Privacy Policy - Mejai's
Last updated: 28 September 2026
Mejai's ("the app") is an unofficial, fan-made companion for the Riftbound TCG by Riot Games and UVS Games. This policy explains what data the app handles, where it's stored, and the choices you have.
Summary
- By default, your data stays on your device. No account is required to use the app.
- Cloud sync and social features are optional and opt-in. If you choose to sign in with Google, the data you create in the app is backed up to your own cloud account so it follows you across devices.
- No advertising and no tracking SDKs, signed in or not. The mobile apps send anonymous crash reports and three anonymous usage events (first successful scan, buy-link taps, rating prompts); the web app sends none. Nothing about your cards or collection is ever included. See "Crash reports and usage analytics" below.
- TCGplayer buy links are affiliate links. When you open a card on TCGplayer from the app, the store may pay us a small commission on what you buy, at no cost to you. See "Network access" below.
- No data is ever sold or shared with third parties for marketing.
Data stored on your device (default)
Everything you create in Mejai's - owned cards, wishlist, trade list, binders, decks, match logs, daily value snapshots, and app settings - is stored locally on your device in a private SQLite database. You can export a backup to a JSON file at any time via the in-app share sheet, and delete everything by clearing the app's storage or uninstalling.
Recent searches are kept on this device only and are not part of any backup. Private notes you write about a friend are stored on your device and, if you sign in, travel inside your cloud backup like the rest of your data. They are never shown to that friend or to anyone else.
Optional account sign-in
Mejai's offers optional sign-in: with Google on every platform, and with Apple as well on iPhone. Both lead to the same kind of account and the same backup. The app runs without either, and you can sign out at any time from Settings → Account.
Sign in with Google (Firebase)
When you sign in with Google, the app uses Google Sign-In and Firebase (operated by Google LLC) to back up your data under your account.
- What we receive from Google when you sign in: your Google account name, email address, profile photo URL, and a stable Firebase user ID.
- What is stored in our Firebase project:
users/<your-firebase-uid>- a single document containing the same backup JSON you can export from the app (collection, wishlist, trade list, binders, decks, match logs, value snapshots, app settings).- Social features (only if you open the Social screen and only for the categories you choose to share): see "Social features" below.
- Where it lives: Cloud Firestore, in the developer's Firebase project. Firestore security rules restrict each user document so that only the signed-in user can read or write their own document; other users cannot access it. The developer, as the project's administrator, can open the database for maintenance and does not read anyone's backup.
- Backup copies: the whole database is copied by Google Cloud on a schedule (daily copies kept for 7 days, weekly copies for up to 14 weeks, plus 7 days of version history) and, when the export job is enabled, to a weekly export kept for 8 weeks. These copies exist so that a failure on our side cannot lose your data. Data you delete leaves them as they expire.
- Encryption: in transit (HTTPS / TLS) and at rest (Firebase default encryption).
- What we never send to Firebase: payment information (handled by Google Play, not by us), advertising identifiers, contacts, photos, files, location, or any data from other apps.
Sign in with Apple (iPhone)
When you sign in with Apple, the app uses Apple's Sign in with Apple and the same Firebase project to back up your data under your account.
- What we receive from Apple when you sign in: your name (only the first time you authorize the app, and only if you allow it), your email address or, if you choose "Hide My Email", a private relay address that Apple forwards to you, and a stable Firebase user ID.
- What is stored in our Firebase project: the same as for Google sign-in above: your backup document and, only if you use them, the social documents described below. Nothing else about your Apple ID reaches us.
- One account per email: Firebase keeps one account per email address. If you first signed in with Google and later sign in with Apple using the same address, the app tells you to use the method you set up first. With "Hide My Email", the relay address is different, so it creates a separate account.
Sign in with GitHub (removed in 1.9.1)
Versions before 1.9.1 offered an alternative sync that stored your
backup as a private gist under your own GitHub account
(mejais-backup.json), authenticated by a Personal Access Token with
the gist scope that was stored only on your device and sent only to
api.github.com. This option has been removed:
- On first launch of 1.9.1 or later, any stored token is deleted from the device. Your local data is not affected.
