App Privacy Policy

Last updated: September 14, 2026. This policy covers The Pod Companion mobile application for Android. The website at thepodcompanion.com has its own separate privacy policy, and the two are not the same: the website carries advertising and analytics, and the app carries neither.

The short version

Signed out, the app is a life counter that sends nothing anywhere. An account is optional. With one, the games you save and the roster of players you keep go to the same account you already have on this website, and nothing else does. There are no ads in the app, no analytics or tracking SDKs, no advertising identifier, and no crash reporting.

Signed out, the app sends nothing

You can install the app, count life for a four-player game, track commander damage and finish the night without ever creating an account. Nothing about those games leaves your phone. They are written to the app's own storage on the device and they stay there.

The one exception is card art. If somebody names a commander, the app asks Scryfall for that card, which is covered in Card lookups go to Scryfall below. That is the only network traffic a signed-out phone produces.

If you create an account

Accounts are optional, and they exist so your games follow you between the app and the website. When you sign in or create one, we collect and store:

Account data is used only to run the account features. We do not sell it, and we do not share it with advertisers.

What an uploaded game contains

A saved game joins an upload queue. If auto-upload is on it goes as soon as the phone has a connection, and if it is off it waits in the queue until you tap Sync now. Either way, an upload only ever happens while you are signed in.

An uploaded game holds the result and the play-by-play: the format, who sat in which seat, the final placements, life totals and how they changed through the game, commander damage, mulligans, the turn count, how the game was won, what knocked each player out, and any notes you wrote on it. It is stored under your account.

Uploaded games also feed the anonymous, site-wide aggregate statistics on the website's stats page, such as win rate by turn order and the most-played commanders. Those aggregates carry no names, no usernames, no account details and no per-game dates.

The names of other players travel with a game

This is the part worth reading twice. Your roster is free text you type, names like “Sam”, “Dad” or “Ben R.”, and those names are uploaded along with a game so that the game has opponents in it rather than blanks. They are stored under your account rather than theirs.

Who can see them: you, and the members of a pod if you tag the game to one. A pod is a group you join by invitation, and tagging a game to a pod shares that game, including the names in it, with every member. The app tells you so wherever a pod is picked. A seat can also be left unnamed, and a signed-out phone uploads nothing at all.

If you tap Invite players to claim, the app offers a named seat to another account so that player can link the game to their own record. That sends the offer and nothing more. It is the only thing in the app that reaches out to another person, and it never happens on its own.

Decks you build

A deck you build in the app stays on the phone until you publish it. Published decks go to your account and are private by default. Making one unlisted or public is your choice, and it is reversible at any time. The website policy sets out what each of those settings shows and to whom.

Card lookups go to Scryfall

Card names, card details and card images come from Scryfall, the free card database this whole project is built on. When you type into a commander field, or a zone needs to draw art, the app asks Scryfall for that card.

Scryfall therefore sees your device's IP address and the card you asked about, exactly as it would if you had opened their website yourself. It is not told who you are, and no account information is attached to the request.

What the app does not collect

Where data is stored, and how it travels

Anything uploaded goes to Supabase, the same database and authentication provider behind this website, which is what makes the app and the site one account rather than two. Sign-in, including Google sign-in, is handled by Supabase on our behalf. Every request the app makes, to Supabase and to Scryfall alike, is encrypted in transit over HTTPS. The app sends nothing in the clear.

Backup and restore

Android's backup is switched on for the app's own record, so restoring onto a new phone brings your games, roster, decks and pods back with it. Your signed-in session is deliberately left out of both cloud backup and device-to-device transfer. A sign-in token restored onto other hardware would be a silent sign-in on a device you never authorised, so it stays on the device it was issued to. The cost is signing in once after a restore, which we think is the right trade.

Deleting your data

There are two separate things to delete, and two separate buttons:

Deleting an account leaves anonymised results behind in the aggregate statistics, and in the history of any pod you tagged a game to. Those describe the game rather than you. You can also email us to ask for deletion.

Children

The app is for a general audience aged 13 and over. It is not designed for children, and it does not knowingly collect personal information from children under 13.

Changes to this policy

If a future version of the app sends something new, this page changes in the same release, and so does the data safety declaration on its Play Store listing. Material changes are noted at the top of this page.

Contact

Questions about this policy can be sent to [email protected].