CardScan AI — Privacy Policy

Effective date: 29 July 2026

Last updated: 29 July 2026 (v1.0.4 release)

Contact: maytinhbentre.com@gmail.com

English Tiếng Việt

At-a-glance

Before Google Play submission: host this exact file at a public, non-PDF HTTPS URL and paste that address into the Play Console Data safety section. This local copy is not a valid Play Console policy URL. The file is a self-contained static document — no tracking, no JavaScript, no third-party requests.

English version

This is the authoritative English-language version. The Vietnamese translation is provided for convenience; in case of any conflict the English version controls.

1. What the app does

CardScan AI (the app) is a mobile utility for trading-card collectors. It performs three things, all of which you can use or skip independently:

  1. Card identification — given a photo of a trading card, the app returns the game (Pokémon, Yu-Gi-Oh!, or One Piece), the card name, set, rarity, language, year, and the card’s primary print identifier.
  2. Live price lookup — for an identified card, the app queries public pricing APIs (Tcgdex, TCGplayer via PokemonTCG, YGOPRODeck) and returns recent market prices.
  3. Reference-only AI condition grading — given a front and back photo, the app returns PSA-style sub-scores (centering, corners, edges, surface) and a short AI note. The result is a reference estimate only, not a professional authentication.

The app also stores the cards you choose to save, displays daily price-change history for Pro users, and includes an optional in-app shop that opens the webthebai.com checkout in an embedded WebView.

2. Images and AI processing

2.1 Consent before upload

Before any AI Scan or AI Grade request, the app displays a consent screen and only proceeds after you tap Allow. You can revoke this consent at any time in Settings → AI image upload; the toggle persists on the device until you turn it back on.

2.2 What is sent

With your consent:

Images are transmitted over HTTPS to our gateway and forwarded to one or more third-party AI processors. We do not include any metadata identifying the user, the device, or the location beyond what the network layer necessarily reveals.

2.3 What our gateway does with images

Our gateway:

The gateway does not retain raw image payloads. Images live only in transient processing memory for the duration of one request, after which they are released.

2.4 What downstream AI processors may do

Downstream AI processors operate under their own contracts and policies. We cannot make retention, training, or secondary-use claims for those processors beyond what is documented in their respective terms. If you do not want your image sent to a third-party AI processor, leave the AI upload consent turned off — the app will continue to work for browsing and editing saved cards.

3. AI consent and your control

SettingWhereWhat it controls
AI image upload (on/off)Settings → AI image uploadBlocks every AI Scan/Grade request. Free-tier features (browsing, editing saved cards) still work.
Delete saved cardCollection → tap trash iconRemoves the card record, local image, and any price snapshots from your device.
Delete saved gradeCollection → tap trash iconRemoves the grade record and the front/back photos from your device.
Clear Android app dataSystem Settings → Apps → CardScan AI → Storage → Clear dataRemoves every local file, every preference, and your consent toggle. The next launch behaves as a fresh install.
UninstallSystem Settings → Apps → CardScan AI → UninstallRemoves the app and all of its local data. Future installs start from scratch.

4. Identifiers and network data

4.1 What our gateway receives on every request

4.2 What the app does NOT use

5. In-app purchases (Pro subscription)

Payment is handled entirely by Google Play. Our app never sees your card number, billing address, or CVC. The flow is:

  1. You tap Upgrade; the app calls Google Play Billing.
  2. Google Play shows the official purchase dialog and charges your saved payment method.
  3. Google Play returns a purchase token + product ID to the app.
  4. The app sends the token + product ID to our gateway, which verifies with Google that the purchase is real.
  5. The gateway flips your Pro entitlement in memory; the app re-reads it on next launch.

Stored on the gateway only for the duration of the verification round-trip; we do not maintain a long-term record of your purchase history.

You can cancel, pause, or resume the subscription at any time in Play Store → Subscriptions.

