The short version: We collect only what we need to run the service. We do not sell your data. We do not store photos you submit. We use Supabase for accounts and Stripe for payments — both are industry-standard secure services.

1 Who We Are

Creature Forge AI ("we," "us," "our") operates the tabletop RPG creature generation service at creatureforgeai.com. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service.

If you have questions about this policy, contact us at [email protected].

2 Information We Collect

We collect the following categories of information:

Category What we collect Why
Account data Email address, name (optional), password (hashed) To create and manage your account
Usage data Number of generations used, credit balance, subscription status To enforce plan limits and credit balances
Payment data Stripe customer ID, subscription ID, payment status To process payments and manage subscriptions
Saved creatures Creature stat blocks and lore you choose to save To populate your collection
Technical logs Server logs, error logs, timestamps To maintain service reliability and debug issues
We do NOT collect or store: photos or images you submit, your payment card details, your IP address beyond standard server logs, or any biometric data.

3 Photos and Images You Submit

This section is important and we want to be completely transparent about it.

When you upload a photograph or image to generate a creature, that image is:

Your submitted image is also transmitted to our third-party AI provider (Anthropic) solely for the purpose of analyzing its content to generate your creature. Anthropic's own privacy policy governs how they handle data transmitted to their API. You can review it at anthropic.com/legal.

Plain English: your photos go in, a creature comes out, and the photo is gone. We never see it, never store it, never use it for anything else.

4 How We Use Your Information

We use the information we collect to:

We do not use your information to:

5 Third-Party Services

We use the following trusted third-party services to operate Creature Forge AI. Each has its own privacy policy governing their handling of data:

Service Purpose Data shared Privacy policy
Supabase Database and user authentication Account data, usage data, saved creatures supabase.com/privacy
Stripe, Inc. Payment processing Email address, payment information stripe.com/privacy
Anthropic, PBC AI text generation Text descriptions, submitted images (not stored) anthropic.com/legal
OpenAI, LLC AI image generation (Pro feature) Image prompts openai.com/policies
Railway Server hosting Server logs only railway.app/legal/privacy
Cloudflare DNS, CDN, and security Standard web traffic logs cloudflare.com/privacypolicy
We carefully select service providers that meet high standards for security and privacy. We do not work with advertising networks or data brokers.

6 Data Storage and Security

Your account data is stored securely in Supabase, which uses industry-standard encryption at rest and in transit. All connections to our Service are encrypted via HTTPS enforced by Cloudflare.

We implement the following security measures:

While we take security seriously, no system is completely immune to breaches. In the event of a data breach affecting your personal information, we will notify you as required by applicable law.

7 Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specific retention periods:

Data type Retention period
Account information Until account deletion is requested
Saved creatures Until deleted by you or account deletion
Payment records 7 years (required for financial compliance)
Server logs 90 days
Submitted photos Not retained — deleted immediately after generation
Text generation inputs Not retained beyond the generation request

8 Cookies and Tracking

We use minimal tracking technologies:

We do not use advertising cookies, third-party tracking pixels, Google Analytics, or any behavioral tracking technology. We do not build advertising profiles from your usage.

We use the minimum cookies needed to keep you logged in and keep the site secure. Nothing more.

9 Your Rights and Choices

You have the following rights regarding your personal data:

To exercise any of these rights, email us at [email protected] with your account email address and your request. We will respond within 30 days.

Note that we are required to retain certain payment records for legal and financial compliance purposes even after account deletion.

10 Children's Privacy

Creature Forge AI is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us immediately at [email protected] and we will delete that information promptly.

Users between the ages of 13 and 18 should have parental or guardian consent before using the Service.

11 California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

We do not sell personal information. To exercise any CCPA rights, contact us at [email protected].

12 International Users

Creature Forge AI is operated from the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States where our servers and service providers are located.

If you are located in the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, you should be aware that your data is processed in the United States, which may not have equivalent data protection laws to your home country. By using the Service, you consent to this transfer.

13 Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page.

Your continued use of the Service after changes take effect constitutes your acceptance of the updated Privacy Policy. If you do not agree with changes, you may request account deletion by contacting us.

14 Contact Us

For privacy-related questions, data requests, or concerns, please contact us:

Creature Forge AI
Email: [email protected]
Website: https://creatureforgeai.com

We aim to respond to all privacy inquiries within 5 business days.

For the fastest response, please include your account email address and a clear description of your request or concern.