Privacy Notice
Effective August 15, 2026
1. Scope
This notice explains how the operator of Campaign Command processes information when you sign in, manage campaigns, connect a public D&D Beyond character sheet, upload artwork, use a shared display, or purchase and manage a paid membership.
2. Information Processed
- Campaign Command Account Information: a permanent Campaign Command account identifier, each linked Clerk user identifier, the verified email address used to link the account, and your display name. Campaigns, uploads, and other saved data are associated with the Campaign Command identifier rather than your email address or one particular Clerk environment.
- Authentication and Connected-Account Information: Clerk processes information needed to create an account, verify your email address, authenticate you, maintain your session, and secure your account. If you choose Google or Discord sign-in, Clerk and that provider may exchange the provider account identifier, email address, display name or username, profile image, verification status, sign-in method, and related authentication metadata authorized by the sign-in flow. Campaign Command does not receive or store your Google or Discord password.
- Campaign Information: campaign names, subtitles, display themes, reusable custom-theme presets, randomly generated share tokens, private share-link labels, shared-view preset choices, sharing status, optional expiration settings, per-link shared-display visibility choices, saved initiative order and encounter reminders, DM-authored prepared encounters and creature visibility choices, campaign relationships, and the most recent dice roll that a DM expressly chooses to share with the party.
- Session Review Information: session titles, DM-authored quick notes and note categories, session start and end times, starting and ending character snapshots, and a private event history of saved changes to hit points, temporary hit points, spell slots, limited-use resources, conditions, concentration, death saves, and combat timing. Automatic event tracking occurs only after the DM expressly starts a session.
- Character Information: names, species or ancestry, class, level, hit points, armor class, ability scores, spell-slot availability, limited-use resources, death saves, conditions, saving throws, senses, languages and other proficiencies, spell names, skills, sync status, and public D&D Beyond character links and IDs.
- Uploads: portraits, maps, or backdrop images you choose to upload.
- Membership and Payment Information: if you purchase a paid membership, Campaign Command stores the internal account relationship to your Stripe customer, subscription and price identifiers, subscription status, renewal period, and cancellation status. Stripe collects and processes payment-card details, billing details, payment authentication information, transaction history, fraud-prevention signals, and related payment information. Campaign Command does not receive or store your full payment-card number or security code.
- Abuse-Prevention Data: a request count stored under a one-way hash of your Campaign Command account identifier for per-user rate limiting. A separate service-wide counter is not tied to a user.
- Technical Information: hosting, security, and authentication providers may process IP addresses, device and browser details, session identifiers, authentication tokens, timestamps, and request or security logs to deliver and protect the service.
3. Cookies and Similar Technologies
Campaign Command, Clerk, and the service's hosting and security providers use cookies and similar browser technologies that are strictly necessary to create and protect accounts, keep users signed in, securely route authenticated requests, remember authentication state, detect abuse, and deliver the service. Clerk may set authentication cookies such as __session and __client_uat. Cloudflare may also set cookies or similar identifiers required for security and service delivery.
These authentication and security technologies are necessary for signed-in features and cannot be disabled within Campaign Command. You can block or delete them through your browser settings, but doing so may sign you out or prevent account and Studio features from working. They remain until they expire, you sign out, or you clear applicable browser data, according to the relevant session configuration and provider practices.
Campaign Command does not currently use cookies for advertising, cross-site tracking, or behavioral analytics. If non-essential cookies or similar technologies are introduced, this notice and any consent controls required by applicable law will be updated before they are used.
When paid memberships are available and you enter a Stripe-hosted checkout or billing-management flow, Stripe may use cookies and similar technologies needed to process payments, authenticate transactions, prevent fraud, remember checkout state, and provide its payment services.
4. D&D Beyond Integration
Only a signed-in Campaign Command user can initiate a request using a submitted public character link. Campaign Command does not ask for D&D Beyond login credentials. The full public response is processed transiently to normalize the character sheet. Campaign Command stores only the selected fields described above, not the full source response, descriptive text, snippets, or D&D Beyond portrait artwork.
Free membership permits manual synchronization no more frequently than once every ten minutes and does not include automatic synchronization. Paid membership permits manual synchronization after one minute and automatic synchronization of the currently active campaign no more frequently than every five minutes. Upstream reads remain limited to 30 per signed-in user and 300 service-wide in each ten-minute window. Shared-display visitors cannot trigger D&D Beyond requests. Shared displays poll Campaign Command for the latest saved copy only.
Session Review compares changes to the limited character fields already saved by Campaign Command. Starting a session, adding a quick note, opening a review, or generating a session summary does not trigger an additional D&D Beyond request.
5. How Information Is Used
Information is used to authenticate users, provide campaign and shared-display features, create DM-only session notes and review summaries, deliver DM-authorized shared dice rolls, synchronize requested public character fields, store and display authorized artwork, process and administer paid memberships, grant the features included with a membership, enforce rate limits, prevent abuse, diagnose failures, and comply with legal obligations.
6. Service Providers and Disclosure
Clerk provides account creation, authentication, connected-account management, session management, and related security services. Campaign Command may link a newly verified Clerk identity to an existing Campaign Command account when the verified email address matches, including when the service moves between Clerk environments. If you choose a social sign-in method, Google or Discord also processes the sign-in under its own privacy policy. Social sign-in is optional, and users may instead use an available email-based sign-in method.
