← Back to homepage

Privacy Policy

Last updated: 20 June 2026

Controller

Moonvine Forge Studios
Derin Schmidt
Vogesenstr. 52
81827 Munich
Germany
Email: contact@moonvineforge.com

General Information

This privacy policy explains how personal data may be processed when you visit this website, contact Moonvine Forge, or submit an idea through the Community Card Forge.

Hosting with GitHub Pages

This static website is hosted through GitHub Pages. When the website is accessed, GitHub may process technically necessary connection and log data, such as IP address, request time, requested resource, browser information, and related security data, in order to deliver and protect the website.

The legal basis for our use of this hosting service is Article 6(1)(f) GDPR. Our legitimate interest is the secure, reliable, and economical provision of this website. Further information is available in the GitHub General Privacy Statement.

Contact by Email

If you contact us by email, we process the information you provide in order to answer your inquiry. Depending on the subject, the legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual communication, or Article 6(1)(f) GDPR for other inquiries. Our legitimate interest is responding to messages addressed to us. The information is deleted when it is no longer required for the inquiry, unless legal retention duties or the establishment, exercise, or defence of legal claims require longer storage.

Website Statistics with GoatCounter

This website uses GoatCounter to measure visits and display a public total visitor count. GoatCounter does not use cookies, local storage, or persistent tracking identifiers in visitors' browsers.

GoatCounter processes aggregated website statistics such as visited pages, referrers, browser and operating-system information, approximate location, language, and screen width. According to GoatCounter, IP addresses and full user-agent strings are not stored in its database and may be held temporarily in memory for up to eight hours to distinguish repeated visits during a session.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is understanding how the website is used and improving its content. GoatCounter.com is operated by Martin Tournoij in Ireland. Further information is available in the GoatCounter privacy policy.

Community Card Forge

Data submitted

When you submit an idea, the Forge processes a submission identifier, a public reference, client and server timestamps, the selected mechanic category, the mechanic description, and any optional fields you complete. Optional fields may include a mechanic name, subtype, cost, rarity, flavour text, upgrade text, detail blocks, and an alias for credit. The Forge also stores the selected public-credit setting, the structured submission payload, processing status, review reference, and technical review notes.

Only the mechanic category and description are required. An alias and consent to public credit are voluntary. No account or email address is required. Please do not enter contact details, confidential information, sensitive personal data, or personal information about another person in free-text fields.

Purposes and legal bases

Submission data is processed to receive voluntary community ideas, prevent duplicate submissions, validate the technical structure, identify potential engine requirements, moderate misuse, review mechanics, and use suitable ideas as design, testing, or architectural references.

The legal basis for receiving and internally reviewing submissions is Article 6(1)(f) GDPR. Our legitimate interests are operating the time-limited Community Card Forge, improving the engine and design process, evaluating submitted mechanics, and protecting the service against duplicate or abusive submissions. You may object to processing based on legitimate interests for reasons arising from your particular situation.

If you actively select the public-credit checkbox, the legal basis for publishing the entered alias is your consent under Article 6(1)(a) GDPR. The checkbox is optional and disabled by default. You may withdraw this consent at any time for future use by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.

Google Apps Script and Google Sheets

Submissions are sent to a Google Apps Script web application and stored in a private, non-public Google Sheet. We use these services through a standard Google account and do not claim that Google acts solely under a Google Workspace data-processing agreement for this setup.

Google may process technical connection data when the Apps Script endpoint is accessed and processes the submitted content to provide Apps Script and Sheets. Google states that it maintains servers around the world and that information may be processed outside the country in which a user lives. Details about Google's processing and international-transfer frameworks are available in the Google Privacy Policy and Google data-transfer information.

Automated technical intake review

A scheduled processor validates new submissions and creates a rough technical classification, including complexity and signals such as recursion, stored state, sequencing, or card-zone interaction. It then marks valid entries as awaiting manual review. This process does not automatically accept, reject, publish, or implement a submission and does not produce a decision with legal or similarly significant effects.

GitHub Actions triggers this processor and receives aggregate counts only, such as the number of processed, invalid, or remaining entries. Card text, aliases, and complete submission payloads are not returned to GitHub Actions.

No persistent browser draft storage

An unfinished Forge entry exists only in the currently open page. The current Forge does not save or read unfinished entries in local storage, cookies, or similar persistent browser storage. Reloading or closing the page discards the unfinished entry.

Retention

The Community Card Forge is a time-limited project with a planned duration of 24 months. Private raw submissions are retained for the duration of the project and for no more than three additional months for final review, export, anonymisation, and deletion. Data may be retained longer only where required by law or necessary for the establishment, exercise, or defence of legal claims.

Mechanics selected as design or technical references may be retained in anonymised form after the private raw submission is deleted. A publicly used alias may remain with published material until consent is withdrawn or the public use ends. The consent record may be retained as necessary to demonstrate the previous lawful publication.

Identifying an anonymous submission

After a successful submission, the Forge displays an MVF-... reference. Please keep this reference if you may later want to request access, correction, deletion, or withdrawal of public credit. Without a reference, alias, or other identifying information, we may be unable to reliably identify an anonymous submission and do not collect additional identity data solely for that purpose.

Recipients

Submission data may be accessed by the operator of Moonvine Forge and processed through Google Apps Script and Google Sheets as described above. GitHub provides the website hosting and receives aggregate processor counts through GitHub Actions, but the processor is designed not to send submission text, aliases, or complete payloads to GitHub Actions.

Your Rights

Subject to the statutory requirements, you may request access to personal data, rectification, erasure, restriction of processing, and data portability where applicable. You may object to processing based on Article 6(1)(f) GDPR and may withdraw consent to future public credit at any time.

Requests can be sent to contact@moonvineforge.com. You also have the right to lodge a complaint with a data-protection supervisory authority. For a private controller based in Bavaria, the competent authority is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Online complaint information

Changes to this Policy

This policy may be updated if the website, Forge workflow, service providers, or legal requirements change. The current version is published on this page.