Privacy Policy
Effective Date: October 7, 2026
Last Updated: October 8, 2026
MTGCommand.com (“MTGCommand,” “MTG Command Center,” “we,” “us,” or “our”) respects the privacy of its users and is committed to handling personal information responsibly, transparently, and securely.
This Privacy Policy explains what information MTGCommand collects, receives, generates, stores, uses, shares, and retains when you access or use MTGCommand.com, create an account, maintain a Magic: The Gathering collection, create decks or event pools, use card-intake or scanning features, use Seller Hub features, or otherwise interact with the service.
This Policy also explains the choices and rights that may be available to you regarding your information.
By using MTGCommand.com, you acknowledge the practices described in this Privacy Policy.
Contents — 48 sections
1. Scope of This Privacy Policy
This Privacy Policy applies to information processed through:
- MTGCommand.com;
- MTG Command Center user accounts;
- Collection and inventory features;
- Card Explorer and search features;
- Deck Builder, Deck Manager, and Deck Lab features;
- Event Pools and limited-event tools;
- Manual Intake;
- Universal Card Scanner and related card-identification tools;
- Seller Hub;
- account and user settings;
- administrative and security systems;
- related APIs and web services operated by MTGCommand.
This Policy does not govern independent websites, applications, marketplaces, card databases, payment processors, social networks, or other third-party services that MTGCommand may link to or interact with.
2. Our Privacy Principles
MTGCommand is designed around several basic privacy principles.
2.1 Private by Default
A user's collection, inventory, card locations, decks, event pools, account information, scanner submissions, and other personal workspace information are private by default unless the user intentionally chooses to publish or share particular information.
2.2 User Isolation
Information belonging to one user should not be made available to another user merely because both users have accounts on MTGCommand.
MTGCommand is designed to maintain logical separation between users' private account and collection information.
2.3 Data Minimization
We seek to collect and retain information that is reasonably useful for operating, securing, improving, and supporting MTGCommand rather than collecting personal information simply because it may be possible to do so.
2.4 Purpose Limitation
Information collected for account security, inventory management, deck building, scanning, event management, or another MTGCommand function should be used for legitimate purposes associated with the service.
2.5 Transparency
When MTGCommand materially changes what information it collects or how that information is used, this Privacy Policy should be updated accordingly.
3. Information We Collect
The information MTGCommand processes depends upon which features you use.
3.1 Account Information
When you create or maintain an MTGCommand account, we may retain information including:
- your internal MTGCommand user ID;
- your name or display name;
- your email address;
- your account role;
- account status;
- account creation date;
- account modification information;
- account preferences and settings;
- access or service-tier information where applicable.
Your email address may be used to identify your account, facilitate authentication, communicate account-related information, and provide account recovery or security functionality.
4. Passwords and Authentication Information
MTGCommand does not need to store your normal account password in readable plaintext.
Authentication information may include:
- a cryptographic password hash;
- authentication/session identifiers;
- hashed session tokens;
- CSRF or similar security information;
- session creation information;
- session expiration information;
- account-security state;
- authentication events.
Password-reset systems may retain:
- your user ID;
- a hashed password-reset token;
- the time a reset token was created;
- the time it expires;
- whether the token has been used, revoked, or invalidated.
Invitation or registration systems may similarly retain token hashes and related creation, expiration, issuance, or use information.
These systems are intended to permit authentication without retaining reusable plaintext passwords or reset credentials.
5. Collection and Inventory Information
MTGCommand's primary purpose includes helping users manage their physical Magic: The Gathering collections.
When you add cards to your collection, MTGCommand may retain information such as:
- the account that owns the inventory record;
- card identity;
- exact printing identity;
- Scryfall or other catalog identifiers;
- set or expansion;
- collector number;
- card treatment or printing;
- finish, such as foil or nonfoil;
- language;
- condition;
- quantity;
- physical storage location;
- binder, box, deck, or organizational assignment;
- date created;
- date modified;
- associated ownership or inventory records.
This information allows MTGCommand to distinguish between merely knowing that a card exists and knowing that a particular user owns a particular physical printing of that card.
6. Physical Storage and Location Information
Users may organize their collections by providing locations such as:
- binder names;
- deck names;
- storage boxes;
- trade inventory;
- cards being used in decks;
- cards being held for sale;
- cards being used in event pools;
- custom organizational locations.
These locations describe where the user has chosen to organize cards.
