First Edition
    ← Back to sets

    Privacy

    First Edition is a non-commercial fan project. We collect as little about you as possible. If you never create an account, nothing about you leaves your own device. This page explains what changes when you do sign in, what we hold, why, and how to control it.

    Who we are

    First Edition is operated by a private individual in the Netherlands as a non-commercial fan project. For the purposes of the GDPR, that operator is the data controller for any personal data described here. For any privacy question, or to exercise the rights described below, email hello@ygofirstedition.com.

    What we collect and why

    You can open packs and export your pulls without an account. Building and saving binders, decks, and banlists needs an account. If you create one, we collect only what the account itself needs:

    • Your email address — the only thing that identifies your account. We use it to sign you in (we send a one-time link — there are no passwords) and to send you essential account emails.
    • Your account record — a small database row marking that your account exists, whether your email is confirmed, and when it was created and last updated.
    • Your saved collection — when you are signed in, the binders, decks, custom banlists, favorites, and pack-opening progression you build are stored on your account so they sync across your devices. This is the card and deck data you create in the app — nothing more.
    • Sign-in session data — while you are signed in we keep a session so you don't have to log in on every page. This includes a session identifier and technical details your browser sends with the request (your IP address and browser user-agent), used only to keep the session secure and to let you sign out.
    • Sign-in link tokens — when you request a sign-in link we store a short-lived, single-use token. It is kept hashed, never in plain form, and only proves that you control the email address.
    • Anti-abuse counters — to stop the sign-in system being abused to send mail to people, we store a one-way hash of your email address (SHA-256 — never the address itself) alongside a request counter.
    • Email delivery data — our email provider processes your address and the delivery status in order to actually send your sign-in and account emails.
    • Social features, if you use them — a username you choose, an avatar and favourite card (both picked from cards in the game), who your friends are, any cube or banlist you choose to share, and your leagues and their match results. None of this exists until you opt into it, and none of it is required to use the rest of the app. The next section explains who can see each part.

    Our lawful bases (GDPR Art. 6) are simple: most of this is necessary to provide the account service you asked for (Art. 6(1)(b)), and the security and anti-abuse pieces rest on our legitimate interest in keeping the service safe (Art. 6(1)(f)).

    What we deliberately don't collect: no real name, no date of birth, no address, no phone number, no payment details, and no passwords at all — sign-in is passwordless. We don't accept uploaded images (avatars are card art), we have no message or comment feature of any kind, and there are no free-text profile fields. We run no advertising, no cross-site tracking, and build no profiles about you.

    Where your collection is stored

    Everything you build in the simulator — packs opened, binders, decks, custom banlists, and your favorites — is saved in your browser's localStorage as you go. If you are not signed in, that data stays on your device only and we never receive it. You can clear it any time from the reset controls in the app or through your browser's settings.

    When you sign in, your binders, decks, banlists, favorites, and pack-opening progression are also saved to your account on our servers in the EU, so they sync across the devices you sign in on. You can delete this account data at any time from your account settings — see your rights below.

    Other players, and what they can see

    The app has optional social features: usernames, profiles, friends, sharing a cube or banlist, and leagues. Everything above this section is data we hold about you. This section is different — it's about what other people can see. If you never claim a username, none of it applies: no other user can see anything about you at all, and nothing prompts you to start.

    Your email address is never shown to anyone. Not to your friends, not to people in your leagues, not on your profile — there is no screen in the app where another user can see it, and no way to look someone up by email. Your username is what everyone else sees instead.

    Who sees what

    • Your username, avatar and the month you joined — visible to any signed-in user who looks you up. But they have to know your username already: you can only be found by typing it exactly. There is no directory, no search and no browsing of users, and none of this is visible to anyone who isn't signed in.
    • Your favourite card, how many packs you've opened, and how big your collection is — visible to your friends only. Not to other signed-in users, and not to people who've merely sent you a friend request.
    • The actual contents of your binders and decks — nobody. Those are never shared, in any form.
    • A cube or banlist you share — visible to your friends, and only while you leave it shared. Nothing is shared automatically; each one is a switch you turn on yourself, and turning it off takes it back.
    • Your leagues and their results — visible to the other people in that league, and nobody else. Leagues are joined with a code somebody gives you; they aren't listed or discoverable.

    Friends

    A friendship only exists if both people agree: one sends a request, the other accepts. Declining a request is silent — the requester is simply never told. Either of you can unfriend at any time, and the moment you do, the friends-only parts of your profile stop being visible to them. We never show anyone a list of who your friends are.

