Privacy Policy

Last updated: July 14, 2026

1. Who we are

MythForge ("we", "us", "our") operates the website app.mythforges.com and the related MythForge SaaS product. We act as the Data Controller for the personal data described in this policy. For any privacy request, contact us via our contact page.

2. Data we collect

  • Account data: email, display name, avatar, authentication identifiers (including Google sign-in).
  • Content you create: RPG sessions, characters, maps, images and other generated media.
  • Payment data: handled by Stripe; we only store status, plan and last 4 digits — never full card numbers.
  • Usage data: pages viewed, actions, device/browser, IP address, approximate location (from IP).
  • Marketing data: when you consent, we share hashed identifiers (email, external id) with Meta and — in the future — Google Ads for ad measurement and personalization.

3. Legal bases (GDPR Art. 6)

  • Contract — to provide the account and the service you signed up for.
  • Legitimate interest — to secure the service, prevent fraud, and produce aggregate analytics.
  • Consent — for non-essential cookies, analytics, marketing tools, Meta Pixel and Conversions API, and (future) Google Ads.
  • Legal obligation — accounting, tax and lawful requests.

4. How we use your data

  • Operate and secure the MythForge platform.
  • Generate the media and content you request via AI providers.
  • Send transactional emails (purchase receipts, password resets, account changes).
  • Measure and improve the product.
  • With your marketing consent, measure and optimize advertising campaigns.

5. Sharing & processors

We share data with vetted service providers acting as processors:

  • Supabase — authentication, database and storage (EU/US).
  • Stripe — payments and billing.
  • Cloudflare — hosting and edge delivery.
  • Meta Platforms — Pixel & Conversions API (only with marketing consent).
  • Google — in the future, Google Ads / Analytics (only with marketing/analytics consent).
  • AI providers used to generate your content (prompts and generated media may be transmitted).
  • Email delivery provider for transactional messages.

We do not sell your personal data.

6. International transfers

Some processors are located outside the EEA/UK. Transfers rely on Standard Contractual Clauses (SCCs) and, where applicable, additional safeguards.

7. Retention

Account data is kept while your account is active and deleted (or anonymized) within a reasonable period after closure. Billing records are kept as required by law (typically up to 10 years). Marketing identifiers are kept only while your consent is valid.

8. Your rights (GDPR / UK GDPR / CCPA)

You have the right to access, rectify, erase, restrict or object to processing, and to data portability. EU/UK users can lodge a complaint with their local supervisory authority. California residents have the right to know, delete, correct, and opt-out of the "sale/sharing" of personal information (we do not sell it).

Exercise any right via the contact page.

9. Cookies

We use strictly necessary cookies plus, with your consent, analytics and marketing cookies. See our Cookie Policy for details. You can change your choices any time from the .

10. Security

We apply industry-standard measures (encryption in transit, row-level security on the database, least-privilege access). No system is 100% secure — please use a strong, unique password.

11. Children

MythForge is not directed to children under 16. Do not use the service if you are under that age.

12. Changes

We will update this policy from time to time. Material changes will be announced in-app or by email.