Privacy Notice
How collection-account data is used, shared, protected, and deleted.
Effective date: 27 August 2026
Who is responsible
MTG FINAL FANTASY Archive, available at mtgfinalfantasy.com, is an unofficial collector reference operated by Vedast Sanxis. Questions and privacy-rights requests can be sent to privacy@mtgfinalfantasy.com.
Data we process
- Technical request data: IP address, date and time, requested URL, referring origin, browser or device headers, and server or application errors may appear in ordinary hosting logs. The application uses pseudonymous rate-limit keys derived from an IP address or submitted account identifier, but does not store the raw IP address in its account database.
- Account data: email address, username, display name, password hash, acceptance of the current Terms, email-verification status, and account creation, update, and last-login timestamps. Passwords are not stored in readable form.
- Project and collection data: project name, optional description, stable project identifier, sharing setting, random share-link token, catalogue identifier, exact item version, project Goal quantity, Have quantity, and creation or update timestamps. Have may exceed Goal. Want is calculated as the greater of Goal minus Have or zero, and Extras as the greater of Have minus Goal or zero.
- Security data: hashed verification and password-reset tokens, expiry times, session information, and pseudonymous rate-limit counters.
- Communications data: an email address and message contents if you contact us.
You can browse the archive without creating an account. The current site does not use analytics or advertising trackers.
Why we process this data
Account, project, and collection data are processed to create and authenticate accounts, verify email addresses, provide password resets, save and display independent project goals and quantities already held, and provide the private, unlisted, or public sharing option selected for each project. This processing is necessary to provide the service described in the Terms of Use.
Technical and security data are processed for the legitimate interests of preventing abuse, protecting accounts, diagnosing faults, and maintaining the service. Information may also be processed to comply with legal obligations or to establish, exercise, or defend legal claims.
The registration checkbox records agreement to the Terms of Use and acknowledgement that this notice has been read. It is not consent to advertising, marketing, or unrelated uses.
Project visibility
- Private: only the signed-in owner can view the project.
- Unlisted: anyone with that project's private share link can view it. A recipient can copy or redistribute the link. The owner can replace it or make the project private.
- Public: anyone who knows or discovers the username and project link can view it.
An unlisted or public project reveals the username, display name, project name and description, and complete saved contents of that project, including exact card versions, sealed products, accessories, event items, their Goal, Have, Want, and Extra quantities. The site does not display its own financial estimates or price performance unless the project owner separately enables the financial sharing setting. However, a viewer can use the visible exact contents and quantities with prices available elsewhere to calculate or infer an approximate value independently. This applies across the Have, Want, and Full goal views. Shared responses do not include other private projects, the account email address, password, verification data, login timestamps, internal user ID, or record timestamps. Changing a project's sharing setting cannot withdraw copies or screenshots already made by other people.
A signed-in viewer may save an unlisted or public project as a new private project in their own account. They can copy Goal only, which starts Have at zero and excludes versions saved only as Extras, or explicitly copy Goal and Have exactly. The new project is independent: it does not retain the source share token, sharing or financial-display settings, price history, or a continuing link to the source. Replacing the source link, making the source Private, changing it, or deleting it later does not alter or delete a copy already created. Current estimates for the new project may still be calculated from the copied contents and the archive's current global price data.
Spreadsheet import and export
Export creates a CSV file in the browser. During import, the browser reads the selected CSV and sends only the exact catalogue identifiers and Goal and Have quantities needed for the chosen project; the original file is not stored as an uploaded document. The server validates the preview and applies a confirmed patch: listed rows may be added, replaced, or removed, while rows absent from the CSV remain unchanged. Informational Want, Extras, and price columns are ignored and recalculated where applicable.
Essential cookie
The site uses an essential cookie named __Host-mtgff_session. It contains a random session identifier used for authentication and request-forgery protection. It is marked Secure, HttpOnly, and SameSite=Lax. The browser cookie lasts for the browser session, and the corresponding server session is configured with a 24-hour lifetime. It is not used for advertising or analytics. Because it is strictly necessary for account and security functions, it is not controlled by an optional cookie-consent banner.
Service providers and external resources
Hostinger provides website hosting, database infrastructure, and transactional email and may process account, collection, email, and technical-log data on our behalf, together with its subprocessors. Its processing locations and safeguards are described in Hostinger's Privacy Policy and Data Processing Addendum.
Card images are loaded from cards.scryfall.io. When an image loads, Scryfall may receive the visitor's IP address, browser request headers, the referring origin, and the image URL that identifies the card. The image request does not deliberately contain an account email address, username, or collection quantity. See Scryfall's Privacy and Security notice.
The site contains ordinary affiliate links to verified TCGplayer product pages through Impact. No Impact advertising script, tracking pixel, prefetch, or automatic redirect is loaded by this site. If you choose one of those links, TCGplayer and Impact may receive the referring origin, IP address, browser request headers, and the destination product URL, and may use their own cookies or similar technologies under their own notices. Account emails, usernames, project names, and Goal, Have, or Want quantities are not added to an affiliate URL.
Following a link to Scryfall, Wizards of the Coast, Square Enix, Ultra PRO, a social network, or another external source sends the visitor to that provider under its own terms and privacy notice. Personal information is not sold, used for advertising profiles, or used for marketing email. Information may be disclosed where required by law or reasonably necessary to protect users, the service, or legal rights.
Retention and deletion
- Account, profile, project, and collection data remain in the live database while the account exists. Deleting one project removes that project's live saved quantities.
- Unverified accounts become eligible for routine deletion seven days after creation.
- Verification links expire after 24 hours and password-reset links after one hour. Expired records and pseudonymous rate-limit records are removed during routine cleanup triggered by later site traffic.
- Hosting logs and backup copies may remain for the periods applied by Hostinger or as required for security, legal compliance, and disaster recovery.
Deleting an account from Account settings removes the account, all its projects and saved quantities, and related verification and reset records from the live application database. It does not necessarily erase pseudonymous rate-limit records, standard hosting logs, or residual backup copies immediately.
Your choices and rights
You can change the display name, username, password, projects, project sharing settings, and saved quantities, or delete individual projects or the account, through Account settings. Depending on applicable law, you may have rights to access, obtain a copy of, correct, delete, restrict, or object to processing of personal data and to receive portable data. You may also have the right to complain to your local data-protection authority.
For requests that are not available through Account settings, including a copy of account data, contact privacy@mtgfinalfantasy.com. We may request enough information to verify that the request concerns your account. The service does not make solely automated decisions that produce legal or similarly significant effects.
Security and changes
The service uses encrypted HTTPS and SMTP connections, one-way password hashing, hashed verification and reset tokens, secure session cookies, request-forgery protection, rate limiting, prepared database statements, access controls, and private server-side configuration. No online service can guarantee absolute security.
This notice may be updated when the service or legal requirements change. The current version and effective date will be published on this page.