- The backup gist remains in your own GitHub account; the developer never had access to it and you can delete it (and revoke the token) from GitHub's settings at any time.
- Older app versions that still show this option keep working as described above until updated.
Social features
The Social screen is opt-in and only becomes active when you sign in with Google. It is built on top of Firebase Auth and Firestore (same rules as above) and uses the following documents in our Firebase project:
- Your public profile (
social_profiles/<your-uid>): a display name, a unique handle derived from your Google name (the app does not offer a way to change it yet; write to us if you need it changed), a short invite code, your friend-visibility toggles, your Mejai's Pro flag (cosmetic gold crest), and, if you choose one, the URL of the League of Legends champion icon you picked as your avatar. This document is readable by other signed-in users so they can find you by handle or invite code. - Friend requests and friend list: when someone sends or accepts a request, the involved profiles' display names and handles are duplicated into the requests / friends sub-collections so both sides can see who you're connected with.
- Shared content (
social_shares/<your-uid>): for the categories you turn on in Social → You, the relevant data is published to this document so your friends can view it. What each category contains: collection is the full list of the cards you own and how many copies of each; stats is how many different cards and copies that adds up to, and value its estimated worth; decks are your deck names, lists and descriptions; binders their names, layouts, descriptions and card slots; trade list and wishlist their cards and the notes you attached to them. The first time you open Social, collection, stats, decks, binders and trade list are on and value and wishlist are off; every category can be switched separately. Toggling a category off deletes the corresponding part of the document on the next sync. Only your direct friends can read this document.
You can disable any category at any time from Social → You, remove friends from your friends list, change or remove your champion avatar, or stop using the social features entirely by signing out. None of this data is shared with anyone other than friends you have added.
Mejai's Pro (in-app purchase)
Mejai's offers an optional paid subscription ("Mejai's Pro") that unlocks additional features inside the app. Purchases are handled by Google Play Billing, and the entitlement is checked through RevenueCat (operated by RevenueCat, Inc.). To do this:
- Until you sign in, RevenueCat identifies this install by a random anonymous ID it generates. Once you sign in, the app gives RevenueCat your Firebase user ID (the same ID your backup lives under) so that a subscription bought on one device follows your account to your other devices. We do not send your Google account email, name, or any other personal data to RevenueCat from the app.
- Google Play handles your payment details directly under Google's own privacy policy. We never see your card details.
- RevenueCat tells the app whether your Pro entitlement is currently
active. That status (
true/false) is mirrored to your social profile so friends can see the cosmetic gold crest; nothing about your purchase history is shared with friends.
You can cancel a subscription at any time from your Google Play account; when it expires, the Pro features turn off automatically.
Network access (default features)
Even without signing in, the app makes a few anonymous network requests for optional content:
- News: the Home screen shows the latest Riftbound news by fetching
Riot's public news page
(
riftbound.leagueoflegends.com/en-us/news). A bundled snapshot is shown if you're offline. - Events: the Home screen lists upcoming events from the official
events locator (
locator.riftbound.uvsgames.com) and can open it, or a store's website, in your browser. See "Location" below for how the area is chosen. - Card data and images: the card catalogue and prices come from our published feed, hosted on GitHub Pages; card thumbnails load from the public RiftScribe, DotGG and TCGplayer CDNs, and set artwork from Riot's public content CDN. All of it is cached locally on your device. In the web app, card images are fetched through a small relay we run on Cloudflare Workers, because the image hosts do not let browsers on other sites load them directly; the relay passes the image through and stores nothing.
- Buy links: the TCGplayer links in the app are affiliate links.
