What this notice covers

This notice explains how DeckFoundry handles information when you use the DeckFoundry website and application. DeckFoundry is a general-audience, unofficial fan-made deck-building tool.

Information DeckFoundry handles

Google sign-in

When you sign in with Google, Google and Streamlit provide identity claims needed to authenticate your session. Those claims can include the identity-provider issuer, a Google account identifier, your display name, and your email address. DeckFoundry derives an opaque account key from the verified issuer and account identifier, and uses your display name only to show your signed-in status during the session. DeckFoundry does not use your email address as an account key and does not store your Google email address or profile name in its application database.

Collections and saved decks

If you sign in, DeckFoundry stores the card quantities you add to your collection and the decks you choose to save. A saved deck can include its name, cards, substitutions, selected settings, score summary, generator version, deck hash, warnings, messages, and creation or update time.

Collection imports

Uploaded CSV files are processed in memory to update your collection. DeckFoundry does not intentionally retain the uploaded file after processing. The collection records created from that file remain until you change or delete them.

Feedback

If you submit in-app deck feedback, DeckFoundry sends the report you review through Resend to a project-controlled inbox. Reports can include deck contents, generation settings, ratings, test status, and your comments. They do not intentionally include your Google profile, email address, collection, or account key. A one-way idempotency value derived from the report and opaque account key is sent to Resend to prevent duplicate delivery; it is not the account key itself. Please do not place personal information in free-text comments.

Technical information

DeckFoundry and its service providers may process ordinary technical information needed to deliver and protect the service, such as IP address, browser information, request timing, cookies, security events, and error logs. DeckFoundry also records aggregate operational counts, such as sessions, deck generations, feedback attempts, account creation, collection updates, and saved-deck creation, to monitor capacity and abuse. Routine operational reports do not include Google profile data, account keys, collection contents, saved-deck contents, or feedback text.

The static DeckFoundry website uses Google Analytics to measure page views and navigation. Google Analytics can process the page URL and title, referring page, approximate location, device and browser information, and a random or pseudonymous client identifier stored in a first-party cookie. Google states that Analytics uses IP addresses during collection but does not log or store them. DeckFoundry does not send Google sign-in identity, collection contents, saved decks, or feedback text to Google Analytics and does not configure a DeckFoundry account identifier as the Analytics User-ID.

DeckFoundry uses technical, operational, and website analytics information to operate and improve the service, not to build advertising profiles.

How information is used

  • Authenticate users and maintain signed-in sessions.
  • Provide collections, saved decks, exports, and other requested features.
  • Deliver and evaluate deck feedback.
  • Protect the service, enforce rate limits, diagnose failures, and measure aggregate usage.
  • Measure visits to the public website and understand which pages and tool links are used.
  • Improve DeckFoundry's deterministic scoring and deck-generation systems using reviewed, de-identified evidence.

DeckFoundry does not sell personal information or share it for cross-context behavioral advertising. Marketplace, affiliate, or voluntary-support relationships never influence card scores, recommendations, or deck generation. DeckFoundry does not use personal information to make decisions that produce legal or similarly significant effects.

Service providers and disclosures

DeckFoundry currently relies on Google for OpenID Connect sign-in and Google Analytics for website measurement, Streamlit Community Cloud for application hosting and session delivery, Neon for PostgreSQL storage, and Resend for feedback and operational email delivery. The voluntary-support button loads through cdnjs and links to Buy Me a Coffee. Card images can load from third-party image hosts. Those browser-loaded services can receive ordinary request information such as your IP address, browser details, and referring page.

These providers handle information under their own terms and privacy practices. DeckFoundry may also disclose information when required by law, to protect the service or its users, or as part of a service transfer with notice and appropriate safeguards.

Cookies and sessions

Streamlit uses an identity cookie to maintain your DeckFoundry session. If you close the application without logging out, that cookie can remain for up to 30 days. Logging out removes the DeckFoundry identity cookie for that session, but it does not sign you out of Google or necessarily end other DeckFoundry tabs that are already open.

The landing site stores your light or dark display preference in your browser. Google Analytics may also set first-party Analytics cookies containing a random or pseudonymous client identifier. You can block or delete these cookies through your browser or use the Google Analytics opt-out browser add-on. Blocking Analytics does not prevent use of DeckFoundry's core features.

Retention, export, and deletion

Your collection, saved decks, and opaque account record remain in the live application database until you change or delete them, or until the service is discontinued. You can export your collection from Data & Privacy and export saved decks individually. You can correct collection quantities and saved-deck names through the application.

When you use the in-app deletion control, DeckFoundry removes your collection, saved decks, and opaque account record from the live database. Recoverable copies may remain in protected backups for no more than 30 days before aging out.

Raw deck-feedback email in DeckFoundry's project inbox is permanently deleted at the 30-day boundary. DeckFoundry limits its accessible Resend delivery history to 30 days and does not intentionally export raw provider records for longer retention. Resend may retain security, delivery, or backup records under its own policies; DeckFoundry has requested written confirmation of the provider's deletion schedule.

DeckFoundry may retain the deck list, settings, ratings, and comments longer only after removing account identifiers and incidental personal information so the review can support auditable scoring and generator improvements.

Google Analytics retains website measurement data according to the Analytics property's configured retention controls and Google's policies. Aggregate reports may not be affected by user-level retention settings. For more information, review Google's Privacy Policy.

Age eligibility

DeckFoundry is not directed to children under 13. You must be at least 13 to create an account, save data, or submit feedback. If you are under 13, do not sign in, upload a collection, submit feedback, or contact DeckFoundry. If we learn that we retained information from a child under 13, we will delete it.

Security and international use

DeckFoundry uses reasonable technical and organizational safeguards, but no internet service can guarantee absolute security. Information may be processed in the United States and other locations where DeckFoundry's service providers operate.

Your choices and contact

You can export, correct, or delete your application data through DeckFoundry. You can log out of DeckFoundry and remove DeckFoundry's connection from your Google Account settings. Depending on where you live, you may also have rights to request access, correction, deletion, portability, restriction, or an appeal concerning personal information. DeckFoundry does not discriminate against users for exercising applicable privacy rights.

For a privacy request, deletion help, or a security concern, contact contact@deckfoundry.ink. We may need enough information to understand and verify a request, but do not send passwords, authentication tokens, collection exports, or unnecessary personal information.

Changes to this notice

DeckFoundry will update this notice before materially changing how it collects, uses, stores, or shares information. The date at the top will change when the notice is revised.