OpenAI Sites and Cloudflare provide hosting, database, object-storage, delivery, and related security infrastructure. These providers process information on the operator's behalf or under their own applicable terms. Information may also be disclosed when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.
Stripe will provide payment processing, subscription billing, checkout, billing-management, fraud-prevention, and related payment services for paid memberships. Stripe processes payment information under its own privacy policy and applicable terms.
Campaign Command does not sell personal information or use saved campaign data for targeted advertising.
7. Shared Displays Are Public to Link Holders
Anyone with a valid shared-display link can view its saved campaign and character information without signing in. Treat the link as public. Share only information and artwork appropriate for everyone who may receive or forward it.
The DM can turn sharing off or replace a share token at any time. A replaced token stops authorizing only the former link. Free membership includes one standard link. Paid sharing controls can create multiple independently configured links, apply shared-view presets, set a separate automatic expiration for each link, and choose whether each shared display includes expandable character details, spell-slot availability, selected limited-use abilities, conditions and concentration, or party-shared DM rolls. These choices filter Campaign Command's saved copy and do not cause the shared display to contact D&D Beyond.
Dice rolls are private by default and remain only in the DM's current browser session. When the DM expressly selects “Share with Party,” Campaign Command stores the latest shared result and makes its expression, individual dice, modifier, total, and timestamp visible to anyone viewing that campaign's shared-display link. A private roll is not sent to or stored in the shared-roll service.
8. Retention
Campaigns, characters, public links, saved custom-theme presets, prepared encounters, session reviews, and current upload references are retained until you delete them or the service is discontinued. Prepared encounters are private to the signed-in DM and are deleted individually or with their campaign, all saved data, or the account. Session reviews are visible only to the signed-in DM, are not included in shared displays, and are deleted when you delete the individual review, its campaign, all saved data, or the account. Only the latest party-shared dice roll is retained for a campaign; it replaces the prior shared roll, stops appearing on shared displays after approximately 90 seconds, and is deleted with the campaign or account data. Private roll history remains only in the current DM browser session and is cleared when that page session ends. Uploaded backdrops referenced by a campaign or saved theme are retained while either reference remains. Replaced or unreferenced uploads are removed from active object storage. Unused uploads are removed when you use “Delete all saved data” or “Delete account.” Per-user rate-limit records are deleted with either control and otherwise become eligible for routine pruning after 24 hours of inactivity. If you use “Delete all saved data,” the minimal Campaign Command account record and linked Clerk identity remain so the signed-in account can be recognized if you start again. They are removed when you use “Delete account.”
Authentication sessions, connected-account information, payment and transaction records, infrastructure logs, caches, and backups are retained according to Clerk's, Stripe's, and the other applicable providers' security, session, payment, tax, fraud-prevention, and backup practices. Campaign Command retains its local membership status records while needed to provide or document the membership. Limited records may remain after deletion where necessary for security, accounting, dispute handling, fraud prevention, backup restoration, or legal compliance.
9. Your Controls and Deletion
- Edit saved campaign and character fields in the Campaign Command studio.
- Turn a campaign's shared-display link off or replace it to invalidate the previous token. Paid sharing controls can also create and delete additional links, apply shared-view presets, and set expiration and content choices independently for each link.
- Create, apply, update, or delete reusable custom-theme presets with paid membership.
- Create, duplicate, update, load, or delete private prepared encounters with paid membership.
- Start and end a private session, add or edit quick notes, review saved character changes, and delete completed session reviews with paid membership.
- Remove a character to delete its saved record and referenced uploaded portrait.
- Delete a campaign to delete the campaign, its saved characters, and referenced uploads.
- Open Settings and use “Delete all saved data” to remove all campaigns, saved characters, uploaded images, and your per-user rate-limit record.
- Open Settings and use “Delete account” to remove that saved data, your internal Campaign Command account and identity links, and your Clerk sign-in account.
- Manage your Clerk profile, email addresses, connected accounts, active sessions, and Clerk account through the account menu.
- Review or revoke Campaign Command's access through Google or Discord account settings when you used that provider to sign in.
- When paid memberships are available, use the billing-management control provided in Campaign Command to review billing details, update a payment method, or manage the subscription through Stripe.
“Delete all saved data” retains the minimal Campaign Command account record, linked Clerk identity, Clerk account, and any membership or transaction records that must remain for subscription administration or legal compliance. “Delete account” removes the deletable Campaign Command records and requests deletion of your Clerk account, but it does not delete or change information held by Google, Discord, D&D Beyond, or Stripe. Likewise, disconnecting a social provider does not by itself delete your Campaign Command data. Use the applicable controls for each service. For an access, correction, deletion, or privacy question that cannot be handled in Settings or the account menu, email support@thecampaigncommand.com.
10. Security
Campaign Command uses authenticated management routes, unguessable share tokens, constrained upload types and sizes, short-lived media caching, server-side rate limits, and access checks. No system is completely secure. Keep shared links private when their contents are sensitive.
11. Children
Campaign Command is not directed to children under 13. Do not submit personal information about a child unless you have authority and any consent required by applicable law.
12. Changes and Contact
This notice may be updated as the service changes. The effective date will be revised when material changes are published. For privacy questions, email support@thecampaigncommand.com.