Privacy Policy
Last updated: 2026-09-15
Who we are
Midpoint - Card Centering Tool ("we", "us", or "our") is operated by I Lov Guitars Inc.. This policy applies to the Midpoint - Card Centering Tool mobile app for iOS and Android (the "App") and our website at https://www.cardcenteringtool.com (the "Site"), together the "Service". By using the Service you consent to the practices described here.
Midpoint - Card Centering Tool is a measurement tool for trading-card collectors. It is NOT a grading service, NOT affiliated with PSA, BGS, CGC, TAG, Nintendo, or The Pokémon Company, and its grade estimates are informational only — they are not predictions of what any grading company will award.
Information you give us
- Email and OAuth profile. When you sign in with Google or Apple, your provider gives us your email address, a unique user ID, and (optionally) your display name. We store this so we can authenticate you and send transactional messages. If you use Apple's Hide-My-Email relay, we only receive the relay address.
- Card photos. Photos you capture with your camera or pick from your photo library are processed to detect the card edge and inner print frame. See "Card photos, camera & photo library" below for how they are stored and deleted.
- Card metadata. When you save a card we store the measured bounding boxes, any name or notes you typed, and the AI surface scan output.
- Support messages. If you contact support from the App or by email, we receive the message and the reply-to email you provide so we can respond.
- Card shop claims and reports. If you claim a shop listing, suggest an edit, report a listing or ask for one to be removed, we receive the name, email or phone and message you enter, the listing it concerns, and your account id if you were signed in. Claims are verified through a contact the shop has already published; a one-time code may be emailed to that address. Submissions are emailed to our support inbox and kept with the listing so the same request is not handled twice.
- Shop owner portal. Verified shop owners, and event organizers who register themselves, get an account (email, name, a hashed password, sign-in times) for cardshops.cardcenteringtool.com. Everything an owner enters there (hours, contact details, games, description, storefront photo) is business information published on the listing in the App and on the Site. The portal uses one session cookie to keep you signed in.
- Billing email. If your sign-in email is a private relay alias, we may ask for a reachable email during a website checkout so the payment processor can deliver a receipt.
Card photos, camera & photo library
The App asks for camera and photo-library access for a single purpose: to let you capture or select photos of trading cards to measure. We do not access your camera or library for any other reason, and we do not scan, index, or upload other photos on your device.
- What we collect. Only the card photos you choose to capture or select, plus the measurement data derived from them.
- How they are used. Photos are analyzed to find the card and print-frame edges, compute a centering measurement, run the AI cleanup pass (background removal + straightening), and run the surface analysis. The cropped card image is sent to our AI providers as part of this pipeline (see "Third parties").
- Where they are stored. Uploaded images and saved cards are stored in Supabase's secure managed cloud storage.
- Retention. A photo is kept only when you save the card; otherwise the upload is discarded after analysis. Bulk-upload raw files are removed once each card is processed (or the batch is cancelled). See "Data retention" below.
- Sharing. Your card photos are never sold and are not shared with anyone except the AI providers used to process them in AI mode. We do not use your photos to train AI models.
- Things you choose to make public. Snapshots you share and Midpoint Grade Certificates you issue are, by design, public: the certificate image, PDF and verification page (reachable by its code or QR) include the card photo you graded, the AI grade, the measured centering, market values at issue and, if you have set one, your community username — never your email or name. You can withdraw a certificate at any time from the App; the files are removed and the verification page shows it as withdrawn.
- Your control. You can delete any saved card or photo at any time in the App, and "Delete my account" removes all of them at once. Once deleted, the data cannot be recovered.
Information collected automatically
- Usage & interaction analytics. We use PostHog (App and Site) and Plausible (Site) to understand how the Service is actually used. PostHog records the pages and screens you open, the buttons, links and controls you tap or click, the order you move through a feature in, how long each step takes, and the errors you run into. It also collects your device type, operating system, browser, app version, an approximate location derived from your IP address, and a session identifier. We use this to find where people get stuck, to measure whether a change helped, and to run A/B tests — which means different people may see slightly different versions of a screen. Once you sign in, this activity is linked to your account so we can follow one person's journey across the App and the Site. Plausible is cookie-less and counts page views on the Site only.
- Location (Card shops). When you open Card shops and allow location access, the App reads your device's position once (while the App is in use) and sends it to our server with that one request to find shops within the radius you pick. We do not store it, attach it to your account, or use it for advertising. If you decline, the screen still works with a city search. The Site's “Card shops near me” does the same with your browser's location.
