Privacy Policy
This Privacy Policy explains how Anvil of Heroes collects, uses, stores, and shares information when you use our website, applications, AI-assisted character and NPC generation tools, printable character sheet builder, and related services.
By using Anvil of Heroes, you acknowledge the practices described in this Privacy Policy.
1. Who We Are
Anvil of Heroes is a tabletop roleplaying game toolkit that helps users create, customize, generate, save, export, and print character sheets, character dossiers, NPC profiles, and related creative materials.
For privacy questions, contact us at admin@anvilofheroes.com.
The data controller is:
[Your legal name or company name]
[Your registered business address]
Poland
2. Information We Collect
We may collect the following types of information.
3. Account Information
If you create an account or sign in to Anvil of Heroes, we may collect:
- Name or display name
- Email address
- Profile image, if provided by your login provider
- Authentication provider identifier
- Account preferences
- Subscription or plan status
If you sign in using Google Authentication, Google may provide us with basic account information, such as your email address, name, profile image, and a unique Google account identifier. We use this information to create and manage your Anvil of Heroes account.
We do not receive your Google password.
4. User Content
We collect content you create, upload, enter, edit, save, or generate through the Service, such as:
- Character sheet layouts
- Character names
- Character concepts
- Backstories
- NPC profiles
- Campaign notes
- Prompts submitted to AI features
- AI-generated outputs
- Printable exports and related settings
This content is referred to as User Content.
5. Usage Information
We may collect information about how you use the Service, such as:
- Features used
- Pages viewed
- Buttons clicked
- Export or print activity
- Error logs
- Session activity
- Device and browser information
- IP address
- Approximate location based on IP address
- Referral source
- Performance and diagnostic data
6. Payment Information
If you purchase a paid plan, subscription, or other paid feature, payments are processed by Stripe. Stripe may collect and process payment-related information, such as:
- Name
- Billing email
- Billing address, if required
- Payment method details
- Transaction identifiers
- Subscription status
- Fraud prevention information
Anvil of Heroes does not intentionally store full payment card numbers. Payment card information is handled by Stripe.
We may receive limited payment-related information from Stripe, such as:
- Payment status
- Subscription status
- Billing email
- Transaction identifiers
- Last four digits of a payment card, if provided by Stripe
7. Communications
If you contact us, we may collect:
- Your email address
- Your message
- Support history
- Feedback or survey responses
8. How We Use Information
We use information to:
- Provide and operate the Service
- Create, save, display, export, and print your character materials
- Provide AI-assisted character, NPC, and backstory generation
- Maintain your account
- Authenticate users through Google Authentication
- Process payments and subscriptions
- Improve features, templates, performance, and usability
- Respond to support requests
- Detect, prevent, and investigate abuse, fraud, security issues, and technical problems
- Comply with legal obligations
- Send service-related messages
- Send marketing messages, where permitted and where you have not opted out
9. AI Features and Your Content
Anvil of Heroes uses AI-assisted features to help generate creative tabletop RPG content, such as character concepts, NPC profiles, backstories, roleplaying hooks, names, descriptions, secrets, motivations, party connections, and adventure ideas.
When you use AI-assisted features, the information you submit may be sent to our AI service provider, currently OpenAI, for processing. This may include character names, concepts, NPC ideas, backstory details, prompts, selected tone, genre, or system preferences, and generated outputs.
You should not submit sensitive personal information, confidential information, private campaign secrets you do not want processed by a third party, or content you do not have the right to use.
AI-generated content may be inaccurate, incomplete, repetitive, or unsuitable for your campaign. You are responsible for reviewing and editing AI-generated content before using it.
The AI features are intended for creative content generation. They are not used to make legal, financial, employment, health, or similarly significant decisions about you.
10. Legal Bases for Processing
If you are in the European Economic Area, United Kingdom, or another region with similar privacy laws, we process personal information under one or more legal bases:
Contract
We process information when necessary to provide the Service you requested, including account access, saved content, printable exports, paid plans, and AI-assisted features.
Legitimate Interests
We process information when necessary for our legitimate interests, such as improving the Service, securing the Service, preventing abuse, debugging technical issues, understanding feature usage, and communicating with users.
Consent
We process information based on consent where required, such as for certain cookies or marketing communications.
Legal Obligation
We process information when necessary to comply with applicable laws, tax obligations, accounting obligations, legal requests, or regulatory requirements.
11. Cookies and Similar Technologies
Anvil of Heroes aims to operate without non-essential tracking cookies. We may use cookies, local storage, or similar technologies only where necessary to:
- Keep you signed in
- Remember your preferences
- Provide account security
- Prevent fraud or abuse
- Operate core features of the Service
We do not use analytics cookies.
If we introduce non-essential cookies in the future, such as marketing or advertising cookies, we will update this Privacy Policy and, where required by law, ask for your consent.
12. Analytics
We use Vercel Analytics to understand how users interact with Anvil of Heroes, improve the Service, identify popular features, diagnose issues, and make product decisions.
Vercel Analytics is designed to provide privacy-friendly, cookie-free analytics. It does not use cookies to track users across websites. Vercel Analytics may collect limited usage information such as:
- Pages viewed
- Referrer information
- Device and browser information
- Country-level location
- General usage events
- Performance information
We use this information in an aggregated way to understand how the Service is used and how we can improve it.
