Privacy

Privacy Policy

Effective: 4 August 2026 · Last updated: 19 August 2026
App: CardScanR: TCG Card Scanner · Package: com.cardscanr.app

Related trust pages

Plain English summaries: Your data · Security · Trust hub

Australian privacy context

CardScanR is operated from Australia. This policy is written with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) in mind for how we describe collection, use, disclosure, access, correction, and deletion. It is information about our practices, not legal advice, and not a guarantee of compliance with every applicable law in every jurisdiction.

1. Who operates CardScanR

CardScanR is operated by Andrew Gore.

Contact for privacy and support: [email protected].

2. Scope

This policy describes information processed by the CardScanR Android application and related backend services used by the app. Where you have rights under applicable law (including APP access and correction rights for personal information we hold), we will respond to valid requests through the contact method above.

3. Information you provide

Account and Google OAuth profile

CardScanR uses Supabase Authentication. You may sign in with:

Profile and onboarding

When signed in, the app may store a cloud profile (for example display name, country code, currency code, pricing market preferences, main use case, TCG interests, and onboarding completion status).

Opt-in cloud sync of collection metadata

Card inventory is stored in a local database on your device by default. Cloud sync of collection metadata is opt-in: it only runs when you are signed in and you explicitly enable sync in the app (and when the build allows it). Synced records can include card identity fields, condition, quantity, purchase and estimate fields, tags, catalogue image URLs, acquisition source text, and related collection metadata. Collection sync does not upload card photographs from your camera or gallery.

In the official Flutter app and web companion, collection item notes are sent as null during sync. Notes are intended to stay on your device. Acquisition source text can sync when cloud sync is enabled.

Scan session metadata

When signed in, the app may save scan session metadata to the cloud (for example scan mode, source, status, counts, and OCR text excerpts). That is metadata about scanning activity, not an upload of full card photographs through collection sync.

4. Camera frames, photographs, and on-device OCR

CardScanR requests camera permission when you open scanning. You may also choose images from your gallery via the system picker.

On-device processing: Camera frames and selected images are processed on the device for OCR and card matching (including Google ML Kit Text Recognition and OpenCV processing). Recognition work for scanning is designed to stay on-device.

No photo upload via collection sync: Enabling cloud collection sync uploads collection metadata, not your card photos. Catalogue artwork shown in the app is typically downloaded from catalogue or image hosts as reference URLs, not copies of your camera captures.

Optional diagnostics or feedback you deliberately export may include scan evidence you choose to share; see below. We do not claim that local frames are encrypted at rest, anonymised, or retained for a fixed period on the device.

5. Market price and catalogue requests

To match cards and show estimated market values, the app may send card identity queries (such as name, set, collector number, language, or variant) to third-party or backend services, including catalogue APIs and any configured CardScanR pricing backend. Those requests are for informational estimates only. Pricing figures are not financial advice.

6. Device preferences and optional diagnostics / feedback

6a. Website feedback form

CardScanR provides a secure feedback form at cardscanr.com/feedback for bugs, suggestions, and data-quality reports about the Android app. This section describes that form only (not in-app diagnostics exports).

Information you may enter

Do not submit passwords, verification codes, payment card numbers, or government identifiers through the form.

Purpose

We use website feedback to investigate issues, prioritise improvements, and correct catalogue or pricing problems you report. Feedback may be used to improve CardScanR features and data quality.

Anti-abuse processing

Submissions pass through a validated server endpoint with size limits and duplicate protection. To reduce spam and abuse, we may derive short-lived rate-limit keys from request metadata using an HMAC with a private rotating salt. We do not permanently store raw IP addresses for this purpose. Derived keys and related anti-abuse logs are kept only as long as needed for rate limiting and security review, then discarded or aggregated.

Cloudflare Turnstile

The feedback page uses Cloudflare Turnstile to help block automated abuse. Turnstile may process browser signals under Cloudflare’s policies. We validate the Turnstile token server-side before accepting a submission.

Supabase storage and processing

Accepted feedback is stored in the CardScanR Supabase project through a dedicated Edge Function. The public website uses only publishable client credentials; service-role keys are not exposed in the browser. Feedback rows are not readable or writable by anonymous browser clients directly.

Retention and deletion

Feedback is retained as needed to handle your report, track resolution, and improve the product. Retention periods may vary by status and operational need. To request access, correction, or deletion of feedback you submitted, contact [email protected] with your public reference ID if you have one. We will respond consistent with applicable privacy rights; deletion may take time where backups or legal holds apply.

7. Purposes for processing

8. Local versus cloud processing

Primarily local
Camera frames for live scanning, on-device OCR/match, local inventory storage, preferences, and optional local diagnostic files.
Cloud / network
Authentication; opt-in collection metadata sync; HTTPS requests for catalogue and market price data; download of catalogue artwork references; OAuth browser return for Google sign-in.

9. Third-party service providers

Depending on features you use, providers may include Supabase (authentication and database), Google (sign-in and on-device ML Kit), catalogue and pricing APIs, and any configured CardScanR pricing or image hosting backends. Each provider processes data under its own policies.

10. Data sharing, advertising, and sale

We do not sell personal information or collection data. We do not use your collection for advertising. No advertising SDKs, Facebook Pixel, Google Ads, or behavioural ad profiling were found in the CardScanR app or public website source reviewed for this policy.

Data is shared with service providers only as needed to operate CardScanR (authentication, sync, catalogue, and pricing lookups), or if required by law. Card identity queries sent to catalogue and pricing APIs are necessary to return match and price estimates.

10a. AI and model training

No customer-data model-training pipeline was found. CardScanR policy: customer data is not used to train CardScanR or third-party AI models unless a future separate opt-in exists. That training path is currently disabled.

On-device OCR (Google ML Kit) runs locally for scanning. It is separate from uploading your collection to train a cloud model.

10b. Google Play Billing

Premium subscriptions are purchased inside the Android app through Google Play Billing. Google processes payment. CardScanR receives purchase verification and entitlement status from Google Play, not your full payment card number.

11. International processing

Supabase and other providers may process data in data centres outside Australia. If that is material to you, contact us before enabling cloud features.

12. Security

The app uses HTTPS for network calls and Supabase client keys intended for publishable client use. No security measure is perfect. Do not email passwords or payment secrets to support. See Security for more detail on protections and limits.

13. Retention

Local data remains on your device until you clear app storage, uninstall, or overwrite it. Cloud account, profile, and opted-in collection metadata remain until deleted through a supported deletion process or otherwise removed by the operator. Optional diagnostics you send are retained only as needed to handle your request.

14. Account and data deletion

You can request deletion of your CardScanR account and associated cloud data:

You can also delete cloud collection data through the server purge RPC (customer_purge_cloud_collection_data) with same-user auth checks; in-app UI for this action is being added.

Subject to verification, a request is intended to cover the authentication account, profile, customer collection items synced to the cloud, binders and memberships where stored server-side, sync preferences/operations, and associated feedback or beta-program records where present. Local device data is separate and may remain unless you clear storage or uninstall. Sign out does not delete the account. See the deletion page for processing expectations and what may be retained (backups, legal holds).

15. Your choices and rights

16. Children and target audience

You must have the legal capacity to agree to use CardScanR where you live. CardScanR is not directed to children.

17. Changes

We may update this policy as the app or providers change. The effective and last-updated dates above will be revised when a new version is published.

18. Contact

Privacy questions for CardScanR: TCG Card Scanner: [email protected].

Support page Deletion page