1. What we collect
- Account details. Your email address, and a name if you give one. Passwords are handled by our authentication provider, Neon Auth — we never see or store your password.
- Your project content. The projects, components, versions, journal entries, rulebooks, playtest sessions, and files you create in the app.
- Playtest feedback. Responses submitted through the feedback links you share. Playtesters do not need an account; what is recorded is whatever your form asks for.
- Checklist signups. If you request the free checklist, the email address you type into that form.
- Basic technical logs. Standard server and error logs our hosting produces, used to keep the service running and secure.
2. Where it lives
Your account and project data are stored in Neon Postgres, a managed database service. Sign-in is handled by Neon Auth. The application is hosted on Vercel. Emails we send — the free checklist download and project collaboration invitations — go through Resend, our email provider, which processes the recipient address to deliver them; account emails such as password resets are sent as part of the Neon Auth sign-in system. These providers process data on our behalf so the service can operate.
3. Why we use it
- To give you an account and show you your own work.
- To share projects with collaborators and playtesters you invite.
- To send email you would expect: password resets, invitations, and — if you asked for the checklist — that file and occasional beta updates. Every marketing email has an unsubscribe link.
- To keep the service working, debug problems, and prevent abuse.
4. What we do not do
- We do not sell or rent your personal data.
- We do not run ads, and we do not embed advertising or analytics trackers for third parties.
- We do not use your game designs or playtest data for any purpose other than operating BoardForge for you.
5. Cookies
BoardForge sets cookies for one purpose: keeping you signed in. There are no advertising cookies and no cross-site tracking cookies. Clearing them signs you out.
6. Feedback your playtesters give you
When someone submits feedback through your link, that feedback is stored against your project and is visible to you and your collaborators. You choose what your form asks for, so please ask for as little as you need and tell playtesters what you are recording. You can revoke a feedback link from inside the app at any time.
7. Keeping and deleting data
We keep your data for as long as your account exists. You can edit or delete most content directly in the app. To get a copy of your data, or to have your account and its data deleted, email billing@krishnahalaharvi.com and we will action it. Backups and provider logs may retain copies for a short period after deletion before they age out.
8. Security
Access to project data is checked on every request against your permissions for that project, and traffic is served over HTTPS. No service is perfectly secure, and BoardForge is in beta — please do not store anything here that would be damaging to lose or expose.
9. Children
BoardForge is not directed at children and is not designed for their use.
10. Changes and contact
If this policy changes, the date on the banner above changes with it, and we will email accountholders about material changes. Questions, access requests, and deletion requests all go to billing@krishnahalaharvi.com. See also our Terms of Use.