Beta Privacy Policy
Published 6 September 2026
BETA PRIVACY POLICY — EFFECTIVE FROM THE PUBLICATION DATE SHOWN ABOVE
This Policy explains how PokeCardr handles personal information during the public beta. It reflects the website, Supabase customer accounts, private collector profiles, collection tools, optional leaderboards, first-party analytics and owner support processes operating now. It also explains how signed-in Camera recognition uses Scrydex by default and the safeguards applied to that processing. It will be updated before new uses such as advertising, subscriptions or marketplace features are enabled.
1. Who is responsible for your information
PokeCardr is currently an independent early-stage project operated from the United Kingdom. “PokeCardr”, “we”, “us” and “our” refer to the person or future legal entity operating the service. The formal controller name and postal address will be added when the operating entity is finalised and before wider commercial launch.
Privacy questions and rights requests can be sent to privacy@pokecardr.com. General support is available at support@pokecardr.com.
2. Who this Policy covers
This Policy applies to the PokeCardr website, customer accounts, future PokeCardr mobile applications, owner support and related collection features. Third-party websites, marketplaces and grading services have their own privacy policies.
Accounts are for people aged 13 or over. Because Pokémon collecting is also likely to interest children, PokeCardr uses private collection settings by default, makes account-only rankings optional and asks users not to publish contact or location details.
3. Information we collect
We collect only information needed to operate, secure and improve the beta.
- Account information: your email address, account identifier, collector display name, password-authentication records, email-confirmation status and the dates or versions associated with age confirmation and legal acceptance. PokeCardr does not receive your password in readable form.
- Collection information: cards, wishlists, quantities, condition, grading company and grade, optional purchase price, notes, set progress and calculated portfolio guides.
- Privacy and profile choices: preferred currency, ranking participation, all-account or friends-only identity visibility, an optional collector name, an optional private About Me and an optional profile picture. Profile pictures are resized, converted and stripped of embedded photo metadata before protected storage.
- Ranking and friend information: if you opt in, PokeCardr stores aggregate ranking statistics and your selected identity audience. Friend codes, pending requests, accepted connections, removals and blocks are used to operate account-only community features. Your email, About Me, private card list, purchase prices, notes and payment details are not shown on rankings.
- Service activity: pages viewed, searches, card and set interactions, a temporary page-session identifier, referring website host, campaign labels, device category and coarse country code. PokeCardr’s first-party analytics table does not store your IP address, although hosting and security providers may process IP addresses in their infrastructure logs.
- Communications: information you include when emailing support, privacy, safety or legal addresses.
- Scanner information: when a signed-in collector uses the Camera or image-upload control, PokeCardr re-encodes, resizes and compresses the selected card image, using the camera-guide crop where available; this removes embedded camera metadata. The prepared image, a random request identifier and necessary technical information are sent to Scrydex for card recognition. A confirmation-only local check may suggest catalogue candidates only after Scrydex completes but cannot produce an exact catalogue match. If Scrydex, catalogue validation or a protected usage control is unavailable, the scan stops visibly and no lower-confidence result is substituted. Manual catalogue search remains available without sending a photograph.
- Scanner outcome information: PokeCardr stores the request time, account and credit usage, exact catalogue candidates, the confirmed or corrected card variant where available and the collector’s reviewed outcome—including when none is correct—so it can operate the service, measure card and variant accuracy, investigate misuse and control spend. PokeCardr does not store the submitted image, raw provider response or grading certification details.
Do not include your full name, school, address, phone number, location or other unnecessary personal information in profile pictures, About Me text, card photographs, notes, display names or support messages.
4. How we use information and our lawful bases
We use account and collection information to provide the service you request, including signing you in, saving cards, showing set progress, applying currency choices and maintaining your wishlist. For UK users, this processing is generally necessary to perform our agreement with you.
We use limited service activity and technical information to operate the beta, diagnose faults, protect accounts, understand which features are useful, prevent manipulation and improve catalogue matching. We rely on our legitimate interests where those interests are not overridden by your rights, and we minimise the information used.
We use information to answer support or rights requests, maintain legal acceptance records, investigate safety reports and comply with legal obligations. We may rely on legal obligation, legitimate interests or the establishment and defence of legal claims as appropriate.
