other content you create and the AI responses generated for you.
- Party-finder profile and listings: if you opt into the Gathering Hall, the profile you build (roles, timezone, recurring availability, play preferences, and the short free-text fields you write), the recruiting listings you publish, the applications and invitations you send or receive, and the messages you post in a table lobby. We ask for a timezone and recurring availability only, never a city, address, workplace, school, venue, or travel radius.
- Safety and moderation records: reports you file or that name you, including a snapshot of the reported content taken at the time of the report, the accounts you block, your acceptance of the Community Guidelines and your confirmation that you are an adult, and any restriction or moderation action applied to your account.
- Usage and metering: counts of turns, generations, and similar, plus per-call cost records, used to enforce limits and operate the Service.
- Legal acceptances: when you accept an updated version of these documents, we record which version you accepted, your account identifier, and the time, so we can show what you agreed to.
- Technical logs: our hosting and database providers keep short-lived request logs to run and secure the Service. These include your IP address, the time of the request, the page or endpoint, and your browser and device type. We use them to operate the Service, investigate faults, and detect abuse.
- Diagnostics: when something goes wrong we record the error, the page or operation it happened in, technical details such as browser type, and your account's internal user identifier so we can tell whether a fault affected one account or many. A report also carries the context the failing operation attached to it, which is usually an internal record identifier such as the campaign a turn belonged to, and, where the failure came from another service, that service's own error object. These identifiers refer to your account and its content, so we treat them as personal information, but we do not put your name or email address in them, and we do not send the text of your play into them deliberately. We do not attempt to reconstruct what you wrote from a diagnostic report.
- Payment data: if you purchase a plan or credits, our payment provider processes your payment. We receive confirmation and subscription status, not your full card details.
- Optional API keys: if you bring your own model provider key or local endpoint, we store the key encrypted and use it only to make model calls on your behalf.
- Product analytics: if you accept analytics cookies, we use PostHog to understand how the Service is used, such as funnels and retention. We record a small set of coarse, predefined events (for example: viewing the landing page, signing up, creating a character, starting a campaign, and taking your first turn in a session) together with a random analytics identifier that links your sessions. These events never contain your email, username, or any game content, and the traffic source we note is only a coarse category (such as "search" or "social"), never the full referring address. In addition, when you first purchase a paid plan, our server sends a single "first paid" event to PostHog containing your account's internal user identifier and the plan tier. That identifier is pseudonymous, meaning it does not contain your name, email, or payment details but does refer to your account, so we treat it as personal information. Because it is sent from our server to measure conversion to a paid plan, it is recorded whether or not you accepted analytics cookies.
- Cookies and similar storage: a session cookie to keep you logged in; storage set by our bot-protection check on the sign-up, sign-in, and password-reset forms, which is strictly necessary for those forms to work; if you accept analytics cookies, a PostHog analytics cookie or similar local storage holding the random analytics identifier described above; and, when we run ads, the Reddit Pixel and Google Ads advertising cookies described under subprocessors below to measure ad performance. The analytics and advertising cookies load only after you accept them in our cookie banner.
How we use it
We use your data to provide and operate the Service: to run the game and tools, send your prompts and play context to AI providers to generate responses, enforce plan limits and rate limits, process payments, secure accounts, understand how the Service is used through product analytics, and improve reliability.
We do not sell your personal information, and we have never accepted money for it. We do use advertising measurement: if you accept advertising cookies, the Reddit Pixel and the Google tag receive the fact that you visited or signed up, tied to an identifier those companies hold, so we can tell which ads worked. California and several other state privacy laws call that "sharing" for cross-context behavioral advertising, so we describe it as such rather than claim it is nothing. It happens only after you accept advertising cookies, it never includes your email address, your username, or your game content, and you can stop it at any time by declining in the cookie settings below or by sending a Global Privacy Control signal. We do not share personal information for advertising in any other way, and we do not share the content of your play with advertisers at all.
Who we share it with (subprocessors)
We share data with service providers who help us run the Service:
- Database, authentication, and storage (Supabase), where your account and content are stored.
- Application hosting (Vercel), which serves the website and app. Vercel also provides our traffic and performance measurement. That measurement is cookieless: it sets no cookies and stores nothing on your device, so unlike the analytics and advertising tools below it runs whether or not you accept optional cookies. Vercel additionally keeps short-lived request and security logs described under "Technical logs" above.
- AI model providers (currently Anthropic and OpenAI) for the text, image, speech, and safety-classification features. Your prompts and the relevant play context are sent to them to produce responses. Specifically: text generation and Scry and Coach output; scene art and portraits; read-aloud narration audio; the optional memory feature, which uses a separate embedding provider; and the automated check applied to free text you write for strangers in the Gathering Hall. If you configure your own provider key or local endpoint, the main text generation routes there instead, but the other features listed here still use our platform providers regardless of that setting.
- Payment provider (Polar, as merchant of record) to process purchases.
