Legal

Privacy Policy

Last updated: March 2026

This Privacy Policy explains how GMForge ("we", "us", or "our") collects, uses, and protects information about you when you use gmforge.app. We keep this simple and honest — we collect only what we need to run the service.

1. Who We Are

GMForge is operated by an individual based in the United States. If you have questions about this policy, please use the contact form on our website.

2. What We Collect

We collect the following information when you use GMForge:

We do not collect names, phone numbers, addresses, or any other personal information beyond what is listed above.

3. How We Use Your Information

We do not sell your data. We do not use your data for advertising. We do not use your generated content to train AI models.

The content you generate using GMForge (NPCs, quests, encounters, etc.) belongs to you. We store it solely to provide the Campaign Vault feature.

4. Third-Party Services

GMForge uses the following third-party services. Each has its own privacy policy governing how they handle data.

SupabaseDatabase and authentication. Stores your account and vault content. Privacy policy →
StripePayment processing for Pro subscriptions. We never see your card details. Privacy policy →
AnthropicAI generation. Your prompts are sent to Anthropic's API to generate content. Privacy policy →
ResendTransactional email delivery (e.g. password reset). Privacy policy →
VercelHosting and anonymous usage analytics. Privacy policy →

5. Cookies

GMForge uses cookies only for authentication — to keep you signed in between sessions. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Vercel Analytics collects anonymous, aggregated usage data with no personally identifiable information.

6. Data Retention

We retain your account and vault content for as long as your account is active. If you delete your account, your data is permanently removed from our database within 30 days. Payment records are retained by Stripe as required by law.

7. Security

Your data is stored in Supabase with row-level security — meaning each user can only access their own data. All connections use HTTPS. Passwords are never stored in plain text. We take reasonable measures to protect your information, though no system is 100% secure.

8. Your Rights (including EU/UK Users)

Depending on where you are located, you may have the following rights regarding your personal data:

To exercise any of these rights, please use the contact form on our website. We will respond within 30 days.

9. Children's Privacy

GMForge is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of GMForge after changes are posted constitutes acceptance of the updated policy.