1. Scope
This policy explains how Riftarc handles personal data in the Riftarc mobile applications and website at riftarc.gg. Public content pages can be used without an account and may display advertising. The iOS app, Android app, and signed-in web workspace remain ad-free. Signed-in features use essential authentication and security cookies; advertising cookies remain disabled unless valid consent or another applicable legal basis has been established.
2. Data Riftarc may process
- Account data: email address, display name, authentication provider and account ID. Secure, single-use confirmation or recovery credentials may be processed briefly by the website when you follow an account email.
- Waitlist data: the email address you choose to submit and its Riftarc waitlist membership. The form requires your express agreement before subscribing you to waitlist messages and future product updates.
- App data: collections, binders, decks, watches, follows and preferences.
- Device data needed for notifications, compatibility, security and diagnostics, including browser push-subscription details when you explicitly enable web notifications.
- Purchase references supplied by Apple, Google and RevenueCat, without full card numbers. Purchases are available in the iOS and Android apps.
- Patreon connection data: Patreon user and member identifiers, campaign and eligible tier identifiers, current patron and charge status, and the time status was last checked. Riftarc does not request a Patreon email address for this connection and does not store the Patreon OAuth access token.
- Bring-your-own-key data: an OpenAI API key you enter is kept in secure device storage on mobile or session storage in the current browser tab. It is sent to Riftarc only with the AI request, used to call OpenAI for that request, and is not stored in Riftarc databases or diagnostics.
- Browser storage: signed catalogue and rules data, recently viewed public information, and short-lived synchronization state may be stored in browser IndexedDB. It is separated by account and removed when the account changes or signs out. Supported offline use is limited to the mobile app.
- Scanner data: recognition runs on device where supported. The web scanner prepares the still frame locally and uploads only the selected frame for server recognition; ordinary scan images are not retained. In the MFA-protected administrator improvement mode, approving a reviewed crop permanently contributes it and its labels to private model-training storage under separate consent.
- Support messages, organizer submissions and public content you choose to provide.
- Advertising data on public content pages: Google and its partners may process cookies or similar identifiers, IP address, device and browser information, and ad impressions or interactions to serve and limit ads, measure performance, prevent fraud, and personalize ads where you permit it.
3. Why we use data
We use data to authenticate users, synchronize app state and mobile offline changes, deliver purchases, send requested waitlist and product updates, deliver email and browser or mobile alerts, identify cards, provide market and tournament features, prevent abuse, diagnose failures, answer support requests and meet legal obligations. On public content pages, advertising providers may also process data to serve and measure ads, limit repetition, prevent invalid traffic, and personalize ads when permitted. We do not sell personal data.
4. Legal bases
Where the GDPR or similar law applies, processing is based on performance of the service contract, legitimate interests in security and product operation, consent for optional processing, or compliance with law. You may withdraw consent without affecting earlier lawful processing.
5. Service providers and disclosures
AI requests include your question and relevant card, deck, collection or conversation context. Requests are processed by the AI provider under its terms and privacy policy. Do not submit sensitive personal information. A personal API key uses your own provider account and its applicable terms; Riftarc does not retain that key on its server.
Riftarc may use Supabase for authentication and storage, Cloudflare for application delivery and AI routing, DeepSeek for AI generation, OpenAI for AI requests made with a user-provided key, Patreon for optional supporter verification, Brevo for waitlist and product-update email delivery, RevenueCat for entitlement processing, Apple and Google for mobile billing, browser push and other email providers, error monitoring, and approved marketplace or tournament sources. Public content pages may use Google AdSense and a Google-certified consent management platform. Google and its advertising partners may use cookies, web beacons, IP addresses and similar technologies as described above. Providers receive only the data needed for their role. Data may also be disclosed when required by law.
6. Retention and security
Account data is kept while your account is active and for a limited period afterward when needed for recovery, fraud prevention, accounting or legal claims. Waitlist contact data is kept until you unsubscribe or ask us to remove it; a minimal suppression record may remain so we can honor that choice. Separately consented scanner-improvement samples are retained permanently for model training; account deletion de-links their account identifier. Riftarc uses encrypted transport, access controls, row-level policies, signed webhooks, rate limits and restricted administrative access. No system can guarantee absolute security.
7. Your choices and rights
You may update app settings, disable notifications, unsubscribe from waitlist or product-update emails through the link in those messages, manage advertising choices through the consent message shown on public pages, clear Riftarc browser storage through your browser, export or delete data where provided, and request access, correction, deletion, restriction, portability or objection where applicable. Withdrawing marketing consent does not affect essential account or security messages. You can start account deletion in Riftarc or at riftarc.gg/delete-account. You may also complain to your local data-protection authority.
8. Children, transfers and changes
Riftarc is not directed to children below the digital-consent age in their country. Service providers may process data outside your country using legally recognized safeguards. We will post material policy changes here and, when appropriate, notify users in the app.
9. Contact
Privacy questions and rights requests can be sent to privacy@riftarc.gg. Do not include passwords, payment details or other unnecessary sensitive information.
