This is the authoritative English-language version. The Vietnamese translation is provided for convenience; in case of any conflict the English version controls.
CardScan AI (the app) is a mobile utility for trading-card collectors. It performs three things, all of which you can use or skip independently:
The app also stores the cards you choose to save, displays daily price-change history for Pro users, and includes an optional in-app shop that opens the webthebai.com checkout in an embedded WebView.
Before any AI Scan or AI Grade request, the app displays a consent screen and only proceeds after you tap Allow. You can revoke this consent at any time in Settings → AI image upload; the toggle persists on the device until you turn it back on.
With your consent:
Images are transmitted over HTTPS to our gateway and forwarded to one or more third-party AI processors. We do not include any metadata identifying the user, the device, or the location beyond what the network layer necessarily reveals.
Our gateway:
The gateway does not retain raw image payloads. Images live only in transient processing memory for the duration of one request, after which they are released.
Downstream AI processors operate under their own contracts and policies. We cannot make retention, training, or secondary-use claims for those processors beyond what is documented in their respective terms. If you do not want your image sent to a third-party AI processor, leave the AI upload consent turned off — the app will continue to work for browsing and editing saved cards.
| Setting | Where | What it controls |
|---|---|---|
| AI image upload (on/off) | Settings → AI image upload | Blocks every AI Scan/Grade request. Free-tier features (browsing, editing saved cards) still work. |
| Delete saved card | Collection → tap trash icon | Removes the card record, local image, and any price snapshots from your device. |
| Delete saved grade | Collection → tap trash icon | Removes the grade record and the front/back photos from your device. |
| Clear Android app data | System Settings → Apps → CardScan AI → Storage → Clear data | Removes every local file, every preference, and your consent toggle. The next launch behaves as a fresh install. |
| Uninstall | System Settings → Apps → CardScan AI → Uninstall | Removes the app and all of its local data. Future installs start from scratch. |
Payment is handled entirely by Google Play. Our app never sees your card number, billing address, or CVC. The flow is:
Stored on the gateway only for the duration of the verification round-trip; we do not maintain a long-term record of your purchase history.
You can cancel, pause, or resume the subscription at any time in Play Store → Subscriptions.
When you save a card or a grade result, the app writes the relevant record (image, prices, notes) to a private folder under the app’s internal storage (filesDir/collection/...). This data is only on your device; it is not synced to our servers.
For Pro users, the app records a daily price snapshot locally to support the price-history chart. Snapshots are tied to your local card record and are deleted when you delete the card.
The optional Shop tab opens the webthebai.com checkout in an embedded WebView. When you reach the checkout page, the shop’s own privacy policy applies to the data you submit (shipping address, payment details handled by the shop’s payment processor). Our app does not relay or store that data.
| Data | Where it lives | Retention | How to delete |
|---|---|---|---|
| Random in-app UUID | Local DataStore | Until you uninstall or clear app data | Uninstall / clear data |
| AI Scan / Grade images | Transient (gateway processing only) | Released after one request — not retained | (automatic; nothing to delete) |
| Public price API query (card identity only) | Public API endpoints (Tcgdex, YGOPRODeck, etc.) | Subject to those providers’ policies | See each provider’ site |
| Server-side IP | Gateway access logs | Short-lived (operational logs only) | Expired automatically per gateway retention policy |
| Google Play purchase token | Gateway verification step | Hours, then discarded | (automatic) |
| Saved card / grade images + records | Local filesDir/collection/... | Until you delete them or uninstall | App → Collection → trash icon / Clear data / Uninstall |
| Price snapshots (Pro) | Local Room database | Until the parent card is deleted | Delete parent card |
You can at any time:
We respond to deletion requests within 30 days.
CardScan AI is not directed at children under 13. The app does not knowingly collect personal information from children. If you believe a child has used the app to submit images or other personal data and you would like it removed, contact us at maytinhbentre.com@gmail.com and we will respond within 30 days.
