Legal
Privacy Policy
Mana Foil ("we", "us", "our") is published and managed by Mana Foil LLC. This policy explains the product data Mana Foil needs for deck building, collection management, recommendations, and sharing.
Last updated August 29, 2026
Information we collect
When you sign in, Mana Foil stores the account details needed to run your account, including your Google account identifier, email, avatar, and the public handle you choose.
If you use deck, collection, or import features, we store the cards, quantities, categories, sideboard entries, selected printings, deck names, visibility settings, and related metadata needed to show and save that work.
We also keep basic technical records such as session cookies, request timestamps, and rate-limit data to protect the service and troubleshoot failures. Our page-view analytics record the paths you visit, your referrer, device details, and your country, which Vercel derives from your IP address.
Our product analytics record more than page views. They automatically log the elements you interact with — including the text on the buttons and links you click, which can be a deck or card name — so we can see which features people use and where they get stuck. For connections outside the no-capture locations described below, session replay can also reconstruct the pages and interactions in a visit. It is not a video or a copy of raw keystrokes: form inputs are masked before replay data leaves the browser, camera and uploaded scan images are blocked, and browser console messages, network headers, network bodies, and canvas pixels are not recorded. A replay can still include other text visible on the page, such as deck and card names. When you are signed in, this activity and any replay are linked to your account by an internal account identifier; we do not attach your email address or your name to it.
How we use it
We use account data to authenticate you, keep your saved decks and collection private by default, and display your chosen public handle when you publish content.
We use deck and collection data to power Mana Foil features such as validation, prices, exports, collection-aware recommendations, and saved deck editing.
Imported and saved decklists may be folded into anonymized, deduplicated aggregate card statistics. Those aggregates are used for recommendation quality and are not linked to your email, Google identity, or public handle.
Card scanning and your camera
When you start a card scan, your browser asks for permission to use your camera. While the scan is open, the scanner captures frames itself. We do not receive a background camera feed. You can upload a photo from your device instead of using the camera. In that case, we receive the image you choose.
Each frame or uploaded image goes to our server over HTTPS. We process it in memory into a visual fingerprint, match it against card data, and discard the image when the request completes. Before anything is sent, your browser crops the image to the card and re-encodes it, so the copy we receive carries none of the photo's location, device, or timestamp details.
Scan photos and uploaded images are never saved to our database, file storage, logs, caches, or error reports.
When you confirm a match, we save the card name, printing, finish, condition, and quantity to your collection like any other collection entry. We do not save the photo.
AI deck building
When you build a deck with Deck Forge, we save a record of that build to your account. For about the first 90 days — until the first successful nightly retention run after the 90-day mark — the record holds the request you typed, the settings we read out of it — things like themes, colors, and budget — the choices the build made on the way to a deck, such as the commander it picked and the card lists it worked from, and the written explanation it gave you. The record also keeps a link to the deck it produced and technical figures for the run: how much text the model read and wrote, what the run cost us, and any error it hit. Please don't type personal information into the request box. We keep what you write there until that retention run.
We keep these records so we can show you your past builds and what they produced, pick a build back up or work out what happened if one is interrupted, count builds against your monthly allowance and refund the ones that fail, and look into misuse of the feature. A build that fails is not counted against your allowance.
To produce a result, Deck Forge sends your request and the deck data derived from it to Anthropic, the company whose AI models we use. Anthropic processes it on our behalf and returns the result to us; it is based in the United States. Per Anthropic's commercial API terms, what we send is not used to train its models, and Anthropic may hold it for a limited period to enforce its own usage policies. We do not send Anthropic your name, email address, or public handle.
We keep AI build records for quota and history for as long as your account exists. After a build passes 90 days, our nightly retention job removes the prompt text, the generated note, the build's working record — the choices and card lists it worked from — the vocabulary-gap report, and the reader's recorded answers to that report. The themes, colors, budget settings, and other build settings stay in the record, along with the counts needed for quotas and history. Deleting your account deletes the records with everything else. Your account export includes the retained build records and marks material removed under this rule. A deck you keep from a build is an ordinary Mana Foil deck from that point on: it is private unless you choose otherwise, and the deck sections of this policy govern it. Deleting the deck does not delete the build record, and deleting the build record does not delete the deck.
We do not sell these records, we do not use them for advertising, and we do not use them to train any AI model of our own.
Card data and external services
Magic card names, rules text, images, legalities, prices, and related metadata come from Scryfall bulk data and linked Scryfall image URLs. Mana Foil does not bulk-rehost card images.
Buy links may point to vendor URLs provided by Scryfall. Prices are estimates from snapshots and are not a live storefront quote.
Imports from Moxfield or Archidekt process the deck or collection data you paste or export for Mana Foil. We do not scrape those services on your behalf.
Service providers
Mana Foil runs on infrastructure operated by other companies, and they process data on our behalf in order to provide the service. We use Vercel for hosting and delivery, Neon for our database, Railway for scheduled background jobs, Upstash for the rate-limit counters that protect the service, Google for sign-in, Anthropic for the AI deck builder, Resend to deliver the price alert emails you opt into, PostHog for product analytics and session replay, and Discord to deliver the price alert messages you opt into. These providers are based in, or store data in, the United States.
We use Vercel Web Analytics and Speed Insights for page-view analytics and performance telemetry. Vercel processes the page path, referrer, device details, country derived from your IP address, and real-user performance measurements on our behalf so we can understand how Mana Foil is used and improve how it performs.
