Privacy Policy — Oldschool MTG

Effective date: September 2026 · Last updated: September 2026

Oldschool MTG (the "App") is operated by Degenerate Design LLC, a Georgia limited liability company ("we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and retain personal information when you use the App and related services or contact us. It also explains your privacy choices and rights.

The App includes a rules reference, card catalog, trade binder, club and event directory, life counter, and AI Judge. Our Terms of Service separately govern use of the App and subscriptions.

For privacy questions or requests, contact support@degeneratedesign.com.

1. Eligibility and children's privacy

You must be 18 years of age or older to use the App. People under 18 are not permitted to use the App.

We do not knowingly collect personal information from people under 18. If you believe someone under 18 has provided personal information to us, contact support@degeneratedesign.com. If we learn that an account belongs to someone under 18, we will take appropriate steps to close the account and delete the associated personal information, subject to applicable law. This age restriction does not waive our legal obligations or transfer them to an underage user.

2. Information we collect and process

Information you provide

Service, purchase, and technical information

Device location

With your permission, the App uses your device location to sort the club directory by distance. The App requests a low-accuracy location and rounds the coordinate to roughly one kilometer before it leaves your device. That coarse coordinate is sent to our server only to calculate distances for the directory sort; it is not stored by us, not shared with any third party, and not written to our logs. If you prefer not to share location, you can choose your region manually instead; a manual region selection is stored only on your device.

Advertising and analytics

We do not display advertisements or use analytics.

3. How we use information

We use personal information to:

4. AI Judge and voice processing

The AI Judge uses third-party AI services:

We do not send your name, email address, or account identifiers to these providers with your questions or audio.

Before your first use of the AI Judge, the App explains what will be shared and with whom and asks for your permission before any question or audio is sent. Microphone access is requested separately when you first use voice mode. You can withdraw your AI permission at any time in the App's profile settings; the AI Judge and voice mode are unavailable without it.

Please avoid including sensitive personal information, or another person's private information, in your questions or recordings.

AI training and provider retention. Under our commercial API agreements, neither Anthropic nor OpenAI uses your questions, answers, audio, or transcripts to train or improve their models, and we do not opt in to any such training. These providers may retain data briefly for abuse monitoring and to operate their services under their own policies — for example, OpenAI retains API data for up to 30 days for abuse monitoring, and longer only where legally required. Our own retention is described in Section 7.

5. When information is shared

Providers and app stores

We use the following services to operate the App:

Provider Purpose Information involved
Clerk Authentication and account management Email address, account identifiers, and sign-in information
Anthropic AI Judge answers Question text and current-conversation context described in Section 4
OpenAI Voice transcription and spoken answers Recorded audio and answer text, as described in Section 4
Apple App Store Purchases and subscription billing Purchase and subscription information processed by Apple
RevenueCat Subscription management Account identifier and purchase or entitlement status
Amazon Web Services (AWS) Hosting, databases, email through SES, and image storage through S3 Information needed to provide those services
Scryfall Card data and images Card and image requests, made by our servers
Sentry Crash and error diagnostics Error details, device and app-version info, and technical context (no questions, audio, account identifiers, or IP)

Card data and images are requested by our servers, not by your device, so your device's IP address is not disclosed to Scryfall through normal use of the App.

Service providers that process information on our behalf are subject to contractual protections and restrictions appropriate to their role. The App Store and some other services may also process information independently under their own privacy policies. Provider privacy information: Clerk · Anthropic · OpenAI · Apple · RevenueCat · AWS · Scryfall · Sentry.

Content you share or submit for publication

If you choose to share a trade binder, the App creates a read-only web page for it at an unguessable link. That page is visible to anyone who has the link, but it is not listed in the App and is marked so search engines do not index it. It shows the binder's name and its for-trade and wants lists, including card condition, quantity, and any notes; it does not include your email address or account identifiers. You can revoke the link at any time in the App, which disables the page.

When a club or event suggestion is approved and published in the directory, the published listing may show the name, region, links, contact details, and logo you provided, and is visible to other people. Your IP address and account identifier are not published.

