The Vault
Privacy notice
Last updated: [date]
Who is responsible
The Vault is run by [name / organisation, address] (the "controller"). Contact: [privacy e-mail].
What we store and why
| Data | Why |
|---|---|
| Your name and e-mail address, and an id from the sign-in provider you use (Google, Microsoft, Apple or Facebook), or a passkey | To create your account and let you sign in. |
| The collection you import: cards, quantities, condition, folders, and the price and date you bought them | To show and value your collection. |
| The buckets your copies are grouped in (one per folder of your file), and tags and notes on cards that you or an assistant you allowed wrote | To organise your collection and keep your own labels. |
| Your import history, saved decks and daily collection value | To show what changed and how your collection's value develops. |
| The cards of the last file you imported, as they were in that file (and, for a file imported into one bucket, as they were in that file) | So a later import applies only what changed in your app and keeps the edits you made in the Vault. |
| If you reset your collection (or one bucket), a copy of the copies it removed, so you can undo it (and of the tags, notes and import history, when you chose to clear them) | To let you undo a reset. It is kept for 7 days, and only the latest reset; then it is deleted. You can choose to keep none. |
| Where you buy: the country you choose in Account, "Where I buy", and up to three shops you type (a name, a web address and, if you paste one, a search address) | To order the shops in the "Where to buy" menu for your country and show your own shops first. This is all that is kept: not a town, postcode, address, position, your connection's address or your browser's language. The Vault never works out your country from your connection. Until you choose one, your browser's own language orders the menu on your device and nothing is sent or saved. The shops you type are shown as links and are never opened by the Vault. You can remove all of it in Account, it is in "Download my data", and it is deleted with your account. The menu's links open the shops' and Wizards' store locator's own sites in a new tab; the Vault does not contact them, and what you type there goes to them, not to us. |
| Who you have shared your collection or decks with | To give those people access. |
| Apps signed in to your account (e.g. "iPhone"), when they were last used, and scrambled (hashed) copies of their sign-in tokens, including replaced ones until they would have expired | To keep those apps signed in, let you sign them out, and sign an app out if a copied token is used. |
| When you ask the Vault to e-mail you a code to confirm it is you (before deleting your account, downloading your data, creating an access token, or adding or removing a sign-in method): the code and a link, sent to an e-mail address that your sign-in provider has confirmed and that has been on your account for a day, and on our side a scrambled (hashed) copy of the code, the browser it was asked from (such as "Chrome on Windows", never your IP address) and the time. Nothing is sent unless you, or anyone using your session, ask. | To check it is really you before a serious action. The code works once and for ten minutes; the record is deleted after two days. |
| Passkeys you add: a public key, a name such as "iPhone", and when it was added and last used. The private key stays on your device. | To let you sign in without a password. |
| Access tokens you create for your own agents or scripts (name, permissions, dates, and a hashed copy) | To let those agents use your vault on your behalf until you revoke them. |
| Apps you connect with OAuth, such as ChatGPT or Claude: the app's name and web address, what you allowed (read, and write if you chose it), when you connected it and last used it, and scrambled (hashed) copies of its tokens, including replaced ones until they would have expired. Short-lived one-time codes and the consent request while you connect (a minute, and ten minutes if you leave it unanswered). | To let that app use your vault on your behalf until you disconnect it (Account, Connected apps), and to disconnect it if a copied token is used. |
The legal basis is the contract with you: we process this data to provide the service you signed up for (GDPR Art. 6(1)(b)). We don't sell data, show ads or use advertising or cross-site trackers; the only visitor statistics are the anonymous, cookieless ones described under "Visitor statistics" below.
Who can see your data
Only you. If you create an invite link for your collection or a deck, the person who accepts it can view that collection or deck (read-only), and sees your display name. What you paid for cards stays hidden unless you choose to include it. You can revoke access at any time from your account page.
Service providers
- Vercel hosts the app. Its request logs include IP addresses for a short period. It also runs Web Analytics and Speed Insights on our public pages and the app: see "Visitor statistics" below.
- Neon hosts the database.
- GitHub runs the daily job that updates card prices. It reads your collection's rows (card names, sets, numbers, quantities and prices) to match them with Scryfall's price list, but not your name or e-mail address.
- Your sign-in provider (Google, Microsoft, Apple or Facebook) confirms who you are.
- Resend (a US e-mail delivery service) delivers the one-time code and link we e-mail you when you ask for one to confirm it is you. It receives your e-mail address and the message. It keeps its own delivery records under its own terms and privacy policy (resend.com/legal/privacy-policy); the Vault stores nothing of this at Resend. It is used only if the Vault has it switched on, and only when you ask for a code.
- Scryfall: your browser loads card images and set icons from Scryfall's image servers, which see your IP address. Card data and prices are fetched by the Vault's server, which sends Scryfall only card identifiers, never who you are.
- Commander Spellbook: when you ask which combos a deck contains, the Vault's server sends that deck's card names to Commander Spellbook's service and shows you the answer. It sends nothing about you (no name, e-mail or account) and the Vault keeps no copy of their data.
- Archidekt: when you give a link to a public Archidekt deck, the Vault's server fetches that public deck by its number. It sends nothing about you.
- Your AI assistant, if you connect one (for example Claude or ChatGPT): it receives what you ask the Vault for, under the permissions (read, or read and write) you granted when you connected it, and under its own provider's terms. You can disconnect it at any time in Account.
Some providers are in the United States. Transfers are covered by their data processing agreements (EU Standard Contractual Clauses / EU-US Data Privacy Framework). [confirm]
How long we keep it
Until you delete your account. Deleted data disappears from database backups within [7] days.
Your rights
- See and take your data: Account → Download my data gives you everything as a ZIP file (CSV and JSON).
- Correct it: change your display name in Account, or re-import your collection.
- Delete it: Account → Delete my account removes your account and all of its data, and first offers you the download.
- Object or restrict processing: e-mail [privacy e-mail].
- You can complain to your data protection authority.
Visitor statistics
To see how many people use the Vault and how fast it loads, the pages and the app load Vercel's Web Analytics and Speed Insights. Both are anonymous and cookieless: a visit is counted by a hash made from the request that is thrown away after 24 hours, never by a cookie, and the Vault cannot tie a data point to you, to your account or to your IP address. Each data point holds the page's address (without anything after the page name: no query, no hash, so an invitation link or a sign-in return is never recorded; for Speed Insights the only addition is the name of the view you are on, when it is one of the app's own: dashboard, browse, sets, decks, lab, ideas, valuation or help, never a set code, a deck number or anything you typed), the time, the referring site, your country, your browser, device type and operating system, and for Speed Insights the page's loading times and network speed. Nothing from your collection or decks is included. If your browser sends Do Not Track or Global Privacy Control, nothing is sent at all. The sign-in and consent pages never load these scripts. Vercel's own descriptions: Web Analytics, Speed Insights.
Cookies and local storage
The app keeps a copy of what the Vault's server sent about your collection in this browser (IndexedDB) so it opens quickly and works offline. It is deleted when you sign out or delete your account. Prices and values are computed on the server; the browser stores nothing else about them.
Two strictly necessary cookies: one keeps you signed in, and the other holds an opaque code for the signed-in account, so this browser's copy of a collection is only ever shown to that account. Both are removed when you sign out. Your browser also stores your display preferences. There are no tracking cookies, and the visitor statistics above use none.
Children
The Vault is not intended for children under 16.