Privacy Policy
Last updated: 6 September 2026
Introduction
This policy describes how Riftseer collects, uses, and protects information when you use our website, API, Reddit bot, and optional Raycast extension. We do not sell your personal information.
Definitions
Riftseer means the Riftseer website, the Riftseer API, the Reddit bot (when installed in a subreddit), the Raycast extension (if you install it from the Raycast Store), and related services. We / us means the operators of Riftseer. Personal data means information that could identify you, such as your IP address or username.
Riftseer website and API
- No account required. You can use the site and API without signing in.
- Optional accounts. If you choose to register, we collect your email address and password to create and authenticate your account. Passwords are hashed and stored securely by Supabase (our authentication provider); we never store plaintext passwords. Upon login, Supabase issues a short-lived access token and a long-lived refresh token; these are stored client-side and sent with authenticated requests. You can revoke your session at any time via the logout endpoint (
POST /api/v1/auth/logout). To delete your account, contact us through the project repository. - Local storage (site only). The website stores preferences in your browser's local storage, including your theme choice (light or dark mode) and, if you accept functional cookies, your cards-per-page search preference, optional site accessibility preferences (for example how card names appear on search, or whether icons are shown as readable text instead), and optional layout preferences (card page detailed/simple view, and gallery/search/set browse layout). These are not personally identifiable and are not sent to our servers. You can clear them by clearing your browser's local storage for this site.
- Deck content and social features (signed in). If you use decks, we store what you create so it can be shown as you direct: your decks (names, descriptions, guides, card lists and per-card tags, with the visibility you chose), comments you post on decks (visible to everyone who can see that deck; deleting one leaves a “comment deleted” placeholder so replies keep their place, and the deck's owner can also remove comments on their deck), comment likes (which comments you liked, used to show a like count and to remember your own like), your favorites (public decks show a favorite count), and your deck folders (private to you). Public content is attributed to your handle. To remove any of it, delete the content or contact us through the project repository.
- Deck view counts. Deck pages keep an aggregate view counter. To count a visitor only once per six hours we briefly keep a one-way digest of your IP address, browser identifier and the current date (or your user ID when signed in) in an expiring cache. The raw IP address is never stored for this purpose and the digest cannot be reversed or linked across days.
- Cookie preferences. Where applicable, we show a consent banner so you can choose whether optional measurement cookies are used before analytics load. Necessary cookies support basic site operation.
- API and server requests. When you visit the site or call the API, our servers receive your requests (for example the URL, search terms, and card lookups). Our hosting provider (and we) may log request metadata such as IP address, timestamp, and path for operation, security, and abuse prevention. We do not use this data to build profiles of you or to advertise.
- Admin edits. If your account has admin access, we may store your account user ID with card and set data edits, manual records, relationship changes, image uploads, deletion records, format definitions, card legality statuses, rulings or notes, and decisions on the marketplace data review queue, so those changes are attributable, reversible, and preserved across data imports.
- PostHog (site analytics). We use PostHog to record site activity, for example page views, search usage, and how people navigate the site, so we can understand usage and improve the product. PostHog may collect information such as your IP address, device and browser type, and interaction data. PostHog's own privacy policy applies: posthog.com/privacy. We do not use this data for advertising.
Metafy account linking
If you choose to link your Metafy account, we store the following in our database server-side: your Metafy username, your Metafy user identifier, your OAuth access token (and refresh token, if issued), and your supporter status. This data is used exclusively to verify your Metafy membership and to enable supporter perks (ad-free experience and supporter badge). Your Metafy OAuth tokens are never exposed to the browser; they remain server-side and are used only to re-check your membership status on login and when you visit your donations settings. Metafy may also notify our server directly when your community membership or subscription changes; we use those notifications only to update the membership and supporter status stored on your linked account, together with the time of the update. We do not keep a separate history of those notifications, and payment details are never sent to us. You can disconnect your Metafy account at any time from the Donations settings page, which deletes all stored Metafy data. Metafy's own privacy policy applies to information held by Metafy.
Riftseer Reddit bot
The Riftseer bot runs on Reddit via Devvit. When it is installed in a subreddit, it reacts to new comments and self-posts that contain card references (for example [[Sun Disc]]) and may post a reply with card information and links.
