← Back to CarmaClouds

Privacy Policy

Last updated: 15 June 2026

CarmaClouds is a free, open-source (MIT) hobby project that syncs your Dungeons & Dragons character data from DiceCloud to virtual tabletops (Roll20, Owlbear Rodeo, Foundry VTT and Coyotes & Candles). This policy explains what data it handles, why, and the choices you have. It is written to meet the EU General Data Protection Regulation (GDPR).

Who is responsible

The data controller is the individual maintainer of CarmaClouds (“Carmabella”). For any privacy question or to exercise your rights, contact caitlyn.c.nayeli@gmail.com or open an issue on GitHub.

This website

The carmaclouds website itself uses no cookies, no analytics, and no third-party tracking. The only thing it stores is a single flag in your browser’s local storage to remember that you dismissed the notice banner. Nothing about that leaves your device.

The browser extension

The extension only does anything when you log in to DiceCloud and choose to sync a character. When you do, it processes and stores the following so your characters can appear on your virtual tabletop:

  • Character data — the D&D characters you sync (names, stats, spells, inventory, and any notes you put on them). These are fictional, but free-text fields may contain whatever you type.
  • A DiceCloud session token — stored so the extension can fetch your characters on your behalf. It is kept encrypted at rest, is accessible only to your own account, and is never shown to other users.
  • Your DiceCloud username and user ID — to associate characters with you.
  • An account identifier — when you sync, the extension signs you in to our database provider. By default this is an anonymous account (no email needed). If you want your characters to appear in a separate app you’re signed into (e.g. the Owlbear Rodeo panel), you can create an optional account with an email and password so both sides share one identity.

The extension does not collect browsing history, and it only runs on DiceCloud, Roll20, Owlbear Rodeo and Coyotes & Candles pages (the sites it integrates with).

Legal basis

We process this data on the basis of your consent, which you give by logging in and choosing to sync a character. The sole purpose is to provide the sync feature you asked for. You can withdraw consent at any time by deleting your data and logging out (see Your rights).

Where your data goes

CarmaClouds relies on a small number of service providers (processors):

  • Supabase — database and authentication, hosting your synced characters and account. Data is stored in the European Union.
  • Vercel — hosts this website and the extension downloads.
  • DiceCloud — the source of your character data, which you already use directly.
  • The virtual tabletop you choose (Roll20, Owlbear Rodeo, Foundry VTT, Coyotes & Candles) — receives the character data you push to it.

Your data is never sold, and is never shared for advertising.

How it is protected

Each user’s data is isolated at the database level so only your own account can read or change your characters and token. Session tokens are encrypted at rest, and all traffic uses HTTPS.

How long it is kept

Synced characters are kept until you delete them or ask us to remove your data. Session tokens are short-lived and refreshed as you use the extension. If you stop using CarmaClouds and want everything removed, contact us (below).

Your rights

Under the GDPR you can:

  • access a copy of the data we hold about you;
  • correct or delete it;
  • withdraw consent and have your data erased;
  • object to or restrict processing;
  • lodge a complaint with your local data protection authority.

You can delete individual characters yourself from within the extension. To erase your account and everything associated with it, email caitlyn.c.nayeli@gmail.com and we will action it promptly.

Children

CarmaClouds is not directed at children under 16 and we do not knowingly collect their data.

Changes

If these practices change, we’ll update this page and the “last updated” date above. Material changes will be noted in the project’s release notes.