Privacy Policy
Last updated: 2026-08-14
Effective date: 2026-08-14
manaruler ("manaruler," "we," "us," or "our") is a fan-made companion tool for Magic: The Gathering Arena players. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over it.
manaruler is an independent fan project and is not affiliated with, endorsed by, or sponsored by Wizards of the Coast. See our Disclosures page for details on our relationship to Wizards of the Coast's Fan Content Policy and any affiliate links.
This policy is issued by Daniel Dubielski, an individual operating manaruler, based in Poland. manaruler does not currently operate through a separate registered company; if that changes, this section will be updated accordingly. The jurisdiction of establishment for this policy is Poland.
1. Who this policy applies to
This policy applies to anyone who creates a manaruler account or otherwise uses manaruler's website (manaruler.com). It does not apply to manaruler's MCP (Model Context Protocol) server, which is a separate development-tooling component used only by approved developer/agent clients over a LAN-closed, client-certificate-authenticated connection — the MCP server never processes, stores, or has access to any account holder's personal data, collection data, or deck data (its database role is structurally excluded from those tables).
2. What data we collect
We collect only the data needed to operate the service. Specifically:
| Category | Examples | Why we collect it |
|---|---|---|
| Account identity | Email address; for social sign-in (Google/Discord), the provider's account identifier and any profile fields it shares with us (typically name and email) | Create and identify your account, let you sign in, send account-related communications (e.g., email confirmation, security notices) |
| Password credentials | A salted, hashed password (for local email/password accounts only) | Authenticate local-password sign-in. We never see or store your password in plain text — password hashing and verification is handled entirely by Supabase Auth, our authentication provider; manaruler's own servers never receive or process the raw password value beyond a single in-transit HTTPS request to Supabase Auth's own API |
| Network/request metadata | IP address, associated with login and registration attempts | Rate-limit tracking — to detect and slow down abusive or automated request patterns (e.g., credential-stuffing, registration spam) |
| Bot-verification signal | A Cloudflare Turnstile verification token and Cloudflare's pass/fail response to it | Confirm registration attempts are made by a human, not an automated script (shown on the registration form only, never on login) |
| Collection and deck data (optional) | Card collection entries you manually import, decks you build/import, deck validation and statistics results | The core product feature — track your collection and build/validate decks. This data is entirely optional; you can use manaruler without ever entering collection data, though most features depend on it |
| Consent records | Which version of this Privacy Policy and the Terms of Service you accepted, and when | Legal requirement to demonstrate you agreed to our terms before using gated features |
| Administrative/audit records | For actions taken by site administrators (e.g., role changes), a log entry recording the action and the administrator who performed it | Operational accountability and abuse investigation; this data is about administrator actions, not typically about your account, except where an admin action was taken involving your account |
We do not collect payment information at this time (manaruler has no billing feature as of this policy's drafting) and we do not collect health, biometric, or other special-category data.
Analytics: We may in the future use a web analytics tool to understand aggregate usage patterns (e.g., which pages are visited). No analytics provider is integrated as of this policy's drafting. If and when one is added, this policy will be updated to name the provider and describe what it collects before it goes live.
3. How we use your data
We use the data described above to:
- Create, authenticate, and maintain your account.
- Provide the core product: collection tracking, deck building/import/export, deterministic deck-legality validation, and plain-language rules search.
- Detect and mitigate abuse (rate limiting, bot verification).
- Communicate with you about your account (email confirmation, security-relevant notices).
- Comply with legal obligations (e.g., responding to a lawful data request).
We do not sell your personal data, and we do not use your data to serve third-party advertising — manaruler does not run a third-party ad network.
4. Legal basis for processing (GDPR, EEA/UK users)
Where GDPR applies, our legal bases are:
- Contract necessity (Art. 6(1)(b)): processing needed to create your account and provide the features you've asked for.
- Legitimate interests (Art. 6(1)(f)): abuse prevention (rate limiting, bot verification), service security.
- Consent (Art. 6(1)(a)): where we ask you to explicitly accept this Privacy Policy and the Terms of Service before accessing gated features (a hard consent gate — see Section 8).
5. Data retention
We retain your personal data for as long as your account exists. If you delete your account, we permanently remove:
- Your account information (email, identity linkage, display name).
