Skip to content

Legal

Privacy Policy

What My Card Wizard collects, why, which companies receive it, and how to get it removed. Every company that receives your data is named.

Version
17 September 2026
Applies to
www.mycardwizard.com and the My Card Wizard app

1 Scope

My Card Wizard identifies trading cards from scans, prices them from market data, and helps you list them for sale. This policy covers www.mycardwizard.com and the My Card Wizard app.

Where another company receives your data, we name it rather than describing it as a category.

Questions, requests and complaints: support@mycardwizard.com.

2 What we collect

Account information. Your email address, and your name and profile picture if you add them. Sign-in is handled by Supabase Auth, so we never receive or store your password. If you turn on two-factor authentication, the code is emailed to you and we store only the fact that it is on.

What you fill in on Profile. Your business name, and the postal address you enter. Both are optional, and nothing in the app reads the address today.

What you tell us at sign-up. Where you sell and whether you have a scanner. We keep those two answers to pick which guides the app offers you, and ticking In person turns on the optional split between online and in-person batches.

Card scans. The images you upload of the fronts and backs of your cards.

Card and pricing data made from those scans. Name, year, set, finish, card number, grading details, estimated value, and the market data behind that estimate.

Workspace data. Your batches, card status, your edits to titles and prices, channel assignments, and any sale price you record.

Connected-account credentials. If you connect eBay, Shopify, WooCommerce, CardTrader, Mana Pool or Square, we store the tokens or API keys that service issues, encrypted at rest, and for Discord the webhook address. We never see your password for any of them.

Billing information. If you buy a paid plan, Stripe processes the payment and we store the customer and subscription identifiers and your plan status. Card numbers go to Stripe and never reach our servers.

Feedback and support tickets. What you send us, the page, the app version and the browser it came from, and, for a ticket, every message in the thread and the address a reply goes to.

How you found us. If you arrive through one of our own campaign links, or from another website, and then create an account, the tags on that link and the page you landed on are saved with your account. It is recorded once, is never shared, and is deleted with your account.

Operational logs. Errors, request timing and integration status, used to keep the service running and to debug failures.

3 What we do not collect

Payment card numbers. Those go to Stripe.

Analytics, advertising or tracking data. The app loads no analytics product, no advertising pixel, no session recorder and no third-party tracking script. The Cookie Policy lists everything the app keeps in your browser.

Personal data bought from anyone else, and personal data about other people's marketplace accounts.

Card scans are meant to contain cards. Do not upload an image showing a personal document, an identity card or other sensitive information.

4 How we use your information

To identify your cards, price them, show you your inventory, and create listings on a connected marketplace when you ask.

To operate, secure, support and debug the service, and to answer you when you contact us.

To bill you, if you are on a paid plan.

To send account and security email: sign-up and sign-in codes, two-factor codes, receipts, and a notice when something security-relevant changes. This email is always sent, because without it you could not get into your own account.

To send occasional product email, such as a welcome note or a summary of what has changed. Every product email carries a one-click unsubscribe link, and unsubscribing changes nothing else about your account.

To improve pricing accuracy, as described in section 8. That is the one use not confined to your own account.

To build our card photo catalog, but only if you turn catalog photo rewards on. It is off by default and it is the only way a scan of yours is ever shown to anyone else. See section 7.

Identification and pricing are automated, and that is the product. No automated decision here has a legal or similarly significant effect on you: no listing is made without a person marking the card ready, you can override any read or price, and nothing automated changes what your account can access or what it is charged. There is no advertising, so there is no profiling for it.

5 The services that receive your data

Supabase. Hosts the database, the file storage for your scans, and the login system. It holds almost everything in your account.

Railway. Hosts the application server.

Resend. Delivers our email, including sign-in codes, security notices and product email. It receives your email address and the message we send you, and nothing else.

OpenRouter. Receives your card scan and passes it to the model that reads it. It sees the scan and the instructions we send with it, and nothing else about your account.

Google. Reads your card scan with its Gemini model, which OpenRouter routes to. We use a paid API, whose terms state that content submitted through it is not used to train Google's models.

Anthropic. The backup identification service. A person can switch the read to Anthropic's Claude model if OpenRouter stops working, and the app never switches on its own. Anthropic's commercial API terms also forbid training on content submitted through the API.

eBay. Receives a card description, such as the name, year, set and number, when we search its current listings to price a card. That search runs on our own eBay credentials and carries nothing about you. eBay also receives a listing when you choose to create one, and if you have connected your eBay account we act on your behalf using the tokens eBay issued.

Stripe. Processes payments and receives the billing details you enter with it.

Shopify, WooCommerce, CardTrader, Mana Pool and Square. If you connect one, it receives the listings you choose to send, and nothing you do not send.

