The Collectibles

Legal

Privacy
policy

Applies to the TC mobile application. Effective 10 September 2026. Last updated 10 September 2026.

The short version. TC keeps the account you create, the cards you choose to save and anything you deliberately post. Card recognition runs on your phone, and images from the scanner are not uploaded. We do not sell personal data and we do not show advertising. You can delete your account and your data from inside the app at any time.

Contents

  1. Who we are
  2. What we collect
  3. The scanner and your camera
  4. Why we use it, and our legal basis
  5. Who we share it with
  6. Where your data is stored
  7. How long we keep it
  8. Your rights
  9. Deleting your account
  10. Children
  11. Security
  12. California residents
  13. Changes to this policy
  14. Contact

1. Who we are

TC ("the app") is published by Questimations OÜ, a company registered in Estonia with its registered office at Hobujaama tn 4, Kesklinna linnaosa, Tallinn, Harju maakond 10111, Estonia. Questimations OÜ is the data controller for the personal data described in this policy.

You can reach us about anything in this policy at support@thecollectibles.io.

This policy covers the TC mobile application and the services it connects to. It does not cover other websites or services you may reach through links in the app, which have their own policies.

2. What we collect

Your account

To save a collection you create an account. We collect your email address and a password, which is stored only as a cryptographic hash, or — if you sign in with Google, Apple or Discord — the email address and name that provider passes to us. If you use Apple's private relay address, we only ever see the relay address. We also collect the handle and display name you choose, and anything you optionally add to your profile: a picture, a short bio and links.

Your collection

The cards you save, their quantity, condition and grade, the collections you organise them into, and when each entry was added or changed. This is the content of the service and is private to your account unless you choose to post a card publicly.

Scan records

When a scan identifies a card we record what was recognised — the text fields read from the card (name, set code, collector number, language), which game the app decided it was, how confident the match was, whether the scan came from the camera or from your photo library, and whether you saved or dismissed the result. We use these records to find and fix cases where recognition gets it wrong. Photographs and camera frames are not part of this record and are not uploaded.

Things you post

Posts and captions, images you attach, comments, likes and reactions, who you follow, and messages you send to other collectors. Posts and profile details are visible to other users of the app unless your profile is set to private. Messages are visible to the people in the conversation.

Things you send us

Feedback you submit from inside the app, and the content of any email or support request, including anything you attach to it.

Device and technical data

Your IP address, device model, operating system version and app version, and the date and time of requests. Our servers keep request logs for security, abuse prevention and diagnostics. If the app crashes, a crash report describing the failure and the device state is generated.

Analytics and attribution

The app records pseudonymous usage events — which screens are opened, that a search or a scan happened, that a card was identified or added. These events describe actions, not the contents of your collection. We use Google Firebase Analytics for this and Firebase Crashlytics for crash reporting. We use AppsFlyer to measure which marketing campaign a new install came from, which may involve your device's advertising identifier. On iOS, the advertising identifier is only used if you allow it through Apple's App Tracking Transparency prompt; declining changes nothing about how the app works.

3. The scanner and your camera

Card recognition runs on your device. The camera preview is read locally by an on-device text recognition model, and the text it extracts is matched against a card catalogue. The image itself is not sent to us, is not stored in your photo library, and is discarded as soon as the frame has been read.

If you dismiss a scan instead of saving it, no card is added to your collection. A scan record as described in section 2 is still kept so we can improve recognition.

Access to your photo library is used only for the specific images you choose: a photo of a card you want identified, or a picture for your profile. The app does not browse or index your library.

4. Why we use it, and our legal basis

Under the EU General Data Protection Regulation, we rely on the following legal bases.

PurposeData usedLegal basis
Creating and running your account, and keeping your collection in sync across your devicesAccount, collectionContract — we cannot provide the service without it
Showing values, sales history and card detailsCollectionContract
Publishing what you choose to post, and delivering messagesPosts, comments, messagesContract
Improving card recognitionScan recordsLegitimate interests — making the core feature work correctly
Security, fraud and abuse prevention, and diagnosing faultsDevice and technical data, crash reportsLegitimate interests — keeping the service safe and available
Understanding how the app is used so we can improve itPseudonymous analytics eventsLegitimate interests, or consent where local law requires it
Measuring which campaign brought you to the appAdvertising identifier, install dataConsent (the iOS tracking prompt, or the equivalent choice on Android)
Answering your support requestsContact data, feedbackLegitimate interests
Meeting our legal and accounting obligationsAs requiredLegal obligation

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can object to that processing at any time — see section 8.

5. Who we share it with

We do not sell your personal data, and we do not share it for advertising purposes. We share it only with the service providers that make the app work, each acting under contract and only for the purposes we set:

We will also disclose personal data where we are legally required to, where it is necessary to establish or defend legal claims, or to protect the rights and safety of our users. If our business is sold or reorganised, data may transfer to the acquiring entity under the same protections.

Public card data sources

To show card details and values, the app queries publicly available card catalogues and price sources. Those requests carry your device's IP address to the provider, as any internet request does, but they do not contain your account details or your collection. Card images and print data originate from those sources and from the rights holders.

6. Where your data is stored

Your account and collection are stored on servers in Germany, within the European Economic Area. Some of our service providers, notably those handling analytics and attribution, may process data outside the EEA, including in the United States. Where that happens we rely on the European Commission's standard contractual clauses or an adequacy decision, and we can provide details on request.

7. How long we keep it

8. Your rights

If you are in the European Economic Area or the United Kingdom, you have the right to:

Write to support@thecollectibles.io and we will respond within one month. We may need to verify your identity first. If you are unhappy with our response you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or to the supervisory authority where you live.

9. Deleting your account

You can delete your account from inside the app: Profile → Settings → Delete account. This removes your account, your collection, your profile and your scan history from our systems within 30 days. It cannot be undone.

You can also ask us by email. The full process, and what is kept afterwards and why, is set out on the account deletion page.

10. Children

TC is intended for people aged 13 and over, and in countries where the age of digital consent is higher, for people of that age or older. We do not knowingly collect personal data from children below that age. If you believe a child has given us personal data, write to support@thecollectibles.io and we will delete it.

11. Security

All traffic between the app and our servers is encrypted in transit with TLS. Passwords are stored only as hashes and are never recoverable in plain text. Session tokens are held in your device's secure storage — the iOS Keychain or the Android Keystore. Access to production systems is restricted to the people who need it. No system is perfectly secure, but if a breach affects your personal data we will notify you and the supervisory authority as the law requires.

12. California residents

If you live in California, the CCPA as amended gives you the right to know what personal information we collect and why, to request its deletion, to correct it, and not to be discriminated against for exercising those rights. The categories we collect are listed in section 2 and the recipients in section 5. We do not sell or share personal information for cross-context behavioural advertising. To exercise these rights, contact support@thecollectibles.io.

13. Changes to this policy

We update this policy when the app changes. The effective date at the top always reflects the current version, and if a change materially affects you we will tell you in the app or by email before it takes effect.

14. Contact

Questimations OÜ
Hobujaama tn 4, Kesklinna linnaosa
Tallinn, Harju maakond 10111
Estonia
support@thecollectibles.io