- Email provider (Resend) to send account, notification, and announcement email.
- Error monitoring (Sentry) to receive the diagnostic reports described above, including your account's internal user identifier, so we can find and fix faults.
- Bot protection (Cloudflare Turnstile) on the sign-up, sign-in, and password-reset forms, to tell people from automated abuse. Cloudflare receives your IP address and browser signals for that check. It is a security measure necessary to operate those forms, so it runs whether or not you accept analytics cookies.
- Advertising measurement: we use the Reddit Pixel, a third-party advertising tracker from Reddit, Inc., and the Google tag from Google LLC, which measures the performance of our Google Ads campaigns, to measure the performance of our ads.
- Product analytics (PostHog, hosted in the United States) to measure how the Service is used through the coarse events described above. PostHog runs in your browser only if you accept analytics cookies; the single server-side "first paid" event described above is sent regardless of that choice and carries the pseudonymous account identifier described above.
These providers process data on our behalf under their own terms; they are not permitted to use it for unrelated purposes.
Sharing within multiplayer
When you invite people to a campaign, the content of that shared table is visible to its members (and to read-only spectators you invite). Secret game-master notes marked private are not shown to players. Only invite people you trust with your table's content.
Sharing in the Gathering Hall
The Gathering Hall is off until you turn it on. Nothing about you is discoverable there until you create a party-finder profile and activate it, or publish a recruiting listing.
When you do, the profile or listing you wrote becomes visible to other signed-in adults using the feature. What is never shown: your email address, real name, IP address, exact location, campaign transcripts, last-seen presence, friend list, or application history. Schedules appear as a timezone and recurring availability, translated into the viewer's timezone.
Pausing your profile or closing a listing removes it from discovery and from recommendations and invitations without deleting your account. Blocking someone removes each of you from the other's active discovery, listings, applications, and invitations. It is not a deletion: an application that was already in flight is settled as removed rather than erased, so it stays in your own application history.
Not everything in the Gathering Hall is broadly visible. A profile and a published listing are the parts strangers can browse. An application is seen only by you and the owner of the listing you applied to; an invitation only by the invited player and the listing owner; and a table lobby's messages only by the people currently in that lobby.
These pages are for signed-in users only and are excluded from search engines: the Gathering Hall is never indexed and is not in our sitemap.
Free text you write for strangers, such as a headline, a table introduction, or an application message, is checked automatically for contact details and for content that breaks the Community Guidelines before it is published. That check is performed by our AI provider on the same terms as other AI processing described above.
Retention and beta resets
We keep your data while your account is active. Because the Service is in beta, we may reset or delete play data between updates. You can delete your account by contacting us, after which we delete or anonymize your personal data except where we must retain it (for example, payment records required by law).
Safety and moderation records fall under that exception. Reports, the evidence snapshot taken with them, and any restriction or moderation action may be kept after the account they concern is deleted, because a report is also a record about the person who filed it and about our own decision. We are still finalizing the exact retention periods for these records and will state them here before the Gathering Hall opens.
Your choices and rights
You can access and update your profile in the app, remove any bring-your-own API key, and request deletion of your account and data by emailing support@thedungeontrainer.com. Account deletion is handled by request rather than by a button in the app today; we act on the request ourselves. Depending on where you live, you may have additional rights to access, correct, export, or delete your personal data, and to appeal a decision we make about such a request. Contact us and we will honor applicable requests. We will not treat you differently for exercising any of them.
You control analytics and advertising cookies through the banner shown on your first visit; declining keeps PostHog, the Reddit Pixel, and the Google tag from loading. You can change that choice at any time, here:
Do Not Track and Global Privacy Control
Some browsers send a "Do Not Track" signal. There is no common standard for how a service should respond to it, and we do not currently change our behavior based on it. Instead, we give you a direct choice: the cookie banner shown on your first visit controls whether any analytics or advertising tool loads at all, and declining keeps them off.
We do recognize the Global Privacy Control signal. If your browser sends one, analytics and advertising cookies stay off, no banner is shown, and the signal continues to apply for as long as your browser sends it, even if you accepted cookies here before. You can confirm what is being applied in the cookie settings above.
Where we run ads, the Reddit Pixel and the Google tag described above are the only parties that receive information about your activity on this Service, and only after you accept advertising cookies. Those two are advertising tools, so what they receive can be connected to the profile each company already holds about you; that is the "sharing" described above, and declining or sending a Global Privacy Control signal is how you stop it. No other third party is permitted to collect information about your activity through the Service.
Security
Access to your data is protected by per-user database access controls, encryption in transit, and encryption of any stored provider keys. No system is perfectly secure, but we work to protect your information and to fix issues promptly.
Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children.
Changes and contact
We may update this policy as the Service evolves; we will update the effective date at the top of this page. For changes that materially affect how we handle your data we will tell you by email and in the app, and we will ask you to accept the updated documents the next time you sign in, recording which version you accepted and when. Questions or requests: support@thedungeontrainer.com.