The essentials
What leaves your PC? Only data from features you enable in Options. Game contributions do not contain your name or Arena account, passwords, chat, or hidden information about your opponent. They use a random technical identifier so you can request deletion.
For how long? About two years after the server first receives them, scheduled maintenance begins deleting Matches/Meta and Draft contributions; for Research, the period starts with the first receipt. If there is a backlog, completion may take more than one maintenance run. You can stop sharing; for Research, withdrawing consent and deleting data remain separate actions.
What can become public? Meta and Draft statistics and, after at least 30 matches with the same variant, an exact observed decklist. A single installation can reach this threshold: a recognizable list could therefore be indirectly linked to a player. The site does not show a name, installation, or personal match history.
How do I stop sharing? Turn off each choice in MOX → Options → Data and privacy. You can delete Matches and Draft there; Research has a separate control. In your personal area you can export data and delete your account or individual sections. For private requests, write to [email protected].
The full explanation of purposes, legal bases, retention, providers, and rights follows below. For the data shared by each feature, also read What MOX sends.
Who handles your data
Dennis Santinelli is the data controller for personal data processed through MOX and MoxTracker.
For privacy inquiries or requests concerning your personal data, write to [email protected].
Purposes and legal bases
- Matches/Meta, Draft and Research contributions, deck sync and optional email notifications: the data subject's consent (GDPR Art. 6(1)(a)), separate for each flow and withdrawable at any time.
- Optional account, installation linking, private dashboard and support tickets: performance of the service requested by the user or pre-contractual steps (GDPR Art. 6(1)(b)).
- Service security, abuse prevention, integrity and minimal technical diagnostics: the controller's legitimate interest in protecting MOX and its users (GDPR Art. 6(1)(f)), balanced with data minimisation.
Providing data for an account or support ticket is optional, but the feature cannot work without the data it needs. Pseudonymized game contributions, deck sync, Research, diagnostic attachments, and email notifications remain optional and are not needed for MOX's local features.
MOX does not make solely automated decisions that produce legal or similarly significant effects and does not perform advertising profiling.
What data MOX sends
Matches, Draft and Research have separate permissions, all off on first install. Enabling one does not enable the others, and data recorded while it was off is not sent retroactively.
Matches
- event, format, date, result, turns, duration, mulligans and play/draw when available;
- your decklist as numeric card IDs and quantities;
- last hand observed in the log, when present in the legacy apertura field: this is not the opening hand;
- only opposing cards actually revealed in the log;
- rank and MOX/Arena versions when available.
Draft
- set, format, offered cards, picks, pool and MOX policy;
- statistical values used by the suggestion, sample size and close alternatives;
- a possible link to a match, without the player's name, only when Arena provides the same verifiable identifier.
Research
MOX Research is optional and separate from other contributions. If you choose to participate, MOX can send observable facts from matches completed after consent to study cards, decks and configurations. Matches played before consent are not included.
- format, event, result, rank when available, turns, play or draw, and mulligans;
- your own decklist and sideboard as declared by Arena;
- your own cards drawn, cast and played as lands, when observable in the log.
Research does not send names, the custom deck name, the original match identifier, passwords or email, or the opponent's unrevealed hand or library. If the Research service is not ready or qualified to receive data, MOX does not send it.
What game contributions exclude
- player or opponent name;
- Arena account name and original Arena identifiers;
- the custom deck name in Matches/Meta, Draft, and Research contributions; private ‘Decks in your account’ sync includes it only after a separate choice;
- opponent's hand, library or unrevealed cards;
- passwords: sign-in uses Google or Discord and MOX does not manage its own credentials.
Contributions are pseudonymized: each installation uses a random identifier instead of a name. The secret used for deletion is stored on the server only as a hash.
Optional accounts and tickets
If you sign in, we store only the OAuth provider identifier, display name and avatar. We do not request or store your Google or Discord email. This data is used only to authenticate the private dashboard and never enters the public meta.
Linking your MOX Account does not enable 'Decks in your account'. MOX sends your decks, including their names, to your private account area only if you enable this sync separately; it does not use them for public statistics.
An installation is linked to an account only with a one-time code and proof of that installation's local secret, even when the user does not send contributions. Authenticated tickets stay in the account; anonymous tickets use a secret link and Turnstile. Email notifications are optional: the address is requested only for that ticket, after explicit consent and confirmation from the received message. Emails contain neither ticket text nor attachments, only a private link; the address and related tokens are deleted with the ticket.
