This privacy policy applies to the Manasuite app for iPhone, iPad, and Mac, the website at www.manasuite.com, and the related application programming interface at api.manasuite.com (together, "Manasuite"). It explains, pursuant to Art. 13 GDPR, which personal data are collected, processed, and stored in that context.
The controller within the meaning of the General Data Protection Regulation (GDPR) is Jan-Hendrik Damerau. Full contact details are available in the Imprint.
Manasuite is a private, non-commercial project. There is no newsletter on the website. In the app, you can reach us through the Feedback chat (see the "Feedback" section). We do not use analytics tools, tracking or marketing pixels, or cookies for advertising or analytics. There is no profiling and no automated decision-making within the meaning of Art. 22 GDPR.
The website and the API behind it are delivered exclusively over an encrypted HTTPS connection.
When you visit the website and on every request to the API, technical access data transmitted by your browser or the Manasuite app are collected automatically. This includes in particular the IP address, the requested URL, and the user agent (browser or app identifier).
These data are technically required in order to deliver the website and the API correctly, and are processed solely to operate and secure the systems, for example to detect and fend off attacks and to keep the systems stable. The legal basis is our legitimate interest in a secure and functioning operation pursuant to Art. 6 para. 1 lit. f GDPR. Log files are retained only briefly and then deleted; they are not evaluated for marketing or profiling.
The website uses only technically necessary first-party cookies from our own server. Because these cookies are strictly necessary to provide functions you have expressly requested, no consent is required under Section 25 para. 2 TDDDG.
In detail:
manasuite-session - stores the login status, progress while scanning the QR code, passphrase-entry attempts, and a binding against cross-site request forgery (CSRF). After a successful sign-in you stay signed in until you log out. Lifetime: 30 days of inactivity, renewed on each visit to the website; login status ends immediately on logout. Attributes: Secure, HttpOnly, SameSite=Lax.
XSRF-TOKEN - holds the CSRF token that protects form and API requests on this website against cross-site request forgery. Lifetime: identical to manasuite-session. Attributes: Secure, SameSite=Lax.
manasuite_browser_guid - a randomly generated, anonymous device identifier (UUID) with no name, email address, or other personal reference. It is set only when you actively open the login area at /user/login, not while browsing the rest of the website. Its only purpose is to recognise the same browser when the same QR code is scanned again, so that the app does not incorrectly add a second "Web" device to the linked-devices list. There is no evaluation, no cross-site tracking, and no profiling. Lifetime: technically persistent (up to 5 years). The legal basis is Art. 6 para. 1 lit. b GDPR in conjunction with Section 25 para. 2 TDDDG, because the cookie is strictly necessary to provide the login process you requested.
Manasuite has no classic account. Login is deliberately not based on an Apple ID, an email address, or a real name. You prove on the website that you hold the anonymous identity already on your device, by scanning a QR code with the Manasuite app - that is the point of the flow, so the anonymity described above is guaranteed rather than optional. A short numeric code shown in the app and typed on the website is only a camera-free stand-in for the same scan; it does not collect a name or an email either.
With the QR code, the actual sign-in - redeeming the login hint - happens exclusively in the app; the website only shows progress. With the numeric code, the website checks the one-time, time-limited code itself and, on success, activates the session. In both cases a public user record (users_public) is created or retrieved only after a successful sign-in. That record is keyed to an anonymous identifier generated on the device. It does not contain an Apple ID, an email address, or a real name.
Manasuite does not store an Apple ID, an email address, or a real name anywhere - not in the app, not on the website, not at login, and not during any other use of the service. The only name that may exist is a username a user optionally chooses.
The camera is used only when you scan a Magic: The Gathering card or a login QR code. Image frames are processed on your device. We do not upload camera frames to our servers.
If you enable notifications, Apple Push Notification service delivers them. We store a device token for that purpose. You can disable notifications at any time in the app or in system settings.
The Feedback chat in the app lets you send us messages. Doing so transmits your message, your anonymous device identifier, app version, operating system, language setting, and time zone offset to our server. If we reply, you receive a push notification, provided notifications are enabled. The Feedback chat is not a general contact form for third parties - it exists solely for feedback about the app.
If the app crashes, it may send a small, anonymous crash report - device identifier, app version, and stack trace - to our server on the next launch, so we can fix the bug.
Collection, decks, and similar library data that you choose to sync are stored in your personal iCloud (CloudKit) container operated by Apple. We cannot read that container. Your iCloud data are not transferred to our servers.
The recipient of your data is solely our hosting provider, who operates the servers on which the website and the API run. That hosting does not receive an Apple ID, an email address, or a real name, because Manasuite never collects those. For our own purposes, there is no transfer to recipients in third countries outside the EU or the EEA.
Under Art. 15 to 21 GDPR you have the right of access to personal data stored about you, of rectification, of erasure, of restriction of processing, of data portability, and the right to object to processing. Please use the contact details given in the Imprint.
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The authority responsible for our establishment in Schleswig-Holstein is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98, 24103 Kiel, Germany