Privacy statement - InfinityCards
We explain which data we collect, why, and which rights you have.
Last updated: July 22, 2026
InfinityCards values your privacy. This statement outlines the personal data we process, why we do it, and your rights.
1. Who are we
InfinityCards is an online platform for scanning, managing, and tracking card collections.
- Contact: support@infinitycards.app
- Company details as applicable (KvK registration)
2. Processed data
We only process data necessary for the platform operation and security.
- Account and profile data such as username, email address, hashed password, avatar, language, region, and public profile slug
- For Google login: Google account ID, verified email address, name, and optional Google profile picture
- Collection data, wishlists, binders, decks, card conditions, notes, and entered purchase, sale, or vendor prices
- Social data and communications such as friendships, follows, reactions, private messages, notifications, and activity
- Subscription, scan credit, vendor, team, inventory, and sales statuses linked to the account
- Scan results and technical scan metadata as described under AI and scans
- Technical and security data such as sessions, device name, IP address, browser/app information, login events, cookie preferences, and error or audit logs
- Information you submit through support requests or bug reports
3. Processing purposes
We process data only for the following purposes and on the corresponding GDPR legal bases:
- Account administration, authentication, collection management, card scanning, social features, and vendor tools: necessary to perform our contract with you (Article 6(1)(b) GDPR).
- Security, fraud prevention, moderation, troubleshooting, and technical logs: our legitimate interest in keeping InfinityCards secure, reliable, and usable (Article 6(1)(f) GDPR).
- Payments, subscriptions, invoicing, and financial administration: performance of the contract and compliance with legal obligations (Article 6(1)(b) and (c) GDPR).
- Support requests and bug reports: performance of the contract or our legitimate interest in resolving problems and improving the service.
- Non-essential cookies, future analytics or marketing, and any use of scan photos for AI training: only after prior, specific consent (Article 6(1)(a) GDPR).
- Establishing, exercising, or supporting legal claims and complying with applicable law: legal obligation or legitimate interest.
- We never sell personal data to third parties.
4. AI and scans
InfinityCards processes a card photo solely to recognize the card and suggest a result.
- The app creates a temporary photo, crops it to the visible card frame, and securely uploads it to InfinityCards.
- The temporary photo is deleted from the device as soon as the scan succeeds or fails.
- Temporary server images and crops are deleted immediately after processing; the photo is not attached to your collection or retained as a permanent file.
- Google Cloud Vision or Google Gemini may process the card photo for text recognition. Google receives the image only for this recognition request.
- The recognition result may remain in a technical cache for up to 60 minutes; this cache does not permanently store the card photo.
- We retain technical scan metadata such as account ID, recognition method, image dimensions, processing time, detected card number, candidates, and selected result for security, troubleshooting, and quality control.
- Scan photos are not used to train AI models without separate, explicit consent.
5. Third parties
We only share data with necessary providers, including hosting and payment providers and Google for card and text recognition, under appropriate privacy and processing agreements.
- With Google Sign-In, InfinityCards receives a temporary ID token to verify your identity.
- InfinityCards does not store your Google password or a Google access or refresh token.
- Google Sign-In does not give InfinityCards access to Gmail, Google Drive, contacts, calendar, or other Google content.
- After verification, InfinityCards creates its own secure session or app token for access to your InfinityCards account.
- Google Sign-In for authentication and Google Vision/Gemini for card scans are separate processing activities.
6. Storage and security
Traffic to InfinityCards is encrypted, passwords are hashed, and access is restricted and logged. External recognition providers may process data through their own infrastructure under the applicable processing agreements.
7. Retention
Account and collection data is retained while the account remains active. Temporary scan photos are deleted immediately after processing, scan results remain in the technical cache for no more than 60 minutes, and technical OCR scan logs are automatically deleted after no more than 90 days. After account deletion we remove the remaining data unless the law requires a longer retention period.
8. Your rights
You can request access, correction, deletion, export, or object. Send requests to support@infinitycards.app.
9. Changes
We update this statement as needed; the latest version stays on this page.
Watch your inbox for updates to our privacy practices.