Privacy Policy
Effective date: May 28, 2026
Who we are
Manatable (the “service”) is operated by William Forsyth, based in Brisbane, Queensland, Australia. For privacy questions or requests, contact [email protected].
Information we collect
- Account information: username, display name, an optional email address, a bcrypt hash of your password, and metadata about any profile photo you upload.
- Gameplay data: commanders you select, life totals, commander damage, game outcomes, and any waitlist signups you submit.
- Bug reports: your reporter id, the title, description and category you submit, a context JSON blob containing
userAgent,viewport,currentUrlandappVersion, and up to 5 screenshots of at most 5MB each. - Technical data: when you give consent, our analytics provider (OpenPanel) records your IP address and user-agent string for aggregate usage measurement. When consent is not given, this data is not collected.
- Cookies: we set a small number of cookies, listed in the Cookies section below.
How we use it
- Provide the service and authenticate you to your account.
- Sync gameplay state in real time between players at a table.
- Send transactional email (e.g. password reset).
- Investigate bug reports and fix issues.
- Measure aggregate usage to improve the product.
Legal bases for EU/UK users
If you are in the European Economic Area, United Kingdom or Switzerland, we rely on the following legal bases under the GDPR / UK GDPR:
- Contract — for account creation and gameplay functionality.
- Legitimate interest — for handling bug reports and protecting the security of the service.
- Consent — for analytics. You can withdraw your consent at any time using the “Manage your cookie choice” button below.
Cookies and similar technologies
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
mtg-token | Authentication (signed JWT, httpOnly) | 30 days | Strictly necessary |
mtg-consent | Records your analytics consent choice | 12 months | Strictly necessary |
When you accept analytics, our OpenPanel integration may also set a small number of first-party identifiers via our /api/op/ proxy. These are blocked entirely until you opt in.
Who we share data with
We use the following sub-processors to operate the service. We do not sell your personal information.
| Provider | Purpose | Location |
|---|---|---|
| Railway | Hosting, PostgreSQL database, persistent file storage | United States |
| Resend | Transactional email delivery | United States |
| OpenPanel | Product analytics (only with consent) | European Union |
| GitHub | Bug report ingestion as issues | United States |
| Scryfall | Card image lookups (no personal data sent) | United States |
International data transfers
Your data is processed in the United States and the European Union. Where data leaves your jurisdiction, we rely on Standard Contractual Clauses (SCCs) and processor-side safeguards offered by our sub-processors.
Data retention
- Account data is retained while your account is active and for 90 days after a deletion request, after which it is removed from production systems.
- Bug reports are retained indefinitely for product improvement unless you ask us to delete a specific report.
- Analytics data is retained by OpenPanel in accordance with their policy.
- Database backups are rotated and overwritten within 30 days.
Your rights
If you are in the EEA, UK, or Switzerland (GDPR / UK GDPR)
You have the following rights:
- Right of access to your personal data.
- Right to rectification of inaccurate data.
- Right to erasure (“right to be forgotten”).
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing based on legitimate interest.
- Right to withdraw consent at any time.
You also have the right to lodge a complaint with your local supervisory authority.
If you are in California (CCPA)
- Right to know the categories of personal information we collect and disclose.
- Right to delete your personal information.
- Right to correct inaccurate personal information.
- Right to non-discrimination for exercising your rights.
We do not sell or share personal information for cross-context behavioural advertising.
If you are in Australia (Privacy Act 1988 / APPs)
- APP 12 — right to access your personal information.
- APP 13 — right to correction of personal information.
- APP 8 — cross-border disclosure. Note that Railway, Resend and GitHub are based in the United States, and OpenPanel is based in the European Union.
Complaints may be made to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Children’s privacy
The service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided personal information to us, contact [email protected] and we will delete it.
Security
- Passwords are hashed with bcrypt (10 rounds).
- Authentication tokens are delivered as httpOnly cookies.
- Traffic is served over HTTPS in production.
- Access to production data is restricted to the operator on a need-to-know basis.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated and the effective date at the top of this page updated.
Contact
For any privacy questions or requests, contact [email protected].
Manage your cookie choice
Use the button below to clear your current consent record and re-display the consent banner.