What We Collect
Adria MTG collects only what is necessary to provide the service:
- Email address: Used for login, account recovery, and service messages; processed by our database host and Resend when email is sent.
- Display name (optional): Shown in the app header.
- Password: Stored as an Argon2id hash. We never store or see your plaintext password.
- LLM API key (optional): Encrypted at rest with AES-256-GCM. Never sent to the client after storage. Used server-side only for AI coaching calls.
- Draft data: Your draft sessions, picks, decks, and analytics.
- Usage and source data: Pages and features used, source/referral parameters, referrer, and related product events used to understand and improve the service.
- Security and diagnostic data: IP address, user agent, request details, error details, and timestamps used for rate limiting, abuse prevention, audit logs, source attribution, and troubleshooting.
What We Don't Do
- We do not sell personal information or use it for third-party advertising.
- No browser fingerprinting
- We do not knowingly collect payment-card details directly; if paid billing launches, Stripe will process payment details.
Cookies
Adria uses essential cookies and similar storage needed for authentication, security, preferences, and anonymous session continuity. Vercel Web Analytics is also enabled and is designed to operate without cookies, but it still processes usage and network data as described below.
- Session cookie: Keeps you logged in between pages. Expires when you log out or after 30 days.
- CSRF token: Prevents cross-site request forgery attacks. Session-only.
We do not use advertising cookies. You can browse some parts of Adria without an account, but essential session storage is required for authenticated and security-sensitive features.
Third-Party Services
Adria MTG connects to the following external services:
- Scryfall API: Card data and images. Subject to Scryfall's privacy policy.
- Vercel: Hosts the application and provides Web Analytics. Vercel may process request, device, browser, page, referrer, and network information to deliver and measure the service.
- Managed PostgreSQL hosting provider: Hosts the production database and therefore processes account, draft, telemetry, security, and audit data stored by Adria. The current provider must be confirmed from the production environment before public launch.
- Sentry: Receives application errors, performance/diagnostic context, and related request or device information so we can detect and fix failures.
- Resend: Processes email addresses and email delivery metadata when Adria sends verification, password-reset, or other service emails.
- OpenRouter / Anthropic: AI requests are sent to the configured provider. Prompts can include draft context, card names, pick history, deck data, and user-supplied text. If you use your own key, the selected provider still processes those requests under its policies.
- Stripe: Stripe integration code exists, but paid billing is currently disabled and Adria is not accepting payments. If billing is launched later, Stripe will process checkout, subscription, and payment information under Stripe's policies.
- 17Lands.com: Card performance statistics. No user data is sent to 17Lands.
Data Security
- Passwords are hashed with Argon2id (industry standard)
- API keys are encrypted with AES-256-GCM
- Session cookies use HttpOnly, SameSite=Lax, and Secure flags (when behind HTTPS)
- Login attempts are rate-limited per email and per IP
- IP addresses and request metadata may be stored in rate-limit, audit, and source-attribution records
Data Retention
- Account data: Retained until you delete your account
- Draft history: Retained until you delete your account or individual drafts
- Security, audit, and product telemetry: Retained for as long as reasonably needed for security, troubleshooting, source attribution, and service operations, then deleted or de-identified where practical
- Provider records: Third-party providers may retain records under their own policies and legal obligations
- Deleted account data: Removed from active Adria systems when account deletion completes, subject to limited security logs, backups, and provider retention obligations
- Session data: Expires after 30 days of inactivity or when you log out
Your Rights
- Export your data: Download account-associated product data as JSON from your profile page and contact us for other access requests.
- Delete your account: Delete your account and associated product data from your profile page. Limited security logs, backups, and provider records may remain for the periods described above.
- No account required: You can use Adria MTG without creating an account. Anonymous usage uses a secure browser cookie that is not linked to personal information.
For Users in the European Union (GDPR)
Under the General Data Protection Regulation (GDPR), you have additional rights regarding your personal data:
Legal Basis for Processing
- Account creation: Contract performance (to provide the service you requested)
- Draft data storage: Legitimate interest (to save your progress and provide analytics)
- Essential cookies: Strictly necessary for the service to function (exempt from consent)
- Security and abuse prevention: Legitimate interests in protecting users and the service
- Product analytics and diagnostics: Legitimate interests in operating and improving the service, subject to applicable opt-out and consent rights
Your GDPR Rights
- Right to access: Download account-associated product data via Profile and contact us for a broader access request
- Right to rectification: Update your email or display name in Profile settings
- Right to erasure: Delete your account and all data permanently via Profile page
- Right to data portability: Export your data in JSON format
- Right to object: You can stop using the service and delete your account at any time
- Right to lodge a complaint: Contact your national data protection authority if you have concerns
Adria's AI coaching produces recommendations about game play; it does not make legal or similarly significant decisions about you. Our providers may process data in other countries under their own transfer safeguards and terms.
Contact
For privacy questions, data deletion requests, or to exercise your GDPR rights, email privacy@adria-mtg.com. We respond to all requests within 30 days.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated 'Last updated' date. Continued use of Adria after changes constitutes acceptance of the updated policy.
Legal Information
Adria MTG is unofficial Fan Content permitted under the Fan Content Policy. Not approved/endorsed by Wizards. Portions of the materials used are property of Wizards of the Coast. © Wizards of the Coast LLC.