Legal

Privacy Policy

Last updated August 25, 2026

PopAlpha ("we," "us," or "our") operates the PopAlpha website and iOS app. This policy explains what information we collect, how we use and share it, how long we keep it, and the choices available to you.

1. Information we collect

Account and profile information

When you create an account through Clerk, we receive your email address and, if provided, your name and profile picture. We also store the public handle, bio, banner image, visibility settings, and communication preferences you choose.

Collection, activity, and personalization information

We store the cards, grades, quantities, prices paid, acquisition details, certification numbers, notes, and wishlist selections you add. We also process your searches, saved and viewed cards, scans, favorite sets, and derived collecting preferences to provide recommendations and Collector Insights. Posts, comments, likes, follows, reports, and other social activity are stored so we can operate community features and notifications.

Scan and Grade Check images

Some card identification begins on your device. When you use online identification, or when on-device recognition is unavailable or uncertain, the app may automatically send a compressed card photo to PopAlpha for server-assisted identification. A scan handled entirely offline does not upload its image unless you later submit a correction or another evaluation action that requires the image.

New online scan images are stored in private server-side storage, and we attempt to store successful Grade Check captures there. Some older scan captures written before our private-storage transition may remain in a legacy public storage location until an approved migration and deletion plan is implemented. We may also store a cropped image, a cryptographic image hash, recognition results, confidence and timing data, OCR output, and measurement results. Certain uncertain captures may be placed in a restricted review queue. If you submit a correction, we store its image, the card you select, and related recognition details in private correction and scanner-evaluation records. We do not use these images for advertising or cross-app tracking, and we do not sell them.

Grade Check may separately ask whether you want to help improve card-edge detection. If you opt in, we privately store a metadata-free copy of the original card scene together with the physical outer edge and printed inner-frame guides you confirm, along with detector diagnostics. These examples enter a restricted candidate queue and are not used for model training until reviewed. You can stop future sharing and request deletion of contributed edge photos from iOS Settings. Deletion removes retained examples, but cannot remove their influence from a model that was already trained before the request.

Optional coarse location

If you allow When-In-Use location access for Shops Around Me, the iOS app obtains your device location. It sends PopAlpha a coordinate rounded to two decimal places (approximately a one-kilometer area) to rank registered shops, and it asks Apple MapKit for nearby points of interest. We do not write that coordinate to our application database, although it may appear temporarily in ordinary network and infrastructure logs. We do not use location for advertising or tracking.

Subscription and transaction information

For App Store purchases, we receive product and transaction identifiers, purchase or trial status, price and currency, expiration and renewal information, and refund or revocation status. Apple processes your payment method; PopAlpha does not receive your full payment-card details.

Device, usage, diagnostic, and request information

We and our service providers collect information such as IP address, browser or device type, operating system, app version and build, timestamps, pages and features used, lifecycle and funnel events, performance measurements, and crash or exception details. PostHog assigns analytics identifiers and, after sign-in, may associate activity with your PopAlpha user ID, email address, and first name. In the iOS app, we record a sample of in-app sessions (periodic screen images and touch interactions) to diagnose usability problems and improve the product. These recordings mask text you type and never include your camera feed: the live camera preview is excluded from recording. Session recordings are processed by PostHog on our behalf and are not shared with advertisers. On the website, PostHog may collect interaction replay data where that feature is enabled.

Push notification information

If you enable notifications, we store the device token or web push endpoint, cryptographic keys, platform, and notification preferences needed to deliver them.

2. How we use information

  • Operate PopAlpha, including accounts, portfolios, watchlists, social features, nearby shops, scanning, Grade Check, alerts, and customer support.
  • Personalize card recommendations, market briefs, and Collector Insights using your collecting activity and derived preferences.
  • Verify purchases, provide subscription entitlements, reconcile billing events, prevent fraud, and respond to support issues.
  • Measure performance and feature use, diagnose errors, protect the service, and improve scanner accuracy and product quality.
  • Send service messages, notifications you enable, optional digests, and product updates you can turn off in Settings.
  • Comply with law, enforce our terms, and protect users, PopAlpha, and others.

3. How we share information

We do not sell personal information or card images, and we do not share them with data brokers. We disclose information to service providers only as needed for the purposes described in this policy, including:

  • Clerk — authentication, account identity, and session management.
  • Supabase — database hosting and private storage for user-submitted scan and Grade Check images.
  • Vercel — application hosting, request logs, web analytics, performance monitoring, and routing AI requests through Vercel AI Gateway.
  • PostHog — product analytics, lifecycle and conversion measurement, diagnostics, and crash reporting.
  • Tailscale and Replicate — Tailscale securely routes image bytes to PopAlpha's self-hosted image-inference service. Replicate may process image bytes or a short-lived private image link if a fallback scanner or embedding path is activated.
  • Google Gemini — AI-generated card summaries, Collector Insights, and authorized visual pre-labeling of scanner-evaluation images. A Collector Insight prompt may include card and market metadata, saved, watchlisted, scanned, or repeatedly viewed card names, favorite sets, and derived collecting preferences. We do not include your direct name, email address, or PopAlpha account identifier in that prompt.
  • Apple — StoreKit purchases, App Store subscriptions, push notifications, and MapKit searches.

