Privacy Policy

Effective August 19, 2026. Last updated on September 23, 2026.

DeckSequence is operated by Ayax Dev Studio LLC, a Delaware limited liability company ("we," "us," or "our"). We respect your privacy and are committed to protecting your personal information across our website, web app, and mobile applications (collectively, the "Services").

DeckSequence is an unofficial, fan-made companion application. It is not affiliated with, endorsed by, sponsored by, or approved by Nintendo, Creatures Inc., GAME FREAK inc., or The Pokémon Company. All Pokémon trademarks are the property of their respective owners.

This Privacy Policy explains how we collect, use, store, share, and protect your information globally, including disclosures required under the General Data Protection Regulation (EU GDPR / UK GDPR) and applicable US privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").

1. Identity of the Data Controller

For users located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the Data Controller responsible for your personal information is:

2. Information We Collect and How We Use It

DeckSequence is an account-based tool for tracking your Pokémon Trading Card Game (TCG) results. We collect only what the Services need to operate effectively:

  • Account and authentication information. When you create an account, we collect your email address and authentication identifiers via our authentication provider, including social sign-in provider IDs (Google, Apple, or Facebook, if used), along with session tokens to keep you logged in.
  • Pokémon TCG Live username and battle logs. If provided, we store your in-game username to attribute imported games to you. Your username, and your opponent's in-game username, may also be extracted from raw battle logs you manually paste into the app — see Section 3 for how we handle information about other players.
  • Tournament decklist details. If you choose to add them, we store your legal first and last name, your date of birth, and your Play! Pokémon Player ID. We use them only to fill in the tournament decklist you create for an event and to work out your age division. The decklist PDF and text are created on your own device. These details are visible only to you: we do not show them to other players or send them to tournament organizers, and our analytics record only whether a field is filled in, never what it says. You can change or clear them at any time in your account settings. The date of birth field does not accept a date showing you are under 13.
  • User-created match data. Matches, deck lists, deck versions, replays, tournament round records, and custom share links you record are stored to display back to you, power your analytics, and enable links you explicitly choose to share.
  • Subscription and billing information. If you subscribe to the Pro plan on our website, payment is taken by Stripe, our payment processor, on Stripe's own checkout page, and Stripe collects your card details and billing address directly. If you subscribe in our iOS or Android app, payment is taken by Apple or Google through your App Store or Google Play account, and our subscription-management provider, RevenueCat, confirms the purchase with them. Either way, we never receive or store your full card number or other payment details. What we do store is the minimum needed to know what you are entitled to: your plan, your subscription status and billing-period dates, the identifiers our payment processor or the store uses for your purchase (for app-store purchases: the store, the product, transaction identifiers, the price and currency, and the country of purchase), a record of your agreement to the auto-renewal terms when you subscribe on the web (when you agreed, which plan, and the price you were shown), and, if you cancel on the web, your optional answer to the one question we ask about why. That answer is read by us to improve the product and is never included in analytics.
  • Product and usage analytics. We use PostHog to understand feature usage and diagnose app performance issues. See Section 7 for what this involves and the consent choices available to you.

We use this information to provide and maintain the Services, generate your match and matchup analytics, manage your trial and any subscription, keep your account secure, improve features, and comply with applicable legal obligations.

3. Information About Other Players

A pasted PTCG Live battle log, or a logged tournament round, necessarily contains your opponent's in-game screen name. We process this information as part of reconstructing and displaying your own match record.

  • This information is visible only to you, the logging user, unless you explicitly share the replay or deck via a share link (see Section 5).
  • We process it under Legitimate Interest (GDPR Art. 6(1)(f)) — enabling you to keep an accurate personal record of games you played, which we consider a reasonable expectation for any player whose name appears in a public match.
  • An opponent who is not a DeckSequence user, and who wants information about them removed from another user's private record, can contact privacy@decksequence.com. We will evaluate the request against the logging user's own right to keep an accurate record of their own games.