They are not intended to represent the user's geographic location.
Users should not place sensitive information such as a home address, access code, Social Security number, financial account information, or other unnecessary personal information into custom binder, deck, storage-location, note, or similar fields.
7. Deck and Deck-Analysis Information
When you create, import, modify, save, or analyze a deck, MTGCommand may retain:
- the account owning the deck;
- deck name;
- format;
- commander or commanders;
- card identities;
- exact card printings where applicable;
- quantities;
- deck sections;
- card finishes;
- ownership relationships;
- card availability;
- physical inventory assignments;
- deck-analysis information;
- recommendations;
- deck configuration;
- timestamps and modification history where supported.
Deck Lab and related tools may analyze information about a deck, including:
- mana requirements;
- curve;
- functional card roles;
- interaction;
- ramp;
- card advantage;
- protection;
- resilience;
- card relationships;
- synergy;
- combo structures;
- redundancy;
- potential weaknesses;
- ownership availability.
These analyses concern gameplay and collection management. They are not used to make legal, employment, insurance, credit, housing, medical, or similarly consequential decisions about users.
8. Event Pool Information
When you create or use a prerelease, sealed, draft, or other event-related pool, MTGCommand may retain:
- the account owning the pool;
- pool name or description;
- cards contained in the pool;
- quantities;
- printing information;
- pool modification information;
- generated or saved deck information;
- pool-analysis data;
- timestamps;
- other information necessary to restore the saved event pool.
Event pools are treated as user-specific information unless the user intentionally shares them.
9. Manual Intake Information
When Manual Intake is used, MTGCommand may process and retain information necessary to add a physical card or other Magic object to an account.
This can include:
- card identity;
- exact printing;
- set;
- collector number;
- finish;
- condition;
- language;
- quantity;
- storage destination;
- collection destination;
- event-pool destination;
- other user-selected inventory information.
10. Card Scanner Information
MTGCommand may offer camera-based or image-based card identification.
Depending on the scanner implementation in use, scanner processing may involve:
- photographs or video frames containing Magic cards;
- detected card boundaries;
- artwork recognition information;
- OCR-derived text;
- card names;
- collector numbers;
- set information;
- candidate card matches;
- confidence scores;
- user confirmation;
- user correction;
- scanner session information;
- resulting inventory records.
Scanner images or processing artifacts may be temporarily retained where necessary for card recognition, debugging, reliability, processing, or scanner functionality.
MTGCommand does not state that every scanner image is permanently retained.
Scanner implementation and retention behavior may change as this feature develops. If MTGCommand begins materially expanding the long-term retention or secondary use of scanner images, confirmations, corrections, or recognition data, this Privacy Policy will be updated as appropriate.
Users should avoid placing unrelated sensitive personal information within the camera's field of view when scanning cards.
11. Search and Usage Information
MTGCommand may process information about how users interact with application features, including:
- searches;
- selected cards;
- requested pages;
- feature usage;
- navigation actions;
- application errors;
- API requests;
- processing results;
- system events.
Some search or activity information may exist temporarily as application state, caching, diagnostic information, or server logging.
MTGCommand does not represent that it maintains a permanent behavioral profile of every search performed by every user unless such functionality is specifically implemented and disclosed.
12. Seller Hub Information
Users who participate in Seller Hub or related seller features may provide additional information such as:
- seller name;
- brand or business name;
- profile information;
- biography;
- tagline;
- logo;
- promotional image;
- external marketplace link;
- Whatnot profile or URL;
- show information;
- promotional description;
- category;
- promotion dates;
- promotion status;
- other seller-provided information.
Some Seller Hub information is intended to be public.
When a user intentionally submits or publishes information for a public seller profile, promotion, advertisement, event, or similar feature, that information may be visible to visitors or other users.
Users should therefore distinguish between information intended for their private MTGCommand account and information they intentionally submit for public display.
13. Card Catalog and Market Information
MTGCommand maintains or accesses information concerning Magic: The Gathering cards and related objects.
This may include information originating from or synchronized with card-data and pricing sources such as:
- card names;
- Oracle information;
- sets;
- artwork;
- collector numbers;
- printing information;
- card identifiers;
- market identifiers;
- pricing;
- pricing history;
- finish-specific pricing;
- related catalog information.
This general catalog and market information is ordinarily not personal information.
