Listings
Listings
Listings

CardIndex

  • Cards
  • Sets
  • Listings
  • My Collection
  • Sign In
  • Sign Up

Tools

  • Card Watchlist
  • Value Checker
  • Cert Lookup

Company

  • About
  • Blog
  • Compare
  • Sitemap
  • Terms
  • Privacy

Mobile Apps

Get the CardIndex app for iPhone:

Download on theApp Store

As an eBay Partner Network affiliate, CardIndex earns from qualifying purchases made through links on this page, at no additional cost to you.

© 2026 CardIndex, a product of Kantei Technologies, Inc. All rights reserved.
Analytics
VolumeMarket TrendsTrending Cards
Pokemon
CardsSets
Analytics
VolumeMarket TrendsTrending Cards
Listings
Pokemon
CardsSets
Analytics
VolumeMarket TrendsTrending Cards
WatchlistMy Collection

Privacy Policy

Last updated: August 31, 2026

This Privacy Policy explains how Kantei Technologies, Inc.("we", "us", or "our") collects, uses, and protects your information when you use CardIndex ("the Service") — including the website at https://www.cardindex.co and the CardIndex iOS app.

1. Data We Collect

Account information

When you create an account we collect your email address and a hashed password. Email is used to identify you, send transactional messages (password reset, watchlist alerts you opt into), and contact you about the Service.

Collection & user content

Cards you add to your collection, watchlist entries, portfolio snapshots, scans, and any notes you save are stored against your account so we can render them back to you.

Camera (iOS app)

The CardIndex iOS app uses your device camera only when you tap "Scan" to identify a card. Camera frames are processed to detect the card and the resulting image is sent to our servers for matching. We do not access the camera in the background and we do not access your photo library, microphone, location, contacts, calendar, or health data.

When a scan does not match a card, we occasionally upload the photo of that failed scan to our servers and retain it to diagnose problems and improve the accuracy of our card recognition. The image is stored on its own, with no account, personal, or device information attached — it is completely anonymous. These images are only used to improve the Service — they are never used to advertise to you and are never sold. You can turn this off at any time in the iOS app under Profile → Scanner preferences; with it disabled, photos of failed scans are not uploaded or kept.

Usage & diagnostics

We collect standard server logs (IP address, user agent, request path, response status) to operate, secure, and debug the Service. On the website we use Google Analytics 4 and Vercel Analytics to understand which pages are used and how performance behaves. The iOS app reports crash/diagnostic data through Apple's standard reporting only when you opt in via iOS Settings.

Product analytics (PostHog)

The CardIndex iOS app uses PostHog for product analytics so we can understand which features people use, diagnose bugs, and prioritize improvements. When you use the app, PostHog records:

  • Product events— screen views, button taps, scan attempts, AI grading requests, paywall interactions, sign-in and sign-up events, and similar interaction events. Free-form text you type (email, password, notes, feedback message body) is not collected as part of these events.
  • Device metadata— device model, iOS version, app version, screen size, and locale.
  • IP address and derived location— your IP is collected with every event and used to derive approximate location (country, region, city). Precise GPS location is not collected.
  • Session replays— screenshot-mode recordings of your app sessions. Text input fields (email, password, notes, feedback) are automatically masked in the recording so what you type is never captured. Images shown on the screen — including photos of cards you scan and card images from our catalog — are visible in the recording so we can reproduce visual bugs.
  • Account linkage— once you sign in, PostHog links the above events and recordings to your account user ID, email address, display name, and subscription plan.
  • Feature-flag exposures— which experimental features and A/B test cohorts your device is assigned to.

PostHog data is transmitted to PostHog's US cloud (us.i.posthog.com) under a Data Processing Agreement and Standard Contractual Clauses for transfers of EEA/UK personal data. Session replay recordings are retained for 30 days; event data is retained per PostHog's standard project retention. Data is used only for product analytics, session replay, and feature-flag delivery — it is never sold, shared with advertisers, or used to build a cross-app profile of you.

Install attribution (Singular)

The CardIndex iOS app uses Singular as its mobile measurement partner so we can understand which marketing channels drive new installs (for example, whether a user installed the app after seeing an Apple Search Ads placement or a Reddit ad). Singular receives:

  • Install attribution signals— via Apple's SKAdNetwork framework (in managed mode, where Singular handles the conversion-value model and the postbacks to ad networks) and Apple's AdServices attribution token (used for Apple Search Ads). Both are privacy-preserving mechanisms designed by Apple.
  • Advertising identifier (IDFA)— on first launch we show the iOS App Tracking Transparency prompt so you can decide whether Singular may read your device's advertising identifier (IDFA). If you grant permission, Singular includes the IDFA in its attribution events to give ad networks a more precise install-to-conversion match. If you decline (the default), Singular falls back to SKAdNetwork + AdServices only and the IDFA is never read. You can change this decision anytime in iOS Settings › Privacy & Security › Tracking › CardIndex.
  • Device metadata— standard SDK telemetry such as device model, iOS version, app version, and IP address.
  • A small set of product events— currently sign-up, card scanned, and AI grading run. These are used by ad networks (via Singular's aggregated postbacks) to optimize ad delivery toward people likely to complete the same action, and to measure the ROI of ad spend.
  • Account linkage— once you sign in, we set your account user ID as Singular's “custom user id” so events and attribution stitch to the same identity used by our product analytics. Signing out clears the linkage.

