Skip to main content

Legal

Privacy Policy

Last updated: 29 de mayo de 2026

This policy explains what personal data Counterdeck collects, for what purpose, on what legal basis it does so, with whom it shares the data and what rights you can exercise. It is drafted to comply with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).

1. Data controller

  • Controller: Raúl Bumar (natural person).
  • Tax ID (NIF): 47960165-J
  • Address: Calle Fluvià, 30 — Barcelona, Spain
  • Contact: raulbumar@gmail.com

We are not required to appoint a Data Protection Officer (DPO) given the volume and nature of the processing. For any matter relating to data protection, you can write to the email address indicated.

2. Data we process and why

2.1. Account data (authentication)

  • What: user identifier, name or alias, email address, profile picture, language, public data from OAuth providers (Google, Discord, etc.) if you sign up through one of them. This data is managed on our behalf by Clerk Inc.
  • Why: to let you sign in, display your identity in the forum and in games, and link your decks, collection and messages to your account.
  • Legal basis: performance of the contract (provision of the service you request when you sign up) — art. 6.1.b GDPR.

2.2. Data you generate by using the product

  • Decks, lists, private notes, card collection, forum posts, messages in multiplayer games, direct messages to other users, comments, conversations with the AI assistant, Guess the Card games, and friend requests and acceptances.
  • Why: so that the platform works (saving your decks, displaying your forum, delivering your message to the recipient, etc.).
  • Legal basis: performance of the contract — art. 6.1.b GDPR.

2.3. Automatic technical data

  • IP address, browser user agent, access timestamps, anonymous session identifier, and error metrics if monitoring is enabled.
  • Why: platform security (anti-abuse, fraud detection in the credits and referrals system, rate limiting), error diagnosis and compliance with legal obligations.
  • Legal basis: the controller's legitimate interest in maintaining the security and integrity of the service — art. 6.1.f GDPR.

2.4. Billing data (only if you buy credits or Premium)

  • Amount, date and transaction reference. Card details or payment method are processed entirely by the payment provider; Counterdeck does not store card numbers.
  • Legal basis: performance of the contract and legal obligation (retention of accounting records) — art. 6.1.b and 6.1.c GDPR.

3. Data processors

To provide the service we rely on providers that act as data processors under contract (art. 28 GDPR). At the time of drafting this policy they are:

ProviderFunctionLocation
Clerk Inc.Authentication and user managementUSA (DPF)
Neon Inc.PostgreSQL database (decks, forum, messages)EU — Frankfurt
Vercel Inc.Application hosting and CDNUSA + global edge (DPF)
DeepSeek (Hangzhou DeepSeek AI)AI model for the assistant and for Guess the CardChina (standard contractual clauses)
Anthropic PBCAlternative AI model for the assistant, depending on configurationUSA (DPF)
Sentry (Functional Software Inc.)Error monitoring (only if enabled)USA (DPF)

When you use the AI assistant or Guess the Card, the text of your query (and, where applicable, the context needed to respond) is sent to the relevant AI provider for processing. We do not send them your email address or direct identifying data.

4. International transfers

Some of the above processors are located outside the European Economic Area. The transfers are covered, depending on the provider, by:

  • the EU–US Data Privacy Framework adequacy decision (Clerk, Vercel, Anthropic, Sentry, to the extent that they are certified), or
  • the Standard Contractual Clauses approved by the European Commission (in the case of DeepSeek and, in the alternative, any non-DPF provider).

5. Retention period

  • Account data and associated content: for as long as the account is active. If you request closure, it is deleted or anonymised within a maximum of 30 days, except where there is a legal obligation to retain it.
  • Messages in games (table chat): kept for the duration of the room and deleted when it is closed or expires (maximum 6 hours).
  • Direct messages between friends: kept while the friendship is active or until either party deletes them.
  • Security and rate-limit logs: up to 90 days.
  • Billing data: the applicable legal period (minimum 6 years under the Commercial Code).

6. Your rights

At any time you can exercise the following rights over your personal data:

  • Access: obtain confirmation of what data we process about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): request the deletion of your data. You can manage this yourself from your account settings when available, or request it by email.
  • Objection to processing based on legitimate interest.
  • Restriction of processing while a complaint is being resolved.
  • Portability: receive your data in a structured, machine-readable format.
  • Withdraw consent when processing is based on it (for example, measurement cookies), without the withdrawal affecting the lawfulness of prior processing.

To exercise any of these rights, write to us at raulbumar@gmail.com stating the right you wish to exercise. We will respond within a maximum of one month.

You also have the right to lodge a complaint with the Spanish Data Protection Agency if you consider that your privacy has not been respected.

7. Automated decisions

We do not make automated individual decisions with significant legal effects. The AI assistant and the "Guess the Card" game generate responses using language models, but these do not produce legal effects nor do they profile you based on personal data.

8. Cookies and local storage

The full details of cookies and local storage are published in the Cookie Policy.

9. Minors

The service is not specifically directed at minors under 14, the minimum age to consent to data processing under article 7 of the LOPDGDD. Minors below that age may only use the platform with the consent of their parents or guardians. If we detect an account belonging to a minor without verifiable consent, we will proceed to delete it.

10. Changes to this policy

We may update this policy to reflect legal changes or new features. When we do, we will update the date shown at the top and, if the changes are substantial, we will notify you through the interface or by email.