Privacy Policy

Last updated 1 August 2026

DM Toolkit is a private tool for running tabletop roleplaying games. It is run by one person for a small invited group, not as a commercial service. This page describes exactly what it stores and what it does not.

Who runs this

This site is operated by an individual, not a company. Questions about anything on this page, or requests to delete your data, go to giarc.luke@gmail.com.

What signing in collects

Signing in uses your Google account. The only things requested from Google are your email address and your name. The email address identifies your account and is checked against the invite list. The name is shown to you in the sidebar.

No access to your Gmail, Drive, contacts, calendar, or anything else is requested, and none could be granted by signing in here. Your Google password is never seen by this site — Google handles that and tells this site only who you are.

What else is stored

  • Everything you type into the toolkit — campaigns, characters, NPCs, locations, story threads, session notes. This is the point of the app.
  • Feedback you submit — the message, plus a name if you choose to type one, the page you were on, and which campaign was open. The name field is optional and free text; it is not taken from your account.
  • A sign-in cookie, so you stay signed in between visits. It expires after 30 days.
  • Your assistant preference, if you choose Claude, Codex, in-site Ollama Cloud, or to be asked each time.
  • Your Ollama Cloud API key, if you enable in-site Ollama Cloud. It is encrypted at rest, used only to make Ollama Cloud requests you initiate, and never displayed again after you save it. You can replace or remove it from the Account page.
  • DM Toolkit connection credentials, so an authorized MCP client can act as you. A new named key is shown once; the server keeps its name, dates, status, and a one-way hash used to verify it. Existing legacy account tokens remain until you revoke them from the Account page.
  • The dates of your first and most recent sign-in.

What is not collected

There are no analytics, no advertising, no tracking pixels, and no third-party scripts of any kind. Your activity is not profiled and nothing is sold or shared. No IP-address log is kept by the application itself, though the hosting provider keeps ordinary server logs as any host does.

AI assistants

External assistants

When you choose an external assistant such as Claude or Codex, AI reasoning happens in that assistant, not on this website. DM Toolkit prepares a request containing campaign and record identifiers. It does not put your campaign prose or an AI-provider credential into a launch link.

Your external assistant can retrieve campaign information through your authorized MCP connection only when you ask it to do so. The assistant may then receive the specific information it retrieves and any text you paste into its conversation. You control what you ask it to read or change, and consequential changes should be shown to you for approval before they are saved through MCP.

If you use the copy-back option instead, you choose what to paste from an external assistant into a signed-in browser session. DM Toolkit treats a pasted copy-back response as untrusted user-provided content and temporarily processes it only to validate its structure and return a draft or answer to the page. It does not store the pasted response or create or update a record automatically. You review the result and choose the page's normal Save or Create action if you want it kept.

You manage the external service, its credentials, and any subscription separately from DM Toolkit. DM Toolkit never asks for or stores an external assistant provider credential. The external service's privacy policy and terms apply to information it processes.

In-site Ollama Cloud

If you voluntarily enable in-site Ollama Cloud, DM Toolkit calls Ollama Cloud on your behalf using your stored Ollama Cloud API key. When you select an Ollama-powered action, DM Toolkit sends the campaign context needed for that request to Ollama Cloud, together with the instructions or question you provide. That information is processed by Ollama Cloud to generate the response.

The response is returned to DM Toolkit as a draft. You review the returned draft before choosing the page's normal Save or Create action; generation does not save campaign changes automatically. Ollama's own privacy policy and terms apply to the information it processes. Removing your Ollama key disables this in-site path without affecting manual editing or external MCP connections.

When an older installation is upgraded, the toolkit removes credentials left in retired server and browser settings without reading or sending the browser value.

Where it is stored, and who can see it

Google Drive image storage is optional and separate from sign-in. If you connect it, DM Toolkit requests access only to files created or selected through the app, stores an encrypted refresh credential, and lets other authorized members of the same campaign view linked images privately through the toolkit.

Data lives in a database hosted by Railway, in the United States. Campaigns are private to the account that owns them: no other signed-in user can read, edit, or export a campaign that is not theirs.

Be aware of the honest exception: the person who runs this site administers the database and can therefore access what is stored in it, as is true of any self-hosted application. Do not put anything here you would not be comfortable with the site owner seeing.

Deleting your data

You can delete your own campaigns from within the app, which removes their contents. To have your account and remaining data removed entirely, email the address above and it will be done.

Children

This site is not directed at children under 13 and no account is created for anyone who has not been individually invited.

Changes

If this policy changes, the date at the top changes with it. Material changes will be mentioned to the people using the site.

Back to sign in

Add DM Toolkit to your Home Screen

Launch DM Toolkit from an icon and use it in its own app window. Your campaigns stay on the server, and the installed app still needs an internet connection.

  1. Open DM Toolkit in Safari, then tap the Share button.
  2. Scroll down and tap Add to Home Screen.
  3. Keep the name DM Toolkit, then tap Add.

Your browser is ready to install DM Toolkit in its own app window.

Open your browser menu and choose Install app or Add to Home Screen.

Installing does not download campaign records or make them available offline.