Legal document
Privacy policy
What data Joutes collects, why, who it is shared with and how to stay in control of it.
Last updated: August 4, 2026
See also the terms of use.
This English version is a courtesy translation. The French version is the legally binding one: in the event of any discrepancy, the French text prevails.
- We only collect what the Platform needs to work.
- Your data is never sold, rented or used for advertising.
- No advertising cookies and no profiling trackers: audience measurement is anonymous.
- Your location is only used if you provide it, to find events near you.
- You can access, correct, export or have your data deleted at any time.
- 1.Who processes your data
- 2.Data we collect
- 3.Why, and on what legal basis
- 4.What other users can see
- 5.Cookies and audience measurement
- 6.Hosting and suppliers
- 7.AI-assisted features
- 8.Transfers outside the European Union
- 9.Retention periods
- 10.Security
- 11.Your rights
- 12.Minors
- 13.Changes to this policy
- 14.Contact
The Joutes platform, available at https://joutes.app, is published by Nakasar, acting as data controller for the data described in this policy.
This policy applies to all the services of the Platform: website, public API, MCP server and Discord bot. It supplements the terms of use.
For any question or request about your data, the contact channels are listed at the end of this document.
We only collect the data needed to run the service. Most of it comes directly from you; some is generated by your use of the Platform.
Account and authentication
- email address;
- one-time sign-in codes, valid for a few minutes, sent by email;
- if you sign in with Discord: the ID, username, avatar and email address associated with that account;
- if you use a passkey: the public key and its technical metadata — no biometric data is sent to us, it never leaves your device;
- active sessions: session token, creation and expiry dates, IP address and browser used when signing in.
Profile and preferences
- username, display name, description, profile picture, website and social links you provide;
- friend code, public profile visibility;
- games and venues followed, display language, theme, notification preferences.
Location
- a default position (latitude and longitude) if you choose to save it in your account;
- a one-off position, entered manually or provided by your browser after your explicit authorisation, used for the duration of a nearby-events search and not stored in the database on that occasion.
Content and activity
- events created and registrations, tournaments and leagues (pairings, results, standings), matches and play groups;
- friends and friend requests, venues followed, membership of private venues;
- collections, wishlists, decks, cubes, trades and sell lists;
- community contributions: rulings, errata and the associated votes, quizzes, news, content reports;
- achievements earned and notifications received.
Integrations and developers
- API keys: name, description, prefix, date of last use and call counter — the key itself is stored hashed;
- third-party applications authorised via OAuth and the permissions granted;
- identifiers required for the Discord bot and the MCP server to work.
Technical data
- logs generated by the hosting provider: IP address, timestamp, resource requested, browser and operating system;
- aggregated audience measurement (pages viewed, referrer) with no identifier that could single you out.
We deliberately collect no special category data within the meaning of Article 9 GDPR. Please do not publish any in free-text fields (profile description, event descriptions, messages).
Each processing operation serves a specific purpose and rests on a legal basis under the GDPR:
| Purpose | Data concerned | Legal basis |
|---|---|---|
| Creating and managing your account, signing you in | Email, sign-in credentials, sessions, profile | Performance of the Terms (contract) |
| Providing the features: events, tournaments, collections, trades, community | The content and activity you create | Performance of the Terms (contract) |
| Showing events near you | Saved position or one-off browser position | Consent (withdrawable at any time) |
| Sending sign-in emails and service notifications | Email address | Performance of the Terms (contract) |
| Sending the weekly digest and Platform news | Email address, games and venues followed | Consent (can be turned off in your preferences) |
| Ensuring security, preventing abuse, moderating reported content | Technical logs, reports, account data | Legitimate interest in protecting the service and its users |
| Measuring audience and improving the Platform | Aggregated browsing statistics | Legitimate interest (anonymous measurement, no profiling) |
| Answering your requests and rights enquiries | Content of the request, account data | Legal obligation |
Your data is never sold, rented or used for targeted advertising, and is not subject to any automated decision producing legal effects concerning you.
Joutes is a community platform: some of your data is, by nature, visible to other people.
- Publicly accessible (including to search engines): your username and avatar wherever they appear on public content, the events you publish, public tournaments and their results, community contributions (rulings, errata, quizzes).
- Visible if you enable it: your profile information (description, website, social links, games and venues followed) when the public profile is switched on in your account.
- Visible to a limited circle: your friends, the members of your play groups and private venues, and the participants and organisers of the events you sign up for.
- Private by default: your email address, your saved position, your collections, wishlists, decks and cubes, as long as you do not share them.
Event and tournament organisers can see the participant information needed to run the event. They are responsible for how they use it outside the Platform.
The Platform deliberately uses very few trackers:
- Strictly necessary cookies: a session cookie that keeps you signed in, a language cookie (
NEXT_LOCALE) and technical security cookies. - Local storage: your theme preference (light, dark or system) is kept in your browser and is never sent to our servers.