It becomes associated with a user when, for example, MTGCommand records that the user owns a particular card or calculates the value of that user's collection.
14. Collection Value and Derived Information
MTGCommand may calculate or derive information from user inventory.
For example, MTGCommand may calculate:
- individual owned-card values;
- deck value;
- event-pool value;
- collection value;
- quantities by category;
- inventory statistics;
- ownership availability.
These calculations may be generated dynamically from the user's inventory and current pricing information rather than stored as a permanent standalone record.
A collection valuation is an estimate based upon available market data and should not be treated as a guaranteed sale price, financial appraisal, investment valuation, or financial advice.
15. Technical and Device Information
When you connect to an Internet service, certain technical information is ordinarily generated or processed to deliver and protect the service.
MTGCommand and its infrastructure providers may process information such as:
- Internet Protocol address;
- request timestamp;
- requested URL or API path;
- HTTP method;
- browser type;
- user-agent information;
- operating-system information;
- response status;
- security events;
- authentication failures;
- application errors;
- network information;
- referring information where transmitted;
- similar server or request metadata.
Some of this information may exist in:
- application logs;
- web-server logs;
- security logs;
- hosting logs;
- Cloudflare or other infrastructure systems;
- operating-system logs.
Retention periods for technical logs may vary depending upon operational, troubleshooting, security, hosting, and legal needs.
MTGCommand does not promise a specific technical-log retention period unless one is separately published or implemented.
16. Cookies and Similar Technologies
MTGCommand may use cookies or comparable browser technologies necessary to operate the service.
These may be used for purposes including:
- authentication;
- maintaining signed-in sessions;
- CSRF protection;
- account security;
- application preferences;
- maintaining application state;
- abuse prevention;
- infrastructure security.
Infrastructure providers such as content-delivery, security, or anti-abuse providers may also use cookies or similar technologies necessary to provide their services.
MTGCommand does not currently intend to use personal information for cross-site behavioral advertising.
If MTGCommand later introduces advertising, non-essential analytics, or additional tracking technologies, this Privacy Policy and any required consent controls will be updated as appropriate.
17. Information We Do Not Intentionally Request as Part of the Core Service
MTGCommand's ordinary collection, deck-building, scanning, and seller-management features do not require users to provide information such as:
- Social Security numbers;
- government identification numbers;
- driver's-license numbers;
- passport numbers;
- medical records;
- health information;
- private banking credentials;
- credit-card numbers;
- precise GPS location;
- private contact lists;
- passwords for other services.
Please do not enter sensitive information that MTGCommand does not request into free-form profile, deck, collection, seller, storage-location, or other fields.
18. Payment Information
Regardless of a user’s subscription tier, membership level, or use of the website, MTG Command Center does not require, collect, save, or retain banking information or payment credentials. This includes bank-account and routing numbers, online-banking credentials, complete credit- or debit-card numbers, card security codes, and PINs.
Any payments for use of the website will be processed exclusively through a secure, qualified third-party payment processor. Before paid features are enabled, the processor must provide a secure payment platform that meets applicable payment-card industry requirements, including PCI DSS where applicable, and the requirements of the relevant acquiring bank and card networks.
Payment details must be entered directly into the third-party processor’s secure payment interface, rather than provided to MTG Command Center. The processor handles those details under its own privacy policy and security practices. MTG Command Center may receive payment confirmation, transaction references, or subscription status, which are not banking credentials or complete payment-card details.
Do not enter banking information or payment credentials into seller profiles, show descriptions, collection notes, uploaded files, support messages, or other website fields. As of this update, the website does not have an active payment-processing integration.
If you choose to tip your host, MTG Command Center may retain your account ID, the tip amount and currency, PayPal order and capture references, payment status, and confirmation dates to verify support benefits and send a thank-you email. We do not retain your banking credentials or complete payment-card information. Optional supporter feedback and Whatnot banners are published only with your express choice and owner approval. Banner records include the public seller username, profile/store link, and chosen advertising dates. Thank-you emails are sent to your account email address; tipping does not automatically publish your identity.
