Privacy Policy

Last updated: 2026-08-14
Effective date: 2026-08-14

manaruler ("manaruler," "we," "us," or "our") is a fan-made companion tool for Magic: The Gathering Arena players. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over it.

manaruler is an independent fan project and is not affiliated with, endorsed by, or sponsored by Wizards of the Coast. See our Disclosures page for details on our relationship to Wizards of the Coast's Fan Content Policy and any affiliate links.

This policy is issued by Daniel Dubielski, an individual operating manaruler, based in Poland. manaruler does not currently operate through a separate registered company; if that changes, this section will be updated accordingly. The jurisdiction of establishment for this policy is Poland.

1. Who this policy applies to

This policy applies to anyone who creates a manaruler account or otherwise uses manaruler's website (manaruler.com). It does not apply to manaruler's MCP (Model Context Protocol) server, which is a separate development-tooling component used only by approved developer/agent clients over a LAN-closed, client-certificate-authenticated connection — the MCP server never processes, stores, or has access to any account holder's personal data, collection data, or deck data (its database role is structurally excluded from those tables).

2. What data we collect

We collect only the data needed to operate the service. Specifically:

Category Examples Why we collect it
Account identity Email address; for social sign-in (Google/Discord), the provider's account identifier and any profile fields it shares with us (typically name and email) Create and identify your account, let you sign in, send account-related communications (e.g., email confirmation, security notices)
Password credentials A salted, hashed password (for local email/password accounts only) Authenticate local-password sign-in. We never see or store your password in plain text — password hashing and verification is handled entirely by Supabase Auth, our authentication provider; manaruler's own servers never receive or process the raw password value beyond a single in-transit HTTPS request to Supabase Auth's own API
Network/request metadata IP address, associated with login and registration attempts Rate-limit tracking — to detect and slow down abusive or automated request patterns (e.g., credential-stuffing, registration spam)
Bot-verification signal A Cloudflare Turnstile verification token and Cloudflare's pass/fail response to it Confirm registration attempts are made by a human, not an automated script (shown on the registration form only, never on login)
Collection and deck data (optional) Card collection entries you manually import, decks you build/import, deck validation and statistics results The core product feature — track your collection and build/validate decks. This data is entirely optional; you can use manaruler without ever entering collection data, though most features depend on it
Consent records Which version of this Privacy Policy and the Terms of Service you accepted, and when Legal requirement to demonstrate you agreed to our terms before using gated features
Administrative/audit records For actions taken by site administrators (e.g., role changes), a log entry recording the action and the administrator who performed it Operational accountability and abuse investigation; this data is about administrator actions, not typically about your account, except where an admin action was taken involving your account

We do not collect payment information at this time (manaruler has no billing feature as of this policy's drafting) and we do not collect health, biometric, or other special-category data.

Analytics: We may in the future use a web analytics tool to understand aggregate usage patterns (e.g., which pages are visited). No analytics provider is integrated as of this policy's drafting. If and when one is added, this policy will be updated to name the provider and describe what it collects before it goes live.

3. How we use your data

We use the data described above to:

  • Create, authenticate, and maintain your account.
  • Provide the core product: collection tracking, deck building/import/export, deterministic deck-legality validation, and plain-language rules search.
  • Detect and mitigate abuse (rate limiting, bot verification).
  • Communicate with you about your account (email confirmation, security-relevant notices).
  • Comply with legal obligations (e.g., responding to a lawful data request).

We do not sell your personal data, and we do not use your data to serve third-party advertising — manaruler does not run a third-party ad network.

Where GDPR applies, our legal bases are:

  • Contract necessity (Art. 6(1)(b)): processing needed to create your account and provide the features you've asked for.
  • Legitimate interests (Art. 6(1)(f)): abuse prevention (rate limiting, bot verification), service security.
  • Consent (Art. 6(1)(a)): where we ask you to explicitly accept this Privacy Policy and the Terms of Service before accessing gated features (a hard consent gate — see Section 8).

5. Data retention

We retain your personal data for as long as your account exists. If you delete your account, we permanently remove:

  • Your account information (email, identity linkage, display name).
  • Your collection entries and decks.
  • The personal-identity link on your consent records.

