OPTCG AI

Privacy Policy

This policy explains how OPTCG AI handles personal data when you browse optcgai.com, play, create an account, or use Sign in with Google.

Last updated: August 9, 2026

Main menu

Who is responsible

OPTCG AI operates optcgai.com. For privacy questions or requests, contact the administrator at:

web@optcgai.com

Data we process

If you create an account, we store your email address, public nickname, chosen leader thumbnail, language and gameplay preferences, account creation and last-login dates, saved decks, and the matches attributed to your account.

When you browse or play, we may process a signed anonymous browser identifier, route templates visited, referral host, limited campaign parameters, language, device category, game and replay data, and your IP address. IP addresses are used for security, capacity limits, and country-level statistics; they are never shown in public replays.

The composition of a custom deck used in a completed match may appear in public community statistics alongside its Leader and play date. We also aggregate appearances of predefined Leaders used by human players. We do not display the player's account, nickname, email address, IP address, or match identifier with those statistics.

One-time codes and request nonces are stored only as hashes. Session records contain identifiers and timestamps; the signed session cookie is HttpOnly, SameSite=Lax, and Secure in production.

Sign in with Google

If you choose Sign in with Google, your browser obtains a Google ID token and sends it to OPTCG AI. The server verifies it locally and reads the stable Google account identifier (sub), email address, email verification status, and hosted-domain indicator. We store the stable identifier and email to create or link your OPTCG AI account.

We never receive your Google password, do not store the Google ID token, do not request a Google access token, and do not access Gmail, Drive, Calendar, contacts, or other Google services. Google may process data and use its own cookies when its optional sign-in components are loaded or used, under Google's own privacy terms.

Why we use the data

We use the data to provide the game, authenticate and secure accounts, synchronize decks, show match history, enforce abuse and capacity limits, diagnose errors, produce aggregate service statistics, and comply with legal obligations. Depending on the applicable law, this processing is necessary to provide the service you request and is based on our legitimate interests in operating and protecting it; we ask for consent where required.

Cookies and local storage

We use essential cookies and browser storage for the signed anonymous identifier, language and gameplay preferences, the login-request nonce, session authentication, and locally saved guest decks. Guest preferences stay on that browser; when you sign in, supported preferences are also synchronized with your account. We do not use advertising cookies. Google may use its own cookies when its optional sign-in components are loaded or used.

Sharing and service providers

We share data only as needed with providers that host the service or database, deliver login emails, and provide the optional Google sign-in flow, or when required by law. We do not sell or rent personal data and do not use Google user data for advertising profiles.

Retention

Account data, saved decks, and account match attribution are retained while the account exists or until a valid deletion request is completed. Operational game, replay, and analytics records may be retained for gameplay, history, security, error diagnosis, and aggregate statistics; they are not used for advertising.

Expired login codes are purged after 24 hours, inactive login-throttle rows after 48 hours, and expired or revoked sessions after 30 days. Active user sessions use a sliding 30-day expiry.

Your choices and rights

You may contact us to request access, correction, deletion, restriction, or objection where applicable. You can sign out to revoke the current session and use your profile to close other sessions.

For account access or deletion requests, we verify control of the email stored on the account by sending a one-time challenge to that address. A completed account deletion removes the user record, sessions, saved decks, and account-to-match attribution. Public replays do not display the account email or nickname and may remain available.

Security

We use HTTPS, secure and HttpOnly session cookies in production, signed identifiers, hashed one-time codes and nonces, rate limits, local verification of Google ID tokens, and restricted database access. No internet service can guarantee absolute security, so please contact us if you suspect misuse.

Changes to this policy

We may update this policy when the service or legal requirements change. The current version and its update date will always be published on this page.