Privacy Policy
Legendecks is in pilot. It is an independent project and is not yet a registered company, so the controller of your data is the operator of Legendecks — the person you reach at the address below. When we incorporate we will name the company here and tell you before the change takes effect.
This policy explains what Legendecks collects, why, who else sees it, and what you can ask us to do about it. It covers the Legendecks app and website. The controller of your personal data is the operator of Legendecks, reachable at the address at the bottom of this page.
What we collect
Your account
Your email address, a hashed version of your password (we never store the password itself), the invite code you used, the date you created the account, and a record of the terms and privacy versions you accepted and when. If you signed up through the waitlist, we also hold what you told us there — what you collect and roughly how large your collection is.
Your collection
The cards you record, the photographs you take of them, what you paid, when you bought and sold, your notes, your goals, your decks and your saved settings. This is the substance of the service and it exists because you put it there.
Technical and diagnostic
When the app crashes we record that it crashed, how many times, the app version, roughly how many cards you hold, and the device type. No cards, no photographs, no account details. We also see the usual server request information, including your IP address, which our host processes to serve and protect the service.
What we do not collect
We do not use advertising trackers, we do not build advertising profiles, and we do not sell or rent your personal data to anyone. There is no third-party analytics SDK in the app.
Why we use it, and on what basis
- To provide the service — storing your collection, syncing it between your devices, valuing cards, estimating grades. Basis: performance of our contract with you.
- To keep accounts secure — sign-in, password reset, email confirmation, abuse prevention. Basis: contract, and our legitimate interest in a service that is not abused.
- To fix faults — crash reports and diagnostics. Basis: our legitimate interest in software that works.
- To send product news — only if you ticked the optional box. Basis: your consent, which you can withdraw at any time using the unsubscribe link or by writing to us.
- To meet legal obligations — where the law requires us to keep or produce something.
Service emails — a password reset, an email confirmation, a notice that these documents changed — are not marketing and are sent on the basis of our contract with you.
Who else processes it
We keep this list short on purpose. Each of these acts on our instructions under a data processing agreement.
- Cloudflare — hosting, storage and network protection for the app, the website and your synced data.
- Resend — sending account emails (confirmation, password reset, notices).
- Google (Gemini) — the photographs you take when you scan a card are sent for identification and condition assessment. They are used to answer that request, not to train a public model.
- Market data sources — to value cards we query third-party sources including eBay and PSA. These queries contain information about the card only — never information about you, your account, or your collection. We cache the results for a limited period so the app is fast and so we do not overload those services. This cached market data is not personal data and is not connected to your account.
We may also disclose data where the law requires it, or to protect the rights and safety of collectors and of Legendecks. If Legendecks is ever sold or merged, your data may transfer with it, and we will tell you before that happens.
Where your data is processed
Legendecks is currently available in the United States only, and our providers process data in the United States. We do not accept accounts from the European Economic Area, the United Kingdom or Switzerland while we complete the arrangements those regions require of a controller based outside them — including an Article 27 representative and executed data processing agreements with each provider. We will say so here before that changes.
How long we keep it
- Your account and collection: for as long as your account exists.
- Recovery points: about two weeks, plus points taken automatically before anything destructive, which are kept until you delete the account.
- Crash reports: 30 days.
- Waitlist entries: until you ask us to remove them, or until the pilot closes.
- Consent records: for as long as the account exists and for a period afterwards, because they are the evidence that we asked properly.
When you delete your account, your data is erased from our live systems immediately and works its way out of short-lived backups as those age out.
Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it — and two of those you can simply do yourself, in the app: Settings › Data exports everything as one file, and erases the account permanently.
If you are in the UK or the EEA you have the rights to access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests, plus the right to withdraw consent at any time. You can complain to your local supervisory authority; in the UK that is the Information Commissioner's Office.
If you are in California, you have the right to know what we collect and why, to delete it, to correct it, and not to be treated differently for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the past twelve months.
To exercise any of this, write to [email protected]. We answer within 30 days.
Security
Passwords are hashed with a server-side secret and are never stored or logged in readable form. Data in transit is encrypted. Access to production data is limited to the people who need it to run the service. No system is perfect; if a breach affects you, we will tell you and the relevant regulator as the law requires.
Children
Legendecks is not for people under 16, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will remove it.
Changes
If we change this policy materially, we will tell you in the app and by email before it takes effect. Every version is numbered by date, and your account records the version you accepted.
Contact
Privacy questions: [email protected]. Anything else: [email protected].