Privacy Policy

Chroma Pulse: TCG Scanner · Last updated 20 August 2026

This policy explains what personal data the Chroma Pulse: TCG Scanner mobile application ("Chroma Pulse", "the app") collects, why it is collected, who it is shared with, and what control you have over it.

Chroma Pulse is developed and operated by Stefan ("we", "us"), acting as the data controller for the processing described below. You can reach us at newtonsykesapi@gmail.com.

This policy applies only to the Chroma Pulse mobile app. It does not cover third-party websites, marketplaces, or services you may reach from the app, which have their own privacy policies.

1. Data we collect

Account data

To create and use an account, we process your email address and an authentication identifier. Depending on how you sign in, we may also receive a display name or profile identifier from your chosen sign-in provider. We never receive or store your password in readable form.

Card images and scan data

When you scan a trading card, the app captures an image using your device camera. That image is transmitted to our card-recognition provider (see section 3) so the card can be identified, and the recognition result — such as card name, set, and edition — is returned to the app.

Camera access is used solely for scanning cards at the moment you initiate a scan. The app does not access your camera in the background and does not read your photo library unless you explicitly select an image.

Collection data

Cards you save, along with related information you enter yourself (quantities, condition, notes, folders, valuations), are stored in your account so your collection is available across sessions and devices.

Purchase data

Subscriptions and in-app purchases are processed by Google Play Billing. We receive a purchase or entitlement token confirming what you are entitled to. We never receive or store your payment card details, bank details, or billing address — those are handled entirely by Google.

Technical and diagnostic data

When the app communicates with our servers we process technical data necessary to deliver and secure the service, including device type, operating system version, app version, approximate region derived from your IP address, and timestamps of requests. This data is used for operating, debugging, and abuse prevention, not for profiling or advertising.

No advertising. Chroma Pulse does not contain third-party advertising, does not use advertising identifiers, and does not sell or share your personal data with data brokers or for cross-context behavioural advertising.

2. Why we process it, and on what legal basis

PurposeData usedLegal basis (GDPR)
Creating and securing your accountAccount dataPerformance of a contract (Art. 6(1)(b))
Recognising scanned cardsCard images, technical dataPerformance of a contract (Art. 6(1)(b))
Storing and syncing your collectionCollection dataPerformance of a contract (Art. 6(1)(b))
Providing paid featuresPurchase data, account dataPerformance of a contract (Art. 6(1)(b))
Keeping the service reliable and secure, preventing abuseTechnical and diagnostic dataLegitimate interests (Art. 6(1)(f))
Responding to your support requestsWhatever you include in your messageLegitimate interests (Art. 6(1)(f))
Complying with legal obligationsAs requiredLegal obligation (Art. 6(1)(c))

3. Who we share data with

We do not sell your personal data. We share it only with the service providers below, who process it on our behalf and under contract:

ProviderPurposeData shared
Anthropic
Claude API
Recognising trading cards from scanned images The card image and the technical context needed to process it
Google
Play Billing
Processing subscriptions and in-app purchases Purchase and entitlement tokens
[HOSTING / BACKEND PROVIDER] Account authentication and storing your collection Account data, collection data

Under Anthropic's commercial API terms, images and other inputs sent through the Claude API are not used to train their models. Anthropic retains inputs only as long as needed to provide the service and to meet its own legal and safety obligations.

We may also disclose data where we are legally required to do so, or where necessary to establish, exercise, or defend legal claims.

International transfers

Some of our providers process data outside the European Economic Area, including in the United States. Where that happens, the transfer is covered by an appropriate safeguard under Chapter V GDPR — typically the European Commission's Standard Contractual Clauses, supplemented by technical and organisational measures.

4. How long we keep it

When you delete your account, associated data is removed as described in section 6.

5. Your rights

If you are in the European Economic Area or the United Kingdom, you have the right to:

To exercise any of these rights, email newtonsykesapi@gmail.com. We respond within one month, as required by the GDPR.

If you are a California resident, you have comparable rights under the CCPA/CPRA, including the right to know, delete, and correct, and the right to opt out of sale or sharing. As stated above, we do not sell or share personal information as those terms are defined under that law.

6. Deleting your account and data

You can request deletion of your account and its associated data at any time:

On deletion we remove your account data and collection data. Records we are legally required to retain — such as transaction records kept for tax purposes — are retained for the statutory period and then deleted. Backups are purged on their normal rotation cycle, within 30 days.

7. Children

Chroma Pulse is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it. Where local law sets a higher age of digital consent — 16 in several EU member states, including the Netherlands — a parent or guardian must consent to the processing on the child's behalf.

8. Security

Data is transmitted over encrypted connections (TLS) and stored on infrastructure protected by access controls. Access to production systems is limited to those who need it. No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the risk, and we will notify you and the relevant authority of a personal data breach where the law requires it.

9. Changes to this policy

We may update this policy as the app changes. The date at the top always reflects the current version. For material changes we will provide notice in the app or by email before the change takes effect. Continued use of the app after an update means you accept the revised policy.

10. Contact

Stefan — developer of Chroma Pulse: TCG Scanner
Email: newtonsykesapi@gmail.com