Privacy
Last updated 23 September 2026
What we hold
- Your email address, so you can sign in and recover the account.
- A display name, if you set one.
- Your password, stored only as a hash. We cannot read it.
- Your characters and everything written on them.
- A session record while you are signed in.
That is all. No tracking pixels, no advertising, no profile built about you, and nothing sold or shared for marketing.
Why
To run the thing: to sign you in, show your characters back to you, and send the emails the account needs — confirming your address and resetting your password.
We also send occasional news about Crawler Play: what has been built, and what is changing. Creating an account signs you up for those. Every one carries an unsubscribe link that does not expire, and unsubscribing stops the news and nothing else — sign-in links, address confirmations and password resets are never affected.
Who else touches it
- Vercel hosts the site and processes requests.
- Neon stores the database.
- Resend delivers account and news emails.
Each of these only handles what the service needs to work. Data is held in the United States.
Cookies
One, holding your sign-in session. There are no analytics or advertising cookies. Your theme choice is kept in your browser and never sent to us.
How long
For as long as your account exists. Deleting it from Settings removes your characters and your account immediately. Backups may hold a copy for a short window before they roll over.
Your rights
You can see and change what we hold from within the app, and delete all of it from Settings. For anything else — a copy of your data, a correction, a complaint — write to system@crawlerplay.com.
The VTT Bridge browser add-on
The Crawler Play VTT Bridge is an optional browser add-on that carries dice rolls from your character sheet into a Roll20 game you have open in another tab. You do not need it to use Crawler Play.
It collects nothing. It has no account of its own, stores nothing on your device or anywhere else, and makes no network requests — so nothing it sees is sent to us or to anyone. It reads two pages and no others: your Crawler Play sheet, to hear a roll you asked for, and your open Roll20 game, to type that roll into the game chat. Both happen inside your browser.
Removing it from your browser removes it completely. Nothing is left behind, because nothing was kept.
Posting to Discord
A GM can point a campaign at a Discord channel in their own server. While that is switched on, rolls shared with the table — and the combat console’s round and step markers — are sent to that channel as they happen, carrying the crawler’s name, its portrait, what was rolled and the result. Rolls made privately on a sheet are never sent.
Those messages leave Crawler Play and become part of that Discord server, governed by Discord’s own terms and by whoever runs the server — we cannot delete or amend them afterwards. The GM chooses the channel and can stop the posting at any time, either in the campaign settings or by deleting the webhook in Discord. We send nothing else to it.
If you would rather your rolls did not go there, roll on the Private tab of your sheet, or ask your GM to turn it off.
Children
Crawler Play is not intended for children under 13.
Contact
system@crawlerplay.com
