Roll Scribe

Privacy Policy

Last updated August 12, 2026

Roll Scribe is a website for tracking D&D campaigns, characters, and dice roll stats, with a companion browser extension that reads rolls from your virtual tabletop and sends them to your Roll Scribe account. This page explains what data the site and extension collect and how it's used.

What the extension collects

The Roll Scribe browser extension only runs on Roll20 pages. It reads:

  • d20 roll results shown in the Roll20 chat log
  • the character name and roll label associated with each roll
  • the Roll20 campaign name (from the page title)

It does not read chat messages, whispers, character sheets, or anything else on the page beyond die-roll results.

Where that data goes

Roll data is sent directly from your browser to the Roll Scribe API (rollscribe.app) over HTTPS, authenticated with the personal API key you generate in Settings → API Keys. It is stored under your account and is not shared with, or sold to, any third party. The extension does not use analytics or advertising trackers.

What's stored locally

Your API key is stored in the extension's local browser storage (chrome.storage.local) so it can authenticate requests. It stays on your device and is only ever sent to the Roll Scribe API over HTTPS.

Website account data

When you create a Roll Scribe account, we store your email address, a hashed password, and the campaigns, characters, and rolls you or the extension add. This data is used solely to provide the service to you and is never sold or shared with third parties.

Your controls

You can revoke an API key at any time from Settings → API Keys, which immediately stops the extension from syncing new rolls. Removing the extension deletes the locally stored key. You can delete campaigns, characters, and rolls from within the app.

Contact

Questions about this policy or your data can be sent to [email protected].