Privacy Policy

Effective date: March 17, 2026

Tavern Bag ("Tavern Bag", "we", "us") is a browser extension that adds inventory management, timeline tracking, and compendium search tools to Roll20 tabletop sessions. This policy explains what data the extension collects, why, and how it is handled.

1. Data We Collect

DataPurposeStorage
Email addressAccount authentication (one-time code sign-in)Supabase Auth
Session tokensKeep you signed in between sessionschrome.storage.local (on your device)
Roll20 campaign IDScope compendium searches to your campaignchrome.storage.local
Character & inventory dataSync your items between Roll20 and Tavern BagSupabase database (your account only)
Subscription / billing statusDetermine which features are availableStripe (via tavernbag.com API)

2. Data We Do Not Collect

3. How Data Is Used

All collected data is used exclusively to provide Tavern Bag functionality:

4. Third-Party Services

These services receive only the minimum data required to perform their function.

5. Permissions Explained

PermissionWhy It Is Needed
storageStore your session tokens and preferences locally on your device.
host: app.roll20.netRun the extension UI and content scripts on Roll20 game pages.
host: files.d20.ioLoad item and character images hosted by Roll20.
host: tavernbag.comCommunicate with the Tavern Bag API for authentication, billing, and AI features.
host: vivvocgiabalwvlaziuf.supabase.coRead and write your inventory data in the Supabase database.

6. Data Retention & Deletion

Your data is retained only while your account is active. You may delete your account and all associated data at any time through our support page. Local extension data can be cleared by uninstalling the extension or clearing the extension's storage from your browser settings.

7. Security

All network communication uses HTTPS. Session tokens are stored locally in your browser's extension storage, which is sandboxed and not accessible to websites. Server-side data is stored in Supabase with row-level security policies that restrict access to authenticated account owners only.

8. Children's Privacy

Tavern Bag is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated through the extension or our website. Continued use of Tavern Bag after changes constitutes acceptance of the updated policy.

10. Contact

Questions about this policy? Visit our support page.


© 2026 Tavern Bag. All rights reserved.