Privacy Policy
Last updated: August 16, 2026
The short version
- We never sell or trade your data. Not to advertisers, not to data brokers, not to anyone, for any price, under any arrangement.
- We don't track you. No analytics, no advertising pixels, no third-party scripts, and no cookies beyond the one that keeps you signed in. Your browser never contacts anyone but us.
- We collect almost nothing on our own. Apart from what you type into your account and your questions to the Arbiter, the service gathers no personal information about you.
- We never see your card. Payments happen on Stripe's own checkout pages; card numbers never reach our servers.
- Usage credits are non-refundable, they're capped at $20 per account, and cancelling never cuts your access short.
- You can have it all deleted. Ask us and your account and everything attached to it is erased.
1. Who this policy covers
This policy explains how Arbiters Grimoire ("we", "the service") handles information belonging to people who register and use the Arbiter, the Rulebook and the Deck Builder at arbitersgrimoire.com. It applies to the website and its API, and it covers everything we hold about you.
2. What we collect
2.1 What you give us
The service does not gather personal information about you on its own. Aside from the account record below and the records your own activity creates, the only personal data we hold is what you deliberately enter:
- Email address - required. It identifies your account for sign-in and billing.
- Password - stored only as an Argon2 hash. We never keep your password, and we cannot read it or recover it for you.
- Display name - optional, shown in the sidebar. Leave it blank and we show your email instead. It can be anything you like; it does not have to be your real name.
- Your questions and decklists - the text you send to the Arbiter and the Deck Builder.
We ask for nothing else. No phone number, no address, no date of birth, no profile photo, no contacts, no location.
2.2 What using the service creates
- Sign-in sessions - we store a one-way hash of your session token together with its expiry, never the token itself.
- Password-reset links - stored as a one-way hash, valid for 24 hours, usable once, then deleted.
- Conversation history - your five most recent conversations are saved so you can pick them back up. Older ones are deleted automatically as new ones are saved.
- Usage records - for each request: the model used, token counts, the cost, and the time. This is how metering works. It does not include the text of your question.
- Credit and billing records - your balance and its history, your monthly spend limit, your subscription status and renewal dates, and the identifier of your Stripe customer record.
2.3 What we deliberately don't collect
- No analytics or tracking of any kind. There is no Google Analytics, no tag manager, no advertising or social pixel, no session recorder, and no fingerprinting. The site loads no third-party code whatsoever, and its content-security policy forbids it outright, so this isn't a promise you have to take on trust.
- No stored IP addresses. Your IP is used only in memory, and only to rate-limit sign-in, registration and password-reset attempts so your account can't be brute-forced. It is never written to our database, and it is discarded when the server restarts.
- No card details. See Payments.
- No advertising profile. We build no profile of you, and we run no ads.
3. Third-party services
The service itself collects no data about you beyond what's listed above, but running it depends on a handful of outside providers. This is the complete list of third parties that receive any data connected to your use of the site. Each one is used to deliver the service you asked for. None of them receive your data for their own marketing, and none of them pay us for it.
| Provider | Why | What it receives |
|---|---|---|
| Anthropic | Generates the Arbiter's rulings and Deck Builder output. | The text of your question or decklist, plus the rules passages we retrieve for it. Sent from our server. Your email, name and account identity are not sent. Anthropic does not receive anything that identifies you as the author. |
| Stripe | Processes subscriptions and credit purchases. | Your email address, your display name if you've set one, an internal account number, and the payment details you enter directly on Stripe's own pages. Stripe is the only provider here that receives your payment information, and it receives it directly from you, not through us. |
| Render | Hosts the application and its database. | Everything the service stores lives on Render's infrastructure, and all traffic passes through it. |
| Cloudflare | Sits in front of the site for TLS, caching and abuse protection. | Connection metadata for every request, including your IP address, as an inherent part of routing traffic to us. |
| Scryfall | Supplies official card data for cards not already in our local database. | Only a card name, and only on a cache miss. The request is made by our server, so your IP address and identity are never exposed to Scryfall. |
Your browser contacts no third party at all. Everything the page loads - code, styles, and the Inter typeface - is served from arbitersgrimoire.com. There is no font CDN, no script host, no image host. The providers above are reached by our server, or by you directly in Stripe's case; none of them see your browser, and only Cloudflare and Render see your IP address, because traffic has to reach us somehow.
Each provider handles data under its own privacy policy and, where applicable, as our data processor. We don't add providers casually; if that list changes, this page changes with it.
4. We do not sell or trade your data
We do not sell, rent, trade, license or otherwise share your personal information with anyone for money or for any other consideration. We do not disclose it to advertisers, data brokers, analytics firms or marketing partners, and we do not use your questions or conversations to build advertising profiles. The providers in section 3 receive only what they need to make the service work.
The narrow exceptions, which apply to any service: we may disclose information if the law requires it (a valid subpoena, court order or equivalent), or where strictly necessary to investigate abuse, fraud, or a threat to the safety of our users or systems. If ownership of the service were ever transferred, your data would move with it under this same policy, and we would tell you before that happened.
