Privacy & security
What we do with your data.
The formal privacy policy is not published yet. This page says what the software actually does in the meantime, which is the part we can state accurately today.
No policy is published yet
A privacy policy is a commitment, and publishing one that has not been properly reviewed would be worse than publishing none โ it would say things about data handling, retention, and deletion that nobody had checked.
So this page does not pretend to be that document. What follows is a description of observable behaviour, not a legal undertaking, and it can change as the product does.
What the software does today
Your decks are private unless you say otherwise
A new deck is visible only to you. Sharing produces an unlisted link; publishing to Community requires a separate, deliberate action and is only possible for a deck that is legal in its format.
An unlisted deck is kept out of search engines. It is excluded from the sitemap, its page and its data both carry instructions not to index or archive it, and it is served with caching that keeps shared proxies from holding a copy. Only a deck published to Community is offered to search engines.
Sign-in uses a session cookie
The cookie is HttpOnly, so page scripts cannot read it, and SameSite=Lax, so another site cannot make your browser act as you. The API does not accept cross-origin browser requests.
Changing your password revokes everything
A password change โ including one made through a reset link โ signs out every existing session and revokes every assistant connection and API key on the account. A reset link expires and can only be used once.
Connected assistants get scoped, revocable access
An assistant receives only the permissions granted to it, and every connection is listed on Account & API keys with what it may do and when it last used it. Disconnecting takes effect immediately and does not depend on the assistant's cooperation.
An assistant cannot change a deck on its own. Deck changes are proposals until you approve them.
You can take your data with you
An account backup is a portable file you can create, validate, and restore elsewhere.
Card data comes from Scryfall
Card and printing information is synced from Scryfall. Card images are served from their source.
Questions this page does not answer
Retention and deletion timelines, what rights you grant over text you write in a deck primer, what happens to your public decks if you close your account, and how long server logs are kept. These need the formal policy, not a paragraph here.
If any of them matters to you before that document exists, ask and you will get a straight answer.