Account-only rankings are enabled only when you actively choose to join. This choice permits PokeCardr to show your aggregate position to signed-in collectors and your collector name, profile picture and active gold PC badge to either all signed-in collectors or accepted friends, according to your setting. Other signed-in collectors see “Anonymous collector” in the same position under friends-only visibility. Your email, About Me, individual card list, notes, purchase prices and payment details are not shown. Friend codes, requests, accepted connections and blocks operate the friend controls you choose. You can leave through profile controls; removing your profile picture or leaving rankings stops PokeCardr serving it there, and the gold PC badge disappears if the entitlement is no longer active. When you select Camera or image upload, the image processing described above is necessary to provide the recognition service requested under the account agreement. If you do not want a card image sent to Scrydex, use manual catalogue search instead. This scanner processing does not rely on a separate per-image consent. Any future photo retention, marketing or non-essential tracking will use a separate choice where consent is required.
PokeCardr does not sell personal information and does not currently use behavioural advertising. Rankings and scanner suggestions do not make decisions that produce legal or similarly significant effects about you.
5. Children and age-appropriate design
You must be at least 13 to create an account. If you are under 18, ask a parent or guardian to help you understand your privacy choices. We design the service on the basis that children may use it, even though it is not specifically directed at younger children.
Collections are private by default. Account-only rankings require a deliberate opt-in, and friends-only identity visibility is available. We do not ask for a date of birth, school, home address or phone number to create an account, and users are warned not to include those details in a collector identity. If we reasonably believe an account holder is under 13, we may restrict the account while the position is checked and remove associated personal information where appropriate.
6. Who processes information for PokeCardr
We use service providers only where needed to run the beta:
- OpenAI Sites and its hosting infrastructure, including Cloudflare services, for website delivery, security, operational databases, private profile-image storage and first-party analytics;
- Supabase for customer authentication, account identifiers and the shared account/database foundation;
- GoDaddy and Microsoft 365 for domain email and owner communications;
- TCGdex and connected catalogue or market-data sources, including TCGplayer information made available through the catalogue feed, to answer card searches and provide available raw-price guides;
- PriceCharting where configured for graded-market guides; and
- Scrydex for licensed card and pricing data and for card-image analysis whenever a signed-in collector uses Camera or image upload; and
- Apple or Google in future only when a user chooses one of those sign-in methods and the provider has been enabled.
Catalogue and pricing requests are not deliberately sent with your email address. Providers may receive technical network information needed to deliver their own service. We may also disclose information where required by law, to protect users or rights, or as part of a future business transfer with appropriate notice and safeguards.
7. International processing
Some providers may process information outside the United Kingdom, including in the European Economic Area or United States. Where UK data-protection law requires a transfer safeguard, we will rely on an applicable adequacy regulation, approved contractual safeguards or another lawful mechanism. A prepared card image may be processed outside the United Kingdom by Scrydex or its infrastructure. Where UK data-protection law requires a transfer safeguard, PokeCardr relies on an applicable adequacy regulation, approved contractual safeguards or another lawful mechanism. PokeCardr continues to review the supplier’s detailed subprocessor and processing information; contact privacy@pokecardr.com for current details.
8. How long information is kept
We use the following beta retention rules or criteria:
- account, profile, profile-picture, collection and wishlist records are kept while your account is active. Profile pictures remain in protected storage and are shown on rankings only while the profile is opted in and only to the signed-in audience selected in its settings. Replaced profile pictures are removed from active storage, and current profile content is removed following self-service account deletion or a verified deletion request, subject to backup cycles and information that must be retained;
- PokeCardr does not retain the submitted Camera image or raw Scrydex response. It keeps only the bounded usage record, exact catalogue candidates and reviewed outcome needed to operate the scanner, measure accuracy, investigate misuse and control spend while the account is active. These account-linked scanner records are included in account export and deletion controls; de-identified aggregate accuracy may remain;
- first-party product analytics are kept for up to 13 months, unless a shorter period is sufficient or a record is required to investigate security or abuse;
- routine support correspondence is normally kept for up to 24 months after the issue closes;
- legal acceptance, serious abuse, security and dispute records may be kept for up to six years where reasonably necessary; and
- hosting and authentication providers retain security and diagnostic logs under their own documented schedules.