TCGplayer's program is run by Impact, so those links go through
partner.tcgplayer.comon the way to the product page, and the store may pay us a small commission on what you buy, at no cost to you. The link names the product you tapped and our partner ID; it carries nothing about you or your collection. Cardmarket links are plain links today; if we join Cardmarket's partner program they will carry its tag and this policy will say so. - Feedback: when you send a bug report or an idea from Settings, the app sends your message, its kind, the app version and platform, and, only if you type one, a reply address so we can answer. No account id and no collection data are included. The message goes to the same Cloudflare Workers relay, which emails it to us through Resend, an email delivery service.
- Suggested decks: the Decks screen can fetch community deck
suggestions from the public DotGG API (
riftbound.gg). - League of Legends champion list (avatar picker only): when you
open the Social → You avatar picker, the app fetches the public
champion roster from Riot's Data Dragon CDN
(
ddragon.leagueoflegends.com) to show the champions and their square icons.
These requests carry only what any web browser sends (your IP address and a generic app user-agent). No account, email, or collection data is ever included.
Camera and on-device OCR
The optional card scanner uses your camera only to read the card name on your device, using Google's on-device Text Recognition (ML Kit). Photos are not saved and nothing is uploaded - recognition runs entirely on the device. Camera access is requested only the first time you open the scanner, and you can decline or revoke it later from Android settings.
Microphone and voice quick add
Current releases do not request microphone permission. A voice version of the quick-add feature (speak a card list, for example "2 ahri alluring foil") is built and being field-tested, but it is disabled in shipped builds while that testing continues. When it ships, it will work as follows: listening is performed by your device's system speech recognizer (on most Android phones, Google's, which processes speech on the device on modern versions); the app receives only the resulting text, and never records, stores or uploads audio itself. Microphone access will be requested only the first time you use the microphone button, the feature will work fully by typing if you decline, and you will be able to revoke the permission from Android settings at any time.
Crash reports and usage analytics
The mobile apps (Android and iPhone) send anonymous crash reports through Google's Firebase Crashlytics when the app hits an error: the crash stack trace, device model, OS version and app version. We use them only to find and fix bugs. Crash reports contain none of your collection data and are not linked to your Google account by us.
Since version 1.9.4 the mobile apps also record three anonymous usage events through Google Analytics for Firebase. The web app records none: analytics is switched off there entirely, so no page or route you open in the browser is reported to anyone. The three events:
- First scan: a one-time signal that the scanner was used successfully on this install. It carries no information about which card was scanned.
- Buy-link tap: that a marketplace link (TCGplayer or Cardmarket) was opened, and from which screen. It carries no card names, no prices and no cart contents.
- Rating prompt: that the app asked Google Play to show its rating sheet, and which moment prompted it (for example a finished deck, or a collection-size threshold such as 250 cards). The store never tells the app what you rated, or whether the sheet appeared at all, so nothing about your rating is recorded here or anywhere else.
We use these three counters to understand whether people who install
the app actually use it, and to measure our own app-install
campaigns. The events are associated with a random per-install
identifier generated by Firebase, not with your name, email or Google
account, and we do not use them for advertising profiles or sell them
to anyone. Google Analytics for Firebase also logs its own standard
lifecycle events on mobile (first_open, session_start,
app_update, and a screen_view for the app's single native screen),
under the same random identifier and with no content of yours. The
advertising ID is switched off in the app's configuration, so none of
this is linked to it. Beyond that, no screens, searches or actions are
tracked.
Location
The app does not use GPS and does not request location permission. To suggest events for your area, the mobile apps ask the official events locator directly, and the locator picks the area from your IP address, the way any website would; the app itself never learns or stores a location. In the web app that request goes through our relay, which hides your IP address, so the app reads your device's region setting (for example, your country) locally and lets you pick the area yourself.
Children's privacy
The app is not directed at children under 13. We do not knowingly collect data from children under 13. If you are a parent or guardian and believe your child has signed in to the app, contact us at the email below and we will delete their cloud backup and social profile.
Your choices and data deletion
- Stay local. Don't sign in. Nothing leaves your device.
- Sign out. Settings → Account → Sign out. Removes the local link to your cloud account; your local data is kept.
- Disable social sharing. Social → You → toggle off any category; the published copy on Firestore is deleted on the next sync.