6. Saved collection & shop data

6.1 Saved cards and grades

When you save a card or a grade result, the app writes the relevant record (image, prices, notes) to a private folder under the app’s internal storage (filesDir/collection/...). This data is only on your device; it is not synced to our servers.

6.2 Price snapshots (Pro)

For Pro users, the app records a daily price snapshot locally to support the price-history chart. Snapshots are tied to your local card record and are deleted when you delete the card.

6.3 Shop WebView

The optional Shop tab opens the webthebai.com checkout in an embedded WebView. When you reach the checkout page, the shop’s own privacy policy applies to the data you submit (shipping address, payment details handled by the shop’s payment processor). Our app does not relay or store that data.

7. Data retention

DataWhere it livesRetentionHow to delete
Random in-app UUIDLocal DataStoreUntil you uninstall or clear app dataUninstall / clear data
AI Scan / Grade imagesTransient (gateway processing only)Released after one request — not retained(automatic; nothing to delete)
Public price API query (card identity only)Public API endpoints (Tcgdex, YGOPRODeck, etc.)Subject to those providers’ policiesSee each provider’ site
Server-side IPGateway access logsShort-lived (operational logs only)Expired automatically per gateway retention policy
Google Play purchase tokenGateway verification stepHours, then discarded(automatic)
Saved card / grade images + recordsLocal filesDir/collection/...Until you delete them or uninstallApp → Collection → trash icon / Clear data / Uninstall
Price snapshots (Pro)Local Room databaseUntil the parent card is deletedDelete parent card

8. Your rights and choices

You can at any time:

We respond to deletion requests within 30 days.

9. Children’s privacy

CardScan AI is not directed at children under 13. The app does not knowingly collect personal information from children. If you believe a child has used the app to submit images or other personal data and you would like it removed, contact us at maytinhbentre.com@gmail.com and we will respond within 30 days.

10. International transfers

The app may send your image (with consent), UUID, and device label to AI processors located in countries other than your own. We rely on processor contracts that include standard data-protection terms; we do not perform additional transfers beyond what is needed to fulfill the request. Local data (saved cards, preferences) never leaves your device.

11. Security

We take reasonable steps to protect the limited data the app processes:

No security measure is absolute. If you discover a vulnerability, please email maytinhbentre.com@gmail.com with details.

12. Changes to this policy

We may update this policy to reflect changes in the app, the law, or third-party processors. The “Effective date” at the top will always reflect the current version. Material changes will be announced in the app’s Settings screen for at least 14 days before they take effect. Continued use of the app after the effective date constitutes acceptance.

13. Contact us

For privacy questions, deletion requests, or vulnerability reports:

Bản Tiếng Việt

Bản tiếng Anh phía trên là bản chính thức. Bản tiếng Việt dưới đây chỉ để tham khảo; trong trường hợp có xung đột, bản tiếng Anh sẽ được ưu tiên.

1. Ứng dụng làm gì

CardScan AI (ứng dụng) là tiện ích di động cho người sưu tầm thẻ bài. Ứng dụng làm ba việc, bạn có thể dùng hoặc bỏ qua độc lập:

  1. Nhận diện thẻ — với ảnh chụp thẻ, ứng dụng trả về game (Pokémon, Yu-Gi-Oh!, One Piece), tên thẻ, set, độ hiếm, ngôn ngữ, năm và mã in chính.
  2. Tra giá — với thẻ đã nhận diện, ứng dụng gọi API giá công khai (Tcgdex, TCGplayer qua PokemonTCG, YGOPRODeck) và trả về giá thị trường gần đây.
  3. Chấm điểm AI tham khảo — với ảnh mặt trước và sau, ứng dụng trả về các điểm phụ theo phong cách PSA (centering, corners, edges, surface) và ghi chú ngắn từ AI. Kết quả chỉ để tham khảo, không phải chấm điểm chuyên nghiệp.

Ngoài ra ứng dụng còn lưu các thẻ bạn chọn giữ, hiển thị lịch sử giá hàng ngày cho người dùng Pro, và có shop trong ứng dụng mở checkout của webthebai.com trong WebView.

