Privacy Policy
Effective date: February 25, 2026
When you sign in with Google, we receive and store the following from your Google account:
- Display name
- Email address
- Profile photo URL
- Firebase user ID (a unique identifier)
When you use Forge of Holding, we also store:
- Character data you import or create (stored as JSON)
- API keys you generate for third-party access
- Share link tokens for characters you choose to share
- Edit timestamps and version numbers for conflict detection
We do not use third-party analytics or tracking services. We do not collect browsing behavior, device fingerprints, or location data.
Your data is used to:
- Authenticate your identity and protect your account
- Store and retrieve your character sheets
- Generate share links when you choose to share a character
- Validate API key access from the Character Vault Foundry VTT module
We do not sell, rent, or share your personal information with third parties for marketing purposes.
We protect your data through the following measures:
- All traffic is encrypted via HTTPS
- Authentication tokens are validated server-side using Firebase Admin SDK
- API keys are stored as salted hashes (the raw key is never stored)
- Database access is restricted to authenticated API routes
- Optional field-level encryption is available for sensitive character data
No system is completely secure. While we take reasonable precautions, we cannot guarantee absolute security of your data.
Your character data is private by default. Data is shared only when:
- You create a share link for a character (anyone with the link can view it)
- You use an API key to grant a third-party application access to your characters
You can revoke share links and API keys at any time from your vault and settings pages. We do not share your data with advertisers or data brokers.
We retain your data for as long as your account is active. You can delete individual characters from your vault at any time.
To delete your account and all associated data (characters, API keys, share links, and profile information), go to Settings and use the “Delete Account” option. Deletion is immediate and permanent.
After account deletion, your data is permanently removed from our database and cannot be recovered.
Contact
If you have questions about this Privacy Policy, contact us at ken@futurehax.com or through our Discord server.