Legal
Privacy Policy
This policy explains what PewPewScan (“the app”, “we”, “us”) collects when you scan and catalog your cards, why we collect it, and who else sees it. It covers the PewPewScan iOS app and this website.
The short version
- No account, ever. No name, no email, no password. The app identifies your device by a random ID, not by you.
- Your collection stays on your iPhone. Cards, photos and values are stored locally on the device — we do not hold a copy of your collection.
- Card photos pass through, they don’t stay. A scan is sent to our server and on to our recognition provider to identify the card, and is not retained on our servers afterwards.
- We don’t sell your personal information and we never receive your payment details — Apple processes every purchase.
1. What we collect
1.1 Card photos and scan images
When you scan, the app takes photos of your cards with the camera. Each new card’s image is sent to our server, which forwards it to our card‑recognition provider so the card can be identified. The image is processed to return the card’s identity, set, year, parallel and estimated value — and is not stored on our servers after the request completes. The copy kept in your catalog lives on your device.
Card images normally show the card itself. Anything else that happens to be in frame — your table, your hands — travels with the image, so keep unrelated personal material out of the shot.
1.2 Your catalog
Cards, copies, quantities, folders, notes, prices and the photos attached to them are stored in the app’s local database on your iPhone. They are included in your device backup if you back up your iPhone (to iCloud or to a computer) — that backup is controlled by Apple and by you, not by us.
1.3 Anonymous device identifier
On first launch the app generates a random UUID and stores it in the device Keychain. It is not your Apple ID, not the advertising identifier, and is not linked to your name or email. We use it to count your free scans, to attach your subscription entitlement, and to prevent abuse of our recognition quota. It is sent with every request to our server.
1.4 Subscription and purchase data
Purchases are made through Apple’s In‑App Purchase system. We never see or receive your card number, billing address or Apple ID. What we do receive and store is the signed transaction information Apple issues — product identifier, transaction identifier, purchase and expiry dates, and subscription status — linked to the anonymous device identifier so the app knows your plan is active.
1.5 Usage and analytics data
The app uses Google Firebase Analytics to understand how the product is used in aggregate. Events we send describe app activity, not card content: onboarding steps completed and the two onboarding answers (which sport you collect, roughly how large your collection is), camera‑permission outcome, scan sessions started and finished with counts of cards added, first successful recognition, free‑limit reached, paywall shown, and purchase started / completed / failed / restored.
Firebase additionally collects a standard set of data on its own: an app‑instance identifier, device model, operating‑system version, app version, language, country and region derived from IP address, and session activity. We do not send card images, card identities, collection contents or values to analytics.
1.6 Advertising identifier (only if you allow it)
On the last onboarding screen iOS asks whether you allow tracking. If — and only if — you allow it, Apple’s advertising identifier (IDFA) may be used to measure the performance of our advertising campaigns. If you decline, no IDFA is accessed and no cross‑app or cross‑site tracking takes place. You can change this at any time in Settings → Privacy & Security → Tracking.
1.7 Technical and log data
Our server records the technical facts of each request: IP address, timestamp, endpoint, response status, and the outcome of a recognition (matched / low confidence / no match). IP addresses are used for rate limiting, abuse prevention and debugging, and are handled by our infrastructure provider (Cloudflare).
2. What we don’t collect
- No name, email address, phone number or password — the app has no sign‑up.
- No access to your photo library, contacts, calendar, microphone or health data.
- No precise location. Firebase derives an approximate country/region from IP; we do not use GPS.
- No payment card details — those stay with Apple.
- No copy of your collection on our servers.
3. How we use it
| What | Why | Legal basis (EEA/UK) |
|---|---|---|
| Card images | Identify the card and return its data to your device | Performance of a contract |
| Anonymous device ID | Free‑scan quota, subscription entitlement, abuse prevention | Performance of a contract; legitimate interests |
| Purchase data | Unlock and maintain your subscription, support requests | Performance of a contract; legal obligation (tax/records, via Apple) |
| Analytics events | See which flows work, fix drop‑offs, improve scanning | Consent where required; otherwise legitimate interests |
| Advertising identifier | Measure ad campaign performance | Consent (ATT prompt) |
| IP address and logs | Rate limiting, security, debugging | Legitimate interests |
We do not use your data for automated decision‑making with legal effects, and we do not build advertising profiles about you.
