Updated 2026-07-29

Privacy Policy

How 21Life - Tracker & Analytics collects, uses, and protects your personal data.

Data controller

The data controller is Marco Andreani, reachable at the contact address shown in this document. 21Life - Tracker & Analytics is the service name.

Data we collect

Account data: email, username, password (hash), optional display name, registration date, and authentication metadata (e.g. Google sign-in). Avatars uploaded with earlier versions are no longer displayed and remain removable with the account.

Usage data: playgroups you create or join, decks, match results, statistics, game-related notes, and access logs (username and timestamp, deduplicated hourly).

Technical data: IP address and browser/device information for security, rate limiting, and captcha verification on sensitive operations.

Aggregated match-sync diagnostics: platform, sync, conflict and error counts, maximum queue depth and duration, and the latest shortened error message. They do not include match events or content.

Mobile-app data: app and operating-system version, device model or category, crash and performance diagnostics when Sentry diagnostics are enabled, and Expo Push token and platform when you allow notifications. Sentry is configured not to send default personal information.

Camera and images: the camera is used only at your request for features such as scanning QR codes. The app does not request photo-library access.

Local preferences: interface language and, if enabled, the "Remember me" option via browser cookies/storage. See our Cookie Policy for details.

Purposes of processing

Provide the service (accounts, data sync, shared playgroups, statistics).

Ensure security, prevent abuse, and manage administrative access.

Send transactional emails (e.g. password reset) through the configured email provider when needed.

Deliver operational notifications requested by the user, such as playgroup invitations and match updates.

Improve service reliability and diagnostics (technical and access logs with limited retention).

Processors and third parties

The service uses self-hosted Supabase infrastructure (database, authentication, and storage) deployed through Dokploy, Resend (transactional email), Google (optional OAuth), Cloudflare Turnstile (bot protection), Expo Push (mobile notifications), and Sentry (diagnostics, only when enabled). They may act as processors or independent controllers depending on the service provided.

Deck imports and card metadata may query external services (e.g. Scryfall, Archidekt, Moxfield, EDHREC) without sharing identifiable personal data beyond what the request requires.

International transfers

Some providers may process data outside the European Economic Area. In those cases, transfers rely on an adequacy decision, Standard Contractual Clauses, or another GDPR-recognized safeguard, according to the applicable provider terms.

Retention

Account data is kept while the account is active or until you request deletion.

Access logs are kept for a limited period (currently 30 days) and then deleted automatically.

Aggregated sync diagnostics are kept for 30 days after their latest update and then deleted automatically.

Notification tokens remain associated with the account while valid or until the account is deleted. Diagnostic events, when enabled, follow the retention configured with Sentry and are kept only as long as needed to identify and fix issues.

Vendor backups and technical logs may have their own retention periods, consistent with the purposes above.

Your rights

You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest, within GDPR limits.

You may withdraw consent where processing is consent-based, without affecting prior lawful processing.

You may lodge a complaint with the Italian Data Protection Authority or the competent authority in your country.

Security

We apply reasonable technical and organizational measures: secure authentication, database Row Level Security, API rate limits, restricted admin roles, and access-log visibility limited to authorized admins.

Minors

The service is not intended for users under 16. If you believe a minor provided personal data, contact us for removal.

Changes

We may update this policy. The last updated date is shown at the bottom of the document. Material changes may be communicated via the service or email.

For questions about this document, write to support@21life.win. Last updated: 2026-07-29.