Privacy
Your collection is private. You choose whether to share a collection template.
Who is responsible
Peaceful_William, Sweden, is the operator responsible for personal data in this app — an individual running it as a free hobby project, not a company. Contact: privacy@senseiset.com. Write to that address for the operator’s full identity where you need it to exercise a right.
What we use and why
When you sign in, we receive your provider’s account identifier and, where available, verified email address. We store those details, account creation and last sign-in times, and a hashed session token so you can securely use your account. We do not store your Google or GitHub password.
We store the collections, card inventory, conditions, quantities, preferences, selected prints, price overrides and history you save. We use these to provide the collection service you request (performance of our agreement with you). Account data is required for saved collections; browsing does not require an account.
If you submit a template, vote or missing-card report, we store that submission and its review outcome. Approved templates publish their name, description, chosen display name and curation rules, but not your inventory or email. The reviewer can see the submitting account’s email. Security and moderation serve our legitimate interests in protecting the service and other users.
Who receives information
Cloudflare provides hosting, database storage and delivery. Google or GitHub handles sign-in when you choose that provider. External card-image hosts (including Pokémon TCG, TCGdex and TCGplayer), Google Fonts and any data services your browser requests receive network information such as your IP address. These providers have their own privacy terms. We do not sell your collection or use it for advertising.
Cloudflare acts as our processor under its data processing addendum; Google and GitHub act as separate controllers for the sign-in you choose, under their own notices. All three operate globally, so information may be processed outside Sweden and the EEA. Those transfers rely on the standard contractual clauses and supplementary measures in each provider’s terms; we do not make transfers of our own beyond using these services.
Cloudflare keeps operational logs of requests reaching the service — including IP address and request metadata — under its own retention periods, which are short and measured in days. We do not run analytics, and we do not build profiles from them.
How long information stays
- Your account and current collection remain until you delete the account. Inactivity alone does not delete a collection.
- Saved price history keeps the most recent 400 days per account; older days are removed by daily maintenance.
- Session tokens expire after 30 days. Expired session rows are removed by daily maintenance or on a later sign-in.
- Recovery backups keep at most 30 automatic copies, 10 manual copies, 5 pre-empty copies and 1 initial-import copy per account. Daily maintenance removes backups older than 90 days.
- Resolved card reports and rejected or superseded templates are removed 90 days after review by daily maintenance. Pending reports/templates and approved templates remain until account deletion or moderation changes their status.
- Deleting an account removes its live database records, including backups, templates, votes and reports, and invalidates all its sessions. Other users’ copies of a previously shared template or downloaded exports cannot be recalled.
- Cloudflare database recovery copies can retain deleted data for up to 30 days on the planned Paid plan. They are separate from the app’s recovery list. Restore procedures must honour prior deletion requests.
Browser caches may remain on other devices or in already open tabs. Account deletion clears this account’s saved app data in the browser handling the request where browser storage is available. You can also clear this site’s data in browser settings. Downloads remain under your control.
Children
You need an account only to save a collection, and sign-in is handled by Google or GitHub, whose own minimum age applies. The Terms set a minimum of 13. We do not knowingly keep an account for anyone younger; tell us at privacy@senseiset.com and it will be removed. We ask for nothing beyond what the sign-in provider returns, and names shown to other people are checked before they are published.
Limits and suspension
Each account has a daily limit on saved changes, and on how many templates may await review and how many card reports may be filed per day. These protect the service for everyone; reaching one never deletes anything you have saved.
An account may be suspended for abuse or for content that breaches the Terms. A suspended account keeps read access to its own collection and can still export it, but cannot save changes, publish, vote or report, and its published templates stop being shown. Contact privacy@senseiset.com to query a suspension.
Your choices and rights
You can edit collection data, export it from Cloud backups, or delete your account from Account. Signing in again after deletion creates a new, empty account. Google and GitHub accounts are separate even when they use the same email address.
Contact privacy@senseiset.com to request access, correction, erasure, restriction or portability of personal data, or to object to processing based on legitimate interests. These rights depend on the circumstances. We may need to verify your identity. You can complain to Sweden’s privacy authority, IMY. Collection exports do not include every account or moderation record; contact us for a full personal-data request.
Last updated 18 September 2026.