- Data we receive from Reddit. For each comment or post it processes, the bot receives from Reddit: the comment or post ID, the author's Reddit username, and the text (title and body). This is the same data Reddit provides to any app that runs in the subreddit.
- How we use that data. We use the text to find card references and to call the Riftseer API to resolve them. We use the author username only to skip replying to accounts whose username ends with
"bot"; we do not persist Reddit usernames in the bot. Card-name and subreddit analytics on our servers are described under What we store. - What we store. The bot stores only Reddit comment and post IDs (in a key-value store) so we do not reply twice to the same item; it does not persist Reddit usernames, subreddit names, or requested card names. Separately, our server-side API may log requested card names and subreddit when the bot calls it to resolve references—for analytics (understanding how the bot is used across communities and improving the service). Those API logs are retained only as long as needed for analytics and product improvement, consistent with how we retain other API and server logs for operation and security. We do not sell this data or use it for advertising.
- Replies. When the bot replies, it does so through Reddit's API. Reddit's own privacy policy and terms apply to how Reddit handles that content and your activity on Reddit.
- Reddit and Devvit. The bot is built on Devvit and runs in Reddit's environment. Reddit and Devvit may process data according to their own policies. We do not control Reddit's or Devvit's data practices.
Riftseer Raycast extension
The optional Raycast extension calls the public Riftseer API to search and display cards. It does not send us your Raycast account or identity.
- Local storage on your Mac. The extension may keep a bounded list of recently viewed cards in Raycast's local storage on your device (you can set the limit to zero to turn this off). That history is not uploaded to Riftseer; it stays in Raycast until you clear it or remove the extension.
Data sharing and third parties
We do not sell or rent your personal data. We may share or expose data only as follows:
- Hosting. The site and API may be hosted by third-party providers (for example cloud or platform services). Those providers may process or store request data (such as IP addresses and logs) as part of running the service.
- Supabase (authentication). If you create an account, your email and hashed password are stored and managed by Supabase. Supabase's own privacy policy applies to that data.
- PostHog. As described above, we use PostHog for site analytics. PostHog processes the analytics data according to their privacy policy.
- Adobe Fonts. We load display fonts (for example Arpona) from Adobe's Typekit CDN so card names and similar text render in the intended typeface. Your browser may contact Adobe's servers to fetch those font files; Adobe's privacy policy applies to that request.
- Card data. Card and set data are fetched from third-party sources (for example RiftCodex). When you search or resolve cards, we do not send your identity to those sources; we only request card data for the lookups you trigger.
- Metafy. If you link your Metafy account, we call the Metafy API using your OAuth access token to verify supporter status. Metafy's privacy policy applies to data Metafy collects or processes.
- Reddit / Devvit. As described above, the bot operates within Reddit and Devvit; their policies apply to data they collect or process.
- Legal. We may disclose data if required by law or to protect our rights, safety, or the safety of others.
Retention
Site preferences in your browser stay until you clear them or withdraw the related cookie consent. Server logs (if any) are kept only as long as needed for operation and security. PostHog retains analytics data according to their policy and your settings. Stored Reddit comment and post IDs (used to prevent double replies) are kept indefinitely so the bot continues to avoid duplicate replies. API-side logs of requested card names and subreddit from bot traffic are retained on the same basis as other API analytics and server logs described above. Account data (email and hashed password) is retained by Supabase for as long as your account exists. Admin edit attribution records may be retained for as long as the related card data override is active or needed for auditability; contact us to request account deletion.
Your rights
Depending on where you live, you may have rights to access, correct, or delete personal data. If you have an account, you can contact us through the project repository to request access to or deletion of your account data. You can clear site preferences by clearing local storage for this site or changing your cookie preferences. PostHog may offer opt-out or privacy controls; see their privacy policy. For Reddit-related data (including API analytics derived from bot traffic, such as card names and subreddit), you can contact us to ask what we hold or to request deletion where applicable. Reddit's own tools and privacy policy also apply to your activity on Reddit.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and, for material changes, we will note the change here. Continued use of Riftseer after changes means you accept the updated policy.
Questions
If you have questions about this Privacy Policy or our data practices, please contact us through the project's repository or the contact method listed on the site.