Cardmon legal

Privacy Policy for Cardmon

Effective date: July 24, 2026

1. Introduction

Cardmon is operated by Atlas Labs. This Privacy Policy explains how Atlas Labs handles information in connection with Cardmon.

2. Information We May Collect

Depending on the features you use, we may collect account or session identifiers; card scan images or card information extracted from them; collection data you save; subscription status; device, app, crash, and diagnostic information; feedback reports; and messages or attachments you send to support.

3. Card Images and OCR Processing

When you use card scanning features, card images may be processed to identify card details and provide estimated market price information. Do not upload images that contain sensitive personal information.

4. Account Information

If account features are provided, we may collect information such as email address, login provider information, and account identifiers.

5. App Usage and Device Information

We may collect basic usage data, crash data, device information, and diagnostic information to improve the app and maintain security.

6. In-App Feedback and Error Reports

Cardmon allows users to submit feedback or error reports from scan results, card details, price information, and collection-related screens. When feedback is submitted, Cardmon may collect the selected feedback type and category, an optional message entered by the user, the screen where the report was submitted, related card, printing, price, or listing identifiers, OCR, candidate-card, recognition-result, and error context generated during scanning, app version, build number, platform, operating system version, device model, language or locale, country or region code, submission time, and the authenticated user identifier, including anonymous authenticated user identifiers. For scan-related feedback, the current scanned card image is sent together with the report when the user taps the final submit button. Card-detail, price, and collection-related feedback can be submitted without an image. Opening or closing the feedback form does not upload an image. When a scan feedback image is sent, Cardmon uses a prepared or resized card image when available rather than the original full-resolution image, and does not intentionally upload the original full-resolution image. Feedback images are stored privately in Supabase Storage and are not made available through permanent public URLs. Operator access uses private or admin access, or short-lived signed access. Feedback images are used only to investigate the report, provide support, improve card data quality, and improve card recognition quality. Feedback images are retained for a maximum of 30 days and then deleted. Feedback metadata is stored in Supabase and may be retained longer than images for support, troubleshooting, abuse prevention, quality improvement, audit, and recordkeeping. Cardmon does not use feedback data for advertising, third-party marketing, cross-app tracking, or sale of personal data. Country or region code may be collected from device or app locale or region settings when available. It is not precise GPS location, is not inferred from GPS, and is not used for tracking. Cardmon does not request location permission for the feedback feature. Feedback submissions are linked to authenticated user identifiers because rate limiting, abuse prevention, support, and debugging require it. Each authenticated user may submit up to 5 feedback reports per UTC day and 2 per minute.

7. Payment and Subscription Information

Apple processes App Store purchases and subscription payments. Cardmon does not receive or store full payment card details. We may use RevenueCat to manage subscription access and receive purchase status, product, renewal, and entitlement information from the App Store. Apple and RevenueCat process information under their own privacy policies.

8. How We Use Information

We use information to provide app features, identify cards, estimate card information, maintain user collections, improve the service, prevent abuse, and respond to support requests.

9. Third-Party Services

Cardmon may use third-party service providers for hosting, analytics, image processing, authentication, payments, or infrastructure. These services may process information only as needed to provide their services.

10. Data Retention

We retain information only as long as reasonably necessary to provide the service, comply with legal obligations, resolve disputes, and enforce agreements.

11. Data Deletion Requests

To request access to or deletion of Cardmon data, email support@atlaslabsstudio.com from the address associated with your account, if applicable. We may ask you to verify your identity. Some information may be retained where required by law or for legitimate security, fraud-prevention, or recordkeeping purposes.

12. Children's Privacy

Cardmon is not intended for children under the age required by applicable law. If we learn that we collected personal information from a child without appropriate consent, we will take appropriate steps to delete it.

13. Security

We use reasonable technical and organizational measures to protect information, but no system is completely secure.

14. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page.

15. Contact Us

Operator: Atlas Labs. For privacy questions or deletion requests, contact support@atlaslabsstudio.com.

16. Trademark Disclaimer

Cardmon is not affiliated with, endorsed by, or sponsored by Nintendo, The Pokémon Company, Game Freak, or Creatures Inc.