Discord. If you connect a webhook, it receives the alert messages we post to it, such as a card that needs review or a card that has sold.

Cloudflare and Google. Mail you send to an address on mycardwizard.com is routed by Cloudflare Email Routing to two Google-hosted mailboxes we read. Both companies see the message and who sent it.

Cloudflare Turnstile. The check that you are a person runs on the sign-in, sign-up and password reset forms. Your browser loads it from Cloudflare, which sees your IP address and your browser details. It sets no cookie on our site.

YouTube. The walkthrough video on the front page is a YouTube player in privacy-enhanced mode. YouTube sees your IP address when the page loads, and stores nothing in your browser until you play the video.

Google, as a sign-in provider. If you sign in with Google, Google sees that you signed in to My Card Wizard, and it sends us your name, your email address and your profile picture.

tcgcsv.com. Publishes the TCGplayer catalog and its daily market prices, which we download once a day into our own price table. We ask for whole price files, never about you or about one of your cards.

thecardapi. A market-data provider. It is switched off today and we may switch it back on. It would receive a card description, such as Charizard Obsidian Flames 125/197, and nothing about you, your scans or your account.

RapidAPI. A second market-data provider, reached the same way. It is switched off today as well, and would receive the same card description and nothing about you.

The Pokémon TCG API (pokemontcg.io). Receives a card name and collector number to confirm which set a card belongs to.

HaveIBeenPwned. When you choose a password, your browser hashes it and sends the first five characters of the hash to our server, which relays them to api.pwnedpasswords.com. That service answers with a block of hashes and your browser checks the block itself. Your password never leaves your browser.

PSA (Collectors Universe). We no longer send certificate numbers to PSA. A graded slab is read from your scan of the label, and to check a certificate number we link you to PSA's own public page, which you visit yourself.

Card picture hosts. The reference artwork beside your scan is loaded by your browser straight from the card databases that publish it: images.pokemontcg.io, images.scrydex.com, tcgplayer-cdn.tcgplayer.com, assets.tcgdex.net, cards.scryfall.io, cards.lorcast.io, optcgapi.com and stock-photos.gletech.com. Listing pictures in the finish picker come from i.ebayimg.com, thumbs.ebaystatic.com and galleryplus.ebayimg.com. The still image of the front-page video comes from i.ytimg.com, and a Google profile picture from lh3.googleusercontent.com. Your browser fetches these directly, so each host sees your IP address and the page you were on. We send them nothing else, and none of them is an advertising or analytics service.

Whatnot, TCGplayer and Square file exports. We send nothing on your behalf. Exporting produces a file we hand to you, and what happens to it afterwards is your upload, under that marketplace's own terms.

We may also disclose information where the law requires it, or to protect the rights and safety of users and of the service. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

6 Card scans and how they are stored

Your card scans are kept in a public storage bucket. Each one lives at a web address that loads for anyone who has the exact link. The addresses are not listed or linked anywhere and are impractical to guess, but they are not password-protected. That is how the app draws your inventory quickly.

Each scan is stored at several sizes, from a small thumbnail for a table to a sharp copy for a listing. They are kept until you delete the card or the account, and deleting a card deletes every size.

Your inventory itself is not public. The cards, prices, edits and the rest of your workspace are restricted at the database level, so an account can read only its own rows.

7 Photo Rewards, if you turn them on

Photo Rewards are off unless you switch them on, from Free scans in the app. Nothing in this section applies to an account that has not opted in, and opting in changes nothing about how your cards are identified or priced.

While it is on, a scan you have already made can be offered to our card photo catalog, but only where no catalog we use has a picture of that card or of the finish you told us it has. Only the first scan of a printing is taken, a scan from a card that needs review is never taken, and nothing extra is uploaded.

A person looks at every scan before anything happens to it. If it is accepted, you earn scans and the picture becomes the catalog photo other people see beside that card, labelled as a seller photo. Your name, your account and your prices are never shown with it.

We record when you opted in and which version of the wording you agreed to, so we can say later what you were told at the time.

You can opt out at any time in the same place. A scan still waiting to be reviewed is withdrawn at once. A scan already accepted stays in the catalog, because other people rely on it to check their own cards, and we remove it on request.

Keep the card and nothing else in the scan. A scan showing a person, a screen or an address is rejected.

8 How we improve pricing accuracy

A sports card is priced from eBay's current listings rather than from a market price, and the app applies a discount, because a listing price runs higher than what a card sells for.

If you record what a card actually sold for, that outcome feeds the calculation of the discount. It is worked out per card set across outcomes from all accounts, and the result is a single ratio used to sharpen estimates for everyone pricing cards in that set.