- Audience measurement: Vercel Web Analytics produces aggregated traffic statistics without setting an advertising cookie, without a persistent identifier and without cross-site tracking.
We use neither an advertising network nor third-party profiling trackers. This processing falls under cookies strictly necessary for the service and anonymous audience measurement, both exempt from consent; no cookie banner is therefore shown.
You can delete these cookies from your browser at any time; you will be signed out as a result.
We rely on a limited number of technical suppliers, which act as processors on our behalf and do not use your data for their own purposes:
| Supplier | Role | Data concerned |
|---|---|---|
| Vercel Inc. | Hosting the Platform, image storage, audience measurement | All data passing through the service, technical logs, published images |
| MongoDB | Database | Accounts, profiles, content and activity |
| Meilisearch | Search engine for cards and game content | Search queries and game data (no account data) |
| Resend | Sending emails | Email address and the content of the message sent |
| OpenAI | AI-assisted features | The content you submit to those features |
| Discord | Discord sign-in, community bot | Discord ID and profile, messages exchanged with the bot |
Beyond these suppliers, your data is only disclosed to third parties in two cases: to the applications you have authorised yourself via OAuth or your API keys, and to administrative or judicial authorities where the law requires it.
Some optional features rely on artificial intelligence models operated by a third-party supplier:
- Card scanning: the picture you take is sent to the supplier to identify the card; it is not stored on our servers.
- Deck checking: the card list submitted is sent for analysis.
- Quiz import and event retrieval: the texts or pages provided are sent so that structured information can be extracted from them.
Only the content needed for the processing is sent, without your identity or contact details. That content is not used to train models. If you would rather avoid this processing, simply do not use the features concerned.
Some of our suppliers are established in the United States or may process data there. These transfers are framed by the safeguards provided for in Chapter V of the GDPR, in particular the European Commission's standard contractual clauses and, where applicable, the supplier's Data Privacy Framework certification.
You can ask us for details of the safeguards applying to a given supplier through the contact channels.
| Data | Period |
|---|---|
| Account, profile and preferences | For as long as the account exists, then deleted or anonymised following your request |
| Sign-in sessions | 7 days maximum, renewed on use and revocable at any time |
| Sign-in codes sent by email | 10 minutes |
| Published content (events, decks, collections, contributions) | Until you delete it or your account is deleted |
| Shared histories (tournament results, matches, trades) | Kept for the consistency of other participants' history, dissociated from your account after deletion |
| API keys and application authorisations | Until they are revoked |
| Content reports | For the duration of the review, then a limited period for moderation follow-up |
| Technical logs | A short period set by the hosting provider, for security and diagnostics |
| Audience statistics | Kept in aggregated form, without identification |
We apply measures appropriate to the nature of the service:
- encrypted traffic over HTTPS;
- passwordless authentication (one-time code, passkey or Discord account), which removes the risk tied to password reuse;
- hashed storage of API keys and sensitive tokens;
- access to production data restricted to the people who need it to operate the service;
- separation of private data and server-side permission checks.
No system is infallible. Should a data breach be likely to result in a high risk to your rights and freedoms, you will be informed under the conditions set out in the GDPR.
Under the GDPR and the French Data Protection Act, you have the following rights:
- Access: obtain a copy of the data we hold about you;
- Rectification: correct inaccurate data — most information can be changed directly from your account;
- Erasure: request the deletion of your account and your data, subject to the data we are required to keep;
- Objection: object to processing based on our legitimate interest;
- Restriction: ask for a disputed processing operation to be temporarily frozen;
- Portability: receive your data in a structured, machine-readable format;
- Withdrawal of consent: at any time, for the processing that depends on it (location, optional emails), without affecting processing already carried out;
- Post-mortem instructions: set out what should happen to your data after your death.
To exercise these rights, contact us through the channels listed below. You will receive a reply within one month, which may be extended for complex requests. We may need to verify your identity, in particular via the email address linked to your account.
If you believe your rights are not being respected, you can lodge a complaint with the French data protection authority (CNIL): www.cnil.fr. You may also contact the supervisory authority of the EU country where you live.
The Platform is intended for people aged 15 or over. Below that age, creating an account requires the consent of the holder of parental authority.
If you become aware that an account was created by a child without that consent, contact us: the account and the associated data will be deleted.
This policy may change along with the features of the Platform or the applicable law. The date of the latest update appears at the top of the page.
Where a change is substantial — a new purpose, a new recipient, a new category of data — you will be informed on the Platform or by email before it takes effect, wherever this is required.
For any question about your personal data, or to exercise your rights:
- Discord: https://discord.gg/dZEGkZwJGB
- GitHub: https://github.com/Joutes
Please mention the email address linked to your account so that your request can be matched to the right user.