Privacy

Privacy Policy for CardScanR: TCG Card Scanner

Effective: 4 August 2026 · Last updated: 4 August 2026
App: CardScanR: TCG Card Scanner · Package: com.cardscanr.app

Australian privacy context

CardScanR is operated from Australia. This policy is written with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) in mind for how we describe collection, use, disclosure, access, correction, and deletion. It is information about our practices — not legal advice, and not a guarantee of compliance with every applicable law in every jurisdiction.

1. Who operates CardScanR

CardScanR is operated by Andrew Gore.

Contact for privacy and support: cardscanr.dev@gmail.com.

2. Scope

This policy describes information processed by the CardScanR Android application and related backend services used by the app. Where you have rights under applicable law (including APP access and correction rights for personal information we hold), we will respond to valid requests through the contact method above.

3. Information you provide

Account and Google OAuth profile

CardScanR uses Supabase Authentication. You may sign in with:

Profile and onboarding

When signed in, the app may store a cloud profile (for example display name, country code, currency code, pricing market preferences, main use case, TCG interests, and onboarding completion status).

Opt-in cloud sync of collection metadata

Card inventory is stored in a local database on your device by default. Cloud sync of collection metadata is opt-in: it only runs when you are signed in and you explicitly enable sync in the app (and when the build allows it). Synced records can include card identity fields, condition, quantity, purchase and estimate fields, notes, tags, catalogue image URLs, and related collection metadata. Collection sync does not upload card photographs from your camera or gallery.

Scan session metadata

When signed in, the app may save scan session metadata to the cloud (for example scan mode, source, status, counts, and OCR text excerpts). That is metadata about scanning activity, not an upload of full card photographs through collection sync.

4. Camera frames, photographs, and on-device OCR

CardScanR requests camera permission when you open scanning. You may also choose images from your gallery via the system picker.

On-device processing: Camera frames and selected images are processed on the device for OCR and card matching (including Google ML Kit Text Recognition and OpenCV processing). Recognition work for scanning is designed to stay on-device.

No photo upload via collection sync: Enabling cloud collection sync uploads collection metadata, not your card photos. Catalogue artwork shown in the app is typically downloaded from catalogue or image hosts as reference URLs, not copies of your camera captures.

Optional diagnostics or feedback you deliberately export may include scan evidence you choose to share — see below. We do not claim that local frames are encrypted at rest, anonymised, or retained for a fixed period on the device.

5. Market price and catalogue requests

To match cards and show estimated market values, the app may send card identity queries (such as name, set, collector number, language, or variant) to third-party or backend services, including catalogue APIs and any configured CardScanR pricing backend. Those requests are for informational estimates only. Pricing figures are not financial advice.

6. Device preferences and optional diagnostics / feedback

7. Purposes for processing

8. Local versus cloud processing

Primarily local
Camera frames for live scanning, on-device OCR/match, local inventory storage, preferences, and optional local diagnostic files.
Cloud / network
Authentication; opt-in collection metadata sync; HTTPS requests for catalogue and market price data; download of catalogue artwork references; OAuth browser return for Google sign-in.

9. Third-party service providers

Depending on features you use, providers may include Supabase (authentication and database), Google (sign-in and on-device ML Kit), catalogue and pricing APIs, and any configured CardScanR pricing or image hosting backends. Each provider processes data under its own policies.

10. Data sharing

We do not sell personal information. Data is shared with service providers only as needed to operate CardScanR (authentication, sync, catalogue, and pricing lookups), or if required by law. Card identity queries sent to catalogue and pricing APIs are necessary to return match and price estimates.

11. International processing

Supabase and other providers may process data in data centres outside Australia. If that is material to you, contact us before enabling cloud features.

12. Security

The app uses HTTPS for network calls and Supabase client keys intended for publishable client use. No security measure is perfect. Do not email passwords or payment secrets to support.

13. Retention

Local data remains on your device until you clear app storage, uninstall, or overwrite it. Cloud account, profile, and opted-in collection metadata remain until deleted through a supported deletion process or otherwise removed by the operator. Optional diagnostics you send are retained only as needed to handle your request.

14. Account and data deletion

You can request deletion of your CardScanR account and associated cloud data:

Subject to verification, a request is intended to cover the authentication account, profile, customer collection items synced to the cloud, binders and memberships where stored server-side, sync preferences/operations, and associated feedback or beta-program records where present. Local device data is separate and may remain unless you clear storage or uninstall. Sign out does not delete the account. See the deletion page for processing expectations and what may be retained (backups, legal holds).

15. Your choices and rights

16. Children and target audience

You must have the legal capacity to agree to use CardScanR where you live. CardScanR is not directed to children.

17. Changes

We may update this policy as the app or providers change. The effective and last-updated dates above will be revised when a new version is published.

18. Contact

Privacy questions for CardScanR: TCG Card Scanner: cardscanr.dev@gmail.com.

Support page Deletion page