← Back to Home

Privacy Policy

Last Updated: November 11, 2025

What Data We Collect

We collect only what's necessary to provide our service:

  • Email address - For authentication and account identification
  • Username - Your display name (optional, auto-generated from email if not provided)
  • Password - Securely hashed if you use email/password sign-in
  • Google account data - Name and ID if you use Google sign-in
  • Your content - Card collections, decklists, and room settings you create
  • Session cookies - To keep you signed in (expires after 30 days)

How We Use Your Data

  • Verify your identity and provide secure access to your account
  • Save and sync your collections and decklists across devices
  • Provide the core functionality of InkwellOverlay
  • Protect against unauthorized access

Data Retention

We keep your data while your account is active. When you delete your account, we permanently delete all your data within 30 days.

Third-Party Services

  • Google OAuth - For Google sign-in (subject to Google's Privacy Policy)
  • Render.com - Cloud hosting provider (US-based)

Your Rights (GDPR)

You can:

  • Access your data - Sign in to access your account settings
  • Download your data - Sign in to export your data
  • Update your data - Change your email and username anytime
  • Delete your data - Sign in to delete your account
  • File a complaint - Contact your local data protection authority

Security

We protect your data with industry-standard security:

  • Passwords are hashed (we never store plain text passwords)
  • All data transmission uses HTTPS encryption
  • Database access is restricted and authenticated

Cookies

We only use essential authentication cookies (JWT tokens) that are strictly necessary for the site to work. We do not use tracking, analytics, or advertising cookies.

Contact

For privacy questions or to exercise your rights, contact us at:
[email protected]

Inkwell Overlay