4. Legal Bases for Processing (EU/UK GDPR)

If you reside in the EEA or UK, we process your personal data under the following legal bases pursuant to GDPR Article 6:

Purpose or activityCategories of personal dataLegal basis (GDPR)
Account management and app functionality. Creating accounts, authenticating users, displaying matches, saving decks.Account information, session data, user-created match dataPerformance of a contract (Art. 6(1)(b))
Attributing games. Attributing imported Pokémon TCG Live matches and processing pasted battle logs.Pokémon TCG Live username, battle logsPerformance of a contract (Art. 6(1)(b))
Tournament decklists. Filling in the player details and age division on a tournament decklist you create.Legal name, date of birth, Play! Pokémon Player IDPerformance of a contract (Art. 6(1)(b))
Managing trials and subscriptions. Issuing the trial, taking payment through our payment processor or the app stores, confirming app-store purchases, keeping your subscription status current, and recording your agreement to the renewal terms.Plan, subscription status and period dates, payment-processor and app-store purchase records, consent record, cancellation answerPerformance of a contract (Art. 6(1)(b)); the record of your agreement to the renewal terms is kept under legitimate interest (Art. 6(1)(f)) — evidencing the consent US auto-renewal law requires us to obtain
Information about other players. Displaying opponent names within your own private match record.Opponent's in-game usernameLegitimate interest (Art. 6(1)(f))
Product analytics and troubleshooting. Improving app features, detecting technical bugs, and monitoring performance via PostHog.IP address, device type, usage and clickstream dataLegitimate interest (Art. 6(1)(f)) — or consent (Art. 6(1)(a)) where the EEA/UK consent banner requires it; see Section 7
App security and fraud prevention. Protecting infrastructure against malicious activity or unauthorized account access.IP address, session identifiers, technical logsLegitimate interest (Art. 6(1)(f))
Legal compliance. Fulfilling statutory, accounting, or tax obligations and responding to legal requests.Account information, interaction logsLegal obligation (Art. 6(1)(c))

5. Sharing, Retention, and Security of Information

  • No data selling. We do not sell your personal information or share it for cross-context behavioral advertising.
  • Privacy by default. Your account and match data are private by default. Information is visible to others only if you generate a share link, which is an unauthenticated URL viewable by anyone who has it. You can revoke a share link at any time, which immediately disables it. If a signed-in user comments on a replay you shared, their username is visible to you as the link owner.
  • Service providers. We share data only with the infrastructure providers that help us run DeckSequence, each under a data protection agreement, covering: database and backend hosting, application hosting, authentication, transactional email (such as verification and password-reset messages), card search, product analytics, payment processing, and subscription management. Our payment processor, Stripe, receives your card and billing details directly when you subscribe on the web and processes them under its own privacy policy; we share with it only your email address, the name on your account, and an account identifier so it can link the payment to your account. When you sign in to our mobile app, RevenueCat, our subscription-management provider, receives an account identifier, along with basic device and app information its software sends, so it can check what you are entitled to. If you subscribe in the app, Apple or Google take the payment under their own privacy policies, and RevenueCat also receives the records of your app-store purchases. We do not send RevenueCat your email address or name.
  • Data retention. We retain your data for as long as your account is active. If you delete your account, your personal data is removed from our live database immediately and purged from backups on a routine schedule, except where limited retention is required by law (such as tax or accounting records of subscription payments, and the record of your agreement to the renewal terms). Deleting your account also removes our copy of your app-store purchase records and has RevenueCat delete its record of your account. Apple and Google keep their own records of any purchases under their own policies. Your analytics profile and its associated events are deleted from our analytics provider within 30 days of the deletion request. Product analytics events are retained for seven years (84 months) from collection. Session replay recordings are retained for 90 days from capture.
  • Data security. We implement administrative, technical, and physical safeguards (including encrypted connections and secure API endpoints) to protect your information. However, no internet transmission or electronic storage method is 100% secure.

6. International Data Transfers

Ayax Dev Studio LLC is based in the United States. If you access the Services from the EEA, UK, or other regions with laws governing data collection and use, your personal information will be transferred to and processed in the United States.

When transferring data outside the EEA or UK, we rely on standard data protection mechanisms approved by the European Commission (such as Standard Contractual Clauses (SCCs)) to ensure your data receives an equivalent level of protection.

7. Cookies, Analytics, and Your Consent Choices

  • Web application. We use essential session cookies to maintain your login state and secure your session. Alongside them we store a record of your answer to the analytics question below, so we can honour it and stop asking, and a short-lived note of which region you are in, so we know whether we are required to ask you in the first place. These are required for the Services to function and are not subject to a consent choice.
  • Analytics consent (EEA/UK). If you access the Services from the EEA or UK, we ask for your consent before setting non-essential analytics cookies or local storage. If you decline or take no action, PostHog runs in a cookieless mode that does not set identifying storage on your device. If you consent, we enable standard analytics as described above.
  • Session replay. Session replay (a recording of on-screen interactions used to diagnose bugs) is a separate, higher-sensitivity feature and requires its own explicit opt-in — your general analytics consent does not turn it on. Anything you type is masked before it leaves your browser, including pasted battle logs.
  • Mobile applications. Mobile apps do not use web cookies — session authentication uses secure device storage, while your analytics answer is stored as an ordinary local preference, not a secret, and it does not survive an uninstall. If you use the app from the EEA or UK, you are shown a one-time dialog before analytics run, the same as on the web; outside those regions, analytics run by default with no prompt, and you can turn them off any time in Profile → Analytics & cookies. Mobile does not offer session replay — there is no recording feature in the mobile app today.