4. Permissions the app asks for
Camera — required. Scanning is the app’s core function; without camera access the app cannot read cards. You can revoke it in Settings → PewPewScan.
Tracking (ATT) — optional. Asked once at the end of onboarding, for ad‑campaign measurement. Declining changes nothing about how the app works.
The app does not request photo‑library, location, contacts or microphone access.
6. How long we keep it
- Card images: processed in transit and not retained on our servers after the recognition request completes.
- Anonymous device ID, scan ledger, subscription records: for as long as the identifier is in use, and afterwards for as long as needed to prevent quota abuse and to keep our accounting consistent.
- Server logs: short‑term, for security and debugging.
- Analytics: per Google Firebase retention settings — event data is retained no longer than 14 months.
- Your catalog: kept on your device until you delete the cards or delete the app.
7. Security
All traffic between the app, our server and our providers uses TLS. The device identifier is stored in the iOS Keychain. Our API is protected by rate limiting and an application secret, and access to production data is restricted. No system is perfectly secure, but keeping your collection on your device — rather than in our cloud — deliberately reduces what a breach of our servers could expose.
8. Where data is processed
The app is offered in the United States and our processing takes place primarily in the United States, on globally distributed infrastructure. If you use the app from the EEA, the UK or Switzerland, data reaching our processors may be transferred outside your country; those transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent safeguard offered by the processor.
9. Your choices
- Turn off tracking: Settings → Privacy & Security → Tracking, or reset your advertising identifier there.
- Turn off camera access: Settings → PewPewScan → Camera. Scanning stops working; your existing catalog stays.
- Delete everything local: deleting the app removes the catalog, the photos and the device identifier from your iPhone. This cannot be undone — there is no cloud copy to restore from.
- Delete server‑side records: send a privacy request from our support page and we will delete the records tied to your device identifier. Note that this also releases your free‑scan counter, so we may decline repeated requests that are used to reset the free tier.
- Manage your subscription: Settings → [your name] → Subscriptions on your iPhone.
10. Your privacy rights
EEA, UK and Switzerland. You have the right to access, correct, delete, restrict or object to processing, and to data portability, plus the right to withdraw consent and to lodge a complaint with your supervisory authority. Because we hold no name or email, we identify your records solely by the device identifier — include it when you write to us (it is shown in the app’s Settings screen).
California. In the last 12 months we have collected the categories described in section 1: identifiers (anonymous device ID, IP address, and — with your permission — the advertising identifier), commercial information (subscription status), internet activity (app usage events), and visual information (card images, processed in transit). We do not sell personal information. If you allow tracking, use of the advertising identifier for ad measurement may qualify as “sharing” for cross‑context behavioral advertising under the CPRA — declining the ATT prompt is the opt‑out, and there is nothing to share if you decline. You have rights to know, delete, correct and to non‑discrimination; exercise them by writing to us.
We answer verified requests within the timeframe the applicable law requires — 30 days (GDPR) or 45 days (CCPA), extendable where the law allows.
11. Children
PewPewScan is not directed to children under 13 (or under 16 in the EEA, where local law sets that age), and we do not knowingly collect their personal information. Card collecting is a hobby families share — if a child uses the app on a parent’s device and you believe we hold data about them, write to us and we will delete it.
12. This website
This site uses Google Analytics to count visits and understand which pages people read. It sets cookies and processes an IP‑derived approximate location. You can block it with a browser setting, a content blocker, or Google’s opt‑out add‑on. The site loads the Figtree webfont from Google Fonts, which means Google receives your IP address when the font is fetched. The site has no login, no forms and no advertising pixels.
13. Changes to this policy
If we change how we handle data — for example if we ever begin storing card images to train our own recognition model, or add iCloud sync for your collection — we will update this page and the “last updated” date, and give notice in the app before the change takes effect where the change is material. Continuing to use the app after that means you accept the updated policy.
14. Contact
Questions, requests or complaints about privacy: support@pewpewscan.com, or use the form on our support page.
PewPewScan · Privacy Policy · Version 1.0