Information we process
We process account identifiers and email, collection and binder records, scan and search activity, subscription status, product diagnostics, and support messages. Camera images are used to recognize cards. Raw scan images remain in temporary app storage and are not retained by our servers; recognition providers may receive an image or bounded derived text only when needed to provide the scan result.
When you create an account, our verification provider may process browser or device characteristics and interaction signals to distinguish people from automated requests. SleeveSignal and the provider also process a network identifier such as an IP address. SleeveSignal receives a short-lived verification result. Our registration-admission database stores only keyed, pseudonymous installation and network hashes used to enforce signup limits; it does not store the raw network address, verification response, or guest installation credential.
How we use information
We use information to authenticate accounts, sync collections, recognize cards, enforce usage limits, provide subscription access, prevent abuse, answer support requests, and keep SleeveSignal reliable and secure. We do not sell personal information, serve third-party advertising, or use card scans to train advertising profiles.
Service providers
Providers may include Supabase for accounts and application data; Apple and Google for app distribution, sign-in where enabled, and payments; RevenueCat for subscription state; Google Cloud Vision for image recognition; OpenAI for bounded text-based recognition assistance (not raw card images); Cloudflare for the website and account-creation verification; and card-catalog or pricing providers used to return requested information. These parties process data for the service they provide under their own terms and safeguards.
Retention and deletion
Account and collection data is kept while your account is active. Short recognition-response caches are kept only long enough to safely replay a request; terminal recognition request records and product events may be kept for up to 400 days for abuse, reliability, and audit purposes. Subscription lifecycle records may be retained for up to 25 months for billing support, fraud prevention, and financial reconciliation. Legal or financial records may be retained longer where required. When deletion is requested, we delete or de-identify data that is not subject to a required retention period. Pseudonymous registration-admission counters are marked for deletion after 24 hours and are normally removed by scheduled or request-triggered cleanup.
Your choices
You can view, correct, and delete collection records in the app. You can request account deletion in Settings or at our account-deletion page. Store subscriptions must be canceled separately through Apple or Google. You may also contact us for privacy access, correction, deletion, or portability requests.
Security, children, and changes
We use encrypted network connections and access controls designed to protect data. No online service can guarantee absolute security. SleeveSignal is not directed to children under 13. We may update this policy as the service changes and will post the new effective date here.
Contact
SLEEVESIGNAL LLC — nick@getsleevesignal.com