Privacy policy
This policy explains what data mtgscan collects, why it collects it, and what you can do about it.
mtgscan is in development for iPhone and is not on the App Store yet. This policy describes how the app handles data as the developer builds it. The app does not have every feature described here yet.
Who runs mtgscan
One individual developer runs mtgscan. This policy calls that person "the mtgscan developer". No company runs mtgscan. You can reach the mtgscan developer at reilleygray@gmail.com.
Data mtgscan collects
Your account
You sign in with Apple or Google. mtgscan gets two things from them:
- an account ID for your Apple or Google identity;
- your email address.
If you choose Hide My Email with Sign in with Apple, mtgscan gets an Apple relay address, not your real email address. mtgscan never gets your Apple or Google password.
Each Apple or Google identity is its own mtgscan account. mtgscan does not link accounts across providers.
Your collection and decks
mtgscan stores the data you create in the app:
- collection entries for the card printings you own, with finish, language, condition, quantity, and whether copies are protected;
- the time you added each copy and its purchase-day price;
- decks, with their commanders, cards, and deck priority;
- deck changes and deck change history;
- deck suggestions from connected AI clients, with their reasons and the name of the AI client;
- planned swaps and buylist cards;
- your settings, such as your currency and whether training crop uploads are on.
Searches
mtgscan logs each collection search and catalog search, from the app or from a connected AI client. A log records the query, the number of results, how long the search took, and the first 20 results. Searches in the app also record which result you opened and whether you searched again soon after. mtgscan keeps search logs for 180 days and uses them to improve search.
Connected AI clients
When you connect an AI client, mtgscan stores a record of that connection so the client can reach your data.
Training crops
If training crop uploads are on, mtgscan stores training crops of scanned cards with their evidence records. The next section explains them.
How scanning works
Card recognition runs on your phone. The camera images used to recognize cards stay on your phone, and mtgscan does not upload them.
To recognize cards, the app downloads a card gallery and a card list to your phone. These files hold card data, not your data.
Your scan batch is saved on your phone until you add it to your collection. When you add it, the app saves the cards to your mtgscan account.
The only scan images that leave your phone are training crops.
Training crops
A training crop is an image of one card that you scanned. mtgscan uses training crops only to improve card recognition. mtgscan never publishes your training crops. The public test images in the mtgscan repository are the developer's own scans.
- Uploads are on by default.
- Before your first scan, the app shows a notice about training crops.
- You can turn uploads off in the settings at any time.
- You can remove every crop you uploaded with "delete all crops" in the settings.
The app uploads a crop after you save the scan to your collection. mtgscan keeps a crop only when all of these are true:
- you saved the scan to your collection;
- the scanner recognized the card from its collector line or from its unique art;
- you did not change the printing.
Some printings have a same-text twin that differs only by a stamp or a symbol. For these, mtgscan keeps a crop only after you confirm the printing.
Each crop has an evidence record. It holds:
- the scanner's decision and its reason;
- the top similarity score and the art margin;
- what the scanner read from the collector line, and whether it named the chosen printing;
- the number of same-text twins;
- the recognizer version and the gallery date;
- the printing you saved, and whether you changed it;
- the version of the rules for keeping crops.
Uploads stop for everyone when mtgscan's file storage is 90% full.
AI clients and the MCP connection
You can connect a compatible AI chat client, such as ChatGPT, to mtgscan through the MCP connection. A client can connect only after you sign in to mtgscan and give your consent.
A connected AI client can read:
- the card catalog, with card prices and Oracle tags;
- your collection entries and your collection summary, including the value of your collection;
- your decks, with deck validity, violations, and the estimated bracket;
- your deck changes, planned swaps, and buylist;
- your deck suggestions, including dismissed and withdrawn ones.
The only data a connected AI client can write is deck suggestions. It can create deck suggestions, withdraw open ones, and replace their reasons. It cannot change your collection or your decks. You make every deck change.
The data an AI client reads goes to the company that runs that client, such as OpenAI for ChatGPT. That company's privacy policy covers what it does with the data.
Where your data is stored
mtgscan stores your account data, app data, and training crops with Supabase in the ap-southeast-2 (Sydney, Australia) region.
The app stores your scan batch, your sign-in session, and the card gallery on your phone.
Your data is private to your account. Other users cannot read or change it. The mtgscan developer can access the stored data to run the service.
mtgscan does not keep backups at the moment.
Service providers
mtgscan uses these providers to run the service:
- Supabase stores your data and runs sign-in, file storage, and the server functions.
- Apple provides Sign in with Apple. Apple also runs TestFlight, if you install a test build through it.
- Google provides Google sign-in.
- Expo builds the app and hosts the sign-in and consent page that AI clients use.
- Cloudflare hosts this website.
- GitHub hosts the source code and runs the jobs that import card data. These jobs do not handle personal data.
Card data and prices come from Scryfall. Combo data comes from Commander Spellbook. mtgscan does not send your account, collection, or deck data to Scryfall or Commander Spellbook. Card images may load from Scryfall's servers, which see your device's IP address, as any website does.
These providers can keep technical logs, such as IP addresses and request times, to run and protect their services.
What mtgscan does not do
- mtgscan does not sell your data.
- mtgscan does not show ads.
- mtgscan does not track you for advertising.
- mtgscan does not use third-party analytics in the app or on this website.
- This website does not set cookies.
Keeping and deleting your data
mtgscan keeps your data while your account exists. mtgscan deletes search logs after 180 days.
In the app, you can delete copies from your collection, delete decks, and delete all your training crops. Deleting a deck is permanent.
To delete your account and all its data, email reilleygray@gmail.com. Say whether you sign in with Apple or Google, and give the email address that mtgscan shows in the settings. Account deletion in the app will come before mtgscan is on the App Store.
Children
mtgscan is not directed at children under 13. If you think a child under 13 has an mtgscan account, email reilleygray@gmail.com.
Changes to this policy
When this policy changes, the effective date at the top changes too. The history of every change is public in the mtgscan repository on GitHub.
Contact
For questions about this policy or your data, email reilleygray@gmail.com.