When information is no longer needed, it is deleted or de-identified. Backup copies may remain for a limited recovery cycle and are not used for ordinary product activity.
9. Your choices and rights
You can change currency and account-ranking choices within PokeCardr, remove your profile picture and leave rankings at any time. You can ask for access to, correction of, or a portable copy of account information, or request deletion or restriction. Depending on the circumstances, you may also object to processing or withdraw consent for an optional feature. These rights are not absolute.
Signed-in collectors can download a portable account-data export through account controls. Where self-service deletion is available, it requires an explicit typed confirmation and permanently clears account-linked PokeCardr records before removing the sign-in. It is blocked while a provider-managed subscription remains live. If the control is unavailable, email privacy@pokecardr.com from your registered address. We may ask for proportionate information to confirm that the request relates to your account. We aim to respond within the period required by applicable law.
You can complain directly to us first. UK users also have the right to complain to the Information Commissioner’s Office at ico.org.uk. Users elsewhere may contact their local data-protection regulator.
10. Security
We use measures including encrypted connections, managed authentication, access controls, row-level database policies, owner-only administration and audit records. Camera recognition uses on-device re-encoding, resizing, compression and metadata removal, the camera-guide crop where available, a server-side provider proxy, restricted supplier credentials, UUID idempotency and daily and monthly spend limits. No online service can guarantee complete security. Use a unique password, protect devices that remain signed in and contact support@pokecardr.com promptly if you suspect unauthorised access.
11. Changes to this Policy
The effective date and version appear on this page. Material changes will be explained in the service or by email where appropriate. If a new use requires consent, it will not be enabled for you merely because this Policy changed.
12. Contact
Privacy and data-rights requests: privacy@pokecardr.com
General account support: support@pokecardr.com
Safety reports: safety@pokecardr.com
Legal notices: legal@pokecardr.com
PokeBot conversation and research with Master
When you ask PokeBot, OpenAI may receive your current question, up to six recent non-Vault session questions, bounded summaries of their replies, relevant catalogue identifiers and the public card evidence needed to answer. This processing provides the conversational service you request under the Master account agreement. PokeBot is available to use when you choose; accepting the agreement alone does not trigger it.
For artwork questions, PokeCardr may send up to three matching public catalogue images as validated image data or image URLs. These are catalogue artworks, not photographs of your physical cards. Camera recognition remains the separate Scrydex service described above.
For current research, a separate OpenAI request receives a bounded public Pokémon topic and relevant catalogue names or printed card numbers. OpenAI's web-search capability retrieves public sources. That search request does not receive the transcript, account identity or Vault holdings, although its topic may reflect your question. Replies include available source links and the date checked.
PokeCardr does not add account identifiers, email addresses, private Vault holdings, notes, storage locations, customer photographs, audio or credentials to conversational or research requests. Private Vault summaries stay within PokeCardr and are excluded from later model context. Anything you type into a question is necessarily processed, so avoid personal or confidential information.
Questions and replies stay in the current client session. Clear chat removes that context and starts again. PokeCardr does not save your conversation as chat history. It retains operational receipts containing outcomes, timing, model identity, token usage and cost information, without the wording of questions or replies, for up to 13 months. These records support service operation, security, reliability and spend controls.
A shared cache retains short public research summaries, source links, retrieval times and hashed lookup keys. Successful research can be reused for up to two hours; older research must be refreshed before it is presented as current. Research records are retained for up to 30 days and removed on subsequent research activity. Failed lookups have a short cooldown. Private conversation and model wording are not promoted into verified card or market evidence.
OpenAI processes this information through its API. PokeCardr requests non-persistent responses, and does not opt API content into model training. This does not promise zero provider retention: OpenAI may retain abuse-monitoring information for up to 30 days, or longer where required by law or reasonably necessary to protect its services or others, unless stricter data controls apply. Processing may take place outside the United Kingdom, including in the United States, subject to the international-processing safeguards and rights explained above.
PokeCardr does not use PokeBot questions for advertising profiles. The existing account export, privacy rights and contact routes in this Policy also apply to this processing. Contact privacy@pokecardr.com with privacy questions.