2. Ảnh và xử lý AI

2.1 Đồng ý trước khi upload

Trước mỗi yêu cầu AI Scan hoặc AI Grade, ứng dụng hiện màn hình xin phép và chỉ tiếp tục khi bạn nhấn Cho phép. Bạn có thể thu hồi đồng ý bất cứ lúc nào trong Cài đặt → AI image upload; cài đặt này lưu trên thiết bị cho đến khi bạn bật lại.

2.2 Cái gì được gửi

Khi bạn đồng ý:

Ảnh được truyền qua HTTPS đến cổng dịch vụ và chuyển tiếp cho một hoặc nhiều bên xử lý AI bên thứ ba. Chúng tôi không gắn kèm metadata nào nhận diện người dùng, thiết bị hay vị trí ngoài những gì tầng mạng bắt buộc phải tiết lộ.

2.3 Cổng xử lý ảnh thế nào

Cổng:

Cổng không lưu giữ payload ảnh gốc. Ảnh chỉ tồn tại trong bộ nhớ xử lý tạm thời trong thời gian một yêu cầu, sau đó được giải phóng.

2.4 Bên xử lý AI có thể làm gì

Các bên xử lý AI hoạt động theo hợp đồng và chính sách riêng. Chúng tôi không thể đảm bảo về việc lưu giữ, huấn luyện hay sử dụng phụ của họ ngoài những gì được ghi trong điều khoản tương ứng. Nếu bạn không muốn ảnh của mình gửi đến bên xử lý AI thứ ba, hãy tắt đồng ý upload AI — ứng dụng vẫn dùng được cho việc xem và sửa bộ sưu tập đã lưu.

3. Đồng ý AI và quyền kiểm soát

Cài đặtỞ đâuQuản lý gì
Upload ảnh AI (bật/tắt)Cài đặt → AI image uploadChặn mọi yêu cầu AI Scan/Grade. Tính năng Free (xem, sửa thẻ đã lưu) vẫn dùng được.
Xoá thẻ đã lưuBộ sưu tập → nhấn biểu tượng thùng rácXoá bản ghi thẻ, ảnh local và mọi snapshot giá trên thiết bị.
Xoá kết quả giám địnhBộ sưu tập → nhấn biểu tượng thùng rácXoá bản ghi giám định và ảnh mặt trước/sau trên thiết bị.

4. Định danh và dữ liệu mạng

4.1 Cổng nhận gì trong mỗi yêu cầu

4.2 Ứng dụng KHÔNG dùng gì

5. Mua hàng trong ứng dụng (Pro subscription)

Thanh toán do Google Play xử lý hoàn toàn. Ứng dụng không bao giờ thấy số thẻ, địa chỉ thanh toán hay CVC của bạn. Quy trình:

  1. Bạn nhấn Nâng cấp; ứng dụng gọi Google Play Billing.
  2. Google Play hiển thị dialog mua hàng chính thức và charge phương thức thanh toán đã lưu.
  3. Google Play trả về purchase token + product ID cho ứng dụng.
  4. Ứng dụng gửi token + product ID đến cổng, cổng xác minh với Google rằng giao dịch là thật.
  5. Cổng bật quyền Pro trong bộ nhớ; ứng dụng đọc lại khi mở lần sau.

Lưu trên cổng chỉ trong thời gian verify; chúng tôi không giữ lịch sử mua hàng dài hạn. Bạn có thể huỷ, tạm dừng hoặc tiếp tục subscription bất cứ lúc nào trong Play Store → Subscriptions.

6. Bộ sưu tập đã lưu & dữ liệu shop

6.1 Thẻ và kết quả giám định đã lưu

Khi bạn lưu thẻ hoặc kết quả giám định, ứng dụng ghi bản ghi (ảnh, giá, ghi chú) vào thư mục riêng trong bộ nhớ trong của ứng dụng (filesDir/collection/...). Dữ liệu này chỉ ở trên thiết bị; không đồng bộ lên server.