Only submit contact information or images that you have permission to provide for the intended use.

Legal and safety disclosures

We may disclose information when reasonably necessary to comply with law or valid legal process, protect rights or safety, investigate fraud or abuse, or enforce our Terms.

Sale and advertising-related sharing

We do not sell personal information and do not share it for cross-context behavioral advertising.

6. Your choices

7. Retention

We retain personal information for the periods needed to provide the relevant features and for the purposes described below. Retention in our systems and retention by providers may differ.

Information Retention period or criteria
Account data While your account remains open, then removed through the deletion process in Section 8. We do not currently expire accounts for inactivity.
Binder data Retained while you keep the binder, until you delete the binder or your account. We do not currently expire binders for inactivity. If we introduce a binder-purge policy, we will notify affected users before it takes effect.
Judge questions and answers (all plans) Stored per user and limited to your most recent questions; older entries are automatically removed. Pro can view this history in the App; other plans cannot view it, though it is stored the same way. Removed when you delete your account.
Raw voice audio and transcripts Not stored on our servers. Audio is sent to the speech provider for transcription and discarded; the resulting text is retained as a Judge question above.
Club/event submissions and images Retained for moderation and abuse prevention; published listings are retained while they remain in the directory. Contact support to request removal.
Support communications Retained as long as needed to handle your request and for a reasonable period afterward.
Usage counters and security or operational logs Usage counters are retained to enforce weekly allowances. Server and security logs are retained for a limited period for operations and abuse prevention.
Purchase and compliance records Your current subscription tier is retained while your account is active. Transaction and billing records are held by Apple and RevenueCat under their policies.
Backups Our database is backed up on a rolling basis; deleted data is removed from backups as they expire on their normal cycle.
Provider-held information Subject to each provider's own retention and deletion practices, including the AI providers described in Section 4.

8. Account and data deletion

You can delete your account in the App at Profile → Account → Delete account. You can also request deletion by emailing support@degeneratedesign.com.

Deleting your account removes your account and associated personal information, including your binders, saved question history, and usage records, and removes your sign-in identity from our authentication provider (Clerk). Club or event suggestions you submitted are de-identified — kept for the directory but no longer linked to you. We complete deletion promptly, ordinarily within 30 days, subject to disclosed lawful retention exceptions and to backups expiring on their normal cycle. We may retain a limited record where necessary for legal, security, or fraud-prevention purposes. Signing out or uninstalling the App does not delete your account.

Deleting your account does not automatically cancel your App Store subscription. Manage or cancel it in your Apple ID subscription settings. Paid access ends according to the App Store's rules for the plan you purchased.

9. Privacy rights

The App is offered in the United States. Depending on where you live and which laws apply, you may have rights to access, correct, delete, or obtain a portable copy of your personal information; to opt out of the sale or sharing of personal information (we do neither); and to withdraw consent where processing relies on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.

To make a request, email support@degeneratedesign.com. We may request information reasonably necessary to verify your identity or authority to act for another person, and we will not discriminate against you for exercising these rights. We respond within the time required by applicable law.

If you are a California resident, you may exercise the rights described above; we do not sell or share personal information for cross-context behavioral advertising, and we do not process sensitive personal information for purposes that would require a right to limit its use.

10. International processing

We are based in the United States, and we and the providers described above process information in the United States and other locations those providers use to deliver their services. We do not target the App to users in the European Economic Area or the United Kingdom.

11. Security

We use reasonable technical and organizational measures designed to protect personal information, including encryption in transit (HTTPS/TLS), access controls, and managed cloud infrastructure. No method of transmission or storage is completely secure.

12. Changes to this policy

We may update this Privacy Policy as our services or practices change. The effective date above identifies when the current version takes effect. We will provide appropriate notice of material changes, such as an in-app notice or email. Where required, we will obtain consent before beginning new processing that requires it.

13. Contact

Degenerate Design LLC Email: support@degeneratedesign.com