IDFA collection is opt-in— Singular only reads the identifier if you grant permission on the App Tracking Transparency prompt shown at first launch. Decline it and the app functions identically, using only Apple's privacy-preserving attribution paths (SKAdNetwork + AdServices token). No cross-app profiling happens regardless of your choice.

No third-party advertising in the app

We do not display third-party advertising inside CardIndex and we do not run any advertising SDK that shows ads to you. Singular (above) measures whether our own outbound ads on other platforms drove installs; it is not an ad-serving SDK and does not deliver ads. We do not sell or rent your personal information.

2. How We Use Your Data

  • To operate the Service (sign-in, sync your collection across devices, render your portfolio).
  • To send transactional email you opt into (password reset, watchlist price alerts).
  • To improve the Service via aggregate usage analytics.
  • To detect and respond to abuse, fraud, and security incidents.
  • To meet legal and tax obligations.

3. Apple App Privacy Categories

For the CardIndex iOS app, the following data is collected and linked to your account, used for App Functionality and Analytics only. None of it is used to track you across other apps.

  • Contact Info: Email address (account).
  • User Content:Cards in your collection, watchlist, portfolio snapshots, scans you save. Screenshot-mode session replays of the app UI (see “Product analytics” above).
  • Identifiers: Account user ID and IP address (used by our product-analytics provider to derive approximate country/region/city). The advertising identifier (IDFA) is read by Singular only if you granted permission on the App Tracking Transparency prompt shown at first launch; declining leaves it uncollected.
  • Usage Data: Product interaction events such as screen views, taps, scans, gradings, and paywall interactions.
  • Diagnostics:Crash reports through Apple's standard reporting if you opt in. Device model, OS version, and app version reported via our product-analytics provider.

The camera is used in-session for scanning. We do not retain camera images, except that — unless you opt out in the app's scanner preferences — a photo of a scan that fails to match may be uploaded anonymously, with no account or device information attached, to help us improve card recognition.

4. Service Providers

We rely on a small set of vendors to run the Service. Each receives only the data needed to perform its function:

  • Vercel — hosting, edge delivery, server logs, Vercel Analytics.
  • Google Analytics 4 — aggregate website usage analytics. IP anonymization is enabled.
  • PostHog(iOS app) — product analytics, session replay, and feature-flag delivery. Receives product events, screen views, device metadata, IP address, screenshot-mode session recordings (text inputs masked), and — once you sign in — your user ID, email, display name, and subscription plan. Hosted in the United States under a Data Processing Agreement and Standard Contractual Clauses for EEA/UK transfers.
  • Singular(iOS app) — mobile measurement partner for install attribution. Receives Apple SKAdNetwork conversion values, the Apple AdServices attribution token, device metadata (model, OS version, app version, IP address), a small set of product events (sign-up, card scan, AI grading run), and — once you sign in — your account user ID. Does not receive the IDFA and does not deliver ads inside the app. Hosted in the United States under a Data Processing Agreement and Standard Contractual Clauses for EEA/UK transfers.
  • Apple App Store — iOS app distribution and standard crash reporting.
  • Cloud database & object storage providers — to store account data, your collection, and uploaded scan images, all hosted in the United States.
  • Email delivery provider — to send password resets and watchlist alerts you opt into.

5. Data Retention & Deletion

We retain account data for as long as your account is active. You can delete your account at any time directly in the CardIndex iOS app (Profile → Settings → Delete Account), from your profile settings on the website, or by emailing support@cardindex.co.

When you delete your account from within the iOS app, all of your data — including your email address, hashed password, collection, watchlist, portfolio history, and saved scans — is permanently and irreversibly deleted from our servers. This action cannot be undone, and we do not retain a copy or backup of your account data afterward. Account deletions requested through the website or by email are processed the same way and completed within 30 days.

Server logs and aggregate, non-identifying analytics are retained for up to 90 days for security and operations, and any disclosures we are legally required to keep are retained only as long as the law requires.

6. Your Rights

Depending on where you live (EEA, UK, California, etc.) you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these rights, email support@cardindex.co. We will respond within 30 days.

7. Children

CardIndex is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.

8. Security

We use HTTPS in transit, encrypted storage at rest, Argon2id password hashing, and short-lived authentication tokens. No system is perfect — if you discover a security issue, please email support@cardindex.co.

9. Changes

We will update this Privacy Policy as the Service evolves. Material changes will be posted here, and the "Last updated" date at the top will reflect the most recent revision. Continued use of the Service after changes indicates acceptance of the revised policy.

10. Contact

Kantei Technologies, Inc., operator of CardIndex, can be reached at support@cardindex.co for any privacy-related question or request.