Skip to content

Privacy Policy

Version 2026-07-28Last updated 2026-07-28

As of: 2026-07-28. The German version is legally binding; this English version is a courtesy translation.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

André Baum Marloffsteiner Straße 36A 91080 Uttenreuth Germany Email: andrebaum.aistudio@gmail.com

These details match those in the Legal Notice ("Impressum").

2. What data we process

When you use CardFolio, we process the following categories of personal data:

  • Account data: your email address, display name (display_name), selected language, and a pseudonymous user identifier (UUID) assigned by Supabase.
  • Collection data: the cards you add to your collection (collection_entries), your collections/folders (collections), and the assignment of cards to collections (collection_memberships), each including the purchase prices, purchase dates, and notes you provide.
  • Wishlist data: cards you add to a wishlist (wishlist), including a target price you set.
  • Sealed product data: sealed products you record (e.g. displays, booster packs, or boxes) in sealed_entries.
  • Value history: the history of your portfolio's total value over time (portfolio_value_history), calculated from your collection and sealed-product data together with external pricing data.
  • Push/notification data: if you enable push notifications, your device push token (push_tokens), your notification settings (alert_settings), and triggered notification events (alert_events).
  • Subscription and purchase metadata: when using CardFolio Pro, in particular the product and package identifier, relevant app store, purchase, trial, renewal, cancellation, expiration and refund status, and the respective entitlement or expiration time. We do not receive complete payment details such as credit-card or bank-account information.
  • Scan photos: when you use the scan feature, the photo you take (single card, binder page, or sealed product) is transmitted to Google's Gemini API for recognition (see section 4). Without your explicit consent we do not store these photos; in that case only technical scan metadata (timestamp, scan mode, model used, success/failure, and duration) remains on our servers — never image content.
  • Scan training data (only with your consent): if you consent under Settings → Data → “Donate scans to improve recognition”, we additionally store the photo you took (always the full image, never a crop) and — once you confirm the result — the card you confirmed, the card the system originally proposed, and whether you corrected it. We do not store a name or an email address alongside the image, only your pseudonymous user identifier, so that we can verify your consent, enforce a daily limit, and remove the data again if you delete your account. Sealed products are excluded from this collection.
  • Usage and security data: scan allowances and technical timestamps required to enforce Free, Pro, and fair-use limits and prevent abuse.
  • Guest scans without an account: if you try the scan feature without signing in, we store a salted hash of your IP address (guest_scans) to enforce the daily limit — never the IP address itself. The legal basis is our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).

3. Purposes & legal bases

We process this data for the following purposes:

  • Providing account and portfolio features (creating and managing your collection, your wishlist, your sealed products, and calculating value): the legal basis is the performance of the usage contract with you or the taking of pre-contractual steps at your request (Art. 6(1)(b) GDPR).
  • Providing and managing CardFolio Pro (purchase attribution, entitlement verification, restoration, renewal, cancellation, expiration, and refunds): the legal basis is performance of the CardFolio Pro contract or taking pre-contractual steps at your request (Art. 6(1)(b) GDPR).
  • Enforcing allowances and preventing abuse: the legal bases are performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in the security, stability, and economically sustainable provision of the service (Art. 6(1)(f) GDPR).
  • Push notifications (e.g. price alerts for wishlist cards or notifications about changes in the value of your collection): the legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw this consent at any time with future effect in the app settings; this does not affect the lawfulness of processing carried out before the withdrawal.
  • Improving card recognition (storing your scan photos together with the card you confirmed, in order to train and evaluate recognition): the legal basis is solely your consent (Art. 6(1)(a) GDPR). Consent is voluntary, switched off by default, and not required to use the scan feature — the scan feature works unchanged without it. You can withdraw it at any time with future effect under Settings → Data; this does not affect the lawfulness of processing carried out before the withdrawal.

4. Recipients / processors

To provide our service, we use the following processors/recipients:

  • Supabase — hosting of the database, authentication, and backend infrastructure. Processing takes place in the EU region Frankfurt am Main.
  • RevenueCat, Inc. — technical management and verification of in-app subscriptions. RevenueCat receives only your pseudonymous Supabase UUID as the app user identifier, not your email address. It also processes the purchase and entitlement metadata required for subscription management, including the product, app store, transaction/purchase status, and expiration time. Processing takes place under a data processing agreement; transfers to the USA are based on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR).
  • Expo — delivery of push notifications to your device. For this purpose, Expo processes push tokens in the USA. This constitutes a transfer of data to a third country outside the EU/EEA. The legal basis for this transfer is the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR).
  • Google Ireland Ltd. / Google LLC (Gemini API) — recognition of the cards and products you scan. The photo you take is transmitted to Google's Gemini API and processed there solely to answer the recognition request; no account data is transmitted, only the image. Processing may take place on servers outside the EU/EEA (in particular in the USA). Legal basis for the processing is performance of the contract (Art. 6(1)(b) GDPR — you actively trigger the scan); the legal basis for the third-country transfer is Google LLC's certification under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023, Art. 45 GDPR), supplemented by the Standard Contractual Clauses. We use the paid Gemini API; the transmitted images are not used by Google to train models.
  • Cloudflare Germany GmbH / Cloudflare, Inc. (R2 object storage) — storage of the scan training data, provided you have consented to it. The storage bucket is explicitly restricted to the EU jurisdiction, so the data is stored in data centres within the European Union; the bucket is not publicly accessible. Processing takes place under a data processing agreement (Art. 28 GDPR); for any access from third countries, the European Commission's Standard Contractual Clauses apply in addition (Art. 46(2)(c) GDPR). Without your consent, no data is transmitted to this recipient.
  • Apple App Store or Google Play Store — conclusion and administration of an in-app subscription, including payment, cancellation, and refunds, under the privacy terms of the store you use. Payment details are processed directly by the store and are not transmitted to CardFolio.

Where a recipient acts as a processor on our behalf, a data processing agreement pursuant to Art. 28 GDPR is or will be concluded before production launch. App-store providers may act as independent controllers for their payment and store services.

5. External data sources

To display catalog, price, and exchange-rate data, the app queries the following external sources: TCGdex/Cardmarket, TCGcsv/TCGplayer, and frankfurter.app. These queries serve solely to retrieve public catalog, market, and exchange-rate data; no user identities or other personal data of yours are transmitted to these sources.

6. Storage period & deletion

We generally store your data for as long as your account exists or the data is required to perform an ongoing contract. The following periods apply in detail:

  • Account, collection, wishlist, and sealed data: until you delete your account.
  • Scan log (scan_events: timestamp, scan mode, model, success/failure, duration — never image content): 30 days, then deleted automatically.
  • Guest scan counter (guest_scans: salted hash of the IP address to enforce the daily limit, never the plain IP): 7 days, then deleted automatically.
  • Subscription metadata (product, store, purchase/entitlement status, expiry): for the duration of the subscription and beyond for as long as commercial and tax retention obligations apply (generally up to 10 years under § 147 AO, § 257 HGB).
  • Push tokens: until consent is withdrawn, the device is deregistered, or the account is deleted.
  • Scan training data (only where consent was given): photos for which you did not confirm a card are deleted automatically after 7 days. Photos with a confirmed card are stored for as long as they are required to improve recognition, and at the latest until you delete your account; withdrawing consent stops any further photos from being stored.

Without your consent to scan training data, we never store scan photos.

The app allows you to request deletion of your CardFolio account and the app data associated with it at any time via Settings → Delete account (right to erasure, Art. 17 GDPR). Account deletion also covers any stored scan training data, including the associated image files in object storage. This also initiates deletion or anonymization of the CardFolio-related RevenueCat subscriber record, unless statutory or mandatory technical retention requirements prevent it. Purchase and billing data remaining with the app store are subject to the respective store's retention periods and privacy policy.

Important: deleting your account does not automatically terminate a subscription concluded through an app store. You must also cancel the subscription through the store's subscription management to prevent future renewals.

7. Your rights

As a data subject under the GDPR, you have the following rights:

  • Access (Art. 15 GDPR) to the data we process about you,
  • Rectification (Art. 16 GDPR) of inaccurate data,
  • Erasure (Art. 17 GDPR),
  • Restriction of processing (Art. 18 GDPR),
  • Data portability (Art. 20 GDPR),
  • Objection to processing (Art. 21 GDPR), and
  • Withdrawal of consent given (Art. 7(3) GDPR) with future effect.

To exercise these rights, you can contact us at any time using the email address given in the Legal Notice.

8. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data. As a rule, the competent authority is the one in your habitual residence, place of work, or our place of business, in particular:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 27, 91522 Ansbach, Germany poststelle@lda.bayern.de

Cardfolio

The calm display case for your collection.

Affiliate links. We may earn a commission.

All displayed values are non-binding market estimates based on third-party data.

CardFolio is independent and not affiliated with Nintendo or The Pokémon Company. Trademarks mentioned belong to their respective owners.

© 2026 CardFolio