Legal document

Privacy Policy

Last updated: 7 September 2026

1. Who we are

SetChase ("SetChase", "we", "us", "our") is a mobile application published by Daniel Moradkhani, a private individual resident in Sweden, who is the data controller for personal information processed through the app. Contact details are in Section 18 (Contact us).

This Privacy Policy explains how we collect, use, store, share and protect your personal information when you use SetChase. If you do not agree with it, please do not use the app.

2. Summary

What we collect: the account details you give us (an email address, or your Apple or Google sign-in), your collector profile (handle, display name, a chosen avatar), the cards and sealed products you add to your collection and want list, price alerts, photographs you take to identify or grade a card, your friends list, and basic device and diagnostic data.

What we do not collect: payment card details (Apple and Google handle those), precise location, your contacts, or photos you have not deliberately taken inside the app.

Why: to run the app, identify and grade cards, track values, notify you, keep the service secure, and comply with the law.

Who we share with: the processors that run the service (Supabase for hosting and sign-in, Google Gemini for card recognition and grading, Scrydex for card data and prices, Apple and Google for purchases, RevenueCat for subscription state, Expo, Apple and Google for push notifications, PostHog for product analytics, Sentry for crash reports). We never sell your data.

Your controls: a switch for usage and crash reports in Settings, a sharing switch for what friends can see, account deletion in Settings, and the rights listed in Section 12.

3. Information we collect

3.1 Account information

Your account. SetChase needs an account. We store your email address and a password (hashed, never readable by us) if you sign up with email, or the identifier and email address Apple or Google provides when you use Sign in with Apple or Google. We never see your Apple or Google password.

Profile. A handle, a display name, one of the app's preset avatars, and your collection-sharing preference.

3.2 Collection data

The cards and sealed products you add, their quantity, condition, finish, grading company and grade if you record them, your portfolios and their names, your want list, price alerts you set and the history of alerts that fired, and the value history the app computes for your collection. Trade and deal checks are kept on your device only. Export files are generated on your device and go wherever you send them.

3.3 Photographs and scans

Scanning. When you scan a card, a sealed product or a binder page, the camera frame is sent to our server and on to Google Gemini to identify what is in it. Scan frames are not stored after the answer is returned.

Grading. When you use AI grading, the front and back photographs you take are uploaded to a private storage area on our servers, tied to your account, and sent to Google Gemini for analysis. The photographs stay with your report until you delete your account, when they are removed together with everything else.

3.4 Friends

If you add friends: the handles you search for, the requests you send and receive, your friends list, and anyone you block. What a friend can see is described in Section 13.

3.5 Purchase information

If you buy SetChase Pro, Apple or Google processes the payment. We receive the plan you bought, purchase and renewal dates, and subscription status, through RevenueCat. We never receive your card number or bank details.

3.6 Device, usage and diagnostic data

Device model and operating system version, app version, language and time zone, your account identifier (a random id), which screens and features you use, crash reports and error logs. Your IP address is visible to our servers when the app talks to them and is kept in server logs for a short period for security and rate limiting. We do not use GPS or precise location.

3.7 Communications

If you write to us, the content of your message and the details needed to help you.

3.8 What we do not collect

Sensitive personal data (health, religion, sexuality, biometrics), payment card numbers, precise location, contacts, calendar, or any photo on your device other than the ones you take inside the app.

4. How we use your information

  • To run the app: create and restore your account, sync your collection between devices, identify cards from your photographs, produce grading estimates, show prices and value history, fire price alerts, and deliver notifications.
  • Friends: show your handle, display name, avatar and, if you allow it, a summary of your collection to friends you have accepted.
  • To communicate: service notices, replies to support requests, and notices of changes to these terms.
  • To improve the app: understand which features are used, find and fix crashes and bugs. You can switch this off in Settings (Section 16).
  • To keep the service safe: rate limiting, abuse and fraud detection, enforcing our terms.
  • To comply with the law: tax and accounting records, lawful requests from authorities.

We do not use your photographs or data to train AI models, we do not sell your data, and we do not share it with advertisers or data brokers.

5. Legal bases (GDPR)

PurposeLegal basis
Providing the app: account, sync, scanning, grading, prices, alerts, notifications you asked forPerformance of a contract, Art. 6(1)(b)
Product analytics and crash reportsLegitimate interests, Art. 6(1)(f), with an off switch in Settings
Security, rate limiting, abuse preventionLegitimate interests, Art. 6(1)(f)
Marketing messages, if we ever send anyConsent, Art. 6(1)(a)
Accounting and tax records, responding to authoritiesLegal obligation, Art. 6(1)(c)

You can withdraw consent at any time; withdrawal does not affect processing that has already happened or processing that rests on another basis.

6. Who we share your information with

We use the following processors. Each is bound by a data processing agreement.