- Delete cloud data: Settings → Account → Delete cloud data, while signed in. It erases your backup, social profile and handle, friends list, pending requests and nudges, and anything you have shared with friends, then signs you out. Your account itself and the Pro record are kept, so you can sign in again and start over. The collection on your device is kept.
- Delete account (iPhone app): Settings → Account → Delete account, while signed in. It erases everything "Delete cloud data" erases, plus the Pro record and the account itself. You are asked to sign in once more first, to confirm it is you; if you cancel at that point nothing is deleted. The collection on your device is kept. A Pro subscription is held by the store, not by the account, and is not cancelled by this (see "Cancel Mejai's Pro" below). On Android and the web, use "Delete cloud data" and then write to us at the email below from the address you signed in with, and we will delete the account itself. Anyone can ask for that by email, on any platform.
- What outlives both, by design: friend requests you sent to people who have not answered stay in their inbox until they decline them (they show only your user ID, which no longer resolves to a profile), and the scheduled backup copies described under "Backup copies" expire on their own timetable.
- Old GitHub backups (before 1.9.1): if you used the retired GitHub
sync, the
mejais-backup.jsongist lives in your own GitHub account; delete it there. The app no longer holds a token for it. - Cancel Mejai's Pro: Google Play → Subscriptions → Mejai's Pro → Cancel, or on iPhone Settings → Apple ID → Subscriptions. The entitlement turns off automatically when the current period ends.
- Delete everything on this device: uninstall the app or clear its storage from Android Settings.
Third-party services
| Service | Used for | Privacy policy |
|---|---|---|
| Google Firebase (Auth + Firestore) | Optional cloud sync and social features via Google sign-in | https://firebase.google.com/support/privacy |
| Google Firebase (Crashlytics + Analytics) | Anonymous crash reports and the three usage events described above (mobile apps only) | https://firebase.google.com/support/privacy |
| Google Sign-In | OAuth for Google sign-in | https://policies.google.com/privacy |
| Google Play Billing | In-app purchase of Mejai's Pro | https://policies.google.com/privacy |
| RevenueCat | Checking the Mejai's Pro entitlement | https://www.revenuecat.com/privacy |
| Google ML Kit (on-device) | Card-name OCR (runs on-device; no data sent to Google) | https://developers.google.com/ml-kit/terms |
| Cloudflare Workers | Image relay for the web app; feedback relay | https://www.cloudflare.com/privacypolicy/ |
| Resend | Delivers feedback messages to us by email | https://resend.com/legal/privacy-policy |
| GitHub Pages | Hosts the card data and price feed the app downloads | https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement |
| GitHub Gist API | Historical (sign-in removed in 1.9.1); old gist backups only | https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement |
| Riot Games / UVS Games public web | News, events, set artwork and (avatar picker) Data Dragon champion list/icons | https://www.riotgames.com/en/privacy-notice |
| RiftScribe | Card catalogue and images | https://riftscribe.com |
| DotGG (riftbound.gg) | Suggested deck lists, card images and Cardmarket price data | https://riftbound.gg |
| TCGplayer | Card prices, some card images and buy links | https://www.tcgplayer.com/privacy-policy |
| Impact | Runs TCGplayer's affiliate program; the buy links pass through it | https://impact.com/privacy-policy/ |
| Cardmarket | Buy links (plain, no partner tag today) | https://www.cardmarket.com |
Official website
The app's official website is https://mejais.gg. The web app lives at https://app.mejais.gg.
Third-party trademarks
Riftbound, League of Legends, and all related names and artwork are trademarks of Riot Games, Inc. UVS Games is the publisher of physical Riftbound product. Mejai's is an unofficial fan project and is not endorsed by or affiliated with Riot Games or UVS Games.
Changes to this policy
If this policy changes, the updated version will be published at the same location with a revised "Last updated" date.
Contact
If you have any questions about this privacy policy, or if you'd like your cloud backup, social profile, or any shared data deleted, contact us at:
support@mejais.gg