6.2 Snapshot giá (Pro)

Với người dùng Pro, ứng dụng ghi lại snapshot giá hàng ngày ở local để hỗ trợ biểu đồ lịch sử giá. Snapshot gắn với thẻ local và tự xoá khi thẻ cha bị xoá.

6.3 Shop WebView

Tab Shop mở checkout webthebai.com trong WebView nhúng. Khi đến trang checkout, chính sách riêng của shop áp dụng cho dữ liệu bạn submit (địa chỉ ship, chi tiết thanh toán do bộ xử lý thanh toán của shop). Ứng dụng không chuyển tiếp hay lưu dữ liệu đó.

7. Lưu giữ dữ liệu

Dữ liệuỞ đâuLưu giữCách xoá
UUID trong appLocal DataStoreĐến khi bạn gỡ app hoặc clear app dataGỡ app / clear data
Ảnh AI Scan / GradeTạm thời (chỉ trong cổng xử lý)Giải phóng sau một yêu cầu — không lưu(tự động; không có gì để xoá)
Query API giá công khai (chỉ định danh thẻ)Endpoint công khai (Tcgdex, YGOPRODeck, ...)Theo chính sách của providerXem site của từng provider
IP phía serverLog truy cập cổngNgắn hạn (chỉ log vận hành)Tự hết hạn theo chính sách retention của cổng
Token mua hàng Google PlayBước verify cổngVài giờ, rồi huỷ(tự động)
Ảnh thẻ/giám định đã lưu + bản ghiLocal filesDir/collection/...Đến khi bạn xoá hoặc gỡ appApp → Bộ sưu tập → thùng rác / Clear data / Gỡ app
Snapshot giá (Pro)Local Room databaseĐến khi thẻ cha bị xoáXoá thẻ cha

8. Quyền và lựa chọn của bạn

Bạn có thể bất cứ lúc nào:

Chúng tôi phản hồi yêu cầu xoá trong vòng 30 ngày.

9. Quyền riêng tư của trẻ em

CardScan AI không hướng đến trẻ em dưới 13 tuổi. Ứng dụng không cố ý thu thập thông tin cá nhân từ trẻ em. Nếu bạn tin rằng trẻ em đã dùng app để gửi ảnh hoặc dữ liệu cá nhân và muốn xoá, hãy liên hệ maytinhbentre.com@gmail.com, chúng tôi sẽ phản hồi trong vòng 30 ngày.

10. Chuyển dữ liệu quốc tế

Ứng dụng có thể gửi ảnh (khi đồng ý), UUID và nhãn thiết bị đến các bên xử lý AI ở nước khác. Chúng tôi dựa vào hợp đồng với bên xử lý có điều khoản bảo vệ dữ liệu chuẩn; không chuyển thêm ngoài những gì cần để thực hiện yêu cầu. Dữ liệu local (thẻ đã lưu, cài đặt) không bao giờ rời thiết bị.

11. Bảo mật

Chúng tôi thực hiện các bước hợp lý để bảo vệ dữ liệu hạn chế mà ứng dụng xử lý:

Không biện pháp bảo mật nào tuyệt đối. Nếu bạn phát hiện lỗ hổng, hãy email maytinhbentre.com@gmail.com kèm chi tiết.

12. Thay đổi chính sách

Chúng tôi có thể cập nhật chính sách này khi ứng dụng, pháp luật hoặc bên xử lý thứ ba thay đổi. “Effective date” ở đầu luôn phản ánh phiên bản hiện tại. Thay đổi quan trọng sẽ được thông báo trong màn hình Cài đặt của ứng dụng ít nhất 14 ngày trước khi có hiệu lực. Tiếp tục sử dụng ứng dụng sau ngày có hiệu lực đồng nghĩa với chấp nhận.

13. Liên hệ

Cho câu hỏi quyền riêng tư, yêu cầu xoá hoặc báo lỗ hổng: