Privacy Policy
Last updated: May 2026
1. The short version
Tavern is a 2014 and 2024 tabletop companion app, free to use with optional paid tiers. We only store what we need to render your character sheet, let your party share it with you, and — if you buy a paid tier — know what you bought. We do not sell your data. We do not run ad networks. You can export everything you've created and delete your account at any time.
2. What we collect
- Account info. Email address (for sign-in and password reset) and, if you signed in with Discord, your Discord user ID + handle so we can post combat events back to your campaign's Discord channel if you opt in.
- Character data. Everything you enter on the character sheet — name, class, abilities, inventory, notes, backstory, custom homebrew. Stored in our Supabase database and visible only to you (and party members you explicitly invite into a campaign).
- Usage events. Lightweight server-side analytics: which page you viewed, when you signed up, when you rolled your first die. We use these to measure where the app is confusing and to fix it. No personal text content, no character names, no notes. Stored in our own database (no third-party analytics vendor).
- Error reports. When the app crashes we capture a stack trace + the path you were on so we can debug. Stripped of any character data or notes before storage.
3. Cookies + browser storage
Tavern uses a small number of cookies and localStorage keys. We do not use marketing or cross-site tracking cookies.
- Authentication cookies (set by Supabase, names prefixed
sb-) — keep you signed in. Required for the app to work. - Session ID (sessionStorage key
tavern_analytics_session_id) — random UUID per browser tab, discarded when you close it. Lets us correlate the events from one session without identifying you across sessions. - Notices you've already seen (localStorage
tavern_cookie_ack_v1,tavern_share_ack_v1,tavern_tour_state_v1,tavern_first_session_checklist_done_v1) — so we don't show you the same banner, share warning, tour or checklist twice. - Your display preferences (localStorage
tavern-theme,tavern-dice-color,tavern-dice-theme,tavern_sound_enabled,tavern_mobile_combat_compact,tavern:creator:fast-mode) — light or dark mode, your dice colours, whether sound is on, and how compact you like the mobile combat bar and the character builder. - Sign-in convenience (localStorage
tavern_remember_me) — remembers whether you ticked "Remember me". It stores the tickbox, not your password. - Product measurement (localStorage
tavern_signup_at,tavern_session_count; sessionStoragetavern_ttfm_fired) — when you signed up and how many sessions you've had, so we can tell whether a change made the app easier to get started with. - Housekeeping (sessionStorage, set by the app when it detects a new version or a failed script load, and when you follow a campaign invite before signing in) — used to reload you onto the current build once, and to remember the invite across the sign-in step.
That list is the whole of it, and it is checked against the code rather than written from memory. If you find a key on this site that is not described here, that is a bug — tell us and we will fix the page.
The site does not currently load Google Analytics, Meta Pixel, or any other cross-site tracker. If we add one in the future, this page will be updated before the SDK ships and an in-app notice will appear.
4. Where your data lives
Account and character data is stored on Supabase (rtiuioknjqqmtixsmwoj.supabase.co), hosted in a Supabase-managed region of AWS. The web app itself runs on Vercel. Both providers see your traffic and IP address while serving requests; neither has read access to your characters beyond what's required to serve the database query you issued.
Two other companies handle a narrow slice, and only if you use the feature that involves them:
- Stripe processes payments if you buy a paid tier. Your card details go straight to Stripe and never touch Tavern's servers — we hold only the customer and subscription identifiers Stripe gives back, plus which tier you are on and when the period ends. Stripe's own privacy policy governs what they keep.
- Resend delivers email. That means the message and the reply-to address you type into the contact form, and internal alerts to us about a purchase, which carry account identifiers rather than your email.
5. Sharing + party campaigns
If you create a public share link for a character (the gold share button on the sheet), anyone with that URL can view a read-only copy of your character. If you remove public sharing or delete the character, the public view stops working immediately.
If you join a campaign, the DM and other party members can see your character's HP, AC, conditions, and active buffs. They cannot see your notes, backstory, or anything outside the live-play surface.
6. Your rights — export + delete
- Export. Account settings includes an "Export my data" button that returns a JSON dump of everything tied to your account (characters, homebrew, campaign roles).
- Delete. The same settings page has an account deletion button. You'll be asked to type "DELETE" to confirm. We immediately remove your characters, homebrew, campaign memberships, and account row. Backups containing your data roll off within 30 days.
- GDPR / CCPA. EU and California residents have the same export + delete rights described above. If you'd like a manual review of an account, email
support@tavernapp.ggfrom the address tied to your account.
7. Children
Tavern is not directed at children under 13. If you are a parent or guardian and believe your child has signed up, email support@tavernapp.gg and we will delete the account and any characters tied to it.
8. Changes
We will update this page when we add or remove a data source. Material changes will be announced on the homepage. Continued use of Tavern after a change means you accept the new policy.
Questions: support@tavernapp.gg