Trust
Built for collectors who want control
CardScanR is a local-first Pokémon collection app with optional cloud sync and opt-in sharing. This hub links our plain English data and security pages, plus quick answers to common questions.
Our plain-English promise
Your collection belongs to you. CardScanR stores your inventory on your device by default. Cloud sync is opt-in. We do not sell your personal information or collection data. We do not run advertising SDKs or behavioural ad profiling. We do not use your collection to train AI models (currently disabled; any future training would require a separate opt-in). Official apps do not upload raw scan photos through collection sync. You can export, delete cloud collection data, and delete your account through supported tools.
This is a product commitment backed by how CardScanR is built today, not a legal warranty or compliance certificate.
Trust and policy pages
Frequently asked questions
- Will you sell my collection data?
- No. We do not sell personal information or collection data.
- Can other collectors see my cards?
- Not unless you turn on a share link on the web companion. Private collections are isolated with database row-level security and ownership checks.
- Do you use my scans to train AI?
- No customer-data model-training pipeline was found. Training on customer data is currently disabled and would require a future separate opt-in if ever offered.
- Does CardScanR upload every card photo?
- No. Collection sync uploads metadata, not raw scan photos. Scan frames stay on your device unless you export diagnostics or attach feedback images.
- What happens if I lose my phone?
- Local-only data goes with the device unless you exported a backup. Cloud sync protects a collection only after you enable it and the app records a successful sync. Sign in on a new device to restore that synced metadata. CSV and JSON exports are for portability. A local backup file can replace the collection on a device through Restore. Scan photos that never left the old device are not recovered from the cloud.
- What if CardScanR shuts down?
- We would aim to give reasonable notice and keep export and deletion paths available for a practical period. Your local exports and backups remain yours regardless. We cannot promise indefinite cloud hosting.
- What if CardScanR is hacked?
- We would investigate, contain where possible, and notify affected users when appropriate. Because scan photos are not uploaded via collection sync, impact would mainly affect metadata you chose to sync and account records. See Security.
- Can I export everything?
- The Android app supports CSV export, JSON export, and local backup from Settings → Data and privacy. Cloud-only fields may require sync to be enabled first.
- Can I delete everything?
- Delete cloud collection data from Settings → Data and privacy, delete your account via the in-app Edge Function or delete-account page, and remove local data by clearing app storage or uninstalling. Account deletion removes cloud collection rows and the Auth user when the server path completes; required billing or audit records are not collection cards.
- Does Google see my collection?
- Google sign-in and Play Billing process authentication and payments under Google's policies. Google does not receive your CardScanR collection through normal app use.
- Do advertisers see my collection?
- No. We do not run advertising SDKs or behavioural ad profiling in the shipped app and public website source reviewed for these pages.
- Can CardScanR admins see my collection?
- Operators can access systems that store cloud data when you enable cloud features, for support and operations. Admin tools require authenticated admin checks. Your collection is not a public admin gallery in the Android app.
- Where can I report a security concern?
- Email [email protected] or read security.txt. Details are on the Security page.