Privacy Policy — ScanLoot
Last updated: May 2026
1. Data Controller
Fuat Sarac
Email: scanloot.app@gmail.com
2. Data We Collect
2.1 Camera Images
- Photos of your trading cards are stored exclusively on your device
- For card recognition, the image is sent to the Google Gemini API (see 3.1)
- We do not store any images on our servers
2.2 Collection Data
- Card names, sets, prices, condition, and quantities are stored locally on your device
- No data is transmitted to our servers
2.3 Marketplace Account Data
- When you connect your eBay, CardTrader, or Shopify account, OAuth tokens or API keys are stored encrypted on your device (flutter_secure_storage)
- We never have access to your passwords
- Tokens are used solely to create listings on your behalf
- You can disconnect any marketplace at any time in Settings
2.4 Subscription Data
- Payments are processed through the Google Play Store
- We use RevenueCat for subscription management
- We never receive credit card or bank details
- RevenueCat receives an anonymous app user ID to associate your subscription
2.5 Price Data
- Market prices are fetched from Cardmarket (publicly available product pages), eBay (Browse API), and other sources
- Cardmarket prices are refreshed hourly in the background and cached locally
- No personal data is transmitted to Cardmarket
2.6 Usage Statistics
- Number of scans per day (stored locally for free tier limit management)
- No analytics, no tracking, no advertising IDs
3. Third-Party Services
3.1 Google Gemini API
- Purpose: AI-powered card recognition
- Data transmitted: Compressed card image (JPEG)
- Storage by Google: Per Google AI Privacy Policy
3.2 eBay API
- Purpose: Price lookup (Browse API) and listing creation (Sell API)
- Data transmitted: Card name, set, condition, images, prices
- Only after explicit user action ("Quick List" / "Create Listing" button)
3.3 CardTrader API
- Purpose: Listing creation and price lookup
- Data transmitted: Card name, set, condition, price
- Only after explicit user action
3.4 Shopify API
- Purpose: Product creation in your own shop
- Data transmitted: Product data, images, prices
- Only after explicit user action
3.5 Cardmarket (Price Data)
- Purpose: Fetching publicly available market prices
- Data transmitted: No personal data
3.6 RevenueCat
- Purpose: In-app subscription management
- Data transmitted: Anonymous app user ID, purchase status
- Privacy policy: revenuecat.com/privacy
3.7 Sentry (crash reporting)
- Purpose: Detecting and fixing app crashes
- Data transmitted: Stack traces, OS and app version, device model, breadcrumbs (in-app event trail). No personal data. IP address is not stored by default.
- Privacy policy: sentry.io/privacy
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — app stability
4. Data Storage
| Data | Location | Encrypted | Deletable |
| Card images | Device (local) | No | Yes, via app or filesystem |
| Collection data | Device (local) | No | Yes, uninstall app |
| Marketplace tokens | Device (Secure Storage) | Yes (AES) | Yes, via Settings |
| Price cache | Device (local) | No | Yes, via Settings |
| Scan counter | Device (local) | No | Yes, uninstall app |
| Subscription status | RevenueCat cloud | Yes | Yes, cancel subscription |
5. Your Rights (GDPR)
You have the right to:
- Access your stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restrict processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Lodge a complaint with a supervisory authority
To exercise your rights, contact us at: scanloot.app@gmail.com
6. Data Sharing
We do not sell your data to third parties. Data is shared only with:
- Google (Gemini API) for card recognition
- eBay, CardTrader, or Shopify for listing creation (only after your action)
- RevenueCat for subscription management
7. Data Security
- Marketplace tokens are stored with AES encryption in Secure Storage
- All API communication uses HTTPS/TLS exclusively
- API keys are embedded at build time, not stored in source code
8. Children
This app is not intended for children under 16. We do not knowingly collect data from children.
9. Changes
We reserve the right to update this privacy policy. The current version is available in the app under Profile > Settings.
10. Contact
For privacy inquiries:
Fuat Sarac
scanloot.app@gmail.com