We anonymize, rather than delete, the bare fact that consent was given. Specifically, your consent records (which document version you accepted and when) are retained with the link to your specific account severed — this preserves evidence that someone accepted a given policy version at a given time (which we may need for our own legal defense), without retaining anything that identifies you once your account is gone. This matches how the deletion feature is actually implemented (see Section 7).

Some records about actions other people (e.g., an administrator) took are retained after your account is deleted, but with any reference to you specifically removed or nulled out, not tied to your identity.

6. Who we share data with

We share data only with the service providers necessary to operate manaruler, and only to the extent needed for their specific function:

Provider What they receive Purpose
Supabase (Supabase Auth / GoTrue) Email address, password (hashed by Supabase, never stored by us in plain text), OAuth tokens/identifiers when you sign in with Google or Discord Authentication backend — handles sign-up, sign-in, session issuance, email confirmation, and (if you choose) linking a social sign-in method to your account
Resend (transactional email relay) Your email address and the content of transactional emails sent on our behalf (registration confirmation, password reset, and similar account emails) Delivers Supabase Auth's transactional email through our own domain (auth.manaruler.com) rather than Supabase's shared mailer; Resend does not have access to your password or any other account data
Google / Discord (only if you choose social sign-in) Whatever standard OAuth profile fields those providers share when you authorize the connection (typically name, email, provider account ID) Social sign-in, at your election — we never see your Google or Discord password
Cloudflare (Turnstile bot-verification service) A verification token generated by your browser when you submit the registration form; your IP address (Turnstile is a client-side widget that communicates with Cloudflare directly, plus a server-side verification call from our backend) Confirm registration attempts are made by a human
Analytics provider Not yet integrated Not yet integrated — this policy will be updated before any analytics provider is added

We do not sell personal data to any third party, and we do not share your collection or deck data with any third party for their own marketing purposes.

manaruler is currently deployed on self-hosted infrastructure (Proxmox), not a public cloud provider, for its application database and web servers.

7. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. manaruler supports these rights as follows:

  • Access: You can view your account and collection/deck data directly in the product at any time while logged in.
  • Correction: You can update your collection and deck data directly in the product.
  • Export: A full personal-data export ("data portability") — a downloadable bundle covering your account, collection, deck, and consent-history data — is planned and will be built and shipped before this policy is published. This is distinct from the existing deck import/export feature, which covers deck data only.
  • Deletion (right to erasure): You can delete your own account and personal data yourself, from your account settings page, without contacting support. This is a genuine self-service feature (not a support-ticket process) that permanently removes your account, collection entries, and decks, and severs the identity link on your consent records (see Section 5). Deletion cannot be undone.
  • Objection/restriction: Contact us (Section 10) and we will address your request individually.

California residents: manaruler does not sell personal information and has not sold personal information in the preceding 12 months. You may still exercise CCPA rights to know, delete, and correct your personal information by contacting us.

Access to collection tracking and deck-building features requires you to affirmatively accept the current version of this Privacy Policy and our Terms of Service. This is enforced as a hard requirement, not a dismissible banner — you can always come back and accept later, but gated features remain unavailable until you do.

9. Cookies and session storage

manaruler uses a session cookie/token issued by Supabase Auth to keep you signed in between requests. We do not currently use third-party advertising or tracking cookies.

10. Children's privacy

manaruler is not directed at children and is not intended for use by anyone under the age of 13 (or the minimum age required by your local law, if higher). We do not knowingly collect personal data from children.

11. Security

We take reasonable technical and organizational measures to protect your data, including encrypted connections (HTTPS/TLS) and delegating password handling entirely to Supabase Auth rather than implementing our own credential storage. No system is perfectly secure, and we cannot guarantee absolute security.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will require you to re-accept the policy before continuing to use gated features (see Section 8), and we will update the "Last updated" date above.

13. Contact us

You can reach us at [email protected] with any questions about this policy or your rights under it.

The Terms of Service cover what you agree to by using manaruler. The Disclosures page covers our relationship to Wizards of the Coast and to any affiliate links.

Terms of Service Disclosures