Privacy Policy

Last Updated: September 28, 2026

This policy describes what Upkeep collects, where it is stored, and who else can see it. In short: building decks requires an account, and creating one stores your email address on our hosting provider’s servers. Your decks are stored there too. Some other things — your card collection, playtest records and interface preferences — still live only in your browser.

1. Accounts and Authentication

Upkeep requires an account to build or save decks. Signing in is handled by Supabase, which acts as our authentication provider and database host. When you create an account, Supabase stores your email address, a unique account identifier, your account creation date, and the authentication credentials or provider tokens needed to sign you in. Upkeep can read your email address, account identifier, and creation date; these are shown to you on your account page.

You can browse cards and public decks without an account. Building or saving a deck needs one.

2. Data Stored on Our Servers

When you are signed in, the following may be stored in our database and associated with your account identifier:

  • Decks — deck name, format, commander, card list, colour identity, estimated value, and any deck primer you write or generate.
  • Deck versions — historical snapshots of a deck’s card list, so you can compare and restore earlier versions.
  • Shared decks — a copy of a deck’s contents created when you generate a share link.
  • Bracket declarations — the bracket and turn expectation you declare for a deck. If that deck is public, your declaration is readable by anyone, in the same way the rest of a public deck is.
  • Problem reports are stored when you use “Report a problem” on a deck page, whether or not you are signed in: the kind of problem you chose, the message you wrote, the address of that page, the time, and which version of the site received it. If you are signed in, the report is linked to your account. An email address is stored only if you type one, or, when signed in, tick the box allowing a reply. It is used only to reply about that report. Reports go to Upkeep, not to the deck’s owner.

When you send a problem report, Upkeep uses your IP address briefly to limit how many reports one connection can send. Upkeep holds it in memory only and does not store it with the report.

Decks are stored on our servers, against your account. This replaces an earlier arrangement in which a deck you built was kept in your browser and might never have reached us at all.

3. Data Stored in Your Browser

Upkeep uses your browser’s localStorage for the following. This data stays on your device: it is not sent to us, and we cannot read it. Clearing your browser data will permanently remove it.

  • Card collection — one entry for each printing you own, with its condition, language and finish, together with the purchase price you type in and any notes you write against it.
  • Playtest match records — the result, opponent, difficulty, game mode and turn count of each finished game. These are kept here and nowhere else: playtest games are not recorded on our servers.
  • Bracket declarations — the bracket and turn expectation you declare for a deck. This is the one item on this list that also leaves your device: when you are signed in, a copy is saved to our servers, and “Data Stored on Our Servers” above describes who can read that copy. Clearing your browser data does not withdraw it.
  • Interface preferences and housekeeping — your theme, how you last chose to view a deck and the deck gallery, which one-time notices you have dismissed, and small bookkeeping values such as when a deck was last snapshotted.

Decks are no longer among these: they are stored against your account, and clearing your browser data does not affect them.

4. Public and Shared Content

Marking a deck as public, or creating a share link, publishes that deck’s contents so that anyone can view them. Public decks appear on the Explore page and are readable without an account. Share links are readable by anyone who has the link. Public deck records currently include the account identifier of the deck’s owner, though not your email address. Share links cannot presently be revoked once created. Treat sharing a deck as permanent.

5. Third-Party Services

  • Supabase — hosts our database and handles authentication. Account and deck data described above is stored there.
  • Scryfall — supplies card data, images, and pricing. Card searches are sent to Scryfall’s servers. See Scryfall’s API documentation and privacy practices.
  • Groq — powers the AI deck primer and the AI rules judge. When you use those features, the relevant deck contents or your question are sent to Groq for processing. Do not enter personal information into AI prompts.
  • Cloudflare Turnstile checks that a problem report comes from a person rather than a script, as it already does when you sign in or sign up. Cloudflare states that Turnstile processes client-side signals such as your IP address, TLS fingerprint, browser user agent and the site key and origin, solely to detect and block bots, and that it does not access, store or transmit form entries or other page inputs. See Cloudflare’s Turnstile privacy addendum.
  • Resend delivers the email that tells Upkeep a problem report was received. The report’s contents, and any reply address you gave, pass through Resend’s servers in that email.
  • Namecheap and Gmail: mail sent to us arrives through Namecheap’s email forwarding into Gmail.
  • Vercel provides Upkeep’s page view analytics. “Analytics” below describes what a page view records and what Upkeep removes from it first.
  • News sources — the news page aggregates public RSS feeds from third-party Magic sites. No information about you is sent to them.

6. Cookies

When you sign in, Supabase sets authentication cookies so your session persists between visits. These are necessary for the account system to function. Upkeep does not use advertising cookies or third-party tracking cookies.

7. Analytics

Upkeep counts page views with Vercel Web Analytics, a service provided by Vercel. For each page view, Vercel may record the time, the address of the page, the site that linked you to it, your approximate location (country, region and city), and your browser, operating system and type of device.

Before a page view is sent, Upkeep removes the query string and anything after a “#” from the page’s address, which is where sign-in and password reset links carry their codes, and replaces the identifier in a share link’s address with a placeholder.

Vercel states that it identifies visitors by a hash of the incoming request rather than a third-party cookie, discards that visitor session after 24 hours, and does not tie page views to an individual or an IP address. Upkeep does not use advertising services, and does not sell or share your data with advertisers.

8. Retention and Deletion

Account and deck records are retained until the associated account is deleted. Deleting your account removes your decks, deck versions, share records, and bracket declarations, which are linked to your account and removed with it. There is currently no self-service account deletion button in the app. Deletion requests go to support@upkeepmagic.com (see the Contact page). Email us from the address on your account, and we’ll confirm with you before deleting anything. Data held only in your browser can be removed at any time by clearing your browser storage.

Problem reports are kept until deleted by hand. A report sent while signed in is deleted if that account is deleted. A report sent while signed out is not linked to any account and stays until it is deleted by hand.

9. Changes to This Policy

We may update this privacy policy from time to time. Changes will be reflected on this page with an updated “Last Updated” date. Material changes to what we collect or who we share it with will be described here rather than made silently.

28 September 2026. Deletion requests now go to support@upkeepmagic.com, as “Retention and Deletion” above describes, and “Third-Party Services” now names the services that mail passes through. Until this date, this page told you to ask through “our community channels”, without naming one.

17 September 2026. Deck pages have a “Report a problem” control. What a report stores, that Cloudflare Turnstile checks it and Resend delivers the notice of it, and how long reports are kept are described under “Data Stored on Our Servers”, “Third-Party Services” and “Retention and Deletion” above. Turnstile was already checking sign-in and sign-up; this page had not said so.

16 September 2026. Upkeep now counts page views with Vercel Web Analytics, replacing this page’s earlier statement that it used no third-party analytics. “Analytics” above describes what a page view records and what Upkeep removes from it first, and Vercel is now listed under “Third-Party Services”.

6 September 2026. Playtest match records are no longer copied to our servers. Until this date, finishing a game while signed in wrote the result to our database and recorded when that deck was last played. The table those records went to was empty, so nothing had to be deleted.

Corrected on the same date, with no change to what is collected: this page did not say that a bracket you declare for a deck is saved to our servers as well as to your browser, and it listed cached card prices among the things kept in your browser, which was never something we stored.