Sign-in, security and the language or theme you pick use cookies the site needs. With your permission we also count page views (without cookies) to see what to improve, and show YouTube videos, which let Google set cookies. You can change this any time under “Cookie settings”. Privacy policy
Technical security & operations
Last updated 29 September 2026
How the site protects your account and data, and how it is run day to day.
1. Where data is kept
The site runs on professional cloud providers. Data is stored in encrypted form, can be reached only by the site itself through secured connections, and the keys to it are kept separately from the code.
2. Connections and the browser
Every connection is encrypted; browsers are told to use only secure connections.
Pages allow only the site’s own code to run, and cannot be embedded in other websites.
Access to your camera, microphone, location and payment features is switched off.
3. Accounts and sign-in
Passwords must be at least 8 characters, are checked against passwords known from data leaks, and are stored so that nobody, including the site owner, can read them.
Email is confirmed with a one-time code before the account can be used; codes expire after a few minutes and allow only a few tries.
Sessions end after a period without use. Resetting a password signs every other device out; a suspended account is signed out everywhere.
Changing the email needs a code sent to the current address first, then one to the new address.
Signing in with Google or Discord joins an existing account only when that provider confirms the email.
4. Protection against abuse
An automatic check that you are a person on sign-up, password reset, code requests, email changes and feedback from visitors.
Limits on how often sensitive actions can be repeated (for example signing in, requesting codes, commenting, reporting, saving and sharing), counted across the whole site.
Limits on sizes and amounts, such as 300 decks per account and 1,000 characters per comment, and a filter for offensive words in English and Thai.
Reports from players go to moderators, who can hide comments, make decks private and suspend accounts.
5. Access control
Every change is checked on the site’s side: who you are, and whether you are allowed to do it. Nothing relies on what the page shows.
Private decks are visible only to their owner; decks shared by link need a secret link; decks shared with people need their account.
Moderator tools are open only to a small list of confirmed accounts; everyone else sees “not found”.
6. Uploaded pictures
Only common picture formats up to 2 MB are accepted. Every picture is converted by the site before it is stored, which removes hidden data and anything that is not an image. Pictures are removed when the account is deleted.
7. Collecting as little as possible
Visitors’ deck views are counted without storing their address, usage statistics are optional and use no cookies, and you can download or delete everything about your account yourself. See the privacy policy for details.
8. Operations
Every change is checked and tested automatically before it goes live, and the live site is tested again after every release.
Changes to stored data are planned and applied in a controlled way before a new version goes live.
The software the site depends on is monitored and kept up to date.
Card pages are built to keep working even when other parts of the system are busy.
Data can be restored to an earlier point in time if something goes wrong.
9. Incidents
If something goes wrong, affected accounts can be signed out or suspended at once and access keys replaced. If personal data is breached, the Office of the Personal Data Protection Committee is notified within 72 hours where the law requires it, and affected users are told what happened and what to do.
10. Reporting a security problem
Found a weakness? Please describe it through the feedback page (choose “Something is broken”), and do not access other people’s data or disrupt the site while looking. Reports are handled first.