Privacy Policy
Last updated: 24 July 2026
1. Who we are
TCG Actana is operated by the person below, who is the controller responsible for data processing under the EU General Data Protection Regulation (GDPR):
David Demircian (provider of the TCG Actana service)
Forstgarten 2
37603 Holzminden, Germany
Email: info@tcgactana.com
2. Scope and principles
This Privacy Policy applies to the tcgactana.com website, the TCG Actana desktop app, and the associated account, scan, synchronisation, and installer services. The alpha has public registration in the desktop app, but no public social features or standalone iOS app. We do not sell personal data or use advertising or analytics trackers.
3. Data we process
a) Website, server requests, and installers
When you access the website or our API, the servers process technically necessary connection data, particularly your IP address, time of access, requested resource, and response status. This is required to deliver the service, diagnose errors, prevent abuse, and keep operations secure. We count successful installer starts only in aggregate by platform and app version; the counter contains no IP address or user identifier. Your IP address is processed temporarily to limit abusive volumes of download requests. The legal basis is Article 6(1)(f) GDPR (our legitimate interest in secure and stable operation).
b) Account and authentication
When you register, we process your email address and your password during secure transmission. We store a cryptographic password hash, a technical user ID, a randomly generated internal profile identifier, language, account and confirmation timestamps, and the versions of the Terms you accepted and Privacy Policy you acknowledged. Your email address and required delivery data are processed for confirmation, security, and password-reset emails. The legal basis is Article 6(1)(b) GDPR; retaining evidence may also be based on Article 6(1)(c) and (f) GDPR.
c) Collection
The card and collection data you record is stored in connection with your account. This includes, in particular, the game, card name, set, card number, language, variant, condition, quantity, time recorded, collection assignment, and assigned market price information. This processing enables synchronisation, management, statistics, and export of your collection. The legal basis is Article 6(1)(b) GDPR.
d) Desktop scanning
During a normal scan in the desktop app, card images remain on your device. The app locally calculates a numerical image feature (embedding) and reads parts of the card using local optical character recognition (OCR). Only that image feature, recognised text, necessary scan settings, and your account assignment are sent to our backend, not the scan image itself. The backend matches this information against the card catalogue. The legal basis is Article 6(1)(b) GDPR.
e) Support
If you contact us by email, we process your sender address, message content, and technical delivery data to respond to your request. Depending on the request, the legal basis is Article 6(1)(b) or (f) GDPR.
4. Hosting and recipients
The website, API, authentication, database, and Storage are operated on infrastructure from netcup GmbH in Germany. We self-host Supabase there; account and collection data is not hosted by Supabase Inc. Other recipients receive data only where required to operate the service. In particular, this includes Resend, a service operated by Plus Five Five, Inc. in the United States, which processes email addresses, message content, and technical delivery data on our behalf for transactional emails. Transfers to the United States are based on its EU-US Data Privacy Framework certification and, where required, the Standard Contractual Clauses in its data-processing agreement. Other recipients include public authorities where we are legally required to disclose information.
5. Card, image, and pricing data from third parties
We obtain card-catalogue and market-price data on the server side from specialist data sources and marketplaces, including Cardmarket and TCGplayer. We do not send your email address or personal collection to these providers. Our backend retrieves Magic set symbols from Scryfall and forwards them to the desktop app, so your device does not connect directly to Scryfall for those symbols.
Card images are loaded partly from our own Storage and partly directly from the image provider recorded in the card catalogue. Direct image sources include cards.scryfall.io, errors.scryfall.com, assets.tcgdex.net, limitlesstcg.nyc3.cdn.digitaloceanspaces.com, optcgapi.com, and cmsassets.rgpub.io. For such an image request, the relevant provider receives your IP address and technically necessary request data. Your email address, access token, and collection data are not transmitted. Depending on the provider's location and infrastructure, this request may also be processed outside the EU/EEA.
6. Local fonts, no trackers, and no advertising
The website and desktop app serve fonts locally and do not connect to Google Fonts for this purpose. We do not use analytics or advertising trackers, create advertising profiles, or use tracking cookies on the public website. Technically necessary session data is stored on the device only where authentication or password recovery requires it.
7. Retention and account deletion
Account and collection data is generally retained while your account exists. We retain technical logs only for as long as required for operational security, abuse prevention, and error investigation; they are then deleted or anonymised. The registration record stored with your account is deleted when the account is deleted. Data from the former test-request and invitation system is deleted as soon as it is no longer required for handling or abuse prevention: pending requests after no more than 90 days, rejected requests no more than 30 days after the decision, and approved requests no more than 30 days after the related code expires. Separate support correspondence and legally required documents may be retained for longer where statutory obligations or the establishment, exercise, or defence of legal claims require it.
You can delete your account in the desktop app under Settings → Account → Danger Zone → Delete account. Once confirmed successfully, TCG Actana removes the authentication account, associated collection and scan data, and files in your avatar folder. The app then removes the local session and account-related caches; device-only preferences such as language and appearance remain. We cannot automatically remove CSV files or backups you saved outside the app. You may alternatively request deletion by email.
8. Your rights
Under the GDPR, you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and the right to object to processing based on legitimate interests (Article 21). To exercise these rights, contact us at the address above. You also have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is the State Commissioner for Data Protection of Lower Saxony.
9. Required information and automated decisions
An email address and password are required to create an account, and you must confirm the email address before using the synchronised account. Without this information, we cannot provide synchronised access. We do not use solely automated decision-making with legal or similarly significant effects, and we do not carry out profiling.
10. Changes
We update this policy when features or the legal position change. The version published here at the relevant time applies.