ProcessorPurposeDataRegion
SupabaseDatabase, storage, sign-inAccount, profile, collection, photographs, push tokensEuropean Union (AWS, Paris)
Google (Gemini API and Google Cloud)Card recognition from scans; AI gradingScan frames; grading photographsGrading runs on Google Cloud in the EU (Belgium, europe-west1); the Gemini API is a Google service, see Section 7
ScrydexCard catalogue, prices and card imagesNone of your personal data; our requests carry no user identifiersUnited States
Apple App Store / Google PlayPurchases and subscription billingPurchase eventsPer Apple's and Google's policies
RevenueCatSubscription statePurchase events and your account idUnited States (Standard Contractual Clauses)
Expo push service, Apple Push Notification service, Firebase Cloud MessagingDelivering notificationsPush token, notification textUnited States (Standard Contractual Clauses)
PostHogProduct analyticsUsage events, device data, your account idEuropean Union (EU-hosted project)
SentryCrash reportsCrash stacks, device data, app version, your account idEuropean Union (EU data residency)

We may also disclose information where the law requires it, to protect the rights and safety of users or the public, or as part of a merger or sale of the business, in which case this policy continues to apply to your data.

7. AI processing

Card recognition and AI grading are performed by Google's Gemini models.

  • When you scan, the camera frame is sent to Gemini and the answer is returned to the app. The frame is not stored by us afterwards.
  • When you grade, your front and back photographs are analysed by Gemini and the result becomes your report.
  • Under Google's terms for the paid Gemini API, Google does not use these prompts, images or responses to improve its products. Google keeps prompts and responses for a limited time solely to detect abuse of its service, and processes them for EU users under its Data Processing Addendum.
  • AI grading is an estimate produced by software. It is not a professional grade, and it is not a statement about a card's authenticity or resale value.

8. Card images and catalogue content

Card images, names, set names and prices shown in the app come from our catalogue provider and are loaded from the provider's servers when a screen needs them. Card images and names belong to their respective rights holders (see the Terms of Service). Requests for these images carry no identifier that links them to you.

9. International transfers

Your data is stored in the European Union with Supabase and processed for grading in the EU; analytics and crash reports are hosted in the EU. Some processors are in the United States: RevenueCat, Expo's push service, and Google's Gemini API. For those transfers we rely on the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU-US Data Privacy Framework.

10. How long we keep it

DataRetention
Account, profile, collection, want list, alerts, friendsWhile your account exists; deleted when you delete your account
Grading photographs and reportsUntil you delete your account
Scan framesNot stored
Push tokensWhile the device is registered; removed when Apple or Google reports the device gone
Usage analyticsUp to 12 months, keyed by your account id
Crash reports90 days
Server logs including IP addressesUp to 30 days
Purchase records7 years after the last transaction (Swedish accounting law)
Support correspondence2 years after the last contact
BackupsUp to 30 days after deletion from live systems

Deleting your account (Settings › Delete account, or by email) removes your account and everything in the first row immediately from live systems.

11. Security

Data travels over TLS. Data is encrypted at rest by our hosting provider. Every database table is protected by row-level security so a user can only reach their own rows, and grading photographs sit in a private storage area with per-user rules. Server-side secrets never ship in the app. No system is perfectly secure; if a breach affects you we will notify you and the Swedish Authority for Privacy Protection (IMY) as GDPR requires.

12. Your rights

If you are in the EU, EEA, UK or Switzerland you have the right to access, correct, delete, restrict, port and object to the processing of your personal information, to withdraw consent, not to be subject to solely automated decisions with legal effect, and to complain to a supervisory authority. Write to setchaseofficial@gmail.com; we answer within 30 days. You may also complain to IMY at https://www.imy.se or to the authority in your country.

Automated processing in SetChase (card recognition, grading estimates, price alerts) does not produce legal or similarly significant effects; it is information you choose to act on.

If you live elsewhere, including in California or another US state with a privacy law, you can exercise the same rights by writing to us; we do not sell or share personal information for advertising, and we treat every request the same way regardless of where you live.

13. Friends and what they can see

  • Your handle is searchable by other users; that is how friends find each other.
  • A friend you have accepted can see your display name, avatar and, while "Friends can see my collection" is on, a summary of your collection: card counts, total value and your newest cards. Never what you paid, never your want list, alerts, grading photographs or reports.
  • You can turn sharing off, remove a friend or block a user at any time in Friends. Blocking hides you from that user and them from you.

14. Push notifications

With your permission we receive a device token from Apple or Google, store it against your account, and use it to deliver grading results and price alerts. Turn notifications off in your device settings at any time; dead tokens are removed when the platform reports them.

15. Children

SetChase is not directed at children under 13 and we do not knowingly collect their data. Users under 18 need a parent's or guardian's permission. If you believe a child under 13 has given us data, write to setchaseofficial@gmail.com and we will delete it.

16. Local storage, analytics and your switch

The app stores your collection cache, settings and sign-in session on your device. It uses no advertising identifiers and no cross-app tracking. Usage analytics and crash reports can be switched off under Settings › Your data › "Usage & crash reports"; when off, no analytics events are sent and no crash reports leave the device.

17. Changes to this policy

We may update this policy. Material changes are announced in the app or by email at least 30 days before they take effect where the law requires notice.

18. Contact us

Daniel Moradkhani, Sweden. Email: setchaseofficial@gmail.com

Supervisory authority: Integritetsskyddsmyndigheten (IMY), https://www.imy.se.