Last updated: 17 July 2026
Privacy Policy
Data controller
The data controller is Fabio Bechini. For any request about your personal data you can write to privacy@mtgdrain.com.
What data we process
Account data: name, username, email address and password (stored only in irreversible hashed form). Your username is visible to other users; your email is not.
Content you create while using the app: card collection, decks, recorded games, play statistics, chat messages (1:1 and guild) and wishlists.
Device push notification token (Firebase Cloud Messaging), used exclusively to deliver the notifications you enabled.
Technical diagnostics: when the application crashes, technical event data (with no intentional personal content) is sent to Sentry so we can fix bugs.
Payments: if you subscribe on the web, the payment is handled by Stripe. We never see or store your card details; we only receive the outcome and the subscription status.
Scanner photos: ONLY if you enable the optional "Help improve the scanner" setting (off by default), the photos of scanned cards and the confirmed card are shared to improve recognition. These samples are automatically deleted after 30 days.
Legal bases and purposes
Performance of the contract: account, collection, decks, games, chat and every feature you use exist only to provide the service you requested.
Legitimate interest: service security (anti-abuse limits, technical logs) and error diagnostics.
Consent: scanner samples (explicit opt-in, revocable at any time from the settings) and push notifications (can be turned on and off from your device).
Cookies
The website uses technical cookies only: the session cookie and the anti-CSRF token, both required for the site to work. No profiling cookies, no third-party analytics tools.
Providers (sub-processors)
DigitalOcean (hosting, EU datacenter) · Sentry (error diagnostics) · Google Firebase Cloud Messaging (push notifications) · Stripe (web payments) · Mailgun, EU region (transactional emails, e.g. address verification).
For providers based outside the EU, transfers are governed by the European Commission's Standard Contractual Clauses and the providers' own certifications.
Card data (names, images, prices) comes from public sources: Scryfall, MTGJSON and CardTrader. These sources never receive any of your personal data.
Retention
Account data and content are kept while the account is active. When the account is deleted they are removed or anonymised.
Scanner samples (if you enabled the setting) are automatically deleted after 30 days. Technical and error logs have a limited retention period.
Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection under articles 15–22 of the GDPR. You can exercise them by writing to privacy@mtgdrain.com; you also have the right to lodge a complaint with your data protection authority.
Changes to this policy
Any substantial change will be published on this page, updating the date at the top. Continued use of the service after publication counts as acknowledgement.