Privacy Policy

Dans MTG is built with privacy as a core principle. This policy explains exactly what data we collect, why, and how it is protected.

What data we collect

Account information

When you create an account, we store your email address and a hashed password (via Amazon Cognito).

Payment information

If you subscribe to a paid plan or buy a credit pack, payment is processed by Stripe, our third-party payment provider. Your card details are entered directly on Stripe's secure, PCI-DSS-compliant checkout — they are never sent to or stored by Dans MTG. We store only a Stripe customer identifier, your current plan, and your credit balance, so we can apply your purchase and let you manage or cancel your subscription. Stripe's handling of your payment data is governed by their own privacy policy: stripe.com/privacy.

Card collection data

If you import a ManaBox CSV export or manually add cards, we store the card names, set codes, quantities, and conditions you provide. This data is associated with your account only and is not shared with other users.

Facebook post scan results

When you scan a card image, we store the identified card data (name, set, foil status, etc.) keyed to the Facebook post URL. We do not store the original image — it is sent directly to the AI for analysis and immediately discarded. The extracted card data may be shown to other Dans MTG users who view the same Facebook post URL, so they do not need to re-scan it.

Credit transaction logs

We maintain a log of credit debits and credits for your account for up to 90 days. This is used to display your balance history and to investigate any disputes.

Usage data

We record aggregate counts of how many AI scans each user triggers. This is used solely to power the credit system and to detect unusual usage patterns that may indicate abuse.

What data we do NOT collect

How your data is stored

All data is stored in Amazon Web Services (AWS) infrastructure in the Sydney (ap-southeast-2) region, using:

Payments are processed by Stripe, a separate provider that stores your card and billing details on its own PCI-DSS-compliant infrastructure (see Payment information above). Dans MTG never receives or stores your card number.

Card image processing

When you trigger a card scan, the image URL is sent to an AWS Lambda function which downloads the image and sends it to Amazon Bedrock (Claude AI) for analysis. The image bytes are used only for this single inference call and are never written to any storage service. The AI returns a JSON description of the card, which is what we store.

Cookies & consent

The DansMTG.com website uses only essential cookies required for the site to function. They do not track you. The site does not serve third-party advertising and sets no advertising or analytics cookies.

You can clear or block cookies through your browser settings at any time.

The Dans MTG browser extension itself does not use cookies. It stores your login session and settings locally in your browser's extension storage, which is never shared with third parties.

Your rights

You can request deletion of your account and all associated data at any time. Upon deletion we will remove your user record, collection data, and credit transaction history within 30 days. Records of completed payments held by Stripe may be retained by Stripe as required by law (for example, tax and accounting obligations) — these are governed by Stripe's privacy policy.

Children's privacy

Dans MTG is not directed at children under 13. We do not knowingly collect personal information from children under 13.

Changes to this policy

We may update this policy as the service evolves. Changes will be posted here with an updated date. Continued use after changes constitutes acceptance.

Contact

For privacy questions or data deletion requests, contact us through the Dans MTG website or the project's GitHub repository.