CardBard

Privacy

Effective 19 August 2026. There is no account in this app, so there is nothing for us to attach to you. That is how it is built, and it is why this page is short and specific rather than long and vague.

No sign-up, no email, no password. No ads and no ad network. No analytics kit, no attribution kit, no crash-reporting kit — none are in the app, so none can be switched on later without shipping a new version. Your collection stays on your phone, your card photos are not kept, and this website sets no cookies.

What a scan sends

The photo goes to our server, the server works out which card it is, and it sends back the card and its price. The photo is used for that and then it is gone — not written to disk, not stored, not kept for training. In the shipped build the setting that would retain a crop is off, and the code behind it refuses to do anything until a retention window and a deletion path are built alongside it.

What we write down, one line per scan, is how the scan went: a scan number our server generates for that one scan and the time; how confident the read was and what the app did with it; which cards came out on top; the parsed fields the reader used, such as a set code and a collector number; stage timings, the software version that answered, and whether that server ran on CPU or GPU; and the image's size in bytes and file type — the numbers, never the image. The raw text the reader saw is not written down, because a camera can be pointed at anything.

That line has no IP address, no phone model, no operating system, no device identifier, no advertising identifier, no file name, no account and no free text. The app does not even send a per-device scan identifier: the field exists in the interface and is deliberately left empty. So one scan cannot be linked to the next, and no scan can be linked to a person.

If you tap wrong card?, we record the scan number, which of the four problem types you picked, and — if you told us — which card it should have been. There is no message box: reports are fixed in a weekly batch rather than answered one at a time.

Your collection never leaves your phone

Your collection — cards, quantities, conditions, notes, folders — is stored on your device and nowhere else. We hold no copy, and there is no sync service and no cloud backup, so there is nothing of yours on our side to lose, leak or hand over. Backup is the CSV export you take, plus your phone's own backup.

Refreshing what your collection is worth asks our server for prices. That request names the cards it asks about; the server answers and forgets. What we log is the shape of the request: how many cards, how many we had prices for, how long it took. The list of cards is deliberately left out of that line. The set of cards you own is exactly the thing a phone-first design promised not to hold.

If you subscribe

Apple and Google take the money. We never see a card number, a billing address, a name or an email: the stores do not give them to us.

To know a subscription is yours without an account, the app makes a random identifier the first time it runs — a UUID, 32 hex digits drawn at random and standing for nothing — kept in your phone's secure storage. It rides along with the purchase and the store hands it back to us. We store it beside the store's own subscription identity to answer one question: is this app entitled to the paid features? Against a subscription we also hold which store, which product, whether it is active, when it renews or ends, whether auto-renewal is on, and a log of the store's messages about it. In that log the identifier is never written in the clear — it is stored as a one-way hash, so the file counts what happened without saying whose subscription it was. Refund requests carry a reason picked from a fixed list of seven; there is no message box there either.

What we never collect

This website, and where the rest lives

The site is static pages: no analytics, no tracking pixel, no cookie banner because there are no cookies, no fonts or scripts from anyone else's server. Our host keeps ordinary logs for delivering and protecting it; we run no measurement tool over them.

The scan and billing records sit on one server we rent in the European Union, and on its backups; the site is served from a content network with points of presence worldwide. Everything between your phone and our server travels encrypted.

How long we keep those records, honestly: today, indefinitely, with no automatic deletion. The logs start a new file each day and those files are not swept up on a schedule; subscription records outlast the subscription. We would rather write that down than imply a policy we have not built. Note what it is a gap in: files containing no name, no address, no identifier of your device, nothing traceable back to a person. When a deletion schedule exists, this page will say what it is.

Who else is involved

We share your data with nobody, because there is nothing to share: no ad network, no data broker, no analytics or attribution vendor, and no sale of data, ever. Three kinds of company are nevertheless in the picture. Apple and Google run the stores and handle every payment under their own privacy policies; what comes back to us is the state of a subscription, not a customer. Our hosting and network providers run the server and deliver this site on our behalf. Card and price sources — TCGdex, carrying TCGplayer and Cardmarket figures, cross-checked against TCGCSV — flow towards us: we fetch the catalogue and the daily prices onto our own server and answer your app from that copy. Your scans, searches and collection are never sent to them.

Card images and takedowns

Card artwork belongs to the companies that made the cards. We show a thumbnail so you can confirm a match and so your collection has pictures in it, and for nothing else. Images come from our own cache with the source recorded, so any rights holder who asks can have an image removed within a day: a takedown here is a config change, not an incident.

Your rights, and what they amount to here

The GDPR in the EU and UK, and the CCPA and CPRA in California, start from one question: what personal data do you hold about me? Here the answer is genuinely none that can be connected to you:

The lawful basis, in GDPR terms, is our legitimate interest in running the service reliably and charging for it correctly, on records carrying no identifier of you. If you think we hold something this page does not describe, write to the address below and we will look.

Children

The app is rated for ages 4 and up: no violence, no gambling mechanics, no chat, no user content, no ads. It is not designed or marketed for children, and the practices here are the same for every user of any age, so there is nothing to switch. Purchases go through Apple's or Google's parental controls.

Changes, and contact

If what the app does changes, this page changes first or at the same time, never afterwards, and the effective date moves. Anything that materially widens what we collect — keeping card photos, adding accounts, adding any third-party kit — also needs a new declaration on both app stores before it ships, so there is a second lock on it that is not ours, and it will be called out in the app rather than slipped in here.

For a privacy question, a rights request, or a takedown notice about a card image, write to [email protected]. That mailbox is being set up as the app goes live; until it answers, the support contact published on our store listings reaches us and is the address to use. It is not a help desk — the support page explains how each thing is fixed without writing to anybody.