We require service providers that handle user data for us to protect it consistently with this policy and applicable law. We may also disclose information when required by law, to protect rights or safety, investigate abuse, or complete a corporate transaction subject to appropriate safeguards.

Advertising measurement (Meta). To understand which ads lead to PopAlpha installs and subscriptions, we send Meta Platforms, Inc. limited app-launch, activation, trial, and subscription-conversion events. A conversion event may include the product, price, currency, and a transaction identifier. If, and only if, you allow tracking through Apple's App Tracking Transparency prompt, the Meta SDK may also use your device's advertising identifier (IDFA) for attribution. Declining does not limit PopAlpha features. We do not intentionally send Meta your collection contents, card images, portfolio value, messages, email address, or PopAlpha account identifier. Meta handles its data under its own Privacy Policy. You can change your tracking choice in iOS Settings → Privacy & Security → Tracking.

4. Cookies and similar technologies

The website uses Clerk cookies that are necessary for sign-in and session security, plus a first-party PostHog analytics and session cookie. We do not use third-party advertising cookies. The iOS app uses SDK and device identifiers as described above; IDFA-based attribution is controlled by your App Tracking Transparency choice.

5. Data retention and deletion

We keep information only for as long as reasonably necessary to provide the service, support the purposes described above, protect the service, and meet legal obligations. Account, portfolio, wishlist, and social information generally remain while your account is active or until you delete the item or account.

Scan images, Grade Check captures, related telemetry, submitted corrections, and review, evaluation, or benchmark examples may be retained longer so we can reproduce results, investigate failures, validate changes, and improve scanner accuracy. New records are stored privately, subject to the legacy-storage disclosure above, and may be keyed by an image hash. Some correction and Grade Check records also contain a PopAlpha user identifier. We do not currently apply one fixed retention period to this scanner-evaluation corpus; we keep it until it is no longer reasonably needed for those purposes or a valid deletion request can be completed, subject to security and legal requirements.

Opted-in card-edge examples are retained until you withdraw consent or they are no longer reasonably needed. The in-app Grade Check privacy control stops future contributions and requests deletion of examples associated with the current device or account.

When you use in-app account deletion, we remove your Clerk authentication identity and attempt to delete core user-facing account data from active PopAlpha tables. The automated flow does not currently delete every scanner correction, Grade Check, analytics, or service-provider record, including some records that contain a user identifier. We may also retain limited transaction, security, fraud-prevention, legal, de-identified, or aggregated records. Contact us to request deletion of additional identifiable records; we will act on valid requests where required and technically feasible. Service-provider logs and backups are removed or overwritten on their ordinary retention schedules.

6. Your rights and choices

  • Export core account data. Settings → Data & Privacy → Export My Data provides a JSON copy of your profile, portfolio, wishlist, posts, and recent activity included in the export.
  • Delete your account. Settings → Data & Privacy → Delete My Account removes your PopAlpha sign-in and initiates deletion of core user-facing account data, subject to the retention and deletion limits described above. Deleting PopAlpha does not cancel an Apple subscription; manage or cancel it in the App Store subscription settings.
  • Control permissions. You can change camera, location, notification, and tracking permissions in iOS Settings. You can use the shop directory without allowing location.
  • Manage communications. Turn optional alerts, weekly digests, and product updates on or off in PopAlpha Settings.
  • Control visibility. Set your profile to public or private, and set activity to public, followers-only, or private.
  • Make a privacy request. Depending on where you live, you may have rights to access, correct, delete, or restrict certain processing. Email us using the address below. We may need to verify your request.

7. Children's privacy

PopAlpha is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us so we can investigate and delete it where required.

8. Security and international processing

We use safeguards including HTTPS, private storage for new user-origin scan captures, authentication, and database access controls, including row-level security where appropriate. No system is completely secure. PopAlpha and its service providers may process information in the United States and other countries where they operate, subject to applicable safeguards.

9. Changes to this policy

If our practices change, we will update this policy and the date at the top. Where required or practical, we will also provide an in-app notice or request consent before a materially different use of personal information.

10. Contact

Questions or privacy requests? Email contact@popalpha.app.