Legal
Privacy Policy
Last updated: September 14, 2026
Overview
This policy describes how Materia Labs LLC ("we," "us," or "our") handles information in Surveil, our iPhone app for tracking the value of a Magic: The Gathering collection. It is specific to Surveil. Book Move has its own policy.
In short: Surveil stores the account and collection data you give it so it can show you your collection's value, records first-party usage events so we can see where people get stuck, and nothing else. No ads, no cross-app tracking, no data sales.
Data We Collect
You can browse the market, search, and view card prices without an account. If you create an account, we collect:
- Email address and sign-in credentials.Email/password, Sign in with Apple, or Google, used to create, sign in to, and recover your account. If you use Apple's "Hide My Email," we only see the relay address.
- A Surveil user ID issued by our authentication provider, used to associate your data with your account.
- Collection data you enter or import: portfolio name, card holdings (printing, finish, quantity), optional price paid and currency, watchlist entries, import resolution choices, and deck notes if you use those features. A price paid is collection metadata, not a payment card or bank account.
- Product usage events: named steps such as app open, onboarding, sign-in, scan, import, and add-to-collection, plus a random app-install identifier, app version, and short non-content values such as the sign-in method. Events recorded before you sign in stay on your device and are uploaded only if you create an account. These events are linked to your Surveil user ID and are used to see where people drop off. They never include emails, card names, tokens, or camera images.
We do not collect precise location, contacts, photos from your library, browsing history, advertising identifiers, crash reports, or payment information in the current Surveil release, and Surveil has no third-party analytics or advertising SDKs.
Camera. If you scan a card, the image is processed on your device to recognize the card. The image itself is never uploaded or stored. Imports. CSV files are parsed on your device; we send only the normalized card rows needed to save your collection, not the original file.
How We Use Your Data
We use this data to provide Surveil:
- Sign you in and keep your collection in sync across your devices.
- Show your portfolio value, price history, market movers, and watchlists.
- Complete and troubleshoot collection imports.
- Understand where people drop off in the app so we can improve it.
- Respond to support requests and comply with legal obligations.
We do not sell your data, use it for third-party advertising, or track you across other companies' apps and websites.
Services That Process Data
- Supabase hosts authentication, your collection database, and the usage events above. Access is row-level: only you can read your holdings, app clients cannot read analytics rows, and anonymous clients cannot write them.
- Apple or Google, if you choose that sign-in method, under their own policies.
- Scryfall for card catalog data, images, and some lookups. We send card names, set codes, or card identifiers, never your Surveil account.
- MTGJSON, on our servers only, to fill gaps in historical prices.
- Archidekt, if you import a deck by URL; we send the deck ID, not your identity.
If you connect an AI assistant to Surveil through our invite-only Collection integration, that assistant can read your collection and manage your watchlist until you revoke its access in the app.
Data Storage and Security
Your data is stored on cloud infrastructure in the United States operated by the providers above, and cached on your device. We use industry-standard protections, but no method of transmission or storage is completely secure.
Account Deletion
In the app: Profile → Manage Account → Delete Account. This removes your Surveil login, the collection data tied to it, and usage events linked to your user ID, and it clears queued events and rotates the local app-install identifier. If you signed in with Apple, deletion also revokes Surveil's Sign in with Apple authorization. You can also email us and we will delete your account for you.
Backups may retain deleted data until they expire. We do not use deleted account data to provide the service.
Children's Privacy
Surveil is not directed at children under 13. We do not knowingly collect any data from children under 13.
Changes to This Policy
We may update this policy occasionally. When we do, we'll update the "last updated" date above. Continued use of Surveil after changes constitutes acceptance of the updated policy.
Contact
Questions about this policy? Email us at support@materia-labs.com.