We use Vercel's country estimate for your connection to decide whether PostHog may send product analytics. When that estimate places you in the United Kingdom or the European Economic Area, the law requires us to ask your permission first. We have not built a way to ask yet, so we do not capture rather than assume. We apply the same no-capture safeguard in Switzerland as a voluntary conservative choice, not because Swiss law imposes the same rule. Missing, malformed, or unassigned country data also fails closed to the same no-capture safeguard. This IP-based estimate can be wrong if a VPN or travel makes your connection appear to come from somewhere else. While the safeguard applies, PostHog sends no events, interactions, session replay, profile, remote-configuration request, or feature-flag request, and stores no analytics cookie or identifier in your browser. Vercel Web Analytics and Speed Insights, described above, do still run there: they set no cookies and identify no one. If we start PostHog product analytics in those places later, we will ask you before it begins.
We use PostHog for product analytics and session replay. PostHog processes the pages you visit, the interactions and replay data described under "Information we collect", your device and browser details, and your country derived from your IP address, which is anonymized rather than stored. The query string is removed from every address before it is sent, including replay URLs, so one-click links such as the unsubscribe link in a price alert email do not carry their token into our analytics. When you are signed in, PostHog also receives an internal account identifier for you — not your email address and not your name.
We use Sentry for error monitoring, so that failures can be diagnosed and fixed. Error reports deliberately exclude your session cookies, request bodies, and URL query strings, and keep only a small set of technical headers. They can still contain the page you were on, the type of error, and identifiers for the deck or card involved.
If you send feedback or a bug report, its contents are relayed to a private team triage channel hosted on Discord — see "Feedback and bug reports" below. If you link a supporter account, Patreon processes your payment and tells us your tier; we never receive your payment details.
Card images are loaded in your browser directly from Scryfall rather than copied onto our servers, which means Scryfall receives your IP address and browser details when a card image loads, the same as visiting any website that links an image.
We do not sell your personal information, and we do not use it for advertising.
Email we send you
Mana Foil notifies you in the app by default. If you turn on email price alerts in account settings, we also send one email a night listing the tracked cards whose prices moved. We send it only while that setting is on, and only to a verified address.
We send it because you asked us to, and you can withdraw that at any time: turn the setting off in account settings, or use the unsubscribe link in any of those emails, which works without signing in. Turning it off stops the email and changes nothing about your in-app notifications.
We use Resend to deliver these messages. To send one, Resend receives your email address and the contents of the message, which includes the cards you track and the prices we observed for them. Resend also tells us when a message bounces or is reported as spam.
We keep a list of addresses that bounced or were reported as spam so we stop sending to them, which we are obliged to do to keep our mail working for everyone else. An entry on that list records the address, the reason, and the date, and nothing else about you. Because its purpose is to stop us contacting an address, it is kept even if the account is deleted; you can ask us to remove an entry through the support page.
Public sharing
Decks are private unless you choose a sharing option. Future public and unlisted deck features will show the deck contents and your public handle according to the visibility you choose.
Do not publish deck names, notes, or categories that contain private information you do not want other people to see.
Supporter status and account linking
If you support Mana Foil through a supporter tier, we store your supporter tier and the identifiers needed to grant your perks — such as the link between your Patreon account and your Mana Foil account, and the Discord role assignment if you join the supporter server. We use them only to show your supporter cosmetics and grant access perks.
You can also connect your Discord account to Mana Foil itself, which is separate from anything Patreon does. When you connect it we store your Discord account ID and the access tokens for that connection; we do not store your Discord username, and instead ask Discord for it each time the page loads. We also ask Discord whether that account is in the Mana Foil server, so we can tell you whether a message could reach you. We use all of this only to deliver the price alerts you switch on, and connecting on its own sends you nothing. You can disconnect it at any time in account settings, which deletes what we stored and stops any Discord messages.
Supporter payments are processed by Patreon. Mana Foil never sees or stores your card, bank, or billing details.
We keep the Patreon link until you unlink it or delete your account. Unlinking removes the link and your live supporter entitlement, but never removes your Hall of Foil engraving.
Supporter walls, such as the Hall of Foil, list your public Mana Foil handle — never your Patreon identity, payment details, or email. You can ask us to hide your wall entry at any time.
Feedback and bug reports
If you send feedback or a bug report, your message and any screenshots you attach are relayed to a private team triage channel and are not published anywhere. Avoid including personal information you would not want the team to see.
We do not store report contents on our servers or in our logs; the private triage channel is the only copy.
Your choices
You can edit your public handle and download a full account export from account settings.
You can also permanently delete your account from account settings. Deletion is immediate and removes your profile, collection, play sessions, AI build records, and all decks, including public decks. There is no soft-delete or grace period.
Aggregated, de-identified deck statistics may be retained after deletion. They contain no link to you, and unshared entries are pruned automatically.
Contact
Questions about this policy can be sent through the support page.
Credits
Artwork and card materials are the property of Wizards of the Coast and the credited artists. Card data and image links are provided by Scryfall. Mana Foil links to card images and never rehosts them.
Card data & images from Scryfall; Scryfall is not affiliated with Mana Foil. Unofficial Fan Content under the Wizards Fan Content Policy — not approved or endorsed by Wizards; portions © Wizards of the Coast.