Privacy Notice
Effective August 5, 2026
1. Scope
This notice explains how the operator of Campaign Command processes information when you sign in, manage campaigns, connect a public D&D Beyond character sheet, upload artwork, or open a shared display.
2. Information processed
- Account information: the email address and display name supplied through ChatGPT sign-in.
- Campaign information: campaign names, subtitles, display themes, randomly generated share tokens, and campaign relationships.
- Character information: names, species or ancestry, class, level, hit points, armor class, ability scores, spell-slot availability, limited-use resources, death saves, conditions, saving throws, senses, proficiencies, spell names, skills, sync status, and public D&D Beyond character links and IDs.
- Uploads: portraits, maps, or backdrop images you choose to upload.
- Abuse-prevention data: a request count stored under a one-way hash of your email address for per-user rate limiting. A separate service-wide counter is not tied to a user.
- Technical information: hosting, security, and authentication providers may process IP addresses, device or browser details, authentication tokens, and request logs to deliver and protect the service.
3. D&D Beyond integration
Only a signed-in Campaign Command user can initiate a request using a submitted public character link. Campaign Command does not ask for D&D Beyond login credentials. The full public response is processed transiently to normalize the character sheet. Campaign Command stores only the selected fields described above, not the full source response, descriptive text, snippets, or D&D Beyond portrait artwork.
Automatic synchronization runs no more frequently than every five minutes. A signed-in user may manually refresh after one minute. Upstream reads are limited to 30 per signed-in user and 300 service-wide in each ten-minute window. Shared-display visitors cannot trigger D&D Beyond requests. Shared displays poll Campaign Command for the latest saved copy only.
4. How information is used
Information is used to authenticate users, provide campaign and shared-display features, synchronize requested public character fields, store and display authorized artwork, enforce rate limits, prevent abuse, diagnose failures, and comply with legal obligations.
5. Service providers and disclosure
OpenAI provides the ChatGPT identity connection. Cloudflare provides hosting, database, object-storage, delivery, and related security infrastructure. These providers process information on the operator's behalf or under their own applicable terms. Information may also be disclosed when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.
Campaign Command does not sell personal information or use saved campaign data for targeted advertising.
6. Shared displays are public to link holders
Anyone with a valid shared-display link can view its saved campaign and character information without signing in. Treat the link as public. Share only information and artwork appropriate for everyone who may receive or forward it.
7. Retention
Campaigns, characters, public links, and current upload references are retained until you delete them or the service is discontinued. Replaced or deleted referenced uploads are removed from active object storage. Unused uploads are removed when you use “Delete all my data.” Per-user rate-limit records are deleted with that control and otherwise become eligible for routine pruning after 24 hours of inactivity.
Infrastructure logs, caches, and backups may retain limited copies for a short period according to provider security and backup schedules.
8. Your controls and deletion
- Edit saved campaign and character fields in the Campaign Command studio.
- Remove a character to delete its saved record and referenced uploaded portrait.
- Delete a campaign to delete the campaign, its saved characters, and referenced uploads.
- Open Settings and use “Delete all my data” to remove all campaigns, saved characters, uploaded images, and your per-user rate-limit record.
Campaign Command deletion does not delete or change information held in your ChatGPT or D&D Beyond accounts. For an access, correction, privacy, or deletion question that cannot be handled in Settings, use the Campaign Command operator contact method provided with your access to the service.
9. Security
Campaign Command uses authenticated management routes, unguessable share tokens, constrained upload types and sizes, short-lived media caching, server-side rate limits, and access checks. No system is completely secure. Keep shared links private when their contents are sensitive.
10. Children
Campaign Command is not directed to children under 13. Do not submit personal information about a child unless you have authority and any consent required by applicable law.
11. Changes
This notice may be updated as the service changes. The effective date will be revised when material changes are published.