LOCAL-FIRST / EXPLICIT CONSENT

Privacy follows the action.

Guest drafts stay in your browser. Riftbound Group will not upload a draft to an account merely because you sign in; a private save will always start with a clear choice.

What the site does today

Accounts and provider sign-in are not enabled yet. The Builder stores drafts in your browser's IndexedDB. Imported files are read in your browser, and Riftbound Group does not retain the original file. Card searches and card-reference resolution requests are sent to the service so results can be returned. A deck in a share-link fragment is handled by the receiving browser and is not included in ordinary HTTP requests.

Service and security data

The website and its Microsoft Azure hosting may process standard request metadata—such as IP address, time, requested path, user agent, and response status—to deliver, secure, and troubleshoot the service. Riftbound Group does not run advertising profiles or sell personal information. Do not place sensitive personal information in deck titles or imported deck text.

Read the Microsoft Privacy Statement →

Accounts and private saves

When account features are activated, Riftbound Group will limit provider data to a stable Google or Discord account identifier and a display name; it will not request provider email. Provider access and refresh tokens will not be retained. An explicit private save will store the canonical deck, its ownership and revision metadata, and the session and security records needed to protect it. Private decks will not be published by default.

Account-data retention

OAuth sign-in transactions expire after 10 minutes. Sessions expire after 30 days without activity and no later than 90 days after they are created; signing out or deleting the account revokes them sooner. Account records remain until the account is deleted. A connected-provider identity remains until it is disconnected or the account is deleted. Private decks remain until you delete the deck or account.

Expired security records are removed by routine cleanup. Account deletion removes the live account, connected identities, sessions, and private decks. Deleted data may remain in platform backups until those backups age out: 7 days in staging and 14 days in production. Production account data will not be copied into staging.

Your control

Today, you can remove local drafts by deleting them in the Builder or by clearing this site's browser storage. Exported files and share links are copies under the recipient's control. Account export, private-deck deletion, session revocation, identity disconnection, and account deletion will be available before account storage is opened to users.

Identity providers

When sign-in launches, Google and Discord will process information under their own policies only when you choose that provider. Google and Discord credentials for staging and production will remain separate, and production account data will not be copied into staging.

Read the Google Privacy Policy →
Read the Discord Privacy Policy →

Contact and updates

Last updated July 28, 2026. Send privacy questions and account-data requests to sungpichung@gmail.com. This address is monitored. Material changes will be reflected on this page before the affected feature is activated.