Privacy Policy
The short version: Ironhold works fully on your own device, with no account needed. Accounts are optional: if you create one, we store your email address and the things you make in Ironhold on our servers in Sydney, Australia, so they sync between your devices. Only you can see them, and you can delete your account, and everything with it, at any time. We never sell your information, show you ads or track what you do. If the app crashes, it sends a crash report (the error, and details of the device it happened on, never anything you wrote or anything that identifies your device) so we can fix it, and you can turn that off in Settings.
Accounts are being introduced gradually. If your version of Ironhold doesn't offer them yet, the Accounts section doesn't apply to you: everything stays on your device.
Who we are
Ironhold is a companion app for the Daggerheart tabletop roleplaying game, made by an independent developer, Nick Livingston, in Australia. In this policy, "we" and "us" mean the Ironhold developer. You can reach us at [email protected].
What stays on your device
Everything you make in Ironhold is stored locally in the app (or, on the web version, in your browser's storage):
- your characters, campaigns, session notes, worldbuilding notes and homebrew content
- images you add, such as maps and portraits
- your settings, such as your theme and layout preferences
Without an account, none of this is sent to us or anyone else. We can't see it, and we can't recover it for you. If you uninstall the app or clear its data (or your browser's site data), it's deleted, so use Settings → Backup to keep a copy.
Accounts (optional)
An account lets your characters, campaigns and homebrew follow you between devices. You don't need one: everything in Ironhold works without it, and sync is free.
Signing in. You sign in with your email address and a 6-digit code we email you. There's no password. The sign-in emails are sent for us by Resend, which handles your email address only to deliver them.
What's stored with your account:
- your email address, and an account number that identifies your records
- when you signed in, and the network (IP) address and browser type you signed in from, kept by our database provider for security (to spot and stop misuse of your account)
- the characters, campaigns (including your session and worldbuilding notes), homebrew, maps and portraits you make while signed in, and the ones already on a device when you sign in on it
- earlier versions of your characters, campaigns and homebrew: each time a newer copy replaces one, the previous copy is kept for 30 days so you can restore it (Settings → Account → Restore an earlier version)
Where. Your account and everything stored with it is kept by our database provider, Supabase, in its Sydney, Australia data centre, and sent there and back encrypted.
Who can see it. Only you, whenever you're signed in. The database itself enforces this, so no other account can read or change your records. We don't look at what you've made, except if you ask us to help with a problem, and we never use it for anything but running Ironhold for you. (We plan to add shared campaigns, where a GM and their players see parts of one campaign. We'll update this policy before that's released.)
How long. Until you delete it, or delete your account. Earlier versions are kept for 30 days, and a map or portrait you delete or replace is removed from our servers 30 days later. If our database provider keeps backups of the database, it keeps them for no more than 7 days, so a deletion is gone from any backup within a week.
Signing out keeps everything on your device, and your other devices stay signed in.
Deleting your account
You can delete your account at any time, in the app at Settings → Account → Delete account, or on the web at ironholdrpg.com/delete-account. Deleting it removes your email address and everything stored with your account from our servers straight away (and from any backups within 7 days). The copies on your devices stay unless you choose to remove them too. If you can't sign in, email [email protected] from the address you signed up with and we'll delete the account within 30 days.
What we don't do
- No analytics, advertising or tracking of any kind.
- We never sell your information, or share it except with the service providers named in this policy, who handle it only to run Ironhold for us.
- No third-party tools inside the app other than crash reporting (Sentry, below), which you can turn off, and, if you use an account, the connection to our database provider (Supabase).
The Android app uses the internet only for crash reports (unless you turn them off) and, if you sign in, for your account and sync. Tapping an outside link (such as the Daggerheart website in Settings) opens it in your browser, where that site's own privacy policy applies.
Crash reports
When Ironhold crashes or hits an error, it sends a crash report to Sentry, a crash reporting service, so we can find out what went wrong and fix it. It's on by default and you can turn it off at any time in Settings → Crash reports → Send crash reports. Turning it off stops reports straight away, and the choice is remembered on your device.
A crash report contains:
- the error message, with any quoted text removed, and where in Ironhold's code it happened
- which screen you were on and the screens just before it, as their general shape (for example "a campaign's Combat tab"), with the identifiers of your characters and campaigns removed
- your device and operating system: in the Android app, the device's make and model, Android version, processor, screen size, memory and storage (total and free), battery level and whether it's charging, whether it's online and on Wi-Fi or mobile data, its language and time zone settings, and when it last restarted; in a web browser, the browser type (the "user agent")
- the Ironhold version, whether it's the Android app or the web version, and when the app was opened
- the approximate city and country the report came from, which Sentry works out when it arrives (see below)
It never contains your characters, campaigns, homebrew, notes, names or anything else you wrote, and Ironhold removes anything that could hold them before a report leaves your device. It doesn't include what you tapped or typed, screen recordings, performance tracking, your email address, or any account or advertising identifier, and nothing that identifies your device or this installation of the app: where a crash reporting tool would add a device or installation ID, every report carries the same placeholder instead. Like any web service, Sentry sees the network (IP) address a report arrives from. It uses that address to record the approximate city and country the report came from, and keeps that with the report; Ironhold is set up so that Sentry doesn't store the address itself.
Reports are stored by Sentry in its European Union data region (Germany) and kept for up to 90 days. We use them only to find and fix bugs.
Backups and homebrew files
When you export a backup or a homebrew file, Ironhold creates the file on your device and hands it to your phone's share sheet or your browser's downloads. Where it goes from there (your storage, a cloud drive, a message to a friend) is up to you, and that service's own privacy policy applies.
If you email us
The "Send feedback" and "Report this problem" links open your own email app with a message already started. That message includes:
- the Ironhold version and build date
- your device's browser and operating system details (the "user agent")
- for crash reports, the error message the app showed
You can read and edit all of it before sending, and nothing is sent unless you press send. We use what you send, along with your email address, only to reply to you and to fix problems. We keep these emails only as long as they're useful for that, and we'll delete them if you ask.
The web version
If you use Ironhold in a web browser at ironholdrpg.com, the site is delivered by a hosting provider (Cloudflare). Like any web host, it may briefly process technical information such as your IP address and browser type to deliver the site and protect it from abuse. We don't use this to identify or track you. Without an account, your Ironhold data stays in your browser, as described above; with one, it syncs exactly as in the app. Crash reports work the same way as in the app, including turning them off in Settings.
Test builds
If you've joined as a tester, pre-release builds are delivered through Firebase App Distribution, a Google service. It uses the email address you signed up with to send you builds, under Google's privacy terms. Ironhold itself doesn't include any Firebase code.
Children
Ironhold isn't aimed at children under 13, and children under 13 shouldn't create an account. We don't knowingly collect personal information from them. If you believe a child has created an account or emailed us, contact us and we'll delete it.
Your choices and rights
You're in control of your Ironhold data: on your device you can view, change, export or delete it at any time, and with an account you can see everything stored with it in the app, restore earlier versions, and delete the account and everything with it (see Deleting your account). The personal information we might hold is your account's email address and sign-in records, and any email you've sent us (crash reports don't identify you). You can ask us for a copy of it, or to correct or delete it, at [email protected].
Changes to this policy
We plan to add shared campaigns, where a GM and their players see parts of one campaign across devices, and optional paid features. These involve handling more data. We'll update this policy before any such feature is released, change the date at the top, and tell you in the app when something important changes.
Contact
Questions about privacy? Email [email protected].