The short version:PipGlyph collects the minimum it needs to run the service — your account, the cards you create, the files you upload, and basic event logs. We don't sell your data.
1. What we collect
Account data
- Email address (for authentication)
- Username + display name (public)
- Bio and website URL (public, optional)
- Hashed password (managed by Supabase Auth)
Content you create
- Cards: title, slug, cost, rules text, flavor text, artwork URL, etc.
- Sets and the cards inside them.
- Likes you give to other people's cards.
- Exported PNGs of your cards in the export bucket.
Operational data
- Standard server logs (IP address, user agent, request paths) for security and abuse prevention.
- Supabase auth logs (sign-ins, password resets) handled by Supabase per their privacy policy.
2. How we use it
- To run your account and render your content.
- To show public cards in the gallery, on your profile, and via Open Graph previews when you publish them.
- To enforce our terms (e.g., investigating reported abuse).
- To improve the product — but we don't train AI models on your private content.
3. Who we share it with
We use a small set of vetted infrastructure providers:
- Supabase — managed Postgres, authentication, and storage. Hosts your account and content.
- Vercel — application hosting and the CDN serving your card pages.
- Anthropic — only when you click an action in the AI assistant. The prompt we send contains the relevant card fields (title, rules, cost, etc.) — never your account email or password.
We don't sell data to third parties or use it for advertising.
4. How long we keep it
- Account data: until you delete your account.
- Public cards and sets: until you delete them.
- Server logs: rolling 30-day window for security investigations.
5. Your rights
- Access — your dashboard shows everything tied to your account.
- Correction — edit profile data in settings, or edit any card or set you own.
- Deletion — delete individual cards and sets any time, or permanently delete your whole account from settings. Account deletion immediately and irreversibly removes your profile, content, and uploaded files.
- Portability — download a full JSON export of your account data (profile, cards, sets, comments) from settings, and export any card as PNG or PDF from the editor.
6. Cookies & analytics
We use first-party cookies for authentication (Supabase session tokens) and your theme preference. We don't use advertising cookies.
We use Google Analytics 4 to understand aggregate usage — which pages are visited and roughly how the product is used. This sets Google's _gacookies and shares usage signals (page URLs, device/browser class, approximate region) with Google. We don't send your email, card content, or other account data to analytics. You can block it with any standard content blocker or Google's opt-out browser add-on; the product works identically without it.
7. Children
PipGlyph isn't intended for users under 13. If we learn we have an account for someone under 13, we'll close it.
8. Changes
We may update this policy. Material changes get a fresh "last updated" date and, when significant, an in-app notice.
9. Contact
Questions or requests? See the contact channels on the about page.