Legal

Privacy Policy

Last updated: April 2026

1. What We Collect

When you use CritSheet, we collect:

  • Account information — your email address when you register
  • Campaign and session data — campaign names, player names, character names, class selections, and session statistics you enter
  • Audio recordings — files you upload for transcription, stored in private cloud storage
  • Transcripts and extracted data — text transcriptions of your sessions and AI-extracted statistics, stored to power box scores and the play-by-play feature
  • Usage data — standard server logs and error reports used to keep the service running

2. How We Use Your Data

We use the data we collect to:

  • Provide the core functionality of CritSheet (session tracking, box scores, leaderboards)
  • Transcribe audio and extract statistics using AI services
  • Authenticate your account and keep it secure
  • Diagnose and fix bugs and performance issues
  • Communicate important service updates to you

We do not sell your data to third parties. We do not use your session content to train AI models.

3. Third-Party Services

CritSheet relies on the following third-party services to operate:

  • Supabase — database, authentication, and file storage. Your data is stored on Supabase infrastructure.
  • AssemblyAI — audio transcription. Audio files are sent to AssemblyAI for processing and are subject to their privacy policy.
  • Anthropic (Claude) — AI stat extraction. Session transcripts are sent to Anthropic for analysis. Anthropic's data usage policies apply.
  • Vercel — hosting and edge infrastructure.

4. Public Data

Box scores, player profiles (character names and stats only — never real player names), and campaign leaderboards are publicly accessible. This is intentional — sharing is a core feature of CritSheet. Any data you save to a session is potentially visible to anyone with the link. Real player names are only visible to the account owner when logged in.

5. Audio Storage

Audio files you upload are stored in private cloud storage with access restricted to your account. Files are used solely for transcription. Transcription jobs that do not result in a saved session are automatically deleted after 7 days.

6. Data Retention

Your account data is retained for as long as your account is active. If you wish to delete your account and associated data, please contact us. We will fulfill deletion requests within a reasonable timeframe.

7. Cookies and Authentication

CritSheet uses cookies solely to maintain your authenticated session. We do not use tracking cookies or third-party advertising cookies. No cookie consent banner is displayed because we only use strictly necessary cookies.

8. Your Rights

You have the right to:

  • Access the data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Export your campaign and session data

To exercise any of these rights, please contact us through the Service.

9. Children's Privacy

CritSheet is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with their information, please contact us so we can remove it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Continued use of the Service after changes are posted constitutes acceptance of the revised policy. We will make reasonable efforts to notify users of material changes.

11. Contact

If you have questions or concerns about this Privacy Policy or how your data is handled, please reach out through the contact information provided in the Service.