Privacy Policy

Version
privacy-2026-05-03
Effective date
2026-05-03

About the Service

Deckonomicon (the “Service”) is a web platform that allows users to track trading card game decks, inventory, and matches.

Controller and contacts

The Service is operated by an individual based in Italy, who is the Data Controller. In this Privacy Policy, “we”, “us”, and “our” refer to the Data Controller. Privacy contact: privacy@deckonomicon.com.

Data we process

Account data: internal authentication user ID, username, display name or nickname, email address, email verification state, roles, login sessions, and authentication security events.

Application data: player profile, profile bio, profile image reference, decks, deck descriptions, card lists, collection items, storage locations, notes, purchase price fields, preferred printings, tags, style presets, playgroups, invitations, matches, games, and UI preferences.

Technical data: request IDs, route names, HTTP method, status code, duration, security/authentication outcomes, device or browser information where needed for security or analytics, and operational logs.

Uploaded images: user-uploaded profile, deck, or other application images, together with related metadata such as owner, storage reference, MIME type, dimensions, file size, checksum, alt text, and timestamps.

Why we process data

We process account and application data to create accounts, authenticate users, provide deck, inventory, playgroup, and match features, save preferences, prevent abuse, secure the Service, troubleshoot errors, and improve performance.

We process optional analytics data, where consent has been given, to understand how the Service is used, improve product functionality, and monitor performance.

Legal bases

Performance of a contract: we process account and application data that is necessary to authenticate users and provide the Service’s core functionalities, including player profiles, inventories, decks, playgroups, match and game records, and related card-management features.

Legitimate interests: we process limited technical and operational data where necessary to protect the Service, prevent abuse, investigate errors, debug reliability or security issues, and maintain user preferences.

Consent: we process optional analytics data for product improvement only when the user has given analytics consent.

Sharing and processors

We use third-party hosting providers for cloud infrastructure and PostHog as analytics provider. These providers are treated as processors. PostHog is used only for optional analytics when enabled and, for browser analytics, only after consent.

The Service’s authentication system is self-hosted by the operator on the deployment infrastructure. It handles account and login data and is not a separate processor for this deployment.

International transfers

We do not transfer personal data outside of the European Union for this deployment. Data is hosted on infrastructure located in the European Union provided by third-party hosting providers, and PostHog is configured to process personal data handled through the Service in the European Union.

Retention

We keep account and application data while the account is active. Users can delete their account from account settings. Account deletion removes the sign-in account and application data, including public decks, private decks, collection records, games, matches, duels, tags, printing preferences, and app preferences. If the user administers a playgroup with other members, administration is transferred to another member; playgroups with no other member are deleted.

Accounts that remain inactive for 1 year are deleted by an automated retention job. Inactive-account deletion uses the same deletion workflow as user-requested account deletion. We retain a minimal account deletion audit log for accountability and security purposes.

Operational logs are retained for at most 1 year. Analytics data is retained for at most 30 days.

Security

We use technical and organizational measures designed to protect personal data, including controlled account access, separation between authentication and application data, encrypted connections, restricted administrative access, careful handling of secrets, and monitoring for reliability and security events.

Security practices are reviewed over time and include access-control review, dependency maintenance, and retention limits for operational records.

Your rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy of your data, withdraw consent, and complain to a supervisory authority.

EU and Italian users can contact the privacy contact above. They may also contact their data protection authority, including the Italian Data Protection Authority (Garante per la protezione dei dati personali) where applicable.

Children

The Service is not intended for children under the age of 14.

We do not knowingly collect personal data from children under 14. If we become aware that such data has been collected, it will be deleted.

Changes

We may update this Privacy Policy from time to time to reflect changes in the Service, applicable law, or our data processing practices.

When we make changes, the updated version will be published on this page and the “Last updated” date will be revised accordingly.

If changes materially affect the way personal data is processed, we will provide additional notice, which may include notification via the Service or by email where appropriate.

Where required by applicable law, we will request the user’s consent for such changes.

Users are encouraged to review this Privacy Policy periodically.

Wizards of the Coast, Magic: The Gathering, and their logos are trademarks of Wizards of the Coast LLC in the United States and other countries. © 1993-2026 Wizards. All Rights Reserved.

Deckonomicon is not affiliated with, endorsed, sponsored, or specifically approved by Wizards of the Coast LLC. Deckonomicon may use the trademarks and other intellectual property of Wizards of the Coast LLC, which is permitted under Wizards' Fan Site Policy. MAGIC: THE GATHERING® is a trademark of Wizards of the Coast. For more information about Wizards of the Coast or any of Wizards' trademarks or other intellectual property, please visit their website at company.wizards.com .

Card data and prices are provided by Scryfall . Scryfall makes no guarantee about its price information and recommends you see stores for final prices and details.

MTG commander precon decks are provided by MTGJSON .

Deckonomicon · About · Help · Terms of Service · Privacy Policy · Cookie Policy · Version 0.0.48