Effective date: 3 August 2026
Provider: Dylan Smith
Contact: support@brightfoundrygraphix.com
Previously named: This software was called DeckSphere from 30 July 2026
until 17 August 2026, and BrightForge TCG before that. Same software, same
provider, same terms — only the name changed. If you installed it under an
earlier name, this document applies to your copy.
This policy describes what OnTheStack does with your information. It is written
against how the app actually behaves, not against what a collection app might
typically do.
OnTheStack is an offline-first application. Your collection, decks, wishlist and
play history are stored on your own device in a local database file. Nothing
is transmitted to us unless you deliberately create an account and turn on sync,
or use friends and messages.
We run no analytics, no advertising, no crash reporting and no tracking of any
kind. There is no third-party SDK in the app collecting anything about you.
Card photographs never leave your device. Scanning is performed entirely
on-device; the image is discarded once the card name has been read from it.
Everything the app is for:
This lives in a database file in the application's own storage directory. We
cannot read it. If you uninstall the app without exporting a backup, it is gone.
To be useful offline, OnTheStack downloads public card catalogues and prices
from the services below. These are ordinary requests for public data. We do not
send your collection, your decks, or any identifier when making them.
| Service | Purpose |
|---|---|
Scryfall (scryfall.com, data.scryfall.io) | Magic: The Gathering cards, images, prices, rulings |
Lorcast (lorcast.com, cards.lorcast.io) | Disney Lorcana cards and images |
YGOPRODeck (db.ygoprodeck.com) | Yu-Gi-Oh! cards and images |
Pokémon TCG data via jsDelivr (cdn.jsdelivr.net) | Pokémon cards and images |
TCGCsv (tcgcsv.com) | Supplementary price data |
Commander Spellbook (commanderspellbook.com) | Combo data |
As with any internet request, these providers necessarily see your IP address
and can apply their own policies to it. We have no control over and no agreement
governing their handling of that; their privacy policies apply.
If you import a deck by URL from Moxfield or Archidekt, the app fetches that
specific public deck page. This happens only when you paste a link and ask for
it.
Sync is off by default and requires an account. If you enable it, the
following are uploaded to our sync provider so your devices can share them:
Play records may include opponent names, if you have entered them. Please
do not enter another person's full name or contact details; a nickname is
sufficient for the feature to work, and it is not our place — or yours — to
upload someone else's identity without their knowledge.
The account itself stores your email address and an authentication
credential. We never see or store your password in readable form; authentication
is handled by our provider.
Sync data is stored with Supabase (supabase.com), acting as our processor,
and is protected by row-level access rules so that one account cannot read
another's rows. Transport is encrypted with TLS.
Friends and direct messages require an account and are off until you use them.
Your profile. If you use friends, your username becomes visible to other
signed-in users so they can find you. Only your username and optional display
name are visible — never your email address. You can turn off "discoverable"
in settings, which removes you from search entirely; people who are already your
friends can still see you.
Friend requests are mutual. Someone must send a request and you must accept
it before either of you can message the other. There is no way to message a
stranger — this is enforced by the database, not just the app.
Messages are stored on our sync provider so they can reach the other person's
device. They are not end-to-end encrypted: we could technically read them,
and we will if a report requires investigating. We do not read them otherwise,
and they are never used for advertising, profiling or training.
Do not send anything sensitive. This is a chat for arranging games and
trades. It is not a secure channel, and you should not send passwords, payment
details, addresses, or anything you would not want a moderator to see while
handling a report.
Blocking removes the friendship, prevents further messages in both
directions, and prevents either of you re-adding the other.
Reporting. If you report a message, we store the report, the reported
account, and a copy of the reported message — kept even if the sender later
deletes the original, because a report with no evidence cannot be acted on.
Reports are reviewed by a person. See our Community Guidelines.
Deleting messages. Either party can delete a conversation from the server.
Deleting your account removes your messages, friendships, blocks and profile.
Reports you have _filed_ are retained without your account link, because a
safety record that vanishes when the reporter deletes their account is not a
safety record.
The desktop application checks our own server
(dl.brightfoundrygraphix.com) for a new version. This request contains no
account information. The mobile application does not do this; it updates through
the app store.
websites.
The app requests camera access only to scan a physical card. When you tap to
scan:
bundled inside the app. No network request is made.
device.
Camera access is requested at the moment you first tap to scan, not when the app
starts, and declining it leaves every other feature working.
OnTheStack is not directed at children under 13, and we do not knowingly collect
personal information from them. Creating an account requires an email address.
Trading card games have young players, so it is worth being precise about what
the messaging feature does and does not allow. **There is no way to message a
stranger.** Both people must accept a friend request first, and nobody is
browsable -- you can only find someone whose exact username you already know.
There is no public feed, no group chat, no voice, and no advertising.
If you believe a child has created an account, write to us and we will delete it.
Use the app without an account. Almost every feature works with no account
at all, and that is the default. Two do not: cloud sync, and — since
2026-08-12 — playing over the internet, where the relay server checks that you
are signed in before it will open a room for you. Playing on the same network
as your opponent still needs no account.
Export your data. The desktop app can export your collection to CSV and a
full backup file at any time.
Delete your account and its data. Account deletion is available in the app
under Settings, and removes your synced rows from our provider. Deleting the
account does not touch the copy on your device.
Ask us directly. Write to the contact address above for access, correction
or deletion, and we will respond within 30 days.
Depending on where you live, you may have specific rights under laws such as the
UK/EU GDPR or the CCPA, including access, correction, deletion, portability, and
objection. We do not sell personal information as those laws define it.
Local data stays on your device until you delete it or uninstall the app. Synced
data stays until you delete the row, or delete your account. Deleted rows are
retained briefly as deletion markers so that the deletion propagates to your
other devices, then removed.
Transport to our sync provider is encrypted with TLS. Access to synced rows is
restricted per account at the database level. No system is perfect, and we
cannot guarantee absolute security — but the strongest protection here is
structural: the default is that nothing leaves your device at all.
If this policy changes materially, we will update the effective date and, where
the change is significant, note it in the app's release notes.