Privacy Policy
Last updated: [DATE]
This is a drafting template, not legal advice. It accurately describes what this app's code actually does with data as of this writing, but it hasn't been reviewed by a licensed attorney or privacy professional. If you serve users in the EU/UK, you likely need a GDPR-compliant legal basis analysis and possibly a Data Processing Agreement with each processor below; California residents have CCPA rights that may need their own dedicated disclosures. Fill in every bracketed item and get this reviewed before relying on it.
This Privacy Policy explains what information Cashd ("we", "us") collects, how we use it, and who we share it with. See also our Terms of Service.
1. Information We Collect
You can use Cashd's scan, pricing, and listing-builder features without an account or providing any personal information. We only collect the following:
- Account information — if you sign in, your name, email address, and profile photo as provided by Google (via Supabase Auth). We don't receive or store your Google password.
- Item photos and details — photos you capture or upload, and the category, brand, condition, price, and other details you enter, are stored so your saved items persist across visits/devices once you're signed in.
- Usage data — standard technical logs (e.g. IP address, browser type, pages visited) collected automatically by our hosting provider.
2. How We Use It
- To operate the Service — authenticate you, save and display your items;
- To generate item recognition, pricing estimates, and listing drafts (see §3 — this involves sending data to third-party providers);
- To maintain and improve the Service, including diagnosing errors.
We do not sell your personal information.
3. Third-Party Service Providers
To provide the Service, we share data with the following processors. Each operates under its own privacy policy, linked below.
- Supabase — authentication, database, and photo storage. Handles your account info and saved items. Privacy policy.
- Google — sign-in (via Supabase Auth, using Google OAuth). Privacy policy.
- OpenRouter, and the underlying AI model it routes your request to (currently Google's Gemini) — receives the photo(s) you scan (including any optional tag/label photo) to identify the item, and receives item category/brand/condition text to generate a price estimate when no real market-data source applies. OpenRouter privacy policy.
- KicksDB, eBay, Scryfall, and pokemontcg.io — receive item category/brand/model text (never your photos) to look up real market pricing data for shoes, general items, and trading cards respectively.
None of these providers receive your name, email, or any other account information unless you are signed in and it's inherent to the request (e.g. Supabase necessarily associates saved items with your account).
4. Cookies & Local Storage
We use an essential session cookie (via Supabase Auth) to keep you signed in. If you start scanning an item as a guest and are asked to sign in before saving it, your in-progress scan is held temporarily in your browser's session storage — this never leaves your device and is cleared automatically once you're back in the app. We don't use advertising or cross-site tracking cookies.
5. Data Retention
We retain your account and saved items for as long as your account is active. You can delete individual items at any time; to delete your entire account and associated data, contact [Contact Email].
6. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, or to object to or restrict certain processing.
- EEA/UK residents (GDPR): [state your legal basis for processing per category of data — e.g. contract necessity for account data, legitimate interest for usage logs — and name an EU representative/DPO if required].
- California residents (CCPA/CPRA): [add the specific disclosures CCPA requires — categories of personal information collected/sold/shared in the last 12 months, and how to submit a Do-Not-Sell/Share or deletion request].
To exercise any of these rights, contact us at [Contact Email].
7. Children's Privacy
The Service is not directed to children under [13/16], and we do not knowingly collect personal information from them.
8. Data Security
We use reasonable technical and organizational measures to protect your information, but no method of transmission or storage is 100% secure, and we can't guarantee absolute security.
9. International Users
Your information may be processed in the United States or other countries where our service providers operate, which may have different data-protection laws than your own. [If you have EU/UK users, add your transfer mechanism here — e.g. Standard Contractual Clauses with each processor.]
10. Changes to This Policy
We may update this policy from time to time; the "Last updated" date above will change accordingly.
11. Contact
Questions about this policy or your data? Contact [Contact Email].