This policy explains what personal data Compendium collects when you use our iPhone app, our Android app, our web app at app.mtg-compendium.tech and this website. It covers why we collect it, who we share it with, what other Compendium users can see, how long we keep it, and the rights you have over it. We have tried to write it plainly. If anything is unclear, email us.
1. Who we are
Compendium is made by Backflip Media ("we", "us"). We are the controller of the personal data described in this policy.
- Who we are: Backflip Media, a sole trader business in the United Kingdom, is the data controller for Compendium.
- Contact: apps.backflip.media@gmail.com
Compendium is not affiliated with Wizards of the Coast.
2. The short version
- You can use most of Compendium without an account. Your decks, collection and game history are then kept on your device, though some features still send data to our servers (explained below).
- If you create an account, we store your email address and sign-in details. With Pro, we also store your decks, collection, wishlist and tags so they sync between devices.
- If you use pods or shared games, other players can see the email address on your account. See section 5.
- When you use the chat assistant or deck tools, your messages, any photos you attach and your deck contents are sent to OpenAI to produce a response, and are recorded with Langfuse, a monitoring service we use.
- Card scanning happens on your device. The camera images used for scanning are not uploaded.
- We do not sell your data and we do not show ads.
3. What we collect and why
For each type of data, we say what it is, why we use it, and the legal basis we rely on under UK data protection law (UK GDPR). "Contract" means we need the data to provide the service you have asked for. "Legitimate interests" means we use it for a reasonable business purpose that we have weighed against your privacy.
Device identifier
The app creates a random ID on your device (shown as "User ID" on your profile screen) and a secret used to prove requests come from that device. We use the ID to link your requests to your data on our servers even when you are not signed in. Basis: contract.
Your account
Accounts are optional. You can sign in with Apple, Google, or an email address and password. Sign-in is handled by Google's Firebase Authentication. On our servers we store your account email address, whether it has been verified, which sign-in methods you have used, your Pro status and expiry date, the date you agreed to our cloud sync terms, and when the account was created. We send verification and password reset emails for email and password accounts. Basis: contract.
Your profile
If you fill it in, we store your display name, preferred formats, budget preference and a signature commander (a card you choose to represent you, whose artwork we then use as your avatar). We also keep counts of which formats and budgets you choose in the deck builder, and when you last used the app. We use these to set defaults and suggestions, and to personalise the chat assistant's answers. Your display name and signature commander art are also shown to other players in some places (see section 5). Basis: contract.
Cloud sync (Pro)
With a Pro subscription and an account, your decks, card collection, wishlist, tags and tag assignments are stored on our servers so they sync across your devices. On the web app, a free account can back up decks created on the web. We ask for your agreement to our sync terms before we store anything. Nobody else can see your synced data unless you choose to share it (see section 5). Basis: contract.
Game logs and shared games
Game logs you record (the deck used, result, opponents, notes, life totals and similar details) are kept on your device. The iPhone app also uploads your game logs to our servers, linked to your device ID and your account if you have one, whether or not you have Pro. If you start a live game or share a game with other players, we store the game session: who took part, their display names, commanders, colour identities and any notes each player adds. We use game logs to show your statistics and to produce personalised insights. Basis: contract.
Pods, trade binders and invites
If you add someone to your pod, we store the connection between your two accounts and its status (pending, accepted or blocked). If you invite someone by email, we store that email address. If they do not have an account yet, we keep it so the invite can be linked when they sign up. Joining a table with a code or QR link can also create or accept a pod connection with the host, if the joiner leaves that option switched on (see section 5). If you publish a trade binder, we store the cards you have listed as haves and wants, with their set, condition, finish, quantity and estimated value. When a pod mate looks at your binder, we record that they viewed it and when. We work out possible trades between pod mates, show a weekly summary of pod activity (trade matches, games played together and a head-to-head record) and record which matches we have already notified them about. Basis: contract.
Chat assistant, deck evaluation and deck building
When you use the Mox chat assistant, deck evaluation, deck building or similar tools, we send the content needed to answer you to our servers. This includes your messages, any photos you attach, the cards and decks you are asking about, and relevant parts of your profile. We store your chat history on our servers so you can return to it. The chat assistant may also save short notes about your preferences from your conversations, called memories, so it can refer back to them later. You can delete chats and memories in the app. If you rate a response or leave a comment on it, we store that too. Basis: contract, and legitimate interests for improving the quality of responses.
On iPhone, voice input uses Apple's speech recognition to convert your speech to text. Depending on your device, Apple may process the audio on its servers. We only receive the resulting text.
Insights
We analyse your game logs to produce a personalised insights dashboard and occasional notifications about your play. We record how you interact with insights (for example, opening or dismissing one) to decide what to show next. Basis: legitimate interests.
Card scanning and camera
Card scanning uses text recognition on your device: Apple Vision on iPhone and Google ML Kit on Android. The camera images used for scanning are processed on your device and are not uploaded to us. This does not apply to photos you choose to attach to a chat message. Those are uploaded, as described above.
Push notifications
If you allow notifications, we store your device's push token (from Firebase Cloud Messaging), an installation ID, your app version, language setting and time zone, and which types of notification you have turned on or off. If you are signed in, we link these to your account. We use them to send the notifications you have chosen, such as card of the week, news, price alerts, pod invites, trade matches and game invites, at a sensible local time. Basis: consent (your device's notification permission), which you can withdraw in your device settings.
Price alerts
If you set a price alert, we store the card, the target price, and whether you are tracking the foil version, linked to your installation and your account if you have one. Basis: contract.
Public deck sharing and comments
If you share a deck, we store a copy of the deck list, its name, format and colours, and any author name you give it. Public shared decks can be found by anyone through search and trending lists. We store votes, favourites and comments on shared decks against a one-way hash of a device token rather than your name or email. Basis: contract.
Subscriptions and purchases
Payments are handled by Apple, Google or, on the web, RevenueCat. We never see your card details. RevenueCat manages subscription status for us. We give RevenueCat your device ID, or your account ID once you sign in, so it can tell us whether you have Pro. We store your Pro expiry date on your account. Basis: contract.
Cancellation survey
If you cancel Pro and answer our short survey, we store the reasons you chose and any comment you write, linked to your device ID and account. Basis: legitimate interests (improving the product).
Contact and feedback
If you use the contact form on this website, we store your name, email address and message. If you send feedback in the app (for example on a deck the builder created or on a chat response), we store your rating and comments along with some details of the deck or response. We forward contact messages and feedback to a private Slack workspace so we can respond to them. Basis: legitimate interests (answering you and improving the product).
Analytics
The apps and web app use Google's Firebase Analytics to record which screens and features are used, together with device and app information and a few properties such as your subscription tier and the size of your library. In the apps, this is linked to your device ID. The web app also uses Vercel Web Analytics for page views. This website uses Google Analytics, which sets cookies. We use analytics to understand how Compendium is used and to improve it. We do not use analytics for advertising. Basis: legitimate interests in the apps. On this website and in the web app, analytics only run if you accept them (see section 12).
Crash and error reports
The apps use Sentry to report crashes and errors. Reports include device and operating system details, app version, what the app was doing when the error occurred, your device ID, and your IP address. Basis: legitimate interests (keeping the app working).
Server logs and security
Like any online service, our servers log requests, including IP addresses, to keep the service running and secure, for example to enforce rate limits. Basis: legitimate interests.
Card images
Card images and some card data are loaded directly from Scryfall's servers, so Scryfall will see your IP address when your device requests an image.
Data kept only on your device
Your decks, collection, wishlist, game logs and settings are also stored locally on your device (and in your browser's local storage on the web app). Uninstalling the app or clearing your browser data removes these local copies.
4. Who we share data with
We use the following service providers to run Compendium. They process data on our behalf and only for the purposes described here. We do not sell your personal data and we do not share it for advertising.
- Amazon Web Services (Lightsail) hosts our servers and database, where the data described in this policy is stored.
- Google (Firebase) provides sign-in (Firebase Authentication and Google Sign-In), analytics (Firebase Analytics and Google Analytics), push notification delivery (Firebase Cloud Messaging) and remote app configuration.
- Apple provides Sign in with Apple, delivers push notifications to iPhones and provides speech recognition for voice input.
- OpenAI processes the text of chat messages, photos you attach to chat messages, deck contents and relevant profile preferences to generate responses, evaluations, deck suggestions and insight summaries. When an insight names one of your accepted pod mates (for example, a trade match or a game you played together), we send that pod mate's display name — never their email address — to OpenAI as part of generating the summary, and it is stored as part of that insight. A pod mate with no display name set is referred to only as "a pod mate".
- Langfuse records the requests we send to OpenAI and the responses we get back, including chat messages and attached photos, together with your device ID. We use it to monitor and improve response quality and to investigate problems.
- Sentry receives crash and error reports, as described above.
- RevenueCat manages subscriptions and receives your device or account ID and your purchase history from the app stores.
- Resend sends our emails (verification, password reset, pod invites and game notifications), so it receives the recipient's email address and the content of the email.
- Slack receives contact form messages and in-app feedback so we can read and respond to them.
- Vercel hosts the web app and provides Vercel Web Analytics.
- Scryfall serves card images directly to your device.
We may also disclose data if the law requires it, or to protect the rights and safety of our users or ourselves. If Compendium were sold or transferred, your data would go to the new owner under this policy.
5. What other Compendium users can see
Some features involve other people. Please read this section before using pods, shared games, invites or sharing links.
What identifies you to other players
Where you have set a display name, that is what other players see. We only fall back to your account email address when you have not set a display name. One exception: we never show or send anyone your email address if it is an Apple private-relay address (the anonymous address Sign in with Apple can generate for you) — that always falls straight through to a generic label instead. In particular:
- Pods: if you invite someone by their account (someone you have already played with) rather than by typing an email address, we hold back your email address from what they can see about the connection in the app until they accept your invite — until then they see your display name if you have set one, or a generic label if not. This does not apply to an invite you send to a typed email address, since the recipient already has that address. Once a pod invite is accepted, either side can see the other's display name, or account email address if no display name is set.
- Pod invites by email: the person you invite receives an email from us showing your display name, or your email address if you have not set a display name.
- Pod invite, live-game and shared-game notifications: the notification telling someone about your invite or game is sent the moment it happens, so — unlike the in-app pod list above — it cannot wait for an invite to be accepted first. It shows your display name, or your email address if you have not set one, or a generic label (such as "Someone" or "A pod mate") if neither is available.
If you do not want other players to ever see your email address, set a display name on your profile.
Pod mates
Once a pod invite is accepted, your pod mate can see your published trade binder (haves and wants, with set, condition, finish, quantity and estimated value) and the possible trades between you. They may get notifications when you have cards they want. They can also see a weekly summary of pod activity between you — trade matches, games you have played together in the last 7 days, and a head-to-head win/loss record from games you have both taken part in — and any personalised insight that names you (see "OpenAI" in section 4). You can remove or block a pod mate at any time, which stops this sharing going forward.
Players in shared games
Everyone in a live or shared game can see the other players' names (display name or email address, following the rule above), the commanders and colours they played, the result, and any notes each player chooses to share.
Joining a table with a code or QR link
Before a live game starts, the host can share a join code or QR link so people can take a seat without being pod mates first — this works even for someone you have never played with, a stranger who just has the code. Anyone who redeems it needs a Compendium account, and:
- before joining, they see only the host's display name (if the host has set one) and how many seats are open — no email address and no other players' names at this stage;
- once they join, everyone already at the table, including the host, sees the new player's name or email address (following the rule above), and the new player sees the same for everyone else already seated;
- if the joiner leaves the "add to pod" option on when they join, joining also creates or accepts a pod connection between them and the host, exactly as if they had sent or accepted a pod invite — so a stranger who joins your table can become a pod mate, with the visibility that brings (see "Pod mates" above), unless they switch that option off first;
- if the host removes that seat again before the game starts, we undo what the join did to the pod connection, as closely as the connection's own history allows.
Links you share
- Trade binders: anyone with your binder link can see its contents. You can revoke the link in the app.
- Shared decks: anyone with the link can see the deck, and public decks can be found by anyone through search and trending lists. Other users can vote on, favourite and comment on public decks. Comments are shown without a name.
Copies on other people's devices
When other players see your information, their app may keep a copy (for example your name or email in their pod list, or a shared game in their history). We cannot delete copies held on other people's devices, even if you delete your account.
6. How long we keep data
We keep your data for as long as you use Compendium, unless you delete it sooner:
- Chat history and game logs: kept until you delete them or your account.
- Server logs (which include IP addresses): kept for 14 days.
Analytics, crash reports and subscription records held by Google, Sentry and RevenueCat are kept according to those providers' retention settings: Firebase Analytics keeps event data for up to 14 months, Sentry keeps crash reports for 90 days, and Langfuse keeps request traces according to its standard retention.
7. Deleting your data
Deleting your account in the app
You can delete your account from the profile screen in the iPhone app, the Android app or the web app. When you do, we permanently delete:
- your account record (email address, sign-in methods, Pro status and sync consent);
- your synced decks, collection, wishlist, tags and tag assignments;
- your published trade binder and its contents;
- your pod connections, including invites you sent or received;
- your sign-in record with Firebase Authentication.
Account deletion does not yet remove everything. At the moment, the following are not deleted automatically when you delete your account:
- your profile (display name, preferences and usage counts), which is unlinked from the deleted account but stays linked to your device ID;
- game logs uploaded to our servers;
- live and shared game sessions, and your entries in them, which other players can still see;
- chat history and saved chat memories (you can delete these yourself in the app first);
- price alerts, and the push notification and preference records for your devices;
- decks you shared publicly, and votes, favourites and comments;
- records of trade binders you viewed and trade-match notifications;
- insights engagement records, cancellation survey answers, feedback, contact messages;
- data held by our service providers, such as analytics, crash reports, RevenueCat subscription records and Langfuse records.
We are working to extend account deletion to cover more of this data. Until then, you can ask us to delete any of it by emailing apps.backflip.media@gmail.com with the User ID shown on your profile screen. We will do this within 30 days.
Deleting your account does not cancel a subscription. Cancel it through the App Store, Google Play or the web billing page.
If you do not have an account
Data linked only to your device ID can be deleted on request. Email us with the User ID shown on your profile screen.
8. Your rights
Under UK data protection law you have the right to:
- Access the personal data we hold about you.
- Portability: get a copy of the data you gave us in a machine-readable format. Email us and we will send you an export of your account details, synced decks, collection, wishlist and tags.
- Correction of inaccurate data. You can edit your profile and synced data in the app.
- Deletion of your data (see section 7).
- Object to processing we carry out on the basis of legitimate interests, such as analytics.
- Restrict how we use your data in certain circumstances.
- Withdraw consent where we rely on it, for example by turning off notifications in your device settings.
To exercise any of these rights, email apps.backflip.media@gmail.com. Include the User ID from your profile screen and, if you have one, your account email so we can find your data. We will respond within one month.
9. International transfers
Our servers are hosted by Amazon Web Services in London, UK. Several of our service providers, including Google, OpenAI, Sentry, RevenueCat, Resend, Slack and Vercel, process data in the United States or elsewhere outside the UK. Where data is transferred outside the UK, we rely on the protections the providers offer, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or, where the provider is certified, the UK-US Data Bridge.
10. Children
Compendium is not directed at children under 13. If you are under 13, please don't create an account or use pods, invites or chat. The apps do not ask for your age. If you believe a child under 13 has given us personal data, contact us and we will delete it.
11. Security
We use encrypted connections (HTTPS) between the apps and our servers, require authentication for account data, and limit access to our systems. No system is perfectly secure, but we work to protect your data and will tell you about a breach where the law requires it.
12. Cookies and local storage
This website uses Google Analytics cookies to measure visits, and the web app uses Firebase Analytics, but only if you choose Accept analytics in the cookie banner. If you choose Reject, or make no choice, no analytics cookies are set. You can change your choice at any time with the Cookie settings link at the bottom of each page. The web app also uses your browser's local storage to keep your decks, collection and settings, and uses Firebase for sign-in; these are needed for the web app to work.
13. Changes to this policy
We will update this policy when Compendium changes. The date at the top shows when it was last updated. If we make a significant change to how we use data you have synced, we will ask you to review and agree to the updated terms in the app before syncing continues.
14. Contact us
For any question about this policy or your data, contact Backflip Media at apps.backflip.media@gmail.com.
