DICEBLOOM
BACK
YOUR DATA

Privacy

Dicebloom and Party Scribe work without an account. Cloud backup, sharing, and anonymous product analytics are optional.
Effective 19 July 2026 · Web Beta
Information stored on your device
Roll profiles, recent roll history, Party Scribe campaigns, session notes, contributor names, campaign records, and data created in limited-development table tools are saved in your browser’s local storage so the tools remain usable without an account.
Optional accounts and synchronization
If you sign in, Supabase processes your email address, authentication session, roll profiles, Party Scribe campaigns, notes, records, Bastions, memberships, and invitations. Database access is restricted by account, membership, and role. Roll history remains browser-local.
Feedback and diagnostics
When you submit feedback, Cloudflare checks the request for abuse and Resend delivers it to dicebloom_admin@pm.me. The report includes the tool, task, feedback type, severity, your written description, device and browser, screen size, page path, platform, app version, and time. You may optionally attach a screenshot and give permission to be contacted; your email is requested only when that permission is enabled. Feedback is not added to product analytics and does not automatically include saved profiles, rolls, campaign notes, or Bastion records. Reports are retained in the support inbox only as long as needed for Beta triage and follow-up.
Optional anonymous analytics
Analytics are off until you allow them. If enabled, this browser receives a random installation ID that is not derived from your account or identity. The server converts it to a one-way HMAC digest and records only allowlisted task milestones, invitation activity, broad synchronization outcomes, app version, device class, and browser family. Dice expressions, results, profile or campaign names, notes, Bastion content, email, account IDs, IP addresses, feedback, tokens, and full URLs are not stored in the analytics dataset. Different devices are deliberately counted as separate anonymous installations, even when signed in to the same account.
Analytics retention and control
Identifier-linked analytics events are rolled into identifier-free daily totals after each completed UTC day and the raw events are deleted, normally within about 26 hours. Daily totals are retained for 400 days. Turning analytics off deletes the random ID and milestones from this browser and requests deletion of any unaggregated events for that ID. Aggregated totals cannot identify a browser and therefore cannot be selectively deleted. Cloudflare may still process standard request security logs under its own operational retention.
Essential reliability monitoring
Dicebloom records content-free operational signals when the website cannot render, a browser asset cannot load, synchronization fails, or feedback delivery is unavailable. These records contain only a fixed error category, affected tool, broad page category, device class, browser family, and app version. They do not contain error messages, full URLs or search parameters, IP addresses, account or installation identifiers, email addresses, tokens, profiles, roll expressions or results, campaign notes, or Bastion content. Operational events are retained for 30 days; identifier-free alert records are retained for 180 days. This limited monitoring is necessary to detect and repair service failures and is separate from optional product analytics.
Backups, retention, and deletion
The Account page can export a signed-in user’s browser-local and accessible synchronized data in a versioned JSON file. Tool-specific exports remain available. Deleting an account removes its active synchronized profiles, memberships, invitations, owned campaigns, and owned Bastions; owned shared workspaces are deleted for every member. Browser-local data is removed only when the user selects that option or clears site data. Provider backups may retain deleted database records until their normal protected-backup rotation completes, but deleted records are no longer available through Dicebloom.
Account and data requests
The Account page provides sign-in recovery, email-change requests, export, and deliberate self-service deletion. If access, export, or deletion fails, Support remains available while signed out and dicebloom_admin@pm.me can help after verifying the request.
Hosting and other services
Cloudflare and Supabase may process standard technical data such as IP addresses and request logs to deliver, authenticate, synchronize, and protect the service. Cloudflare Turnstile temporarily evaluates technical request information to prevent automated feedback abuse, and Resend processes submitted feedback to deliver it to the support inbox. Dicebloom does not currently use advertising trackers. Party Scribe does not send notes to a generative AI service.
Questions
During the Beta, send privacy questions to dicebloom_admin@pm.me.
Anonymous usage analytics
Off. Dicebloom is not sending product analytics from this browser.