Legal

Privacy Policy

Last updated: July 28, 2026

1. Who We Are

CardDex ("we," "us," or "our") is a trading card collection tracker and market intelligence platform. CardDex is available as a web application at carddex.gg and as a native iOS app on the Apple App Store.

CardDex is operated by CardDex Inc., a North Carolina corporation (SOSID: 3342658), located at 4030 Wake Forest Rd Ste 349, Raleigh, NC 27609.

Contact us at support@carddex.gg for any privacy-related questions.

2. What We Collect

Account data: When you create an account, we collect your email address, display name, and optional profile photo. If you sign in via Google or Apple, we receive your name and email from those providers — we never receive your passwords.

Collection data: Cards you add to your collection, including card IDs, conditions, grades, purchase prices, and notes you add.

Want list data: Cards you mark as wanted, including desired conditions and quantities.

Scan images — read this carefully: When you scan a card using the CardDex scanner (Buying Buddy, collection scanner, or trade scanner), the following happens:

  1. Your card image is captured by your camera.
  2. The image is sent to Scrydex Vision (our card identification service) to identify the card.
  3. CardDex permanently stores the full-resolution original scan image in Cloudflare R2 (our private cloud storage at cdn.carddex.gg), linked to a hashed version of your user ID.
  4. We retain these images to improve scan accuracy and may share them with Scrydex for that same purpose.

This image storage is the data practice we most want you to understand. By scanning a card, you are consenting to permanent storage of that image. If you do not want your scan images stored, use manual search to add cards instead — no images are captured or stored during manual search.

Scan logs: A log of each scan event: card identified, confidence score, timestamp, and user ID.

Payment data: Subscription billing is handled by Stripe. We do not store your credit card number or full payment details. We store your subscription status, plan type, renewal date, and billing email.

Usage data: Which sets and cards you view, which features you use, session duration, and error events. This helps us improve the product.

Device and log data: IP address, browser or app version, device type, and timestamps collected automatically when you access the service.

3. Scan Image Storage — How It Works

This section explains the most important data practice in detail:

  • Who stores it: CardDex stores scan images in our own private Cloudflare R2 bucket. Scrydex also processes images through their Vision API and may retain them per their own policies.
  • What is stored: The full-resolution JPEG image from your camera at the moment of scan.
  • How it is linked to you: Images are stored with a one-way hash of your user ID — not your name or email. We can link multiple scans to the same account, but the link is not human-readable.
  • Why we store it: To improve card identification accuracy over time, and to support potential data partnerships with Scrydex for that purpose.
  • How long: Currently stored indefinitely. We are building a time-based retention and deletion tool.
  • Can you prevent it: Yes. Add cards via manual search instead of scanning — no images are captured or stored.
  • Can you delete existing images: Yes. Email support@carddex.gg and we will delete your scan images within 30 days.

4. How We Use Your Data

We use your data to:

  • Create and manage your account
  • Display your collection, prices, set completion, and trading tools
  • Process and manage your Pro subscription through Stripe
  • Identify trading cards via camera scan and return pricing data
  • Improve scan accuracy using stored scan images (see Section 3 above)
  • Send transactional emails (account confirmation, password reset, subscription receipts, trial reminders)
  • Monitor app performance and fix errors
  • Respond to your support requests
  • Improve the product based on aggregated usage patterns

We do not sell your personal data. We do not use your data for targeted advertising.

5. Sign In with Apple and Google

Sign in with Apple: Apple may provide us with a unique identifier and optionally your name and email. You may choose to hide your email — Apple provides a private relay address instead. We respect this and use it only for account communications.

Sign in with Google: We receive your name, email address, and profile photo from Google. We do not receive access to your Google account beyond basic profile information.

In both cases, we never receive or store your password. Authentication is handled entirely by Apple or Google.

