Privacy Policy · Last updated 2026-04-30
Stardeck Privacy Policy
This policy describes what information Stardeck collects, why we collect it, who we share it with, and how you can exercise your rights over your data. It applies to the Stardeck website, web application, and browser extension.
1. Who is responsible for your data
Stardeck is operated by Polypixel. For privacy-related questions or to exercise your rights, contact [email protected].
2. Account data
Authentication is handled by Supabase, our authentication provider. When you create an account, Supabase stores your email address and a hashed (non-reversible) representation of your password on Stardeck's behalf. Stardeck never sees your plaintext password.
Stardeck stores a profile record linked to your Supabase identity, including: your email address (for account identification and required communications), an optional display name, an optional avatar URL, an optional short bio, and per-user preference settings (e.g. theme).
3. Application data
Stardeck stores data you create or import while using the Service:
- Hangar snapshots: ships and upgrades you have synced from your account on the RSI website via the browser extension (item names, prices observed at the time of sync, ownership state). This data is associated with your Stardeck account.
- Chain plans: the upgrade chains you create, including any chain names, descriptions, and pinning configurations you set.
- Organization membership: if you belong to a Stardeck organization, your role and permissions within it.
- Plan / Donator Tier metadata: your current Donator Tier, billing interval, and the corresponding Stripe customer and subscription identifiers used to coordinate billing with Stripe.
We do not collect data outside of what is necessary to operate the features described above.
4. Browser extension
The Stardeck browser extension reads ship, upgrade, and pricing information that is already visible to your own authenticated session on the RSI website (for example, your hangar page) and transmits the parsed results to Stardeck's backend, where it is associated with your Stardeck account so the data is available when you log in.
The extension does not read, store, or transmit your RSI username, password, two-factor codes, or session tokens. It does not log into the RSI website on your behalf and has no mechanism to do so.
5. Public RSI store data
Stardeck operates an automated process that periodically fetches publicly visible pricing and listing data from the RSI store. This process does not collect personal information, does not require any user authentication, and is independent of any individual user's account.
6. Third-party processors
Stardeck relies on the following third-party services to operate. Each is bound by its own privacy policy:
- Supabase: authentication and identity (email, hashed password, session management).
- Stripe: payment processing for Donator Tier contributions. When you donate, you interact with Stripe directly; Stripe collects payment-method information and shares with Stardeck only the metadata needed to recognize your tier (such as customer ID, subscription ID, and current status). Stardeck never sees your full payment-method details.
- Google Cloud Platform: hosting infrastructure.
- Cloudflare: DNS and content delivery for the Stardeck website.
8. How long we keep your data
We retain account and application data for as long as your account exists. If you delete your account, we delete your associated profile, chain plans, and hangar snapshots within 30 days, except for billing records that we are required to retain for accounting and tax-compliance purposes.
9. Your rights
You have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate.
- Delete your account and the associated data, subject to retention requirements imposed by law (e.g. billing records).
- Export your chain plans and hangar data, where reasonable.
To exercise any of these rights, email [email protected]. We will respond within a reasonable time.
10. Children
Stardeck is not directed at children under 13 (or under 16, depending on your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us so we can delete it.
11. Changes to this policy
We may update this policy from time to time. We will indicate changes by updating the “Last updated” date at the top of this page. For material changes, we will provide reasonable notice (for example, by email to active users, or by a prominent notice on the site).