19. How We Use Information
MTGCommand may use information described in this Policy to:
- create and maintain accounts;
- authenticate users;
- protect accounts and sessions;
- provide collection-management features;
- identify exact card printings;
- maintain inventory quantities;
- maintain physical card locations;
- calculate collection value;
- provide card-search functionality;
- create and manage decks;
- analyze decks;
- generate gameplay recommendations;
- manage event pools;
- provide manual intake;
- operate scanner features;
- provide Seller Hub functionality;
- publish information a user intentionally designates for public display;
- provide account recovery;
- respond to support requests;
- diagnose errors;
- investigate abuse;
- detect fraud or unauthorized access;
- protect the service;
- enforce applicable site rules;
- maintain backups;
- improve application performance;
- develop and improve features;
- comply with applicable law;
- establish, exercise, or defend legal claims.
20. Automated Analysis and Recommendations
MTGCommand may use automated rules, algorithms, statistical techniques, artificial-intelligence-assisted processes, or similar technologies to perform functions such as:
- card identification;
- exact-printing resolution;
- image recognition;
- card matching;
- deck analysis;
- synergy analysis;
- card-role analysis;
- card recommendations;
- collection analysis;
- search-result ranking.
These systems may make mistakes.
Where a scanner or resolver is uncertain about an exact printing or physical characteristic, MTGCommand may request user confirmation rather than silently treating an uncertain result as fact.
Automated gameplay or collection recommendations do not have legal or similarly significant effects on users.
21. How We Share Information
MTGCommand does not need to make private user collections publicly accessible merely to operate the service.
Information may nevertheless be disclosed in the circumstances described below.
21.1 Service and Infrastructure Providers
Information may be processed by service providers that help us operate MTGCommand, such as providers of:
- web hosting;
- network infrastructure;
- content delivery;
- security;
- email;
- database or storage services;
- error monitoring;
- payment processing if introduced;
- other necessary technical services.
These providers may process information necessary to perform services on our behalf.
21.2 At Your Direction
We may disclose information when you deliberately choose to publish, share, export, or otherwise provide it to another person or service.
Examples can include:
- public Seller Hub profiles;
- public promotions;
- shared deck information;
- exported data;
- links you intentionally publish.
21.3 Legal Requirements
We may preserve or disclose information where reasonably necessary to:
- comply with applicable law;
- respond to lawful legal process;
- comply with a valid court order, subpoena, or governmental request;
- investigate fraud;
- protect the security of the service;
- prevent abuse;
- protect users or others from harm;
- enforce our legal rights;
- defend legal claims.
We do not interpret this section as granting government agencies unrestricted access to MTGCommand user data.
21.4 Business Transfers
If MTGCommand or substantially all of its relevant assets are acquired, merged, reorganized, sold, or transferred, user information may be transferred as part of that transaction subject to applicable law.
21.5 Aggregated or De-Identified Information
We may use or disclose information that has been aggregated or reasonably de-identified so that it is not reasonably linked to an identifiable individual.
22. Sale of Personal Information
As of the effective date of this Privacy Policy:
MTGCommand does not sell users' personal information for money.
MTGCommand also does not intend to share users' personal information for cross-context behavioral advertising or targeted advertising as those concepts are defined under applicable privacy laws.
If these practices materially change, this Privacy Policy and legally required opt-out mechanisms will be updated before or when such changes become applicable.
23. Public and Private Information
MTGCommand distinguishes between private workspace information and information intentionally submitted for publication.
Private by default may include:
- account email;
- authentication information;
- collection inventory;
- exact owned printings;
- quantities;
- private card locations;
- private decks;
- event pools;
- scanner submissions;
- account settings;
- private analyses.
Potentially public information may include:
- seller names;
- brand names;
- seller biographies;
- public Seller Hub profiles;
- approved promotions;
- public images or logos;
- marketplace links;
- deck information a user deliberately chooses to publish;
- other information a user expressly makes public.
Once information is made public, other people may view, copy, screenshot, save, or redistribute it outside MTGCommand's control.
Users should not publish information they wish to keep private.
24. Third-Party Card, Pricing, and Marketplace Services
MTGCommand may use, reference, link to, or obtain information from third-party services relating to Magic: The Gathering cards, pricing, marketplace information, or seller profiles.
Third-party services may have their own privacy policies and terms.
MTGCommand's Privacy Policy does not govern information that a user independently submits directly to those third parties.
25. External Links
MTGCommand may contain links to third-party websites or services.
For example, a seller may provide a link to a marketplace profile.
If you follow an external link, the third party may collect information according to its own practices.
MTGCommand is not responsible for the privacy practices of independently operated third-party websites.
26. Data Security
MTGCommand uses administrative, technical, and organizational measures intended to protect information against unauthorized access, misuse, modification, destruction, or disclosure.
