Privacy Policy - Mejai's

Last updated: 28 September 2026

Mejai's ("the app") is an unofficial, fan-made companion for the Riftbound TCG by Riot Games and UVS Games. This policy explains what data the app handles, where it's stored, and the choices you have.

Summary

Data stored on your device (default)

Everything you create in Mejai's - owned cards, wishlist, trade list, binders, decks, match logs, daily value snapshots, and app settings - is stored locally on your device in a private SQLite database. You can export a backup to a JSON file at any time via the in-app share sheet, and delete everything by clearing the app's storage or uninstalling.

Recent searches are kept on this device only and are not part of any backup. Private notes you write about a friend are stored on your device and, if you sign in, travel inside your cloud backup like the rest of your data. They are never shown to that friend or to anyone else.

Optional account sign-in

Mejai's offers optional sign-in: with Google on every platform, and with Apple as well on iPhone. Both lead to the same kind of account and the same backup. The app runs without either, and you can sign out at any time from Settings → Account.

Sign in with Google (Firebase)

When you sign in with Google, the app uses Google Sign-In and Firebase (operated by Google LLC) to back up your data under your account.

Sign in with Apple (iPhone)

When you sign in with Apple, the app uses Apple's Sign in with Apple and the same Firebase project to back up your data under your account.

Sign in with GitHub (removed in 1.9.1)

Versions before 1.9.1 offered an alternative sync that stored your backup as a private gist under your own GitHub account (mejais-backup.json), authenticated by a Personal Access Token with the gist scope that was stored only on your device and sent only to api.github.com. This option has been removed:

Social features

The Social screen is opt-in and only becomes active when you sign in with Google. It is built on top of Firebase Auth and Firestore (same rules as above) and uses the following documents in our Firebase project:

You can disable any category at any time from Social → You, remove friends from your friends list, change or remove your champion avatar, or stop using the social features entirely by signing out. None of this data is shared with anyone other than friends you have added.

Mejai's Pro (in-app purchase)

Mejai's offers an optional paid subscription ("Mejai's Pro") that unlocks additional features inside the app. Purchases are handled by Google Play Billing, and the entitlement is checked through RevenueCat (operated by RevenueCat, Inc.). To do this:

You can cancel a subscription at any time from your Google Play account; when it expires, the Pro features turn off automatically.

Network access (default features)

Even without signing in, the app makes a few anonymous network requests for optional content:

These requests carry only what any web browser sends (your IP address and a generic app user-agent). No account, email, or collection data is ever included.

Camera and on-device OCR

The optional card scanner uses your camera only to read the card name on your device, using Google's on-device Text Recognition (ML Kit). Photos are not saved and nothing is uploaded - recognition runs entirely on the device. Camera access is requested only the first time you open the scanner, and you can decline or revoke it later from Android settings.

Microphone and voice quick add

Current releases do not request microphone permission. A voice version of the quick-add feature (speak a card list, for example "2 ahri alluring foil") is built and being field-tested, but it is disabled in shipped builds while that testing continues. When it ships, it will work as follows: listening is performed by your device's system speech recognizer (on most Android phones, Google's, which processes speech on the device on modern versions); the app receives only the resulting text, and never records, stores or uploads audio itself. Microphone access will be requested only the first time you use the microphone button, the feature will work fully by typing if you decline, and you will be able to revoke the permission from Android settings at any time.

Crash reports and usage analytics

The mobile apps (Android and iPhone) send anonymous crash reports through Google's Firebase Crashlytics when the app hits an error: the crash stack trace, device model, OS version and app version. We use them only to find and fix bugs. Crash reports contain none of your collection data and are not linked to your Google account by us.

Since version 1.9.4 the mobile apps also record three anonymous usage events through Google Analytics for Firebase. The web app records none: analytics is switched off there entirely, so no page or route you open in the browser is reported to anyone. The three events:

We use these three counters to understand whether people who install the app actually use it, and to measure our own app-install campaigns. The events are associated with a random per-install identifier generated by Firebase, not with your name, email or Google account, and we do not use them for advertising profiles or sell them to anyone. Google Analytics for Firebase also logs its own standard lifecycle events on mobile (first_open, session_start, app_update, and a screen_view for the app's single native screen), under the same random identifier and with no content of yours. The advertising ID is switched off in the app's configuration, so none of this is linked to it. Beyond that, no screens, searches or actions are tracked.

Location

The app does not use GPS and does not request location permission. To suggest events for your area, the mobile apps ask the official events locator directly, and the locator picks the area from your IP address, the way any website would; the app itself never learns or stores a location. In the web app that request goes through our relay, which hides your IP address, so the app reads your device's region setting (for example, your country) locally and lets you pick the area yourself.

Children's privacy

The app is not directed at children under 13. We do not knowingly collect data from children under 13. If you are a parent or guardian and believe your child has signed in to the app, contact us at the email below and we will delete their cloud backup and social profile.

Your choices and data deletion

Third-party services

Service Used for Privacy policy
Google Firebase (Auth + Firestore) Optional cloud sync and social features via Google sign-in https://firebase.google.com/support/privacy
Google Firebase (Crashlytics + Analytics) Anonymous crash reports and the three usage events described above (mobile apps only) https://firebase.google.com/support/privacy
Google Sign-In OAuth for Google sign-in https://policies.google.com/privacy
Google Play Billing In-app purchase of Mejai's Pro https://policies.google.com/privacy
RevenueCat Checking the Mejai's Pro entitlement https://www.revenuecat.com/privacy
Google ML Kit (on-device) Card-name OCR (runs on-device; no data sent to Google) https://developers.google.com/ml-kit/terms
Cloudflare Workers Image relay for the web app; feedback relay https://www.cloudflare.com/privacypolicy/
Resend Delivers feedback messages to us by email https://resend.com/legal/privacy-policy
GitHub Pages Hosts the card data and price feed the app downloads https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
GitHub Gist API Historical (sign-in removed in 1.9.1); old gist backups only https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement
Riot Games / UVS Games public web News, events, set artwork and (avatar picker) Data Dragon champion list/icons https://www.riotgames.com/en/privacy-notice
RiftScribe Card catalogue and images https://riftscribe.com
DotGG (riftbound.gg) Suggested deck lists, card images and Cardmarket price data https://riftbound.gg
TCGplayer Card prices, some card images and buy links https://www.tcgplayer.com/privacy-policy
Impact Runs TCGplayer's affiliate program; the buy links pass through it https://impact.com/privacy-policy/
Cardmarket Buy links (plain, no partner tag today) https://www.cardmarket.com

Official website

The app's official website is https://mejais.gg. The web app lives at https://app.mejais.gg.

Third-party trademarks

Riftbound, League of Legends, and all related names and artwork are trademarks of Riot Games, Inc. UVS Games is the publisher of physical Riftbound product. Mejai's is an unofficial fan project and is not endorsed by or affiliated with Riot Games or UVS Games.

Changes to this policy

If this policy changes, the updated version will be published at the same location with a revised "Last updated" date.

Contact

If you have any questions about this privacy policy, or if you'd like your cloud backup, social profile, or any shared data deleted, contact us at:

support@mejais.gg