CardComps Privacy Policy
Last updated: September 28, 2026
CardComps is a mobile app for scanning and collecting Pokémon Trading Card Game cards. It is made by XEPATOP, an independent developer in Subotica, Serbia (“I”, “me”). This policy explains what the app collects, why, where it goes and how you can delete it. Contact:dev@xepatop.com.
Short version: the app needs photos of your cards to recognise them and an account to keep your collection. There are no ads, no analytics or tracking SDKs, and I don't sell or share your data for marketing.
1. What the app collects
- Account. Your email address, and your name if you sign in with Google. If you sign up with a password, it is stored only as a hash by the sign-in provider; I never see it.
- Scan photos. When you scan, the app sends camera frames of the card (usually two photos and a few small frames taken while you tilt the phone) to the recognition server. Frame the card, not your surroundings: anything else in the frame is sent too.
- Your collection. The cards you add, with quantities, printing, language, condition, grade, favourites, price alerts and daily snapshots of the collection value. It lives on your phone and is synced to my server so it survives a new phone.
- Card photo backup (optional, off by default). If you turn it on in Settings, the scan image of each card in your collection is stored on my server.
- Push token. If you allow notifications, a device token so the server can send your price alerts.
- Purchases. Subscriptions are bought through Google Play. I get the subscription status and purchase record, never your card details.
The app does not collect your location, contacts, advertising ID or device identifiers beyond the push token.
2. Why
- To recognise the card and its printing, and show its price (scan photos).
- To keep and sync your collection and send the alerts you set (account, collection, push token).
- To provide the subscription you paid for (purchases).
- To improve recognition: photos of scans where you told the app its answer was wrong (see section 4).
Legal bases under the GDPR: performance of our agreement with you (running the features you use), and my legitimate interest in fixing recognition errors you report.
3. Where it is stored and who processes it
- Recognition server: Hetzner Online, data centre in Helsinki, Finland.
- Collection, alerts and photo backup: my server at CLOUD.DOG, Estonia.
- Sign-in: Supabase (account email and sign-in sessions).
- Card recognition service: when the app can't identify a card from its printed text alone, the photo may be sent to a third-party recognition API (currently Ximilar, Czech Republic; I may switch to Scrydex, USA). They receive the image only, without your account.
- Subscriptions: Google Play and RevenueCat (USA), which manages subscription status. RevenueCat receives a random account ID, not your email.
- Notifications: Expo push service and Google Firebase Cloud Messaging deliver alerts to your phone.
- Google Sign-In, if you choose it.
Some of these providers are outside the EU/EEA; transfers rely on the providers' standard contractual clauses.
4. How long I keep it
- Scan photos are deleted automatically. The full scan is deleted as soon as you accept the card; the straightened card image stays at most 24 hours so the scan queue can show it. Scan photos are not linked to your account on the server.
- Scans you mark as wrong (wrong card or wrong printing) are kept to find and fix the recognition error. They are moved off the public server within about two hours and kept in my private test set without your account or email.
- Account and collection data are kept until you delete your account.
- Backup photos are kept until you turn backup off or delete your account.
5. Your rights and deleting your data
You can see and export your collection in the app (CSV export). You can delete your account and all data linked to it in the app: Settings → Account → Delete account and data. Or follow the steps onthe account deletion page. You can also ask me by email to access, correct or delete your data, or object to processing. If you are in the EU, you can complain to your data protection authority; in Serbia, to the Commissioner for Information of Public Importance and Personal Data Protection.
6. Children
CardComps is not directed at children under 13, and I don't knowingly collect data from them. If you think a child has created an account, write to me and I'll delete it.
7. Security
All traffic between the app and the servers is encrypted (HTTPS). Server access requires your sign-in token, and each user can reach only their own data.
8. Changes
If this policy changes, I'll update the date above. For significant changes, the app will tell you.