What declining actually does. We want to be exact here, because "we don't track you if you decline" would not be true. If you decline, PostHog stores nothing in your browser — no cookies, no local storage — but it still counts your visit, using a privacy-preserving hash calculated on its servers rather than an identifier kept on your device. So declining removes the browser storage and the ability to recognise you across visits; it does not make the visit invisible. If you would rather not be counted at all, a tracker-blocking browser extension will do that, and we do not attempt to defeat one.

Outside the EEA, EU, and UK, analytics are enabled by default and you are not shown a banner. This is a deliberate choice, not an oversight: we do not interrupt people to ask for something the law where they are does not require us to ask for. You can still change every setting at any time, and it works identically.

How to change your mind, at any time and as easily as you agreed in the first place. On this site, use Cookie settings in the footer to reopen the banner. In the web app, go to Profile → Analytics & cookies. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it. Your choice is stored on decksequence.com and applies to the web app as well, so you only have to answer once. In the mobile app, your answer is separate — set it under Profile → Analytics & cookies there.

8. Automated Decision-Making

We do not use your personal data for any processing that produces legal effects concerning you, or similarly significantly affects you, based solely on automated decision-making, including profiling, within the meaning of GDPR Article 22.

9. Your Data Rights and Account Deletion

Depending on your physical location (including the EEA, UK, and various US states such as California), you have specific rights regarding your personal information:

  • Right to access or know. Request details about and copies of the personal data we hold about you.
  • Right to rectification. Request correction of inaccurate or incomplete personal data.
  • Right to erasure ("right to be forgotten"). Request permanent deletion of your account and personal data.
  • Right to data portability. Request a copy of your user-created match and deck data in a structured, standard format.
  • Right to object or restrict. Object to or request restrictions on certain processing activities based on legitimate interests.
  • Right to withdraw consent. Where processing is based on consent (such as analytics cookies or session replay), withdraw that consent at any time without affecting the lawfulness of prior processing.
  • Right to non-discrimination (California). We will not deny you goods or services, or otherwise discriminate against you, for exercising any of these rights.

California-specific disclosures (CPRA)

In the preceding 12 months, we have collected the categories of personal information described in Section 2 (identifiers, account credentials, user-generated content, and — for subscribers — commercial information such as plan, subscription status, and payment-processor and app-store purchase records) from you directly, from the third-party sign-in providers you choose to use (Google, Apple, Facebook), from our payment processor, and — for purchases in our mobile apps — from Apple or Google through our subscription-management provider. We disclose these categories to the service providers named in Section 5 for the business purposes described there. We do not sell or share personal information as those terms are defined under the CPRA. An authorized agent may submit a request on your behalf with proof of authorization. We will verify your identity before fulfilling a request and will respond within 45 days, with one 45-day extension where permitted by law.

How to delete your account

You can permanently delete your account and all associated personal data directly inside the Services at any time:

If you are unable to log in, visit our Support page or email privacy@decksequence.com to request manual account deletion.

10. Children's Privacy

DeckSequence is not directed to children under 13 years of age in the United States, or under 16 years of age in the European Economic Area and United Kingdom. We do not knowingly collect personal data from anyone below that threshold. The optional date of birth field used for tournament decklists does not accept a date showing you are under 13.

If you are a parent or legal guardian and believe your child has created an account or provided us with personal information without the required age or consent, contact us at privacy@decksequence.com. We will verify the request and remove the relevant data without undue delay.

11. Regulatory Complaints (EU/UK Users)

If you reside in the EEA or UK and believe our processing of your personal data violates data protection laws, you have the right to lodge a complaint with your local data protection authority:

12. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our legal obligations, features, or data practices. If we make a material change, we will notify you via in-app notice or email in addition to updating the "Last updated" date on this page.

13. Contact Us

If you have questions about this Privacy Policy, wish to exercise your data rights, or need support, contact us at privacy@decksequence.com, or visit our Support page. We are Ayax Dev Studio LLC.