- Your collection entries and decks.
- The personal-identity link on your consent records.
We anonymize, rather than delete, the bare fact that consent was given. Specifically, your consent records (which document version you accepted and when) are retained with the link to your specific account severed — this preserves evidence that someone accepted a given policy version at a given time (which we may need for our own legal defense), without retaining anything that identifies you once your account is gone. This matches how the deletion feature is actually implemented (see Section 7).
Some records about actions other people (e.g., an administrator) took are retained after your account is deleted, but with any reference to you specifically removed or nulled out, not tied to your identity.
6. Who we share data with
We share data only with the service providers necessary to operate manaruler, and only to the extent needed for their specific function:
| Provider | What they receive | Purpose |
|---|---|---|
| Supabase (Supabase Auth / GoTrue) | Email address, password (hashed by Supabase, never stored by us in plain text), OAuth tokens/identifiers when you sign in with Google or Discord | Authentication backend — handles sign-up, sign-in, session issuance, email confirmation, and (if you choose) linking a social sign-in method to your account |
| Resend (transactional email relay) | Your email address and the content of transactional emails sent on our behalf (registration confirmation, password reset, and similar account emails) | Delivers Supabase Auth's transactional email through our own domain (auth.manaruler.com) rather than Supabase's shared mailer; Resend does not have access to your password or any other account data |
| Google / Discord (only if you choose social sign-in) | Whatever standard OAuth profile fields those providers share when you authorize the connection (typically name, email, provider account ID) | Social sign-in, at your election — we never see your Google or Discord password |
| Cloudflare (Turnstile bot-verification service) | A verification token generated by your browser when you submit the registration form; your IP address (Turnstile is a client-side widget that communicates with Cloudflare directly, plus a server-side verification call from our backend) | Confirm registration attempts are made by a human |
| Analytics provider | Not yet integrated | Not yet integrated — this policy will be updated before any analytics provider is added |
We do not sell personal data to any third party, and we do not share your collection or deck data with any third party for their own marketing purposes.
manaruler is currently deployed on self-hosted infrastructure (Proxmox), not a public cloud provider, for its application database and web servers.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. manaruler supports these rights as follows:
- Access: You can view your account and collection/deck data directly in the product at any time while logged in.
- Correction: You can update your collection and deck data directly in the product.
- Export: A full personal-data export ("data portability") — a downloadable bundle covering your account, collection, deck, and consent-history data — is planned and will be built and shipped before this policy is published. This is distinct from the existing deck import/export feature, which covers deck data only.
- Deletion (right to erasure): You can delete your own account and personal data yourself, from your account settings page, without contacting support. This is a genuine self-service feature (not a support-ticket process) that permanently removes your account, collection entries, and decks, and severs the identity link on your consent records (see Section 5). Deletion cannot be undone.
- Objection/restriction: Contact us (Section 10) and we will address your request individually.
California residents: manaruler does not sell personal information and has not sold personal information in the preceding 12 months. You may still exercise CCPA rights to know, delete, and correct your personal information by contacting us.
8. Consent gate
Access to collection tracking and deck-building features requires you to affirmatively accept the current version of this Privacy Policy and our Terms of Service. This is enforced as a hard requirement, not a dismissible banner — you can always come back and accept later, but gated features remain unavailable until you do.
9. Cookies and session storage
manaruler uses a session cookie/token issued by Supabase Auth to keep you signed in between requests. We do not currently use third-party advertising or tracking cookies.
10. Children's privacy
manaruler is not directed at children and is not intended for use by anyone under the age of 13 (or the minimum age required by your local law, if higher). We do not knowingly collect personal data from children.
11. Security
We take reasonable technical and organizational measures to protect your data, including encrypted connections (HTTPS/TLS) and delegating password handling entirely to Supabase Auth rather than implementing our own credential storage. No system is perfectly secure, and we cannot guarantee absolute security.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will require you to re-accept the policy before continuing to use gated features (see Section 8), and we will update the "Last updated" date above.
13. Contact us
You can reach us at [email protected] with any questions about this policy or your rights under it.
The rest of the paperwork
The Terms of Service cover what you agree to by using manaruler. The Disclosures page covers our relationship to Wizards of the Coast and to any affiliate links.