Privacy Policy

Last updated: July 2025

1. Who We Are

TheBreakingDeck ("we", "us") is a Magic: The Gathering Commander deck optimisation tool. Questions? Contact us at founder@thebreakingdeck.com.

2. What Data We Collect

Category Examples Purpose
Account data Email address, username, subscription tier Authentication and billing
Deck & collection data Card names, deck lists, owned collection Core service (optimisation)
Behaviour analytics Page visits, form submissions, feature usage, time on page Product improvement (see §3)
Device fingerprint Browser/hardware hash generated by FingerprintJS Anonymous rate-limiting; linked to behaviour events
Session identifier Random UUID stored in sessionStorage Grouping events within a single browsing session

We do not store IP addresses in our analytics system. Your IP appears in standard web server logs (Render infrastructure) for security purposes and is not linked to your behaviour events.

3. Legal Basis for Analytics

We process behaviour analytics data under Legitimate Interest (GDPR Art. 6(1)(f)). Our legitimate interest is understanding how users interact with the product so we can fix bugs, prioritise features, and improve the overall experience. This processing is limited, privacy-preserving (no IP, no cross-site tracking), and we believe it does not outweigh your fundamental rights.

Account and billing data are processed under Contract performance (Art. 6(1)(b)) and Legal obligation (Art. 6(1)(c)) where applicable.

4. Data Retention

5. Your Rights (GDPR Art. 15–22)

You have the right to:

To exercise any of these rights, email founder@thebreakingdeck.com. We will respond within 30 days.

6. Device Fingerprinting Disclosure

We use FingerprintJS (open-source) to generate a pseudonymous device fingerprint in your browser. This hash is used only to enforce per-device generation limits for anonymous users and to link behaviour events to a consistent device identity without requiring a login. It is not shared with any third party and is permanently erased from our analytics records when you delete your account.

7. Third-Party Services

8. Cookies & Local Storage

We use localStorage to store your JWT authentication token and generation usage counts. We use sessionStorage for your session identifier. We do not use third-party advertising cookies.

9. Magic: The Gathering & Third-Party Disclaimers

Wizards of the Coast, Magic: The Gathering, and their logos are trademarks of Wizards of the Coast LLC in the United States and other countries. © 1993–2026 Wizards. All Rights Reserved.

TheBreakingDeck is not affiliated with, endorsed, sponsored, or specifically approved by Wizards of the Coast LLC. TheBreakingDeck may use the trademarks and other intellectual property of Wizards of the Coast LLC, which is permitted under Wizards' Fan Site Policy. MAGIC: THE GATHERING® is a trademark of Wizards of the Coast. For more information about Wizards of the Coast or any of Wizards' trademarks or other intellectual property, please visit their website at company.wizards.com.

Moxfield LLC is not affiliated with, endorsed, sponsored, or specifically approved by Wizards of the Coast LLC. Moxfield LLC may use the trademarks and other intellectual property of Wizards of the Coast LLC, which is permitted under Wizards' Fan Site Policy. MAGIC: THE GATHERING® is a trademark of Wizards of the Coast.

Some card prices and other card data are provided by Scryfall. Scryfall makes no guarantee about its price information and recommends you see stores for final prices and details.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to registered users. The "Last updated" date at the top of this page reflects the most recent revision.