No other user can see your prices, your cards, your scans or your identity through this. What is shared is the ratio, not the sales behind it. Recording a sale price is optional, and everything else works if you never do.

9 How long we keep your information

Your inventory, scans and workspace stay until you delete them or delete the account. Deleting a card removes the row and its scan, and disconnecting a channel removes the stored tokens or keys.

A photo waiting in the phone tray is deleted after 30 days if no batch has used it.

The record of how many cards you have scanned is kept until you delete the account, because it is what your plan is counted against.

Operational logs are short-lived and are kept only while they are useful for debugging.

A sale outcome already folded into the ratio described in section 8 may persist in that aggregate form after an account is deleted, because the ratio is a statistic and not a record about you.

A scan accepted into the catalog stays while it serves as that card's reference picture, including after the account that gave it is deleted. It carries no name and no account with it, and we remove it on request.

Feedback and support tickets are kept after an account is deleted, with the account and the email address unlinked, because they record a problem we may still owe a fix for. Ask us and we will delete a ticket outright.

10 Your rights and choices

These rights are offered to everyone, whatever country or state you are in.

Access and portability. Email us from the address on your account and we will send you a copy of your data.

Correction. You can edit your cards, prices and profile in the app, and you can ask us to correct anything else.

Deletion. You can delete a card in the app, which removes the card and its scan. You can delete the whole account from Security, which deletes your cards, batches, scans, saved settings and marketplace connections and then closes your sign-in. It cannot be undone. Listings already live on eBay are not affected, because only eBay can end those.

Connections. You can disconnect any marketplace or store at any time, which removes the stored tokens or keys.

Email. You can turn off product email with the unsubscribe link in any one of them. Sign-in codes, two-factor codes and receipts keep arriving, because without them you could not get into your own account.

Photo Rewards. You can turn them off at any time from Free scans, which withdraws every scan still waiting to be reviewed. An accepted picture is removed on request.

We will not charge you or reduce your service for exercising any of these rights. If you believe we have mishandled your data you can complain to your data-protection authority.

11 If you are in California or another US state with a privacy law

California residents have the right to know what personal information is collected and why, to receive a copy, to ask for it to be deleted or corrected, and not to be treated differently for exercising any of those rights. Use the contact address above.

If you live in another state with a comprehensive privacy law, such as Colorado, Connecticut, Virginia, Texas, Oregon or Utah, you have substantially the same rights, plus the right to opt out of targeted advertising, the sale of personal data, and profiling with legal or similarly significant effects. We do none of those three, so there is nothing to opt out of. If we decline a request you can appeal by replying to our answer, and a person will review it again.

We do not sell your personal information and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for any purpose beyond running the service.

12 If you are in the UK or the EEA

We are the data controller for the information described here. The companies in section 5 act as our processors, except the marketplaces, which are separate controllers for what you send them.

Our legal bases are these. Running your account, storing your cards, identifying and pricing them, and making the listings you ask for are performed to carry out our contract with you, and account and security email is part of that. Keeping the service secure, preventing abuse and fixing faults rest on our legitimate interests. Product email rests on our legitimate interest in telling our own customers about the service they signed up for, and you can object at any time with the unsubscribe link. Photo Rewards rest on your consent, which you can withdraw at any time without affecting anything already done.

You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority. In the UK that is the Information Commissioner's Office.

13 Where your data is processed

The service and the companies named in section 5 operate mainly in the United States, so your data is processed there. Using My Card Wizard from another country means sending your data to the United States, which may have different data-protection rules than your own.

Where a transfer out of the UK or the EEA is involved, it is covered by the transfer terms our providers publish. Supabase, Railway, Google, Anthropic, Stripe and the others named in section 5 each offer Standard Contractual Clauses in their data processing terms.

14 Security

Traffic is served over HTTPS. Marketplace tokens are encrypted before they are stored. Database access is restricted so an account can read only its own inventory, and every write endpoint requires authentication.

You can turn on two-factor authentication in Security settings, and end every active session from the same screen. We recommend both if you have connected a marketplace account.

No service can promise perfect security. If we become aware of a breach affecting your data, we will tell you promptly and tell you what happened.

15 Children

My Card Wizard is for adults. You must be 18 or older to create an account, which is stated at sign-up and in the Terms.

We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal data, email support@mycardwizard.com and we will delete the account and everything in it.

16 Changes to this policy

We may update this policy as the app changes, for example if we add a service that receives your data. When a change is material we will make a reasonable effort to tell users rather than editing the text quietly. The date at the top shows the current version.

17 Contact

Questions about privacy, a request about your data, or a problem with this policy: support@mycardwizard.com. Please send it from the address on your account so we can verify the request.