Depending upon the system involved, these measures may include:
- password hashing;
- hashed session credentials;
- limited-lifetime authentication sessions;
- CSRF protections;
- access controls;
- user-specific authorization;
- encrypted HTTPS connections;
- network security services;
- web-server protections;
- infrastructure security;
- application logging;
- security monitoring;
- backups;
- administrative access restrictions;
- software updates;
- server-level protections.
No Internet-connected system can guarantee absolute security.
Accordingly, MTGCommand cannot promise that unauthorized access, compromise, hardware failure, software vulnerabilities, or other security incidents will never occur.
Users are responsible for protecting their own account credentials and should use a strong, unique password.
Do not provide your MTGCommand password to another person.
27. Security Incidents
If MTGCommand discovers a security incident involving personal information, we may:
- investigate the incident;
- preserve relevant evidence;
- contain the incident;
- reset or revoke affected sessions;
- require password changes;
- correct vulnerabilities;
- notify affected service providers;
- notify users when appropriate;
- notify governmental or regulatory authorities when required by applicable law.
The exact response will depend upon the nature and scope of the incident and applicable legal requirements.
28. Data Retention
MTGCommand retains information for periods reasonably necessary to provide, secure, maintain, and improve the service and to satisfy applicable legal obligations.
Retention depends upon the type of information and why it is processed.
For example:
Account information
Account information may generally be retained while an account remains active and for an appropriate period afterward where necessary for security, fraud prevention, dispute resolution, backup integrity, or legal compliance.
Collection, deck, and event information
User-created collection, inventory, deck, and event-pool information may generally remain associated with an account until the user deletes the applicable information, closes the account, or requests deletion, subject to legitimate retention exceptions.
Sessions
Authentication sessions may be retained until they expire, are revoked, are invalidated, or are no longer required.
Password-reset and invitation records
Security-token records may be retained long enough to operate the feature and maintain appropriate security or audit information.
Logs
Technical and security logs may be retained according to operational, troubleshooting, security, provider, and legal requirements.
Backups
Deleted information may temporarily continue to exist in backups until those backups rotate, expire, or are replaced in the ordinary course.
Backups are intended for disaster recovery and system integrity and are not intended to be used to restore individual deleted records except when necessary for system recovery.
Legal and security retention
Information may be preserved longer where reasonably necessary to:
- comply with law;
- respond to litigation;
- enforce agreements;
- investigate security incidents;
- prevent fraud or abuse;
- protect legal rights.
We seek not to retain identifiable information indefinitely when there is no legitimate reason to continue retaining it.
29. Account Deletion
Users may request deletion of their MTGCommand account and associated personal information.
Subject to applicable exceptions, deletion may include information such as:
- account information;
- collection records;
- decks;
- event pools;
- account settings;
- other user-specific application records.
Certain information may remain temporarily in backups, security logs, fraud-prevention records, or records that we are legally required or reasonably entitled to retain.
Information that has been properly de-identified so that it can no longer reasonably be associated with the user may also be retained.
Public information that has been independently copied or distributed by other users or third parties may remain outside MTGCommand's control.
30. Access, Correction, and Export
Users may request, where applicable:
- access to personal information associated with their account;
- correction of inaccurate information;
- deletion of personal information;
- a copy or export of certain account information;
- information concerning categories of data collected;
- information concerning the purposes for which data is used;
- information concerning categories of recipients to whom personal information is disclosed.
Some information may also be directly editable within MTGCommand.
31. Privacy Rights Under Applicable Law
Depending upon where you live and which privacy laws apply, you may have rights such as:
- the right to know whether personal information is being processed;
- the right to know categories of personal information collected;
- the right to access personal information;
- the right to correct inaccurate personal information;
- the right to request deletion;
- the right to receive certain information in a portable format;
- the right to restrict certain processing;
- the right to object to certain processing;
- the right to withdraw consent where processing depends upon consent;
- the right to opt out of certain sales, sharing, targeted advertising, or profiling where applicable;
- the right not to receive unlawful discriminatory treatment for exercising privacy rights;
- the right to appeal certain privacy-request decisions where applicable;
- the right to complain to an appropriate data-protection authority.
These rights are subject to applicable legal requirements and exceptions.
32. Verification of Privacy Requests
Before disclosing, modifying, exporting, or deleting account information, MTGCommand may need to verify that the requester is authorized to exercise rights concerning that account.
Verification may involve:
- account authentication;
- confirmation through the account email address;
- information reasonably necessary to verify account ownership;
- another appropriately secure verification method.
We will not request unnecessary sensitive information merely to process a privacy request.
Authorized agents may submit requests where applicable law permits, subject to appropriate verification of their authority.
33. Appeals
Where applicable law provides a right to appeal a decision regarding a privacy request, users may submit an appeal through the privacy-contact method identified below.
We may request sufficient information to identify the earlier request and reconsider the decision.
34. California Privacy Rights
Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), applies to MTGCommand or a particular processing activity, eligible California residents may have rights including:
- the right to know what personal information is collected;
- the right to access certain personal information;
- the right to know how personal information is used and disclosed;
- the right to request deletion, subject to exceptions;
- the right to request correction;
- the right to opt out of the sale or sharing of personal information where applicable;
- the right to limit certain uses of sensitive personal information where applicable;
- the right not to receive discriminatory treatment for exercising applicable privacy rights.
As of the effective date of this Privacy Policy, MTGCommand does not sell personal information for money and does not intend to share personal information for cross-context behavioral advertising.
35. European Economic Area, United Kingdom, and Similar Jurisdictions
Where the European Union General Data Protection Regulation (“GDPR”), United Kingdom GDPR, or similar privacy law applies, MTGCommand will process personal information using an applicable lawful basis.
Depending upon the processing activity, a lawful basis may include:
- performing a contract or providing a requested service;
- legitimate interests in operating, maintaining, securing, and improving MTGCommand;
- compliance with legal obligations;
- consent, where consent is required.
Eligible individuals may have rights including access, correction, erasure, restriction, portability, objection, withdrawal of consent, and the right to lodge a complaint with an appropriate supervisory authority.
The availability and scope of these rights depend upon applicable law and the circumstances of the processing.
36. International Users and Data Transfers
MTGCommand is operated using infrastructure that may be located in the United States.
If you access MTGCommand from another country, information may be transferred to, processed in, or stored in the United States or another jurisdiction where a service provider operates.
Privacy and data-protection laws in those jurisdictions may differ from the laws of your country.
Where legally required, appropriate mechanisms will be used for international transfers of personal information.
37. Global Privacy Control and Do Not Track
Some browsers or extensions provide signals such as Global Privacy Control (“GPC”) or “Do Not Track.”
Where applicable law requires recognition of a legally valid browser-based opt-out signal, MTGCommand will seek to honor that requirement.
Because MTGCommand does not currently sell personal information or use it for cross-context behavioral advertising, such a signal may not result in a visible change to the service.
Traditional “Do Not Track” signals do not have a universally adopted legal or technical standard.
38. Children's Privacy
MTGCommand is a general-audience Magic: The Gathering service and is not directed specifically toward children under 13 years of age.
We do not knowingly seek to collect personal information from children under 13 in violation of the Children's Online Privacy Protection Act (“COPPA”).
Where another jurisdiction establishes a different minimum age for independent consent to data processing, applicable local requirements may apply.
If we learn that personal information has been collected from a child in circumstances requiring parental consent and that legally sufficient consent was not obtained, we will take reasonable steps to delete or otherwise appropriately address the information.
A parent or legal guardian who believes a child has provided personal information improperly may contact us using the privacy-contact information below.
39. User Responsibilities
Users can help protect their privacy and security by:
- using a strong and unique password;
- keeping credentials confidential;
- signing out on shared devices;
- securing the email account associated with MTGCommand;
- avoiding unnecessary sensitive information in custom fields;
- reviewing information before making it public;
- keeping browser and operating-system software updated;
- promptly notifying MTGCommand of suspected unauthorized account access.
40. Public Seller Content and User-Submitted Material
Users are responsible for content they intentionally publish through public features.
Do not publish:
- private credentials;
- another person's personal information without authorization;
- financial account numbers;
- home addresses unless genuinely necessary and intentionally public;
- government identifiers;
- sensitive personal information that is unnecessary for the feature.
MTGCommand may remove or restrict information that presents a security, privacy, legal, or abuse concern.
41. De-Identified and Aggregated Information
MTGCommand may create statistics or datasets that do not reasonably identify individual users.
Examples might include aggregated information about:
- popular cards;
- commonly used commanders;
- deck archetypes;
- scanner accuracy;
- feature usage;
- catalog coverage;
- application performance.
Where information is maintained in a de-identified form, we may use it for product development, statistics, research, reliability, and other legitimate purposes.
We do not intend to deliberately re-identify properly de-identified information except where necessary to test or maintain de-identification protections or where otherwise permitted by law.
42. Changes to MTGCommand
MTGCommand is under active development.
Features may be added, modified, removed, or redesigned.
New functionality may create new categories of information processing.
Examples could include:
- improved scanner recognition;
- scanner learning from user corrections;
- additional seller functionality;
- subscriptions;
- payment processing;
- social or sharing features;
- additional analytics;
- collection import/export;
- integrations with other services.
If a new feature materially changes how personal information is collected, used, retained, or shared, this Privacy Policy will be updated as appropriate.
Where legally required, additional notice or consent will be obtained.
43. Changes to This Privacy Policy
We may revise this Privacy Policy periodically.
When we make changes, we will update the “Last Updated” date at the top of the Policy.
If a change materially affects how existing personal information is used, additional notice may be provided through methods such as:
- a notice on MTGCommand.com;
- an account notification;
- email;
- another reasonable communication method.
Continued use of MTGCommand following an update is subject to the revised Policy, except where applicable law requires additional consent.
44. No Sale of User Collections
A user's collection is one of the core private datasets maintained by MTGCommand.
MTGCommand does not treat private collection information as a commercial mailing list or a dataset to be sold to card stores, marketplaces, advertisers, data brokers, or unrelated third parties.
This includes information concerning:
- cards owned;
- exact printings owned;
- quantities;
- collection value;
- binder or storage locations;
- private decks;
- private event pools.
Disclosure may still occur where specifically described elsewhere in this Policy, such as at the user's direction, to necessary service providers, or where legally required.
45. Ownership of User Data
Providing information to MTGCommand does not transfer ownership of a user's physical Magic cards, decks, collection, or other property to MTGCommand.
Users retain their rights in their own user-created content and collection information, subject to the limited rights necessary for MTGCommand to host, process, display, analyze, back up, and otherwise provide the service.
Magic: The Gathering card names, artwork, trademarks, game information, and related intellectual property may be owned by Wizards of the Coast, Hasbro, artists, licensors, or other respective rights holders and are separate from user personal information.
46. Privacy by Design for Future Features
As MTGCommand develops new functionality, the service intends to continue applying several principles:
- collect only information reasonably necessary for a feature;
- keep private information private by default;
- separate users' private records;
- avoid silently guessing uncertain scanner information;
- avoid unnecessary sensitive-information collection;
- use public visibility only where intended;
- provide reasonable controls over user information;
- protect authentication credentials;
- disclose material changes in data use;
- avoid selling private collection information.
These principles are intended to guide both existing and future MTGCommand development.
47. Contact Us and Privacy Requests
Questions, concerns, privacy requests, account-deletion requests, data-access requests, correction requests, or other privacy-related communications may be submitted to MTGCommand through its designated privacy contact.
Website: MTGCommand.com
Privacy Contact: [email protected]
Please include enough information for us to understand and appropriately respond to your request.
Do not send your password, complete payment-card information, Social Security number, or other unnecessary sensitive information in a privacy request.
We may need to verify account ownership before fulfilling a request involving account information.
48. Effective Date
This Privacy Policy is effective as of:
October 7, 2026
The current version should be made available from MTGCommand.com wherever users can reasonably access legal and privacy information.
Last Updated: October 8, 2026
Device copies and anonymous performance measurements
You may choose to save private collection and deck copies in this browser for offline access. These copies are kept for up to 30 days. Pending intake remains on the device until synchronized or cleared. Device copies are separated by account and cleared when you sign out or switch accounts through Command Center. Anyone with access to your unlocked browser may be able to view an enabled offline copy; enable this option only on a device you control. Browser storage can be removed by your browser or device, so export important pending entries before clearing data.
We collect limited first-party, anonymous daily counts and performance histograms to diagnose loading, responsiveness, layout stability, application errors and scanner operation. These measurements do not include card names, email addresses, camera images, error messages, stack traces, visitor identifiers or cross-visit browsing profiles. They are retained for up to 30 UTC days. You can turn these measurements off in Settings; the browser's Do Not Track preference is also respected. Ordinary account and security logs are described elsewhere in this Policy.