Privacy policy

What data Cardhigher handles, why, for how long, and what you can do about it. It is written from what the code does, and it can be checked.

This document is incomplete

The operator’s identifying details have not been filled in yet: they appear in brackets, like [TITULAR_LEGAL]. Until they are, this page is not indexed by search engines and is left out of the sitemap, because a half-finished legal document in public is worse than none.

If you got here and need that information, write to us with the feedback button on any screen.

First, in one line

Coming to Cardhigher and playing stores nothing on any server and leaves no cookies. Data only leaves your browser if you do something specific: submit a streak to the leaderboard, or write a message.

Controller: [TITULAR_LEGAL], [NIF_CIF], [DOMICILIO_LEGAL]. For anything about your data: [EMAIL_PRIVACIDAD].

What is stored in your own browser

Nothing until you do something that can only work by remembering it. If you arrive, look and leave, your browser is left as it was. All of this stays on your device, is sent nowhere, and is cleared from Settings or by clearing your browser data.

What is storedWhat forWhen it appears
topdeck.v1.favsWhich games you marked as yours, to show them firstWhen you pick them
topdeck.v1.settingsTheme, animation, haptics and soundWhen you change a setting
topdeck.v1.langYour language, if you choose one other than the browser’sWhen you choose it
topdeck.v1.bestsYour best streak in each modeWhen a run ends
topdeck.v1.careerHow many runs you have played and how many you got rightWhen a run ends
topdeck.v1.yearsThe year filter you set on a gameWhen you set it
topdeck.v1.nameThe name you play underWhen you type it
topdeck.v1.deviceA random number identifying this browserWhen you submit a streak or a message
topdeck.v1.boardtagA mark to recognise your row on the leaderboardWhen you submit a streak

If you submit a streak to the leaderboard

The server stores: the name you type, the streak, when it was submitted, and your browser’s random identifier. Nothing else. No email, age, location or anything else is asked for or stored.

The name and the streak are public: they are in the table anyone can see. The identifier is not: it does not appear in the table, it exists so that you take one row and so that you can ask for it to be deleted.

Legal basis: your consent, given by typing a name and pressing submit. Retention: while the streak stays in that mode’s top fifty, or until you ask for it to be deleted, whichever comes first. You can delete it yourself from Settings, with the button that removes your name from the leaderboard, with no explanation and without writing to anyone.

If you write through the feedback box

What is stored: the text of the message, when it was sent, the language the page was in, and which screen you were on. The last two exist so that a “this is broken” can be understood without guessing where.

No email is asked for, which is why there can be no reply: it is a postbox, not a conversation. The User-Agent, the country and your browser’s identifier are not stored with the message.

Legal basis: your consent, given by writing and sending. Retention: 60 days, after which the message deletes itself.

Per-connection limits

So that nobody can flood the leaderboard or the postbox, the server counts how many submissions arrive in a day from the same connection. It does not store your IP address: it stores a signature of it, computed with a server secret, which tells two connections apart without saying which is which. That counter expires on its own after 24 hours.

Legal basis: legitimate interest in protecting the service against abuse and automated submissions.

Who it is shared with, and what each one receives

Cardhigher does not sell data and does not pass it to anyone for commercial purposes. These are all the third parties involved, and what each one receives:

WhoWhat forWhat they receiveWhen
CloudflareHosting for the site and the server, and the store for the leaderboard and messagesYour IP address and the request data, like any web serverAlways
wsrv.nlResizes the card imagesYour IP address and the request data. Its policy says logs are kept for 7 daysOn any screen with cards
ScryfallServes Magic card imagesYour IP address and the request dataWhen you play Magic
Pokémon TCG APIServes Pokémon card imagesYour IP address and the request dataWhen you play Pokémon
dotGGServes One Piece card imagesYour IP address and the request dataWhen you play One Piece
PayPalReceives voluntary contributionsWhatever you give it once you are on its pageOnly if you press the support button
Amazon, Cardmarket, TCGplayerShops linked to for looking a card upWhatever any visitor arriving from a link gives themOnly if you press a shopping link
X, Facebook, WhatsApp, Telegram, Bluesky, RedditPosting a streak on that networkWhatever any visitor opening their page gives themOnly if you press that share button

The share buttons are links

When a run ends you can tell someone about it. Those buttons load nothing from anyone: they are ordinary addresses, like any other link on the page, and until you press one your browser talks to no social network. There is no Facebook SDK, no X widget and no third-party script anywhere on this site.

That matters because it is what most sites do the other way around: a Facebook like button contacts Facebook and drops its cookies the moment the page opens, whether you pressed it or not. That does not happen here, and you can check it in your browser’s network tab.

The image of your streak, if you save one, is drawn in your own browser and is sent to no server, ours included.

Transfers outside the European Economic Area

Some of those providers are US companies or use global infrastructure, so processing may take place outside the EEA. The specific mechanism covering each transfer depends on each provider’s terms and has not been verified against documents: it is pending legal review and will be stated here once it is. No safeguard is claimed that has not been checked.

Analytics, advertising and profiling

There is none of the three. No Google Analytics, no Tag Manager, no Meta Pixel, no heatmaps, no pixels, no SDKs. No ads either. There is no profiling and no automated decision-making about you.

You can check this: open your browser’s developer tools, the network tab, and look at which domains the page connects to. You will see only its own and the card image ones.

Children

Cardhigher does not ask for your age, and it does not ask because it does not need to: there are no accounts, no profiling, no advertising, no marketing messages and no purchases. Asking for a date of birth for nothing would be collecting one field too many.

The only data a child could supply is the name typed on the leaderboard or the text of a message. That is why both explicitly ask for no real names and no personal details, and why the leaderboard entry can be deleted from Settings with no explanation.

Your rights

You can ask for access to your data, for it to be corrected or deleted, for processing to be restricted or objected to, and for portability. Where processing is based on your consent, you can withdraw it at any time, without affecting what was done before.

Two of them need no asking: deleting your leaderboard entry is in Settings, in the button that removes your name, and deleting everything held in your browser is there too, in the button that wipes your data.

For the rest, write to [EMAIL_PRIVACIDAD]. Bear in mind that Cardhigher has no accounts: to find your data we will need the name you played under or your browser’s identifier, which you can see in Settings. If you cannot supply them, it may not be possible to locate any data of yours, and you will be told so.

If you believe your data is not being handled properly, you can complain to the competent supervisory authority: [AUTORIDAD_DE_CONTROL].

Security

The site is served over HTTPS only, with headers that stop it being embedded in another page, stop third-party code being loaded, and turn off browser permissions it does not use. Messages and streaks are stored in Cloudflare’s store, which only the operator can reach.

No measure makes an incident impossible. If one occurred affecting personal data, it would be handled in accordance with the applicable rules.

Date

Last updated and in force since: 23 September 2026. Earlier versions of this document are in the project repository’s history.