Legal
Privacy Policy
Last updated: 6 August 2026
What we collect
When you use Hikari, we store your Discord user ID, Discord username, and Discord avatar URL. We also store your card collection, pull history, coin and gem balances, trade history, guild membership, and daily activity timestamps. No email addresses, passwords, or payment information are ever collected.
Discord OAuth
When you log in to the Hikari website, we request the 'identify' OAuth scope from Discord. This gives us access to your Discord user ID, username, and avatar only. We do not request access to your email, server list, messages, or any other Discord data.
How we use your data
Your data is used solely to operate the Hikari service — tracking your collection, processing trades, running the economy, and displaying your public profile. We do not sell, share, or license your data to any third party.
Data storage
All data is stored in a Supabase (PostgreSQL) database. Card images are served via a proxied route — the source CDN domain is never exposed to your browser. Session data is stored in a signed JWT cookie with a 30-day expiry.
Public information
Your username, avatar, showcase cards, collection statistics, and guild membership are publicly visible on your Hikari profile page. Your Discord ID is never displayed publicly. Trade history is visible on your profile page.
Data retention
Your data is retained for as long as your account is active. If you request deletion, we will permanently remove your player record, card collection, and all associated data within 14 days.
Data deletion requests
To request deletion of your data, contact us in the Hikari Discord server. Please send the request from the Discord account associated with your Hikari account.
Changes
This policy may be updated at any time. Material changes will be announced in the Hikari Discord server. Continued use of the service constitutes acceptance.