    League history when someone deletes their account

    This is the one place where deleting your account doesn't remove a row outright, so it's worth stating plainly. Your league match results are also your opponents' results: their record is worked out from the same rows as yours. If we deleted them, other people's standings would silently change because you left. So instead we strip your name from those matches — they show as “Deleted user” from then on, with nothing left that identifies you: no username, no avatar, no link to any account. The result stays; you don't. A league you created keeps running for its other members rather than being deleted with your account.

    Reporting, and no notifications

    Profiles and shared items have a Report link. It sends us your username, whose profile or item it was, and anything you type — read by us only, never shown to the person reported or to anyone else. It's deleted if either account is deleted. Filing one alerts us by email so it doesn't sit unread, but that alert deliberately contains no names and none of what you wrote — only that a report exists. The report itself never leaves our database.

    Finally: we send you no email about any of this. No friend-request emails, no league notifications, no digests, no push. The only email you will ever get from us is about your own account — your sign-in link, and a confirmation when you delete. Anything social is shown to you inside the app when you next open it, and nowhere else.

    Cookies

    If you are not signed in, we set no cookies at all.

    When you sign in, we set a single strictly-necessary session cookie (__Secure-better-auth.session_token) so you stay logged in. It is HttpOnly, Secure, and SameSite=Lax. We use no tracking or advertising cookies. Because the session cookie is essential to a feature you asked for, no consent banner is required for it.

    Analytics

    We use Cloudflare Web Analytics to understand roughly how many people visit and which pages are popular. It is cookieless, measures only aggregate statistics, does no cross-site tracking, and does not build a profile that could identify you. See Cloudflare's privacy policy for details.

    Who we share data with

    We don't sell your data and we don't share it for advertising. We rely on two service providers (“processors”) to run the site:

    • Cloudflare — hosts the site, runs the account backend and its database (located in the EU), stores card images (img.bxxwlvnd.org), provides the cookieless analytics above, and provides the anti-abuse challenge (“Turnstile”) shown on the sign-in form, which receives your IP address to check that you are a real person. See Cloudflare's privacy policy.
    • Brevo — an EU email provider that delivers your sign-in links and account notifications. See Brevo's privacy policy.

    How long we keep it

    We keep your account and its email address for as long as your account exists. Everything else is short-lived by design:

    • Sign-in links expire soon after they are sent and can be used only once.
    • A signed-in session ends automatically after a period, and immediately when you sign out.
    • If you request an account but never confirm your email, that unconfirmed account is removed automatically after a short time.
    • The anti-abuse email hashes are discarded automatically after a short window.
    • Anti-abuse counters for the social features (how many lookups or friend requests you've made recently) are discarded automatically after a couple of days.
    • Anything social — your username, profile, friends and leagues — lasts as long as your account, or until you remove it yourself. A finished league stays until whoever created it deletes it.

    When you delete your account we erase it immediately; any residual copies held in routine database backups age out shortly afterwards. The one deliberate exception is described above under league history: your name is removed from past match results, but the results themselves stay, because they are other players' records too.

    Your rights

    Under the GDPR you have the right to access your data, to correct it, to erase it, to port it, and to restrict or object to how we use it. Because we hold so little, most of these are quick to honour.

    The fastest way to erase everything is the Delete account button on your account page — it deletes your account and all associated data straight away. For anything else, email hello@ygofirstedition.com and we will respond within one month.

    If you think we have handled your data improperly, you have the right to complain to your data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.

    Where your data is processed

    Your account data is stored in the European Union, and our email provider is EU-based. Cloudflare, however, is a US-headquartered company, so some processing may involve a transfer outside the EEA. Where that happens it is covered by Cloudflare's standard data-protection safeguards — the EU Standard Contractual Clauses and its certification under the EU–US Data Privacy Framework.

    Security

    We keep the amount of personal data we hold deliberately small, which is our strongest protection. Sign-in tokens and anti-abuse identifiers are stored hashed rather than in the clear, traffic is encrypted in transit, and access to the account database is restricted. No online service can promise perfect security, but a breach here is limited by design: there is little to lose beyond an email address.

    Changes to this policy

    If what we collect or how we use it changes, we update this page to reflect exactly what is collected, why, who can see it, and how to manage it — in the same change that ships the feature, not afterwards. The git history of this page is public.

    Last updated: July 2026 (v3 — added the social features section).