5. Payments and billing
- Card details never touch our servers. Subscribing and buying credits both hand you off to Stripe's hosted checkout. You enter your card on Stripe's page, and we never see, receive or store the number, expiry, or security code.
- What we keep is the identifier of your Stripe customer record, your subscription status and dates, and a ledger of credits purchased and spent. That's what the Account page shows you.
- Payment confirmations are verified. We only credit a purchase from a cryptographically signed message from Stripe, or by asking Stripe directly. A browser cannot convince us a payment happened.
- To manage or remove your payment methods, use Manage subscription on the Account page, which opens Stripe's own customer portal. Your payment methods are held by Stripe, not by us.
6. Credits, refunds and cancellation
Usage credits pay for the AI's actual work, which we're billed for the moment a question is answered. Because of that:
- Credits are non-refundable. Once purchased, credits cannot be exchanged back for money. They never expire, so there is no deadline to use them.
- Purchases are capped at $20 per account. You can never hold more than $20 in credits at a time. Pack buttons that would take you over the limit are disabled on the Account page, and the purchase is refused if attempted anyway. Once you've spent some, you can top up again.
- Cancelling never cuts your access short. When you cancel, you keep access until the end of what you've already got, the rest of your free trial, or the billing period you've already paid for, so you always have the chance to spend the balance you bought. You won't be billed again.
- Cancelling is reversible. Use Resume on the Account page any time before your access actually ends.
- You control your monthly spend. Set a monthly limit on the Account page. It starts out matching your credit balance, and topping up never raises it - only you can.
- Subscription charges are handled by Stripe under its terms. If you believe you've been charged in error, contact us at privacy@arbitersgrimoire.com and we'll look into it.
Nothing here overrides rights you may have under the consumer-protection laws where you live, or the terms of your card issuer.
7. How we protect your data
These are the concrete measures in place:
- Passwords are hashed with Argon2, a memory-hard algorithm built to resist offline cracking. A minimum length of 12 characters is enforced. We can't read your password, and neither could anyone who stole the database.
- Session and reset tokens are stored hashed. The database holds only a one-way hash, so even a full copy of it would not yield a usable sign-in token.
- Sign-in cookies are locked down. They are inaccessible to JavaScript, sent only over HTTPS, and restricted from cross-site requests. Sessions expire after 30 days, and signing out revokes them immediately on the server.
- Reset links are single-use, expire after 24 hours, and are deleted the moment they're used. Setting a new password signs you out everywhere.
- Brute-force protection rate-limits sign-in, registration and reset attempts per account and per network address, with responses that don't reveal whether an email is registered.
- Requests that change your account or spend money must come from our own site, blocking cross-site request forgery.
- Browser-level hardening on every response: a strict content-security policy that permits no third-party scripts and no outbound connections beyond our own server, enforced HTTPS, a ban on embedding the site in frames, and a referrer policy that leaks nothing to other sites.
- Encryption in transit for all traffic, including everything exchanged with Stripe and Anthropic.
- Administrative access is limited to accounts explicitly marked as administrators and is used only to operate the service.
No service can promise perfect security, and we won't pretend otherwise. What we can say is that the measures above are implemented today, and that we designed the service to hold as little about you as possible. The surest protection for data is not having it.
8. How long we keep things
- Account details - for as long as your account exists.
- Conversations - only your five most recent; older ones are deleted automatically.
- Sessions and reset tokens - deleted automatically once expired or used.
- Usage and credit ledgers - kept while your account exists, as the record behind your balance.
- IP addresses - held in memory only, for minutes, and never stored.
9. Your choices
- See what we hold - most of it is on the Account page already: your email, display name, balance, limit, subscription status and recent activity. Ask us for the rest and we'll send it.
- Correct it - change your display name or password yourself on the Account page.
- Delete it - email privacy@arbitersgrimoire.com from your account address and we'll erase your account. That removes your profile, sessions, conversations, and usage and credit history together; deletion cascades, so nothing is left orphaned behind. It cannot be undone, and unspent credits are not refunded on deletion.
- Delete a single conversation - remove any saved conversation from the sidebar at any time.
- Cancel - from the Account page, whenever you want.
Records Stripe keeps for its own legal, tax and accounting obligations remain with Stripe after we delete our copy; that's outside our control. Depending on where you live, you may have additional statutory rights over your data.
10. Cookies
One cookie, for one purpose: keeping you signed in. It holds a random session token, nothing more - no personal information and no identifiers usable for tracking. Choosing not to stay signed in makes it disappear when you close your browser. There are no advertising, analytics or third-party cookies on this site, which is why you've never seen a cookie banner here.
11. Children
The service isn't directed at children under 13, and we don't knowingly collect information from them. If you believe a child has created an account, write to us and we'll investigate and/or remove it if we find it to be in violation.
12. Changes to this policy
If this policy changes we'll update the date at the top of the page. For any change that materially affects how we handle your information, a new provider, a new category of data - we'll tell you in the app before it takes effect.
13. Related
The Terms of Use cover the rules of using the service itself - what the Arbiter's answers are and aren't, what you may do with the service, and the contract around credits and cancellation.
14. Contact
Questions about this policy, requests about your data, or anything that looks wrong: privacy@arbitersgrimoire.com. We aim to reply within a few days.