Screenshots and MOX diagnostic packages stay in a private R2 archive. A package may include Player.log only when the user explicitly selected it in MOX; it is available only to the ticket owner and support administrators, never in the public Meta.
Where, for how long, and when we publish
Cloudflare hosts the service and D1 databases. Pseudonymized Matches/Meta and Draft contributions become due for deletion 730 days after receipt by the server; for Research, the 730 days run from first receipt, even if the contribution is updated. Scheduled maintenance begins deleting expired contributions: it removes matches, Draft indexes and their complete traces in the private R2 bucket, as well as Research contributions and directly related data. If there is a backlog or an interruption, completion may require more than one run. The identifier of a Research contribution deleted after expiry remains suppressed to prevent resubmission. Expiry does not withdraw Research consent: you can keep sharing new matches, withdraw consent, or request deletion separately. Public data is recalculated from contributions still retained. Attachments from closed tickets are deleted after 90 days and the full closed ticket after 365 days. Account sessions last at most 30 days; OAuth states and one-time linking codes expire after 10 minutes. Account data remains until account deletion.
Public statistics remain subject to minimum thresholds. A Draft percentage requires at least 100 picks and a game result requires at least 30 linked matches; the meta does not show percentages below 30 matches.
A complete decklist can become public when the same variant reaches at least 30 matches, even if all contributions come from one installation. The site does not publish the player's name, Arena account, installation identifier, or personal match history. A recognizable list may still allow an indirect link.
The mox-meta reference lists are a separately curated public catalog: they are not reconstructions of decklists observed from MOX users.
Revocation and deletion
Disabling consent stops future uploads and clears the related online queue without deleting personal statistics stored on the PC.
The command “Delete matches and Drafts from the site” in MOX Options deletes contributions associated with that installation from the databases and R2. Local copies remain on the user's computer.
For Research, you can withdraw consent and request deletion separately. If the service does not immediately confirm withdrawal or deletion, MOX keeps the request and retries it, including after a restart, until it is confirmed.
Once Research withdrawal is recorded on your PC, MOX opens no new Research uploads. If the settings file is unreliable, MOX restores available preferences but treats Matches/Meta, Draft and 'Decks in your account' consent as off until you choose again.
Site, cookies and external services
The site uses no advertising cookies or profiling systems. The interface uses one dark theme and stores no visual preferences in the browser.
Cloudflare Web Analytics measures visits, page views, where visits come from, and site performance in aggregate. It uses no cookies for this analysis and is not used to show ads or build advertising profiles.
Cloudflare handles the standard technical requests needed to deliver the site and API. Card images are requested from Scryfall only for cards the frontend is authorized to show, including public catalog lists and observed decklists that have passed the publication threshold. A protected observed decklist generates no image or hover requests for its cards. As with any external web resource, Scryfall may receive standard technical request data; this data is not added to MOX databases.
Recipients, providers and transfers
Data may be processed, only as necessary for the service, by the technical providers listed below and by people authorised to provide support. We do not sell personal data.
- Cloudflare: Pages, Workers, D1 databases, R2 storage, Turnstile and Web Analytics; infrastructure, security, abuse protection and site statistics.
- Google and Discord: OAuth providers chosen by the user for sign-in; MOX requests an identifier, display name and avatar, not the email address.
- Resend: sends ticket email notifications, only when requested.
- Scryfall: card API and images requested directly by the browser on enabled pages.
- GitHub: release distribution and download lookup; public repository pages are external to MOX.
Some providers may process data outside the European Economic Area. Where applicable, transfers rely on an adequacy decision, the EU-US Data Privacy Framework for participating organisations, or the European Commission's Standard Contractual Clauses and related supplementary measures. Information or copies of applicable safeguards can be requested from the privacy contact.
Data-subject rights
Where provided by the GDPR, you may request access, rectification, erasure, restriction of processing, data portability and object to processing; you may also withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
You can exercise your rights by writing to [email protected]. You also have the right to lodge a complaint with the Italian Data Protection Authority or the competent supervisory authority in your Member State.
Contact and changes
During the beta, non-confidential questions and requests may be opened in the MoxTracker GitHub repository. Never publish deletion secrets, complete logs, or personal data in a public issue.
For confidential or personal-data requests, write to [email protected]. Any material change to collection, sign-in, purposes or providers will require this page to be updated and, when necessary, consent to be requested again.