Last updated: May 26, 2026
CardSignal ("we," "our," or "us") is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your choices. By using CardSignal you agree to the practices described here.
When you create an account, we collect your first name, last name, email address, and a securely hashed password. This is managed by Supabase (our database and authentication provider) and is used solely to authenticate you and personalize your experience.
Cards and sealed products you add to "My Products" are stored on your device and securely synced to our cloud database (Supabase). This allows your portfolio to be restored if you reinstall the app or switch devices. Your portfolio data is linked to your account and is accessible only to you. It is never shared with or sold to third parties.
Subscription status and transaction history are managed by RevenueCat and Apple. We receive only entitlement status (whether you have an active subscription) — we never see your payment details, card numbers, or Apple ID credentials.
The card scanner feature requests access to your camera to identify Pokémon cards. Camera data is processed entirely on-device and is never transmitted to our servers or stored in any form.
We do not use analytics SDKs or behavioral tracking. We do not collect device identifiers, location, contacts, or browsing history.
We do not sell, rent, or share your personal information with third parties for marketing.
CardSignal integrates the following third-party services:
Your account data is retained for as long as your account is active. Portfolio data is retained in our cloud database while your account exists. You may request deletion of your account and all associated data (including portfolio data) at any time by contacting us at the address below. Local data on your device can be cleared by deleting the app.
CardSignal is not directed to children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
All data transmitted between the app and our servers uses TLS encryption (HTTPS). Passwords are never stored in plaintext — authentication is handled by Supabase using industry-standard hashing. We do not store payment credentials of any kind.
Depending on your location, you may have the right to access, correct, or delete the personal data we hold about you. To exercise these rights, contact us at the email below. We will respond within 30 days.
We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top. Continued use of the app after changes constitutes acceptance of the updated policy.
If you have questions or requests regarding this privacy policy, please contact:
Theodore Cook
twcook8910@gmail.com