Privacy Policy
Last updated September 9, 2026. This describes what Mystic Ledger stores today.
What we collect
- Account data: display name, email, hashed password, session tokens.
- Collection data: printings, quantities, finishes, conditions, purchase prices, storage notes, and decks.
- Billing data: Stripe customer and subscription identifiers. Card numbers stay with Stripe.
- Password-reset tokens, stored only as hashes, until they expire.
What we do not collect
We do not sell your inventory data. We do not run advertising pixels on the product pages. We do not store raw payment card numbers.
How data is used
We use your account to sign you in, calculate portfolio totals, process subscriptions, and send transactional email such as password resets. Shared catalog rows (card names, set codes, Scryfall prices) are not personal and are reused across accounts.
Cookies
A single HTTP-only session cookie named mystic_session keeps you signed in. It is not used for advertising. A language cookie remembers English or French.
Third parties
Stripe processes payments. Resend sends password-reset email when configured. Scryfall provides card data and hosts card images that the app displays. Hosting and database providers for a given deployment can also process the data needed to run the app.
Retention and deletion
We keep your account until you delete it in Settings or ask us to remove it. You can export your collection as CSV at any time. After deletion, billing history may remain in Stripe.
Contact
Privacy requests can be sent to the operator of this deployment using your account email.