Card Arena — Privacy Policy

Status: DRAFT. Not reviewed by a lawyer.

This describes what the application actually does, established by auditing the code and schema — see PRIVACY_DATA_INVENTORY.md, which is the evidence base for every statement below. It is written to be accurate, not to be sufficient: a qualified reviewer must approve it before external distribution, and it must be published at a public URL before App Store submission.

That warning is deliberate. The previous state of this repository had no policy at all, on the stated grounds that writing legal copy nobody had reviewed was worse than a broken link. Writing an honest draft and labelling it a draft is better than both, but it is not a substitute for review.

Last updated: 2026-08-12 · Applies to: the Card Arena private beta


In short

Card Arena stores your account, the cards you add, and photographs of those cards, in a database we control. We do not sell your data. There is no advertising, no tracking SDK, no crash reporting, and no payment processing. Two outside services are involved: our database host, and Google, which serves the app's fonts and therefore sees your IP address. Your card photographs are private to you. Your collection is private unless you choose to make it public.


1. What we collect

Account. Your email address and a securely hashed password, handled by our authentication provider. We never see your password. Email addresses are not currently verified in the beta, so we cannot treat an address as proof of identity.

Profile. Your display name, username, when you joined, and your privacy preferences.

Your collection. For each card you add: which card it is, its condition, your own notes, quantity, whether you favourited it, and when it was added. A purchase-price field exists in the database but no screen in this build lets you enter one, so it is empty for beta accounts.

Card photographs. The front and back images you capture or choose when adding a card. Two honest limitations: this build stores them but does not yet show them back to you, and there is no way to delete an individual photograph — they are removed when your account is deleted.

Scanning. Scan sessions and the candidate matches the scanner considered, so a scan can be reviewed or resumed.

Verification. When you request a possession review: the request, its status, and the challenge code issued for it.

Gameplay. Matches you play: participants, the lineup you locked, each action, the result and the winner. For Practice, a frozen copy of the performance data the match resolved from.

Product analytics. A small set of events about how the card scanner is used — that a scan started, that a match was confirmed. They go to our own database, not to any third party, carry no free text, no IP address and no device identifier, and no client can read them back. The scanner is the only feature that records them. They are kept after account deletion with your identifier removed.

2. What we do not collect

We state these explicitly because their absence is a design decision, not an oversight:

One thing we do disclose rather than omit: the app loads its fonts from Google, so Google sees your IP address on launch. See §6.

3. Camera and photo library

We ask for camera access so you can photograph a card, and photo-library access so you can choose an existing photo instead. Access happens only when you take that action — the app has no background or continuous access to your library.

Card recognition runs on your device. Images are uploaded only when you confirm adding the card.

4. Who can see your information

5. Why we use it

To run your account; to store and show the collection you built; to identify cards you scan; to run matches; to review a possession request you make; to keep the service secure and diagnose problems; and to understand which features are used so the product can be improved.

6. Service providers

Supabase hosts our database, authentication and file storage. It processes the information above because it is the system of record.

Google Fonts serves the typefaces the app uses. Your device requests them from Google when the app loads, which means Google receives your IP address and basic request information, as it would for any website using its fonts. It receives nothing about your account, your collection or your cards. We intend to serve these fonts ourselves so this request stops happening.

No other service receives your data. We do not sell it and we do not share it for advertising.

7. Retention and deleting your account

You can request account deletion in Settings → Account → Delete account. Confirming it requires your password.

When you do: your account is locked immediately — it can no longer be used to write data — your privacy settings are forced to private, and any saved carts, saved listings and shipping addresses are deleted straight away. (The deletion routine covers those tables so nothing is missed later; in this beta the marketplace and checkout are switched off, so there is nothing in them to delete.) A deletion date is recorded, and remaining data is then removed.

Being accurate about the current limits: the automated final-erasure step is not yet running on a schedule, so complete removal of every record is not yet immediate or automatic. We are not going to claim otherwise. Some records are retained with your identifier removed rather than deleted: audit entries recording that a deletion was requested, the scanner analytics events above, and match history shared with another player — that history is re-pointed to an anonymous placeholder so your opponent keeps their own record.

If you need deletion completed, contact us using the details in §10 and we will action it.

8. Security

Data is transmitted over HTTPS and access is enforced per row in the database, so one account cannot read another's data. Card photographs are stored in a private bucket. Passwords are hashed by our authentication provider and are never visible to us.

No system is perfectly secure, and we do not claim otherwise.

9. Your choices

10. Contact

There is no published contact address yet, and we have not invented one to fill this space. While Card Arena is a closed private beta, reach us through whoever invited you to it — that is a real route to us, which a made-up address would not be. A published address is required before the app is distributed outside this beta.

11. Children

Card Arena is not directed at children. We have not yet set a minimum age or implemented an age check, and we are not making a compliance claim we cannot support. This is an open decision recorded in PRIVACY_DATA_INVENTORY.md §7 and must be resolved before public release.

12. Changes

If this policy changes we will update the date above and make the current version available in the app.


Before this can ship externally

Tracked so none of it is mistaken for done:

  1. Legal review. Nobody qualified has read this.
  2. A public URL. App Review requires the policy to be reachable outside the app.
  3. A real published contact address (§10).
  4. A minimum-age decision (§11).
  5. The account-deletion purge worker deployed and scheduled (§7) — an open P0, tracked separately in PRIVATE_BETA_COMPLETENESS_AUDIT.md.