Privacy policy
What data Cardhigher handles, why, for how long, and what you can do about it. It is written from what the code does, and it can be checked.
This document is incomplete
The operator’s identifying details have not been filled in yet: they appear in brackets, like [TITULAR_LEGAL]. Until they are, this page is not indexed by search engines and is left out of the sitemap, because a half-finished legal document in public is worse than none.
If you got here and need that information, write to us with the feedback button on any screen.
First, in one line
Coming to Cardhigher and playing stores nothing on any server and leaves no cookies. Data only leaves your browser if you do something specific: submit a streak to the leaderboard, or write a message.
Controller: [TITULAR_LEGAL], [NIF_CIF], [DOMICILIO_LEGAL]. For anything about your data: [EMAIL_PRIVACIDAD].
What is stored in your own browser
Nothing until you do something that can only work by remembering it. If you arrive, look and leave, your browser is left as it was. All of this stays on your device, is sent nowhere, and is cleared from Settings or by clearing your browser data.
| What is stored | What for | When it appears |
|---|---|---|
| topdeck.v1.favs | Which games you marked as yours, to show them first | When you pick them |
| topdeck.v1.settings | Theme, animation, haptics and sound | When you change a setting |
| topdeck.v1.lang | Your language, if you choose one other than the browser’s | When you choose it |
| topdeck.v1.bests | Your best streak in each mode | When a run ends |
| topdeck.v1.career | How many runs you have played and how many you got right | When a run ends |
| topdeck.v1.years | The year filter you set on a game | When you set it |
| topdeck.v1.name | The name you play under | When you type it |
| topdeck.v1.device | A random number identifying this browser | When you submit a streak or a message |
| topdeck.v1.boardtag | A mark to recognise your row on the leaderboard | When you submit a streak |
If you submit a streak to the leaderboard
The server stores: the name you type, the streak, when it was submitted, and your browser’s random identifier. Nothing else. No email, age, location or anything else is asked for or stored.
The name and the streak are public: they are in the table anyone can see. The identifier is not: it does not appear in the table, it exists so that you take one row and so that you can ask for it to be deleted.
Legal basis: your consent, given by typing a name and pressing submit. Retention: while the streak stays in that mode’s top fifty, or until you ask for it to be deleted, whichever comes first. You can delete it yourself from Settings, with the button that removes your name from the leaderboard, with no explanation and without writing to anyone.
If you write through the feedback box
What is stored: the text of the message, when it was sent, the language the page was in, and which screen you were on. The last two exist so that a “this is broken” can be understood without guessing where.
No email is asked for, which is why there can be no reply: it is a postbox, not a conversation. The User-Agent, the country and your browser’s identifier are not stored with the message.
Legal basis: your consent, given by writing and sending. Retention: 60 days, after which the message deletes itself.
Per-connection limits
So that nobody can flood the leaderboard or the postbox, the server counts how many submissions arrive in a day from the same connection. It does not store your IP address: it stores a signature of it, computed with a server secret, which tells two connections apart without saying which is which. That counter expires on its own after 24 hours.
Legal basis: legitimate interest in protecting the service against abuse and automated submissions.
Who it is shared with, and what each one receives
Cardhigher does not sell data and does not pass it to anyone for commercial purposes. These are all the third parties involved, and what each one receives:
| Who | What for | What they receive | When |
|---|---|---|---|
| Cloudflare | Hosting for the site and the server, and the store for the leaderboard and messages | Your IP address and the request data, like any web server | Always |
| wsrv.nl | Resizes the card images | Your IP address and the request data. Its policy says logs are kept for 7 days | On any screen with cards |
| Scryfall | Serves Magic card images | Your IP address and the request data | When you play Magic |
| Pokémon TCG API | Serves Pokémon card images | Your IP address and the request data | When you play Pokémon |
| dotGG | Serves One Piece card images | Your IP address and the request data | When you play One Piece |
| PayPal | Receives voluntary contributions | Whatever you give it once you are on its page | Only if you press the support button |
| Amazon, Cardmarket, TCGplayer | Shops linked to for looking a card up | Whatever any visitor arriving from a link gives them | Only if you press a shopping link |
| X, Facebook, WhatsApp, Telegram, Bluesky, Reddit | Posting a streak on that network | Whatever any visitor opening their page gives them | Only if you press that share button |
The share buttons are links
When a run ends you can tell someone about it. Those buttons load nothing from anyone: they are ordinary addresses, like any other link on the page, and until you press one your browser talks to no social network. There is no Facebook SDK, no X widget and no third-party script anywhere on this site.
That matters because it is what most sites do the other way around: a Facebook like button contacts Facebook and drops its cookies the moment the page opens, whether you pressed it or not. That does not happen here, and you can check it in your browser’s network tab.
The image of your streak, if you save one, is drawn in your own browser and is sent to no server, ours included.
Transfers outside the European Economic Area
Some of those providers are US companies or use global infrastructure, so processing may take place outside the EEA. The specific mechanism covering each transfer depends on each provider’s terms and has not been verified against documents: it is pending legal review and will be stated here once it is. No safeguard is claimed that has not been checked.
Analytics, advertising and profiling
There is none of the three. No Google Analytics, no Tag Manager, no Meta Pixel, no heatmaps, no pixels, no SDKs. No ads either. There is no profiling and no automated decision-making about you.
You can check this: open your browser’s developer tools, the network tab, and look at which domains the page connects to. You will see only its own and the card image ones.
Children
Cardhigher does not ask for your age, and it does not ask because it does not need to: there are no accounts, no profiling, no advertising, no marketing messages and no purchases. Asking for a date of birth for nothing would be collecting one field too many.
The only data a child could supply is the name typed on the leaderboard or the text of a message. That is why both explicitly ask for no real names and no personal details, and why the leaderboard entry can be deleted from Settings with no explanation.
Your rights
You can ask for access to your data, for it to be corrected or deleted, for processing to be restricted or objected to, and for portability. Where processing is based on your consent, you can withdraw it at any time, without affecting what was done before.
Two of them need no asking: deleting your leaderboard entry is in Settings, in the button that removes your name, and deleting everything held in your browser is there too, in the button that wipes your data.
For the rest, write to [EMAIL_PRIVACIDAD]. Bear in mind that Cardhigher has no accounts: to find your data we will need the name you played under or your browser’s identifier, which you can see in Settings. If you cannot supply them, it may not be possible to locate any data of yours, and you will be told so.
If you believe your data is not being handled properly, you can complain to the competent supervisory authority: [AUTORIDAD_DE_CONTROL].
Security
The site is served over HTTPS only, with headers that stop it being embedded in another page, stop third-party code being loaded, and turn off browser permissions it does not use. Messages and streaks are stored in Cloudflare’s store, which only the operator can reach.
No measure makes an incident impossible. If one occurred affecting personal data, it would be handled in accordance with the applicable rules.
Date
Last updated and in force since: 23 September 2026. Earlier versions of this document are in the project repository’s history.