Privacy Policy
Effective July 30, 2026 · Arcane Ledger is made by TCGora
This policy explains what information the Arcane Ledger app collects, why, and what happens to it. The short version: we collect what the app needs to work, we don't run ads, and we never sell your personal information.
Information you give us
- Account. If you create an account, we store your email address and a securely hashed password (handled by our backend provider, Supabase) so you can sign in, recover your account, and restore your collection on a new device.
- Profile. An optional display name and an auto-generated friend code, used for the Playgroup features.
- Your collection. The cards you add (names, printings, conditions, quantities, prices paid). With an account, your collection syncs to our cloud so backup/restore and friend features (like shared-deck matching and trade suggestions) work.
- Messages. Direct messages you send to friends in Playgroup are stored so they can be delivered, and are visible only to you and the recipient. You can block users at any time.
- Community submissions. Decks you submit to the Community tab, with your display name, shown publicly after moderator approval.
Card scanning
Card recognition runs on your device by default. Camera frames are read locally and are not uploaded. A resized image of the card being scanned is sent to our image-recognition partner (Ximilar) in exactly two cases: when premium exact-printing matching refines a scan, and when you tap the photo-identification option on a card the on-device reader couldn't make out (available on every tier, with a daily limit). In both cases Ximilar processes the image solely to return a result and does not store it, and neither we nor Ximilar use your scans to train models. We don't keep the image either — it's deleted right after the scan.
Rue (AI advisor)
When you chat with Rue, your messages are processed by our AI provider (Anthropic) to generate the response, along with a summary of your collection and relevant card data to make answers useful. Don't put sensitive personal information in chat messages; it's a deck advisor, not a diary.
Collected automatically
- Push token. If you allow notifications, a device push token is stored so the app can deliver them (deck alerts, friend messages, community updates).
- Device identifier. A device ID is checked when starting a free trial, used only to prevent repeat-trial abuse.
- Card data requests. Card information and prices come from Scryfall's public API; those requests carry standard technical information (like any web request) but no account data.
- Usage events. The app records basic usage events (for example, that the app was opened or a deck was generated) with your app version and platform, so we can tell which features are working. These are tied to your account, never sold or used for advertising, deleted automatically after 180 days, and deleted immediately when you delete your account.
Purchases
Subscriptions are billed entirely by your app store (Google Play on Android, the App Store on iOS), so we never see or store your payment details. We use RevenueCat to confirm your subscription status and unlock premium features; it receives a purchase token and an app-specific user identifier to validate the subscription, never your payment information.
What we don't do
- No advertising, no ad trackers.
- No selling or renting your personal information. Ever.
- No collecting more than the features need.
Data retention & deletion
Your data is kept while your account is active. You can clear your collection in the app at any time (Settings → Account & Backup). Usage events are automatically deleted after 180 days regardless of account status.
Delete your account & data
In the app (instant): open Settings → Account & Backup → Delete Account and confirm. This permanently removes your account, your email identity, and all cloud data (collection backups, profile, messages). This works even on the free tier and takes effect immediately.
If you've uninstalled the app: email support@arcaneledger.app from the email address on the account and request deletion. We'll remove the account and all associated cloud data and confirm back to you. No account? Nothing is stored server-side beyond what's described above.
Delete specific data without deleting your account: you can remove cards, decks, wishlist entries, and messages yourself inside the app at any time. For anything else (for example, clearing your cloud backup or full message history), email support@arcaneledger.app from the account's email address and tell us what to remove. Your account stays intact.
Deletion removes account data (email, profile, cloud collection backups, friends/messages). Anonymized, non-identifying records (such as aggregate usage counts) may be retained.
Children
Arcane Ledger is intended for users 13 and older. We don't knowingly collect information from children under 13.
Service providers
We use Supabase (accounts, data storage, messaging), Google Play and the Apple App Store (billing), RevenueCat (subscription management), Expo with Google Firebase Cloud Messaging (app delivery and push notifications), Anthropic (AI responses), Ximilar (card-image identification), Resend (delivery of account emails such as password resets), and Scryfall (card data and images). Each receives only what its job requires.
Changes
If this policy changes meaningfully, we'll update this page and the effective date above.
Contact
Questions? support@arcaneledger.app