HIKARI

Legal

Privacy Policy

Last updated: 6 August 2026

01

What we collect

When you use Hikari, we store your Discord user ID, Discord username, and Discord avatar URL. We also store your card collection, pull history, coin and gem balances, trade history, guild membership, and daily activity timestamps. No email addresses, passwords, or payment information are ever collected.

02

Discord OAuth

When you log in to the Hikari website, we request the 'identify' OAuth scope from Discord. This gives us access to your Discord user ID, username, and avatar only. We do not request access to your email, server list, messages, or any other Discord data.

03

How we use your data

Your data is used solely to operate the Hikari service — tracking your collection, processing trades, running the economy, and displaying your public profile. We do not sell, share, or license your data to any third party.

04

Data storage

All data is stored in a Supabase (PostgreSQL) database. Card images are served via a proxied route — the source CDN domain is never exposed to your browser. Session data is stored in a signed JWT cookie with a 30-day expiry.

05

Public information

Your username, avatar, showcase cards, collection statistics, and guild membership are publicly visible on your Hikari profile page. Your Discord ID is never displayed publicly. Trade history is visible on your profile page.

06

Data retention

Your data is retained for as long as your account is active. If you request deletion, we will permanently remove your player record, card collection, and all associated data within 14 days.

07

Data deletion requests

To request deletion of your data, contact us in the Hikari Discord server. Please send the request from the Discord account associated with your Hikari account.

08

Changes

This policy may be updated at any time. Material changes will be announced in the Hikari Discord server. Continued use of the service constitutes acceptance.