Legal

Privacy Policy

Effective September 27, 2026. Replaces the April 2026 policy.

1. What stays on your Mac

Everything you put into Magical Piles is stored locally, inside the app's own data folder on your Mac:

~/Library/Containers/R.Robinson.Magical-Piles/Data/Library/Application Support/Magical Piles/

None of this is uploaded anywhere unless you use one of the features described in sections 3 and 4. It's included in your Mac's own backups (for example Time Machine) like any other file.

2. Your customers' information

If you sell cards, the TCGplayer packing slips you import contain your buyers' names and shipping addresses, and Mana Pool orders you fetch include the buyer's shipping address. Magical Piles handles them like this:

We, the developers of Magical Piles, never receive your customers' information. As the seller, you're responsible for handling it according to the marketplace's rules and the laws that apply to you.

3. What we receive

You can use Magical Piles without an account. We only receive data if you sign in and share something.

Sign in with Apple

Signing in is only needed for sharing. When you sign in, Apple gives us an anonymous, stable user ID (a string like 000123.abc…). Our sign-in doesn't ask Apple for your name or email address, so we never receive them. We store that ID and a random session token that expires after 90 days.

Shared decks and binders

When you share a deck or binder, we store its name and card list (card names, printings, quantities, card images, and prices), along with its format and commander for decks. Shared items are public:

You can update or delete any share from My Shares in the app, and deleted shares are removed from our servers immediately. Nothing else from your collection, such as your Keeps, Listings, storage, or sales, is ever uploaded.

4. Services the app connects to

Some features talk directly to other services. That data goes from your Mac to the service, not through us, and each service's own privacy policy applies to it.

ServiceWhenWhat is sent
ScryfallWhenever the app looks up cards, prices, or imagesThe card names, set codes, and card IDs being looked up. Card images load from Scryfall's image servers.
ArchidektWhen you import a deck from ArchidektThe ID of the public deck you're importing.
EDHRECWhen you run the AI Deck Advisor, with any provider (including Apple Intelligence)Your commander's name (or the deck's name, if it has no commander), to fetch EDHREC's public recommendations.
Your AI providerWhichever you choose: Anthropic (Claude), OpenAI, xAI (Grok), Google (Gemini), OpenRouter, Mistral, DeepSeek, a local Ollama or LM Studio server, a custom endpoint you enter, or Apple IntelligenceOnly when you run the AI Deck AdvisorThe deck list (commander or deck name, color identity, format, and card names and types) and the names of eligible cards from your Keeps, with their types and mana values, so it can suggest cards you already own. Cloud providers receive it with your own API key, and your use is also covered by your own agreement with that provider (with OpenRouter, also the model's provider). Local models (Ollama or LM Studio) receive it at the address you set, so it stays on your Mac or network. Apple Intelligence runs on your Mac and sends nothing.
TCGTrackingOnly if you turn on TCGTracking shippingHand-off mode: the app opens TCGTracking in your browser and shows the packing slip in Finder; you choose what to upload. API mode: for each order, the order number, buyer name, shipping address, and the cards and prices, which TCGTracking needs to create a shipping label. The app then asks TCGTracking for tracking status.
Mana PoolOnly when you connect it (Settings ▸ Mana Pool) and use a Mana Pool actionSent: your Mana Pool listings (card IDs, condition, finish, language, quantity, and price) and fulfillment and tracking info (carrier, tracking number, and tracking link) for orders you mark shipped, along with your Mana Pool email and access token to sign the requests. Received: your Mana Pool inventory, and your orders, including buyers' shipping addresses (handled as described in section 2). Saving a Mana Pool CSV sends nothing; you upload it yourself.
ApplePurchases, trials, and Sign in with AppleHandled by Apple (see section 6 and section 3).

Magical Piles doesn't connect to TCGplayer. It only reads files you export from TCGplayer yourself, like inventory CSVs and packing slips.

5. Passwords and API keys

API keys and credentials you enter, such as AI provider API keys, TCGTracking credentials, and your Mana Pool email and access token, are stored in your Mac's Keychain. They are only sent to the service they belong to, never to us, and they're never included in Export All Data.

6. Purchases

Upgrades and free trials are handled entirely by Apple through the Mac App Store. We never see your payment details. The app checks which upgrades you own with Apple's StoreKit, on your Mac. Apple's own privacy policy covers the App Store.

If you've turned on "Share with App Developers" in your Mac's privacy settings, Apple may pass us anonymized crash reports and usage statistics. You can turn this off at any time in System Settings ▸ Privacy & Security ▸ Analytics & Improvements.

7. This website

magicalpiles.com has no analytics, advertising, or tracking scripts, and sets no cookies. If you choose a light or dark theme, that choice is saved in your own browser's local storage and never sent to us. The site and the sharing service are hosted on Cloudflare, which processes standard request data (such as IP addresses and browser headers) to deliver the site and protect it from abuse.

8. Your choices and rights

9. How long data is kept

10. Children

Magical Piles isn't directed at children under 13, and we don't knowingly collect personal information from them. If you think a child has shared something through the app, contact us and we'll remove it.

11. Changes to this policy

If we change this policy, we'll update the date at the top of this page. If a change affects what data leaves your Mac, we'll also mention it in the app's release notes.

12. Contact

Questions or deletion requests: email [email protected].