CardRavenBack to sign in

Privacy and data

How CardRaven handles your data

This notice is for the CardRaven friend beta. It describes the app as it works today, not a future marketplace or photo-upload service.

What is stored with your account

After you sign in, CardRaven stores your account identity, inventory, saved challenges, and the timestamps needed to keep those records working. These account-owned records are stored in Supabase and are separated by account.

We also keep limited, privacy-safe product events for reliability and beta learning. Search text is not kept as an indefinite event history.

What stays in your browser

Camera and image-assisted matching runs in your browser. A photo you choose is not sent to CardRaven’s server for matching. Local text reading and image comparison use the selected photo on your device.

Evaluation-photo capture is off by default. If you turn on Contribute evaluation examples in account settings, each future exact photo confirmation may save a compressed labeled photo and learned match association in this browser only. Turning it off stops future capture without deleting existing examples. You can export or delete that local dataset from the image-assisted search screen. Clearing browser storage can also remove it.

Other services we use

CardRaven requests catalog information and reference card images from TCGdex so it can search and identify cards. It sends catalog search terms, not your selected card photo. Supabase provides authentication and account-data storage.

Retention and deletion

Your account-owned server data stays with your account until deletion completes. Choosing Delete account while signed in permanently removes the authentication identity, active sessions, beta enrollment, collection lists, inventory, saved challenges and requirements, account preferences, administrative access if applicable, collection revision state, and account-linked product events. This cannot be undone.

Browser-local labeled photos and learned match examples are separate from account data. They remain in each browser where you saved them until you delete them from the image-assisted search controls or clear CardRaven site data.

Short-lived abuse-prevention counters contain only one-way hashes and expiration times, not account content. They stop affecting requests no later than one hour after creation. After that, a stale hash may remain until a later rate-limited request runs cleanup; it cannot restore an account or reveal account content.

Your choices

You can avoid image-assisted search and use manual catalog search instead. You can sign out at any time. For a deletion problem or a privacy question, use Support.