Privacy
Last updated October 10, 2026
ScanComps helps Pokémon card vendors price cards, slabs and sealed products from a photo, make QR price labels and keep track of deals. This page explains what the app collects, who handles it, how long it is kept and how to remove it.
What we collect
- Your account: when you sign in with Google or Apple, we receive your name, email address and an account ID. We never see your password. For Sign in with Apple we also keep a token, encrypted, so we can cancel the sign-in when you delete your account.
- Photos: photos you take or choose in the app to identify an item, and what was read from them.
- Your work: labels, stock counts, label prices, asking prices and completed deals you create.
- Searches: card and product names, numbers and sets you search for, and the matches found.
- Usage and diagnostics: a record of steps in the app (scans, searches, confirmations, labels, errors), photo sharpness and brightness scores, and your browser type, used to fix problems and improve matching.
- IP addresses: kept in short-lived counters that limit abuse, deleted within 2 days.
- Cookies: one cookie keeps you signed in (30 days) and a short-lived one protects sign-in. No advertising or tracking cookies.
- On your phone only: settings such as your cash offer and label size, and the deal you are building.
Photo recognition (AI)
Photos are sent to an AI model only after you allow it in the app. To identify the item, the photo is sent to OpenRouter, which passes it to Google's Gemini model. Only the photo and our instructions go; your name and email are never sent.
- OpenRouter says it does not store the content of requests unless the account owner turns on logging, which ScanComps does not; it keeps metadata such as request size and timing (OpenRouter data policy).
- Google, under its paid Gemini API terms, does not use the photos or results to improve its products, and logs them for a limited time only to detect misuse (Gemini API terms).
You can turn photo recognition off at any time in Settings → Privacy. Manual search keeps working.
Who else handles data
- Cloudflare hosts the app and stores its data and photos.
- Pokémon Price Tracker and TCG API receive the card or product name, number and set being searched and catalog IDs, to look up prices. No personal details are sent.
- TCGplayer serves the catalog pictures your phone shows, so it sees your IP address like any website.
- Google and Apple handle sign-in.
These service providers may use the data only to provide their service to us, and their terms bind them to protect it at least as well as this policy does. We don't sell your data and there are no ads.
Public price pages
A QR label links to a public page showing that item and its price. Anyone with the link can open it. It does not show who you are.
How long we keep it
- Photos: deleted automatically after 30 days. If you turn on Keep my photos, they are kept to improve matching until you turn it off or delete your account.
- Account, labels, deals, searches and usage records: until you delete your account.
- IP addresses: up to 2 days.
Deleting your account
In the app, open Settings → Delete account. This permanently deletes your account, sign-in, labels and their public price pages, deals, photos, scans and usage records, and cancels Sign in with Apple. It can't be undone.
Children
ScanComps is a tool for card vendors and is not directed to children under 13. We don't knowingly collect their data; if you believe a child has given us data, contact us and we will delete it.
Contact
Questions or requests: mjpeters1987@gmail.com. If this policy changes, this page will be updated.