CardHit CardHit

Privacy Policy

Last updated: March 22, 2026

Sports Card Scanner - CardHit ("CardHit", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile application.

1. Information We Collect

1.1 Card Images

When you scan a sports card, the photo is sent to Google Gemini (AI) for card identification and valuation purposes only. Card images are:

  • Processed in real-time for identification
  • Not stored on our servers or by Google after processing
  • Not used for AI model training
  • Subject to zero data retention policies

1.2 Collection Data

Cards you add to your collection are stored locally on your device using Apple's built-in storage. This data includes card details (player name, brand, year, estimated value) and the card image. This data is not transmitted to our servers.

1.3 Device Information

We generate a random device identifier (UUID) stored locally on your device for rate-limiting purposes. This identifier cannot be used to identify you personally.

1.4 Usage Data

We log scan requests on our server for operational purposes. Logs contain: timestamp, anonymized IP address, card identification results (player name, brand, value), and error messages. Logs do not contain card images or personal information.

2. Third-Party Services

2.1 Google Gemini (AI)

Card images are sent to Google Gemini via Vercel AI Gateway for identification. Google Gemini operates under zero data retention — your images are not stored or used for training. Processing occurs on Google's servers (primarily US-based). For more information, see Google's Gemini API Terms.

2.2 Vercel AI Gateway

We use Vercel AI Gateway to route requests to Google Gemini. Vercel enforces zero data retention and does not store prompts or responses. See Vercel's Data Processing Addendum.

2.3 eBay

We display eBay listings using the eBay Browse API. Some links may be affiliate links. See our Terms of Use for details.

3. Data Retention

Card images: Not retained (zero data retention).

Server logs: Retained for up to 30 days for operational and debugging purposes, then automatically deleted.

Collection data: Stored locally on your device until you delete it.

4. Data Security

All communication between the app and our servers is encrypted using HTTPS/TLS. API requests are authenticated using HMAC-SHA256 signatures with nonce-based replay protection.

5. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the right to:

  • Access your personal data
  • Request deletion of your data
  • Object to data processing
  • Data portability

Since we do not store personal data on our servers (card images are not retained, and collection data is local to your device), most of these rights are automatically satisfied. To exercise any rights or ask questions, contact us at [email protected].

6. Children's Privacy

CardHit is not directed at children under 13. We do not knowingly collect personal information from children.

7. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date.

8. Contact Us

If you have questions about this Privacy Policy, contact us at:

[email protected]

CardHit © 2026 CardHit. All rights reserved.
  • Terms of Use
  • Privacy Policy
  • Contact