Sparkles MTG

Sparkles MTG

Privacy policy

Effective August 12, 2026 · version 2026-08-12

Sparkles MTG is operated by Cognima Creative Concepts. Questions and privacy requests may be sent to privacy@cognima.net.

What the Android app keeps locally

Your card collections, decks, acquisition costs, scans, condition-grading captures, preferences, and most cached market data live in app-private storage on your device. Grading photos are temporary: completed/reset sessions are deleted immediately and abandoned sessions are swept under bounded age and storage quotas. Local data leaves the device only when you deliberately use a hosted feature, send feedback/diagnostics, or export/share it.

Account and hosted data

Account records can include your verified email, display name, linked sign-in providers, membership/entitlement state, access-code redemption, passkeys, legal acceptance, and account-deletion status. Google, passkeys, and email magic links can be linked to one account. Passkey public keys are stored; private passkey material stays with your credential provider.

Hosted AI

When you use hosted AI, the prompt and the context you chose to include are sent through the Sparkles Cloudflare Worker to the configured model provider. Sparkles records metering and operational facts such as provider, model, token/byte counts, latency, status, and coarse country/region. Sparkles does not intentionally store raw hosted prompts or responses in its account database. If you report an AI response, the report category, your optional comment, a one-way response identifier, and bounded diagnostics are stored for review.

Optional analytics, crash reports, and feedback

Product analytics are opt-in. When enabled, Sparkles may record route names, time on a screen, app version, platform, coarse region, and aggregate inventory count/value snapshots. It does not send card, deck, chat, or scan names in those events. Crashlytics is separately user-controlled and may receive crash stacks, device/app facts, and diagnostic breadcrumbs. Feedback sends the text and diagnostics you review. Scanner traces are local and account-gated; they are not uploaded merely because scanning is used.

News and market data

The service fetches official Wizards announcements and public market/catalog sources to build shared product records. This work is not connected to your personal inventory unless the app later fetches those public records for display.

Providers and purposes

Cloudflare hosts the API, site, database, scheduled jobs, and operational logs; Resend delivers magic-link email; Google provides account and Play purchase verification; Ollama Cloud currently provides hosted model inference; Firebase Crashlytics is used only when crash reporting is enabled; and public Magic data providers supply catalog, rules, pricing, and metagame information.

Retention and deletion

You can request deletion in the app. The account remains usable for a 30-day recovery period and clearly shows the countdown whenever you return. Cancelling deletion restores ordinary status. After the due date, account-linked hosted records are purged. To prevent repeated free-trial abuse, a non-reversible hash indicating that an authentication identity used a trial may be retained for up to ten years; it contains no email, display name, inventory, prompt, or response. Legal, fraud, security, and financial records may be retained when reasonably required.

Your choices

You can disable optional analytics and crash reporting, request a portable hosted-account export, request or cancel account deletion on the web, and export/delete local collection data using Android tools. Contact privacy@cognima.net for access or correction questions that the app cannot resolve.