Legal
Privacy Policy
This policy describes what personal data Monsterbrew processes, for which purposes, and the rights you have over it.
Last updated: 2 September 2026
1. Data Controller
Monsterbrew is operated by an individual developer based in Belgium, who is the data controller within the meaning of Art. 4(7) GDPR and is referred to as "we" in this policy.
For all matters relating to this policy or to your personal data, contact [email protected].
2. Data Stored on Your Device
Creatures, statblocks, collections, and related content you create are stored locally in your browser using IndexedDB. Unless you sign in and sync a creature, this content is not transmitted to or stored on our servers. Clearing your browser storage permanently deletes it.
The application additionally stores functional settings in your browser, such as your theme choice and whether CR suggestions are enabled. These remain on your device and are not used to identify or track you.
Cloudflare, the network that sits in front of our hosting provider, sets one short-lived cookie, called __cf_bm, to distinguish visitors from automated bots. It contains no personal information and expires after about half an hour. Signing in sets a session cookie used solely for authentication. Both are strictly necessary for the operation of the site, which is why no cookie consent banner is required.
3. Account Data
An account is optional. If you create one, authentication is performed by Discord. We receive and store from your Discord profile: your display name, your email address, and your avatar, together with the technical tokens Discord issues to verify your identity. We never receive or store a password, and we read nothing else from your Discord account.
For each sign-in we create a session record containing your IP address and browser version. Session records exist to secure your account and expire automatically.
Legal bases: account data is processed for the performance of a contract (Art. 6(1)(b) GDPR); session records are processed on the basis of our legitimate interest in account security (Art. 6(1)(f) GDPR).
4. User Content on Our Servers
Creatures you choose to sync are stored in our database for the sole purpose of providing them back to you (Art. 6(1)(b) GDPR). They remain your data. We do not read, analyse, sell, or use them to train AI models.
Synced creatures are private by default. You may set a creature to unlisted, accessible to anyone with the link, or public, listed for all visitors, and you may revert that at any time. Where another user forks a public creature, the fork is a separate copy belonging to that user and is unaffected by later deletion of the original.
5. Analytics
We use Umami Analytics, a privacy-focused service, to measure use of the Service in aggregate, on the basis of our legitimate interest in understanding and improving the Service (Art. 6(1)(f) GDPR). Umami:
- Sets no cookies and stores nothing on your device.
- Does not track you across websites or build profiles.
- Uses your IP address transiently to derive an approximate country and a daily visitor count. The address itself is not stored, and the count cannot be linked back to you or joined up across days.
- Records aggregated data only: page views, referring sites, visitor counts, and which features are used. It never records what you typed: no creature names, no statblock text, nothing you have saved.
- Measures page load and response times, so that performance problems can be found and fixed. Those are measurements of the page, not of you.
6. Error Logging
We use Sentry to log errors occurring on the live site, on the basis of our legitimate interest in maintaining a working Service (Art. 6(1)(f) GDPR). When an error occurs, Sentry receives a technical report containing:
- The error itself: what went wrong and where in the code it happened.
- The page you were on when it happened.
- Your browser and operating system version.
These reports are not linked to you, including when you are signed in. IP addresses are not stored with reports, no cookies or persistent identifiers are used, and your creatures and other saved content are never transmitted. Error logging runs only on the live site, never in development or preview builds.
7. Recipients and Processors
We share personal data only with the processors needed to operate the Service: DigitalOcean for hosting and the database, with Cloudflare in front of it as DigitalOcean's content delivery network, and the providers of Umami Analytics and Sentry as described above. Each processes data only to the extent needed for its function, under a data processing agreement.
Discord provides sign-in as an independent service under its own privacy policy. We receive the profile data described in Section 3 from Discord, and Discord learns that you signed in to Monsterbrew. We do not sell, rent, or otherwise disclose your data to third parties.
8. International Transfers
The Service and its database are hosted by DigitalOcean on servers in the United States. Where personal data of EU residents is transferred there, the transfer takes place on the basis of DigitalOcean's certification under the EU-U.S. Data Privacy Framework, with the European Commission's Standard Contractual Clauses incorporated into DigitalOcean's data processing agreement as a fallback. Error reports are processed by Sentry in the United States on the same basis: Sentry holds an active certification under the EU-U.S. Data Privacy Framework. Umami Analytics anonymises visitor data at the point of capture, as described in Section 5, and retains no personal data.
9. Retention
Account data and synced creatures are retained until you delete them or your account. Session records are deleted when the session expires. We keep no copies for other purposes. Deleted data may persist in the hosting provider's automatic database backups for up to approximately seven days before being removed entirely.
10. Your Rights
Most of your data is stored in your own browser, where you control it directly. For the personal data we hold on our servers, your account data and synced creatures, you have the rights set out in Arts. 15 to 21 GDPR:
- Access and portability: you can export your creatures from the application at any time, in portable formats.
- Rectification: you can edit your creatures in the application.
- Erasure: you can delete your account from the account settings. Deletion takes effect immediately and removes your account, sessions, Discord link, and all synced creatures; share links to those creatures stop resolving. Forks made by other users are their own copies and are unaffected. Your local library remains in your browser.
- Restriction and objection: contact us at the address in Section 1.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in your EU member state of residence. The authority responsible for us is the Belgian Data Protection Authority.
11. No Advertising, Profiling, or Sale of Data
We do not process personal data beyond what is described in this policy. We do not use your data for advertising or marketing, do not sell or rent it, do not build profiles, and do not subject you to automated decision-making within the meaning of Art. 22 GDPR. We do not use your creatures or other content to train AI models.
12. Changes to This Policy
We may update this policy from time to time, for instance when the Service changes. The current version is always available on this page, together with its effective date.