6. Third-Party Services

CardDex integrates with the following services that may process your data:

  • Scrydex — Scan images are sent to Scrydex Vision API for card identification; scan metadata may be retained by Scrydex per their policies. Privacy Policy
  • Supabase — Database storage and auth session management (US East, AWS). Privacy Policy
  • Cloudflare R2 — Scan images and profile photos are stored in our private R2 bucket. Privacy Policy
  • Upstash Redis — Caching layer that may hold hashed user IDs and subscription status. Privacy Policy
  • Stripe — Payment processing for Pro subscriptions. Privacy Policy
  • Sentry — Error monitoring; error reports may contain stack traces with user IDs. Privacy Policy
  • Vercel — Web hosting; processes request logs including IP addresses. Privacy Policy
  • Apple — App Store distribution, Sign in with Apple, push notifications. Privacy Policy
  • Google — Google Sign-In. Privacy Policy
  • eBay — We query eBay's Browse API for sold listing price data only. No user data is sent to eBay.
  • PSA — Cert numbers you look up are sent to PSA's public API for verification. Privacy Policy

7. Subscriptions and Payments

CardDex Pro is billed by Stripe. We receive your subscription status (active, trialing, canceled), your billing email, your plan type (monthly or annual), and your renewal date. We never see your full credit card number, CVV, or full bank details. All payment processing occurs on Stripe's servers.

8. Data Retention

  • Account data, collection data, want list data: Retained until account deletion.
  • Scan images (Cloudflare R2): Currently indefinite. Deletion tool in development. Email us to request deletion now.
  • Scan logs (metadata): Retained until account deletion.
  • Payment and transaction records: 7 years (legal requirement).
  • Error reports (Sentry): 90 days.
  • Server and CDN logs: 30 days.
  • Anonymized aggregated usage stats: Indefinitely.

Account deletion: When you delete your account, your profile, collection, want list, and scan logs are deleted within 30 days. Scan images in R2 are not yet automatically deleted on account deletion — email support@carddex.gg to request manual deletion of your scan images.

9. Your Rights

Regardless of where you live, you can:

  • Export your collection — Settings → Export Collection (CSV)
  • Delete your account — Settings → Delete Account, or email support@carddex.gg
  • Request deletion of your scan images — Email support@carddex.gg; we will process within 30 days
  • Correct your account info — Update directly in Settings
  • Opt out of push notifications — Disable in your device settings

California residents (CCPA): You have the right to know what data we collect, request deletion, and opt out of sale. We do not sell personal data. Contact support@carddex.gg to exercise CCPA rights.

European residents (GDPR): You have the right to access, rectify, erase, restrict processing, or object to processing of your personal data. Legal basis: contract performance (providing the service), legitimate interest (service improvement, fraud prevention), and consent (scan image storage). Contact support@carddex.gg to exercise GDPR rights.

10. Children's Privacy (COPPA)

CardDex is not directed to children under 13 (under 16 in the EEA/UK). We do not knowingly collect personal information from children under these ages. Users must be at least 13 years old to create an account.

If you believe a child under 13 has created a CardDex account, contact us immediately at support@carddex.gg. We will verify and delete the account and associated data promptly.

11. Security

We take reasonable measures to protect your data including encrypted connections (HTTPS/TLS), row-level security on our Supabase database, secure credential hashing, and a private Cloudflare R2 bucket (scan images are not publicly accessible). No system is 100% secure. Contact support@carddex.gg immediately if you suspect unauthorized access to your account.

12. Cookies and Local Storage

Our web app uses functional cookies to keep you logged in (Supabase session token) and browser localStorage to remember UI preferences and consent flags. You can clear cookies and localStorage at any time via your browser settings — this will log you out. Our iOS app uses on-device storage for session management and does not use tracking cookies.

13. Changes to This Policy

We will update this policy as the product evolves. For significant changes (new data practices, new third-party services, changes to retention), we will notify you by email at least 14 days before the change takes effect. The "Last updated" date at the top reflects the most recent revision.

14. Contact

Questions or data requests: support@carddex.gg

We aim to respond within 5 business days.

CardDex Inc. — support@carddex.gg — carddex.gg
4030 Wake Forest Rd Ste 349, Raleigh, NC 27609

Terms of Service← Back to CardDex