Privacy Policy
Last updated: September 18, 2026
What we store
- Account: the email address and display name your sign-in provider shares with us — Google, Discord or GitHub — only when the provider has verified the address (we never see your password), plus your token balance and when your account was created. If you sign in by emailed link instead, that is the address you typed, confirmed by your clicking the link we sent to it.
- Sign-in links: when you ask for an emailed sign-in link we store the address, a hash of the one-time token, and the IP that asked, so the link can be checked and abuse can be rate limited. Links expire after 15 minutes and the rows are deleted within a day.
- Generated content: the class concepts you enter and the classes/cards the site generates for you, so your library persists.
- Donations: a record of each donation (amount, thank-you tokens, date, Stripe reference ids). Payments are processed by Stripe — your card details go to Stripe directly and never touch our servers.
- Generation usage: for each forge, how many model tokens it consumed and an estimated cost, so we can keep pricing honest. This is volume only — no prompt or key contents.
- Feedback: ratings and notes you submit on cards/mechanics, used to improve the generator.
What we deliberately don't store
- BYOK API keys. If you bring your own API key, it stays in your browser's local storage and is sent to our server only inside that one generation request, which relays it to the provider you chose — for the text generation and, where that provider offers an image API (OpenRouter, OpenAI, Google Gemini, xAI), for the class art as well. It is never written to our database or logs.
- Card numbers or any payment credentials (Stripe handles those).
How your data is used
- To run the service: sign you in, save your classes, track your token balance, and show your donation history.
- Concepts and feedback may be used in aggregate to improve generation quality.
- We don't sell your data or use third-party advertising/tracking.
Third parties
- Google — sign-in (OAuth), if you choose it.
- Discord — sign-in (OAuth), if you choose it.
- GitHub — sign-in (OAuth), if you choose it.
- Resend — sends the sign-in link email, if you choose email sign-in. They receive your email address for that purpose only; we don't use them for anything else.
- Stripe — payment processing and receipts.
- Model providers — your class concept is sent to an AI model to generate the class (our hosted model providers for token forges, or the provider you chose when bringing your own key).
Your choices
- You can delete any class from your library at any time.
- To delete your account and its data, email us from the account's address — the verified address your sign-in provider gave us, or the one you sign in to with an emailed link.
Contact
Questions: ryan.r.rinkel@gmail.com.