We aim to avoid sending character names, backstories, prompts, generated content, email addresses, or other user-generated content to analytics as event names or event properties.
13. Google Sign-In
Anvil of Heroes allows users to sign in using Google Authentication. When you choose to sign in with Google, Google may share certain basic account information with us, such as your name, email address, profile image, and a unique account identifier.
We use this information only to authenticate you, create or manage your account, secure your login, provide access to the Service, and maintain account-related records.
Your use of Google Authentication is also subject to Google's own privacy practices and account settings. We do not receive your Google password.
14. How We Share Information
We do not sell your personal information.
We may share personal information with trusted service providers that help us operate, secure, improve, and monetize Anvil of Heroes. These providers process information only as needed to provide their services to us.
| Provider | Purpose | Possible Data Processed |
|---|---|---|
| Supabase | Database, authentication, file storage, backend infrastructure | Account data, email address, saved character sheets, generated content, app data, logs |
| Google Authentication | Account sign-in and authentication | Email address, name, profile image, Google account identifier, login metadata |
| Vercel | Website hosting, deployment, serverless functions, performance infrastructure | IP address, device/browser data, usage logs, request data |
| Vercel Analytics | Privacy-friendly, cookie-free analytics and usage measurement | Page views, referrer information, device/browser data, country-level location, usage events |
| OpenAI | AI-assisted character, NPC, backstory, and creative text generation | Prompts, character ideas, selected character/NPC content, generated outputs |
| Stripe | Payments, subscriptions, invoicing, fraud prevention | Billing details, payment status, transaction identifiers, subscription status, limited card information |
We may also share information with legal authorities if required by law, to protect our rights or users, to investigate fraud or security incidents, in connection with a merger or sale of assets, or with your consent.
15. International Data Transfers
Your information may be processed in countries other than where you live. Some of our service providers, including Supabase, Vercel, OpenAI, Google, and Stripe, may process data in countries outside Poland or the European Economic Area.
Where required, we rely on appropriate safeguards for international transfers, such as contractual protections, data processing agreements, standard contractual clauses, adequacy decisions, or other legally recognized transfer mechanisms.
16. Data Retention
We keep personal information for as long as reasonably necessary to provide the Service, maintain your account, comply with legal obligations, resolve disputes, enforce agreements, and maintain security. For example:
- Account information is generally retained while your account exists.
- User Content is generally retained while your account exists or until you delete it, where deletion is available.
- Payment and transaction records may be retained as required for tax, accounting, and legal purposes.
- Security logs and technical logs may be retained for a limited period to protect the Service and investigate abuse or errors.
- Support messages may be retained to handle your request and maintain support history.
You may request deletion of your account or certain personal information by contacting us at admin@anvilofheroes.com.
We may retain some information where required by law or where necessary for legitimate business purposes, such as security, fraud prevention, tax records, payment records, dispute records, or enforcement of agreements.
17. Your Rights and Choices
Depending on where you live, you may have rights to:
- Access your personal information
- Correct inaccurate information
- Delete your personal information
- Object to certain processing
- Restrict certain processing
- Export your data
- Withdraw consent
- Opt out of marketing communications
- Lodge a complaint with a data protection authority
To make a request, contact us at admin@anvilofheroes.com. We may need to verify your identity before fulfilling a request.
If you are located in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.
18. Marketing Communications
If you subscribe to updates, create an account, or otherwise agree to receive communications, we may send you product updates, feature announcements, or promotional messages.
You can unsubscribe from marketing emails by using the unsubscribe link or contacting us at admin@anvilofheroes.com.
We may still send non-marketing messages, such as account, security, billing, legal, or service notices.
19. Security
We use reasonable technical and organizational measures to protect personal information.
However, no online service is completely secure. We cannot guarantee that information will never be accessed, disclosed, altered, or destroyed without authorization.
You are responsible for keeping your account credentials secure and maintaining access to the Google account you use to sign in.
20. Children's Privacy
Anvil of Heroes is not intended for children under the age required by applicable law to use online services without parental consent.
We do not knowingly collect personal information from children without appropriate consent. If you believe a child has provided us personal information, contact us at admin@anvilofheroes.com. We will take appropriate steps to review and delete the information where required.
21. Third-Party Links and Services
The Service may contain links to third-party websites, tools, platforms, or game publisher resources.
We are not responsible for the privacy practices, content, terms, or policies of third parties. You should review their privacy policies before using them.
22. Do Not Submit Sensitive Information
Anvil of Heroes is designed for tabletop RPG creativity and preparation. You should not submit sensitive personal information into the Service, including:
- Government identification numbers
- Financial account information
- Health information
- Precise location information
- Private information about other people
- Confidential business information
- Content you do not have the right to use
This is especially important when using AI-assisted features, because prompts and related content may be processed by third-party AI providers.
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we will take reasonable steps to notify you, such as by posting the updated Privacy Policy in the Service or sending a notice.
Your continued use of the Service after the updated Privacy Policy becomes effective means you acknowledge the updated policy.
24. Contact Us
For questions, requests, or concerns about this Privacy Policy, contact us at admin@anvilofheroes.com.