The app may send your image (with consent), UUID, and device label to AI processors located in countries other than your own. We rely on processor contracts that include standard data-protection terms; we do not perform additional transfers beyond what is needed to fulfill the request. Local data (saved cards, preferences) never leaves your device.
We take reasonable steps to protect the limited data the app processes:
X-Quota-Daily-Used / X-Quota-Daily-Limit) limit how many AI requests a single UUID can make per day.No security measure is absolute. If you discover a vulnerability, please email maytinhbentre.com@gmail.com with details.
We may update this policy to reflect changes in the app, the law, or third-party processors. The “Effective date” at the top will always reflect the current version. Material changes will be announced in the app’s Settings screen for at least 14 days before they take effect. Continued use of the app after the effective date constitutes acceptance.
For privacy questions, deletion requests, or vulnerability reports:
Bản tiếng Anh phía trên là bản chính thức. Bản tiếng Việt dưới đây chỉ để tham khảo; trong trường hợp có xung đột, bản tiếng Anh sẽ được ưu tiên.
CardScan AI (ứng dụng) là tiện ích di động cho người sưu tầm thẻ bài. Ứng dụng làm ba việc, bạn có thể dùng hoặc bỏ qua độc lập:
Ngoài ra ứng dụng còn lưu các thẻ bạn chọn giữ, hiển thị lịch sử giá hàng ngày cho người dùng Pro, và có shop trong ứng dụng mở checkout của webthebai.com trong WebView.
Trước mỗi yêu cầu AI Scan hoặc AI Grade, ứng dụng hiện màn hình xin phép và chỉ tiếp tục khi bạn nhấn Cho phép. Bạn có thể thu hồi đồng ý bất cứ lúc nào trong Cài đặt → AI image upload; cài đặt này lưu trên thiết bị cho đến khi bạn bật lại.
Khi bạn đồng ý:
Ảnh được truyền qua HTTPS đến cổng dịch vụ và chuyển tiếp cho một hoặc nhiều bên xử lý AI bên thứ ba. Chúng tôi không gắn kèm metadata nào nhận diện người dùng, thiết bị hay vị trí ngoài những gì tầng mạng bắt buộc phải tiết lộ.
Cổng:
Cổng không lưu giữ payload ảnh gốc. Ảnh chỉ tồn tại trong bộ nhớ xử lý tạm thời trong thời gian một yêu cầu, sau đó được giải phóng.
Các bên xử lý AI hoạt động theo hợp đồng và chính sách riêng. Chúng tôi không thể đảm bảo về việc lưu giữ, huấn luyện hay sử dụng phụ của họ ngoài những gì được ghi trong điều khoản tương ứng. Nếu bạn không muốn ảnh của mình gửi đến bên xử lý AI thứ ba, hãy tắt đồng ý upload AI — ứng dụng vẫn dùng được cho việc xem và sửa bộ sưu tập đã lưu.
| Cài đặt | Ở đâu | Quản lý gì |
|---|---|---|
| Upload ảnh AI (bật/tắt) | Cài đặt → AI image upload | Chặn mọi yêu cầu AI Scan/Grade. Tính năng Free (xem, sửa thẻ đã lưu) vẫn dùng được. |
| Xoá thẻ đã lưu | Bộ sưu tập → nhấn biểu tượng thùng rác | Xoá bản ghi thẻ, ảnh local và mọi snapshot giá trên thiết bị. |
| Xoá kết quả giám định | Bộ sưu tập → nhấn biểu tượng thùng rác | Xoá bản ghi giám định và ảnh mặt trước/sau trên thiết bị. |
Thanh toán do Google Play xử lý hoàn toàn. Ứng dụng không bao giờ thấy số thẻ, địa chỉ thanh toán hay CVC của bạn. Quy trình:
Lưu trên cổng chỉ trong thời gian verify; chúng tôi không giữ lịch sử mua hàng dài hạn. Bạn có thể huỷ, tạm dừng hoặc tiếp tục subscription bất cứ lúc nào trong Play Store → Subscriptions.
