HitLegend Privacy Policy
Draft for counsel review — not yet in force. Effective date: [to be set]. Controller: Unobstructed, LLC, [address], support@hitlegend.com.
1. In one paragraph
You give us your email, a password or a sign-in from Google, Microsoft or Apple, and photos of your cards. We use the photos to identify the cards, we store your collection, and we estimate values from market data. We do not sell your data or show you ads. We use a handful of service providers to run the product, named below. You can export or delete everything at any time.
2. What we collect and why
| Data | Why | Legal basis (where applicable) |
|---|---|---|
| Email, name, password hash, or a provider identity (Google/Microsoft/Apple subject id) | your account and sign-in | contract |
| Photos of cards you upload or capture (pages, crops, backs) | identifying and filing your cards; the record of your collection | contract |
| Card records: what you own, condition, grade, cert number, notes, tags, binders, lists, values | the product | contract |
| Device identifier, app version, platform | sessions per device, compatibility, security | contract, legitimate interest |
| Usage events (which features are used; no content) | improving the product; measuring reliability | legitimate interest |
| Questions you type into the natural-language box | understanding what collectors ask so we can answer more; reviewed only by our operators | legitimate interest |
| Crash and error reports (device model, OS, app version, stack trace) | stability | legitimate interest |
| Payment details | billing — held by Stripe or Apple, never by us; we store the subscription status and a customer id | contract |
| Support emails | helping you | contract |
We do not collect precise location, contacts, health data or advertising identifiers. We do not use tracking for advertising.
3. How photos are processed
Card photos are stored privately (no public URL, ever) and read by automated systems: our own detection, a machine-reading provider (OpenAI), and a card-identification provider (CardSight) that receives the crop of a card to identify it. These providers process the image to return an answer; our agreements do not permit them to use your images to train their models. Catalogue artwork shown beside your photo comes from TCGdex and is not your data.
4. Who we share with (processors)
Vercel (hosting), Neon (database), Cloudflare R2 (photo storage), OpenAI and Anthropic (card reading and text drafting), CardSight (card identification), JustTCG and sales-data providers (market prices — receive card identifiers, never your identity), Stripe (payments), Apple (App Store purchases and Sign in with Apple), Google and Microsoft (sign-in, if you choose them), Resend (email), Sentry (crash reports). Each processes data on our instructions under a data-processing agreement. We share data with authorities only when legally required, and with a successor if Unobstructed is acquired (you will be told).
5. International transfers
Our providers operate in the United States; if you are outside the U.S., your data is transferred there. Where EU/UK law applies we rely on standard contractual clauses with our processors.
6. Retention
Your account data lives as long as your account. A deleted card's photos are kept 30 days (so a mistake can be undone) and then removed. Scan records are hidden from you when you clear them and kept as the audit of how a card was identified until the account is deleted. Usage events and typed questions are kept 13 months, then anonymised. When you delete your account we remove your shelves, cards, photos, scans, tokens and identities; we keep an anonymised record of sales you logged (no identity, no photos) for tax and accounting, and invoices as the law requires.
7. Your rights and controls
- **Export**: Settings → Download shelf export gives you everything in one file, any time.
- **Correction**: every card is editable; identifications and facets can be corrected in the product.
- **Deletion**: Settings (web) or Profile (app) → Delete my account. It is immediate and not reversible.
- **Access, restriction, objection, portability** (GDPR/UK GDPR), **know / delete / correct / opt out of sale** (CCPA/CPRA — we do not sell): write to privacy@hitlegend.com. We answer within 30 days (45 under CPRA). You may complain to your supervisory authority.
- **Email**: transactional messages (verification, reset, receipts, alerts you turned on) are part of the Service; there is no marketing list yet, and any future one will be opt-in.
8. Children
HitLegend is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has an account, tell us and we will delete it.
9. Security
TLS everywhere; passwords hashed with bcrypt; photos in private storage reached only through short-lived signed URLs; tenant isolation enforced on the server; secrets never in client apps; access logged. No system is perfectly secure; if a breach affects you we will tell you as the law requires.
10. Changes
We will post changes here and, for material changes, tell you in the product or by email at least 14 days in advance.
11. Contact
privacy@hitlegend.com · Unobstructed, LLC, [postal address].