Privacy Policy
- Effective date: 19 July 2026
- Last updated: 5 October 2026
This policy explains what Sanctum ("the app", "we") collects, why, and what you can do about it. Sanctum is an unofficial life and lore tracker for tabletop card games. It is not affiliated with Wizards of the Coast.
Sanctum is operated by Vizanalysis LLC ("we"), contactable at mate@vizanalysis.com.
The short version
- You can use the whole in-game tracker without an account. In that mode your games stay on your device; the only things that leave it are card lookups (see "Card data").
- If you create an account, we store your email, your profile, and the content you choose to save (decks, game history, groups, photos you upload).
- Every image you upload is public while it exists. Profile photos, playmat images, pet-card art, and board photos are served from public links that anyone can open. Don't upload anything private.
- Board photos are deleted when the game ends — we don't keep photographs of your table around.
- We use no analytics, no advertising, no trackers, and no third-party marketing SDKs. We do not sell or share your personal data, and we do not profile you.
- You can delete your account from inside the app at any time — Profile → Account → Delete account — which erases your profile, decks, photos and personal records. Games recorded by other people may keep the name you played under.
What we collect
If you don't sign in: nothing about your games leaves your device. Your in-progress game and local history are stored only on your phone. The one exception is card data (below).
Card data. Whenever you search for cards, build or import a deck, or use the dungeon and Planechase trackers, the app first looks the cards up in our own copy of Scryfall's card data, held on our servers. Our server receives what you searched for and, like any web request, your IP address; if you're signed in, the request is tied to your account. We use it only to answer the search and don't keep a history of your searches, though our hosting provider keeps routine request logs for a short period.
If our copy doesn't have what you need, and for a few lookups such as listing a card's printings, your device asks Scryfall's public API directly. Card images are always loaded straight from Scryfall's image servers. In those cases Scryfall receives the card names or images requested, your IP address, and our app's identifier — never your account, email, or handle. This happens whether or not you have an account. Scryfall's own privacy policy governs what they do with it.
Account information. When you create an account we collect your email address and a password. Passwords are handled by our authentication provider and stored only as a salted hash — we never see or store your password. You also choose a handle and a display name, and may optionally upload a profile photo.
Content you create. Depending on which features you use, we store: decks and card lists you save or import; pet cards; custom playmat colours and images; saved game history (player names, results, format, duration, and the in-game event log); groups you create or join and your membership/role; achievements and titles; cosmetic items you own; and tournaments you create, join, or play in.
Images you upload. Profile photos, playmat images, pet-card art, and board photos you take during a game are stored in our file storage. All of them are served from public URLs. Anyone who has the link can open it, whether or not they use Sanctum. We don't index or publish those links, but they are not secret. Please don't upload anything you wouldn't want publicly visible, and don't photograph people who haven't agreed to it.
Board photos are temporary. A board photo is a during-play aid — it shows the physical table to players following along remotely. We delete board photos as soon as the game ends, and again whenever you start a new game. If a game is abandoned rather than finished, its photos are removed the next time you open the app. They are also removed if you delete your account, and we run periodic cleanups to catch any left behind by a device that never comes back. Profile photos, playmats, and pet-card art are kept until you change or delete them.
Other players ("guests"). When you record a game or run a tournament you can type in names for people who don't have a Sanctum account. We store those names as part of your game and tournament records. Please only enter names those players are comfortable with. If someone wants their name removed from a record, contact us.
Live and spectated games. If you start a live game, the game's state (player names, life totals, and other tracked values) is sent to our server so other devices in that game stay in sync. If the host additionally makes the table public for spectating, that state becomes visible to the seated players' friends. Only the host can turn spectating on. When you are not in a live game, no game state is sent to us.
Groups, events and invites. If you ask to join a group, we store your request and any message you write; that group's admins see your name and message. If you invite a friend, or are invited, we store who invited whom and to what. Event sign-ups record whether you're going or on the waitlist. A group admin can list a group in the directory, which shows other signed-in users its name, description, rough area, formats, usual meeting time, icon, member count and upcoming event titles and times — never its member names or game history. An admin can also turn on a public page for a single event: anyone with that link, signed in or not, can see the event's title, description, times and number of open spots, plus the group's name, area and member count. Public event pages never show the event's location or who is going.
Notifications. If you're signed in, we store notifications meant for you (for example a friend's invite, an answer to a join request, or your turn in a draft) so the app can show them, until you delete your account. If you allow push notifications, we store your device's push token with your account so we can deliver them; it's removed when you sign out or delete your account, and when the device stops accepting notifications. Push notifications are delivered through Google's Firebase Cloud Messaging (and, on iPhone, Apple's Push Notification service), which receive the token and the notification's text.
Subscription status. If you subscribe we store your entitlement tier and, for trials, an expiry date. We never receive or store your payment card details — those go to Apple or Google and are handled under their terms.
Moderation reports. If you report an image, we record that you reported it, the image, and the account it belonged to, so repeated abuse can be actioned.
Feedback and crash reports. If you send feedback or report a bug, we store your message together with your app version, device model, OS version, and — if you reported from inside a game — a summary of that game (player count, format, turn). No player names, life totals or photos are included. If the app crashes, the error is saved on your device only; the next time you open Sanctum we show you what was recorded and ask whether to send it. Nothing is ever transmitted automatically, and declining deletes it.
What we do NOT collect. No advertising identifiers, no location data, no contacts, no device fingerprinting, no behavioural analytics, no third-party crash-reporting SDK, no automatic crash telemetry (see "Feedback and crash reports" above), no cross-app or cross-site tracking. The app contains no ad networks or marketing SDKs of any kind.
Device permissions
- Camera — used to scan QR codes (to join a tournament, group, or friend) and, if you choose, to take a board photo during a game. QR scans are processed on your device and never uploaded. Board photos you take are uploaded to our file storage and, like every uploaded image, are served from a public URL — but they are deleted when the game ends.
- Photo library — used so you can pick a profile photo, a playmat image, or pet-card art. We access only the file you choose.
- Notifications — used to tell you about invites, join requests, events and your turn in a draft while the app is closed.
All are optional; declining them only disables those specific features.
Why we use your data (and legal bases)
- To operate the account and features you asked for — performance of our contract with you.
- To keep the service secure and prevent abuse, including moderation — our legitimate interests.
- To provide and administer subscriptions, and to keep tax and accounting records — contract, and legal obligation.
- To comply with the law — legal obligation.
Where we rely on legitimate interests, we've limited processing to what the feature actually requires. We do not process data for advertising, profiling, or automated decision-making that has legal effects.
Who your data is shared with
We do not sell your personal data and we do not share it with advertisers. Data reaches these parties only as described:
- Supabase — our hosting, authentication, database, and file-storage provider, processing data on our behalf under a data-processing agreement.
- Scryfall — as described under "Card data" above.
- Google (Firebase Cloud Messaging) and Apple (Push Notification service) — deliver push notifications if you allow them; they receive your device's push token and the notification text.
- Archidekt / Moxfield — only if you paste one of their public deck URLs to import a deck, in which case your device fetches that deck at your direction.
- Apple and Google — handle all purchases and subscriptions through the App Store and Google Play. Once paid subscriptions launch we also use RevenueCat to manage entitlements; we receive only your subscription status.
- Discord — only if an administrator of your group configures a Discord webhook, in which case group notifications (which may include player names and results) are posted to that channel. Group admins choose this; ask your admin if unsure.
- Other users — by design, your handle, display name, profile photo, title, and subscription tier are visible to other signed-in users; your game results, decks, and achievements are visible to the groups you join and the friends you add. What a group shows in the directory, and what a public event page shows to anyone with its link, is described under "Groups, events and invites" above.
We may also disclose data where legally required, or to establish or defend legal claims.
International transfers
Our infrastructure providers may process and store data outside your country, including in the United States. Where required, such transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
How long we keep it
We keep your account data for as long as your account exists. The exception is board photos, which are deleted as soon as the game they were taken in ends — see "Board photos are temporary" above.
When you delete your account, your profile, decks, pet cards, achievements, group memberships, personal game records, and every image you uploaded are deleted immediately and irreversibly. Copies may persist briefly in encrypted backups before being overwritten on our provider's normal backup cycle.
Two things deliberately survive:
- Games recorded by other people. A game another member recorded is their record, not yours, and isn't deleted with your account — the name you played under may remain in it. Games you recorded yourself are deleted.
- Moderation records. If an image of yours was reported, we may keep that report after deletion where necessary to prevent abuse and to establish or defend legal claims.
Your rights
Depending on where you live (for example under the GDPR or the CCPA/CPRA), you may have the right to access, correct, export, delete, or restrict processing of your personal data, to object to processing, and to lodge a complaint with your data-protection authority. We do not sell or "share" personal information as those terms are defined under California law, so there is nothing to opt out of.
You can exercise the most important of these directly in the app: edit your profile in Profile, and delete everything via Profile → Account → Delete account. For anything else — including a copy of your data, or a request to remove your name from someone else's game record — contact mate@vizanalysis.com and we will respond within the time required by applicable law (usually within one month).
Children
Sanctum is not directed at children under 13 (or under 16 in regions where that is the relevant age), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact mate@vizanalysis.com and we will delete it.
Security
Data is transmitted over encrypted connections (TLS) and access is enforced at the database level by row-level security, so accounts can only reach their own data and the data of groups they belong to. Passwords are stored only as salted hashes. No system is perfectly secure, but we design access rules to be restrictive by default. Note the caveat above: uploaded images are served from public URLs and are not protected by those rules.
Changes to this policy
If we make material changes we will update the "Last updated" date and, where the change is significant, notify you in the app. Continuing to use Sanctum after a change means you accept the updated policy.
Contact
Questions, requests, or complaints: mate@vizanalysis.com.