Khi bạn lưu thẻ hoặc kết quả giám định, ứng dụng ghi bản ghi (ảnh, giá, ghi chú) vào thư mục riêng trong bộ nhớ trong của ứng dụng (filesDir/collection/...). Dữ liệu này chỉ ở trên thiết bị; không đồng bộ lên server.
Với người dùng Pro, ứng dụng ghi lại snapshot giá hàng ngày ở local để hỗ trợ biểu đồ lịch sử giá. Snapshot gắn với thẻ local và tự xoá khi thẻ cha bị xoá.
Tab Shop mở checkout webthebai.com trong WebView nhúng. Khi đến trang checkout, chính sách riêng của shop áp dụng cho dữ liệu bạn submit (địa chỉ ship, chi tiết thanh toán do bộ xử lý thanh toán của shop). Ứng dụng không chuyển tiếp hay lưu dữ liệu đó.
| Dữ liệu | Ở đâu | Lưu giữ | Cách xoá |
|---|---|---|---|
| UUID trong app | Local DataStore | Đến khi bạn gỡ app hoặc clear app data | Gỡ app / clear data |
| Ảnh AI Scan / Grade | Tạm thời (chỉ trong cổng xử lý) | Giải phóng sau một yêu cầu — không lưu | (tự động; không có gì để xoá) |
| Query API giá công khai (chỉ định danh thẻ) | Endpoint công khai (Tcgdex, YGOPRODeck, ...) | Theo chính sách của provider | Xem site của từng provider |
| IP phía server | Log truy cập cổng | Ngắn hạn (chỉ log vận hành) | Tự hết hạn theo chính sách retention của cổng |
| Token mua hàng Google Play | Bước verify cổng | Vài giờ, rồi huỷ | (tự động) |
| Ảnh thẻ/giám định đã lưu + bản ghi | Local filesDir/collection/... | Đến khi bạn xoá hoặc gỡ app | App → Bộ sưu tập → thùng rác / Clear data / Gỡ app |
| Snapshot giá (Pro) | Local Room database | Đến khi thẻ cha bị xoá | Xoá thẻ cha |
Bạn có thể bất cứ lúc nào:
Chúng tôi phản hồi yêu cầu xoá trong vòng 30 ngày.
CardScan AI không hướng đến trẻ em dưới 13 tuổi. Ứng dụng không cố ý thu thập thông tin cá nhân từ trẻ em. Nếu bạn tin rằng trẻ em đã dùng app để gửi ảnh hoặc dữ liệu cá nhân và muốn xoá, hãy liên hệ maytinhbentre.com@gmail.com, chúng tôi sẽ phản hồi trong vòng 30 ngày.
Ứng dụng có thể gửi ảnh (khi đồng ý), UUID và nhãn thiết bị đến các bên xử lý AI ở nước khác. Chúng tôi dựa vào hợp đồng với bên xử lý có điều khoản bảo vệ dữ liệu chuẩn; không chuyển thêm ngoài những gì cần để thực hiện yêu cầu. Dữ liệu local (thẻ đã lưu, cài đặt) không bao giờ rời thiết bị.
Chúng tôi thực hiện các bước hợp lý để bảo vệ dữ liệu hạn chế mà ứng dụng xử lý:
X-Quota-Daily-Used / X-Quota-Daily-Limit) giới hạn số yêu cầu AI mỗi UUID trong ngày.Không biện pháp bảo mật nào tuyệt đối. Nếu bạn phát hiện lỗ hổng, hãy email maytinhbentre.com@gmail.com kèm chi tiết.
Chúng tôi có thể cập nhật chính sách này khi ứng dụng, pháp luật hoặc bên xử lý thứ ba thay đổi. “Effective date” ở đầu luôn phản ánh phiên bản hiện tại. Thay đổi quan trọng sẽ được thông báo trong màn hình Cài đặt của ứng dụng ít nhất 14 ngày trước khi có hiệu lực. Tiếp tục sử dụng ứng dụng sau ngày có hiệu lực đồng nghĩa với chấp nhận.
Cho câu hỏi quyền riêng tư, yêu cầu xoá hoặc báo lỗ hổng: