Privacy policy
Effective date: August 3, 2026 · Last updated: August 3, 2026
WHO WE ARE AND HOW TO REACH US
Cascade MTG LLC ("we", "us", "our", or "Cascade") operates the Cascade apps for iOS and Android and the website cascademtg.com. This policy explains what personal data we collect across all three, why we collect it, and what your rights are. We aim to collect as little personal data as necessary, and we never sell your data.
For any privacy question or request, email us at privacy@cascademtg.com. We respond to data-subject requests within 30 days (GDPR) or 45 days (CCPA). We have not appointed a data protection officer; privacy inquiries are handled directly through this address.
DATA WE COLLECT, AND WHY
For each category below we list what we collect, what we use it for, and the legal basis we rely on under the GDPR:
- Account information – Your email address, a hash of your password (never the password itself), your sign-in provider identity if you use Google, Apple, or Discord sign-in, and your language preference. Used to authenticate you and operate your account. Legal basis: performance of our contract with you.
- Your content – Your inventory, decks, lists, wishlist, and watchlist. Used to provide the core features of Cascade. Legal basis: performance of our contract with you.
- Subscription and billing state – Whether you have an active subscription, and transaction references from Google Play, the App Store, or Stripe. We never see or store your card number. Used to grant Premium entitlements and process payments. Legal basis: performance of our contract; keeping minimal transaction records is a legal obligation (tax and audit).
- Push notification data – A device push token (FCM on Android, APNs on iOS) and your notification preferences, collected only if you enable notifications. Used to deliver the notifications you asked for. Legal basis: consent (the system permission plus in-app toggles); disable notifications at any time to withdraw it.
- Support conversations – Messages you send through in-app support chat or the contact form. Used to answer you. Legal basis: performance of our contract with you.
- Feature usage events – A small set of first-party events (for example, which onboarding step you reached, or that an upgrade screen was shown) recorded on our own servers and tied to your account. These events contain no IP address or device identifiers and are never shared with anyone. Used to understand which features matter. Legal basis: our legitimate interest in improving Cascade.
- Analytics and crash data (mobile apps) – Collected only with your opt-in consent; see the next section.
- Card scanning (mobile apps) – Camera images are processed entirely on your device and are never uploaded. Only the recognized card text (card name, set, and collector number) is sent to our servers to find the matching card, and those lookups are not stored against your account. Legal basis: performance of our contract with you.
ANALYTICS AND CRASH REPORTING (OPT-IN)
The mobile apps include Firebase Analytics and Crashlytics, but they are off by default. They run only if you explicitly opt in, and you can change your mind at any time in Settings → Privacy on iOS and Android — withdrawal takes effect immediately.
When enabled, this data is pseudonymous: it is keyed to identifiers such as the Firebase installation ID and an app user ID rather than to your name or email address. Because those identifiers are distinct per install or account, it is not anonymous data, and we describe it here precisely.
Retention is limited: analytics events are kept for 14 months and crash reports for 90 days, after which they are deleted automatically.
SERVICE PROVIDERS WE RELY ON
We share data with the following providers only to the extent needed to run Cascade. None of them may use your data for their own purposes on our behalf:
- Google Firebase – Crash reporting and analytics (only with your consent, as described above) and delivery of push notifications. See the Firebase privacy documentation.
- Google Play Billing – Processes subscription purchases made in the Android app. Google handles all payment details. See Google's privacy policy.
- Apple – Processes subscription purchases made in the iOS app. Apple handles all payment details. See Apple's privacy policy.
- Stripe – Processes subscription payments made on the web, including your payment card and billing details. See Stripe's privacy policy.
- Sign-in providers (Google, Apple, Discord) – If you choose social sign-in, the provider confirms your identity and shares your email address with us at that moment. They perform no ongoing processing for Cascade.
- Amazon Web Services – Hosts our servers and database in the United States; the data described in this policy is stored there. See the AWS privacy notice.
- Google Workspace – Delivers our transactional emails (password resets, confirmation codes), so your email address and the message content pass through Google's mail servers.
- Scryfall – Card data and card images are provided by Scryfall. Most card images are served from our own content delivery network, but some load directly from Scryfall's servers (cards.scryfall.io); for those requests Scryfall receives your IP address and the requested image URL, as with any content delivery network. Cascade sends no other data to Scryfall. Cascade is not produced by, endorsed by, or affiliated with Scryfall.
COOKIES (WEB)
The website uses a minimal set of cookies:
- Strictly necessary cookies – A session cookie that keeps you signed in, required for authentication and security. It cannot be disabled.
- Preference cookies – Remember settings such as your language. Theme and view preferences are stored locally in your browser.
The website sets no advertising cookies and no third-party analytics cookies.
HOW LONG WE KEEP YOUR DATA
Our default is simple: your data is kept while your account exists and deleted when your account is deleted. You can delete your account in the apps under Settings → Delete account (iOS and Android) or on the web at cascademtg.com/account. Specifically:
- Account details, your content, support conversations, push tokens, and notification preferences – Deleted immediately and permanently when you delete your account. Push tokens are also removed earlier if they become invalid.
- Billing records – When you delete your account we also delete your customer record at Stripe. We keep a minimal, anonymized record of past transactions (no longer linked to you) because tax and audit law requires it. Legal basis: legal obligation.
- Feature usage events – The link to your account is severed on deletion; what remains is anonymous.
- Analytics and crash data – Deleted automatically after 14 months (analytics) and 90 days (crash reports) regardless of your account status.
YOUR RIGHTS (GDPR)
If you are in the EU, EEA, or UK (and in many other jurisdictions), you have the following rights. Each entry says how to exercise it:
- Access – Ask for a copy of the personal data we hold about you. You can export your inventory from the app; for a full copy, email privacy@cascademtg.com.
- Rectification – Your email address, password, and all of your content are directly editable in the app and on the web.
- Erasure – Delete your account in the apps under Settings → Delete account, or on the web at cascademtg.com/account. Deletion is permanent and cannot be undone.
- Portability – Export your data in common formats from the app; for anything not covered by the built-in exports, email us.
- Restriction – Ask us to restrict processing of your data while a dispute or verification is resolved, by emailing us.
- Objection – Object to processing based on legitimate interests (such as the first-party feature usage events) by emailing us.
- Withdraw consent – For analytics and crash reporting, turn off the toggle in Settings → Privacy; this takes effect immediately. For push notifications, disable them in system or app settings.
For any of these, or if you believe we have not honored your rights, email privacy@cascademtg.com. We respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.
CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the following rights:
- Right to know – Request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the third parties we share it with.
- Right to delete – Request deletion of your personal information; the in-app and web account deletion described above fulfills this, subject to legal retention exceptions.
- Right to correct – Correct inaccurate personal information; your account data is directly editable in the app.
- Right to opt out of sale or sharing – Not needed in practice: we do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have done neither in the preceding 12 months.
- Right to non-discrimination – We will never treat you differently for exercising any of these rights.
Categories of personal information we collect: identifiers (email address, account identifiers, device push tokens); commercial information (subscription and transaction records); internet or other electronic network activity (feature usage events; analytics only with consent); and user-generated content (your inventory, decks, and lists).
We do not collect: precise geolocation, biometric information, protected classifications, sensory data, or professional, employment, or education information.
To submit a verifiable consumer request, email privacy@cascademtg.com. We respond within 45 days.
CHILDREN'S PRIVACY
Cascade is not directed at children under 13, and we do not knowingly collect personal information from them. If we learn that we have collected personal data from a child under 13, we will delete it. If you believe this has happened, email privacy@cascademtg.com immediately.
DATA SECURITY
We take reasonable measures to protect your personal data, including:
- Passwords are stored as salted hashes, never in plain text.
- All data is transmitted over HTTPS/TLS encryption.
- Access to user data is restricted to authorized personnel only.
- Infrastructure runs in secured AWS data centers.
While we strive to protect your personal data, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
DISCLOSURE REQUIRED BY LAW
We may disclose personal data where the law requires it — for example to comply with a subpoena or similar legal process — or where necessary to enforce our agreements or to protect the rights, property, or safety of Cascade, our users, or others.
INTERNATIONAL DATA TRANSFERS
Cascade is hosted in the United States, so if you use it from the EU, EEA, UK, or elsewhere, your data is transferred to and processed in the United States. For these transfers we rely on Standard Contractual Clauses as incorporated in the data processing terms of our providers (AWS, Google, and Stripe). We are not certified under the EU-U.S. Data Privacy Framework.
CHANGES TO THIS POLICY
We may update this policy as Cascade evolves. Material changes will be posted on this page with a revised effective date, and significant changes will be highlighted in the app or by email where appropriate. Continued use of Cascade after a change constitutes acceptance of the updated policy.