Privacy
Deckwarden has optional sign-in, no ads, and no analytics. Cookies exist only to keep you signed in — nothing tracks you. This page lists everything it does store.
Accounts (optional)
You never need an account to build, share, or browse — signing in just keeps your decks across browsers. Sign-in is via Discord or Google only; there are no passwords here. From the provider we store your display name, email address, and avatar URL, used solely to show you your account and tie your decks to it — never for marketing, and never shared. The avatar URL is refreshed each time you sign in; your name and email are not.
You can also choose a different picture on the account page. Then we store that choice: for a Magic card’s art, the card’s name, which printing the art comes from, and the artist’s name for the credit line; or simply that you chose your initial. Nothing is uploaded.
Choosing a username is optional and is the one thing that makes any of that public: it publishes a profile page at /u/<username> showing your display name, your picture (with its artist credit when it is card art), and your public decks and folders. Never your email. Skip the username and nothing about your account is browsable.
Importing a collection is optional too. If you upload a ManaBox or Moxfield CSV export on the account page, the file is read in your browser and only three things per line reach our servers: which card printing, its finish, and how many. Purchase prices, conditions, languages, and binder names are never sent. The collection is private — it only ever shows you which cards you own in decks you view — and you can wipe it from the account page at any time.
While signed in, a session cookie keeps you signed in; it is strictly functional and is the only cookie this site sets. Decks built on a browser before signing in are attached to your account when you sign in on that browser; their localStorage edit keys are retired in the process. You can delete your account yourself from the account page — it permanently and immediately removes your account and everything in it: decks, folders, likes, bookmarks, and your imported collection. If you can no longer sign in, email contact@deckwarden.gg instead and removal is handled manually — privately, not through a public issue tracker.
Decks you build
Decks are stored on our servers: the card list, deck name, description, and visibility (public, unlisted, or private). Anyone you give a share link can view a public or unlisted deck — that’s the point of the link. Private decks are viewable only from the browser that created them or by the signed-in account that owns them.
The edit key for each deck lives in your browser’s localStorage (not a cookie — it is never sent automatically). Clearing site data deletes your edit keys, and without a key a deck can no longer be edited or deleted from your browser, so export anything you care about first.
You can delete a deck yourself from the editor at any time; deletion is immediate and permanent. Housekeeping also deletes anonymous decks left empty for 30 days or untouched for 12 months.
IP addresses
When a deck is created we record the creating IP address, used only for spam control and abuse cleanup. Rate-limit counters keyed by IP are kept for at most two days. Our hosting providers keep standard server logs.
Error reporting
When something breaks, an error report (stack trace, browser version, the failing URL, and possibly your IP address) may be sent to Sentry, our error-monitoring service, so we can fix it. Error reports are not used for anything else.
Where things run
Hosting is on Vercel, the database on Neon (US region), and encrypted backups on Cloudflare R2. Card images load directly from Scryfall’s CDN, so your browser makes requests to scryfall.io when viewing cards — governed by Scryfall’s privacy policy.
Questions or removal requests
Email contact@deckwarden.gg for anything private, or open a GitHub issue for bugs — either way we’ll sort it out. Attribution and terms live on the legal page.