Privacy Policy
Last updated: August 11, 2026
This policy describes how Four Cores handles personal information. It covers the web application at fourcores.gg and its iOS and Android versions, together with the Four Cores Discord bot. Personal data is not sold, and no advertising is served.
The application
Accounts
An account is not required for most features. Where one is created, Four Cores stores the email address supplied, the username chosen, and the date of registration. Authentication is handled by Google Firebase Authentication; passwords are managed by Firebase and are not visible to Four Cores. A verification message is sent to the address on registration, and may be sent again on request. An account, and the data held against it, may be deleted at any time — see Retention and deletion below.
Usernames are held in a public register, which the application reads to establish whether a name is already taken. A username is therefore visible to others, and should not be chosen to contain personal information.
Saved data
Data saved against an account falls into two groups — the public and the private.
Public, meaning visible to any visitor, signed in or not:
-
Decklists. Every saved decklist is visible in the Community tab, at
its share link, and in link previews generated by Discord and other services,
displayed alongside the username of its author. Decklists are additionally served in
machine-readable form at public addresses under
fourcores.gg/api/decks/, which third-party deck sites use to import them; a decklist retrieved in this way may be retained by that site independently of Four Cores. No private-deck option is currently offered, and deck names should not be used to hold personal information. - Likes. A record of which decklists an account has liked is stored against the username and is publicly readable, as is each decklist's total.
Private, meaning stored against the account and not shown to others:
- Collection data — the cards recorded as owned, with their finish and quantity. Card quantities attached to a decklist form part of that public decklist.
- The Wishlist and the Binder — the cards recorded as wanted and as available to trade. These lists are saved against the account rather than held on the device, so that they follow a signed-in user between devices. They are not displayed to other users, save where a QR code is shared as described below.
A trade in progress is not saved. The two sides assembled in trade mode exist only for as long as the tab is open; they are neither transmitted nor stored, and are lost when the application is closed. Cards received in a completed trade are added to the Binder, which is saved as described above.
Trade matching by QR code
In trade mode the application can display a QR code identifying the signed-in account's lists, and can scan the code of a trade partner. The code encodes an account identifier and nothing further — it carries no username, email address, or card data. Scanning a partner's code reads that partner's Wishlist and Binder in order to work out which cards each side could supply, and pre-fills the trade accordingly.
Displaying the code therefore makes the associated Wishlist and Binder readable to whoever scans it, and it should be shown only to a trade partner. Camera access is requested only while the scanner is open; the image is processed on the device to read the code, and no photograph or video is stored or transmitted.
Prices
Card prices shown in the application, and the estimated values derived from them in Collection Stats and on the trade screen, originate with TCGplayer and are retrieved through the Four Cores card data service as a single catalogue-wide table. The table holds no user data. Which cards a given account holds is never sent to TCGplayer: the value of a collection, a wishlist, or a trade is calculated on the device from the table already downloaded to it.
The Content tab
The Content tab lists articles and videos published elsewhere by third parties. Only the listing is retrieved by Four Cores; opening an item hands over to the publisher's own site or application — YouTube, for instance — where that provider's privacy policy governs, and which will see the visit as its own.
Analytics
Google Analytics, by way of Firebase, is used to measure feature usage — for example the tab opened, the card viewed, the creation of a decklist, a card added to a list, or an item opened from the Content tab. Google additionally collects standard information such as device type, browser, language, and an approximate location derived from IP address. Where a user is signed in, the username is attached to these events.
Data held on the device
Card data, the price table, preferences, mana counter state, and any trade in progress are held in browser local storage, in ordinary page memory, and in an offline cache so that the application functions without a connection. Clearing browser data, or uninstalling the application, removes this information.
Surveys
Where an in-app survey is offered, responses are stored without any account identifier attached. The follow-up field is optional; an email address or Discord handle entered there is used solely to make contact regarding the feedback given.
Affiliate links
Links to TCGplayer are affiliate links served through the Impact network, which may set its own cookies and from which Four Cores earns a commission. Order and payment details are not disclosed to Four Cores.
The Discord bot
The bot operates without a database and stores nothing. Message text
is read solely to identify (( )) card queries, is used to perform a card
lookup, and is then discarded. It is not written to disk, retained, or transmitted.
The bot does not read or record Discord user identifiers, usernames, or server names. For error monitoring and usage measurement, the command invoked and the card to which a query resolved are recorded — never the text entered. These reports are sent to Sentry, the error monitoring provider used by Four Cores.
Card and price links posted by the bot are the TCGplayer affiliate links described above. Use of Discord is separately governed by Discord's own privacy policy.
Service providers
The following providers process data on behalf of Four Cores: Google Firebase (accounts, database, analytics), Netlify (website hosting), Heroku (card data API and Discord bot), and Sentry (error monitoring). Their servers are located in the United States, and data is therefore transferred there. Personal data is not sold or otherwise disclosed, except where disclosure is required by law.
Retention and deletion
Account data is retained for as long as the account remains open. Individual decklists may be deleted, and collection, wishlist, and binder entries removed, within the application at any time.
Deleting an account
An account may be deleted without making a request of anybody. The control sits at the foot of the Settings screen in the application, and — so that it can be reached without installing anything — on the web at fourcores.gg/account-delete. Confirmation requires the account's username and password to be entered, the password because deletion is permanent and must not turn on a session left open on a shared device.
Deletion is immediate and cannot be undone. It removes:
- every decklist saved by the account, including its public share links;
- every like placed by the account, each deducted from the deck's total;
- the collection, the wishlist, and the binder;
- the sign-in credentials, and with them the email address held by Firebase.
Two things deliberately survive deletion:
- The username remains reserved in the public register described above, marked as belonging to a deleted account, so that it cannot afterwards be claimed by somebody else and used to impersonate the former holder. The record retains the username and the internal account identifier; it holds no email address and no card or decklist data.
- Likes placed by other users on decklists that have been deleted remain as records held against those users, since no user may alter another's data. They refer to decklists that no longer exist and are displayed nowhere.
Analytics events already collected are not identifiable to the account once its username is gone, and expire on Google's own retention schedule. Backups held by the service providers named above expire on theirs.
Requests
To request access to or correction of the data held, to have the reserved username released, or to have an account deleted where the in-application route is for any reason unavailable, contact michael@herbig.dev from the email address registered to the account. Requests are actioned within 30 days. This applies regardless of location, including rights arising under the GDPR and the CCPA.
Children
Four Cores is not directed at children under 13 and does not knowingly collect their personal data. Where such data has been collected, contact the address above and it will be deleted.
Changes
Amendments to this policy are published on this page, and the date above is updated accordingly.