- Session replay. PostHog can reconstruct a visit as a replay of what happened on screen, so we can watch how the measuring, grading and checkout flows are really used. The two halves of the Service behave differently, and it is worth reading both:
- In the App, session replay is always on. It records the screen as you use it — including the card photos you capture or view and text you type into the App, such as card names, notes and community posts. On Android it also captures the app's diagnostic logs; on iOS, the timing of network requests. The App has no password field — you sign in through Google or Apple, or stay a guest.
- On the Site, everything typed into a form field is masked before the replay leaves your browser, so text you enter on the website is not captured.
- Device & app data (mobile). Device model, operating-system version, app version, language, and unique device identifiers, plus in-app events (screens viewed, actions taken) used to operate and improve the App.
- Crash & diagnostics. We use Firebase Crashlytics to collect crash logs and error reports so we can fix problems.
- Attribution & advertising identifiers (mobile). With your permission, granted via Apple's App Tracking Transparency (ATT) prompt on iOS or your device's ads-personalisation setting on Android, the App accesses your advertising identifier (IDFA on iOS, Google Advertising ID on Android) and shares it with AppsFlyer and the Meta SDK to measure which marketing campaigns led you to install or subscribe. If you decline ATT, the App functions normally and we do not associate your device identifier with third-party data. See the dedicated "App Tracking Transparency (iOS)" section below for the full breakdown.
- Device fingerprint (website). On website signup we compute a browser-fingerprint hash via the open-source FingerprintJS library, used only to stop the same device from re-claiming free trial credits with multiple emails. We do not sell or share it.
- Server logs. Standard request logs (IP address, user agent, path, status, timestamp) are retained for ~30 days for debugging and abuse prevention.
How we use your information
- To authenticate you and keep your saved cards available.
- To run the centering analysis, the surface inspection, and the AI-cleanup pass that removes the background and straightens the card. Each analysis sends your card image to our model providers — see "Third parties" below.
- To process subscription purchases — through the Apple App Store on iPhone, or Stripe on the website, both routed via RevenueCat.
- To send transactional messages (receipts, security alerts) and to respond to support requests.
- To measure marketing performance and improve the product based on aggregated usage signals.
We do not use your card images to train AI models and we do not sell your personal information.
App Tracking Transparency (iOS)
On iPhone the first time you open the App, before any tracking data is collected, iOS shows Apple's App Tracking Transparency (ATT) prompt asking whether you allow Midpoint - Card Centering Tool to track your activity across other companies' apps and websites.
What "tracking" means here. Linking data collected from this App (your device identifier and install / subscription events) with data collected by other companies' apps or websites for the purpose of targeted advertising or advertising measurement, or sharing it with a data broker. Tracking is strictly an opt-in marketing measurement use — it never affects which features of the App you can use or the functionality of the centering analysis.
If you tap "Allow". We access your iOS advertising identifier (IDFA) and forward a small set of install + subscription events (timestamp, country, locale, campaign source if known, subscription product and revenue amount) to AppsFlyer and the Meta SDK so we can attribute installs to the marketing campaign that brought you in and stop spending on campaigns that don't work. We do not share your email, card photos, saved cards, or any other content of your account.
If you tap "Ask App Not to Track". We do not collect your IDFA, AppsFlyer and Meta receive only non-identifying aggregate counters (if anything at all), and we make no attempt to fingerprint you for tracking. The App continues to work fully — every feature, every measurement, every saved card, every subscription option remains available.
Changing your mind. You can revoke or grant tracking permission any time in iOS Settings → Privacy & Security → Tracking →Midpoint - Card Centering Tool, or by resetting tracking entirely in Privacy & Security → Tracking → Allow Apps to Request to Track.
Android. Android does not present an ATT prompt — it uses its own ads-personalisation system. You can reset your Google Advertising ID or opt out of personalised ads in Settings → Privacy → Ads. We honour that setting the same way ATT "deny" is honoured on iOS.
Children. The App is not directed at children under 13 and we do not knowingly track children.
Advertising & analytics partners
When you have granted ATT permission (or are on Android and have not opted out of personalised ads), we share limited campaign-measurement data — advertising identifier, install and subscription events, and revenue amount — with these partners solely to measure marketing performance:
- AppsFlyer — mobile attribution. Tells us which ad placement drove an install or subscription.
- Meta SDK (Facebook / Instagram ads) — campaign measurement for the Meta Audience Network.
- Snap (Snapchat) Pixel and Conversions API — the Site runs the Snap Pixel, a Snapchat script that records page views and sets a first-party cookie so Snapchat can tell whether an ad led to a visit. It also reports when you open the subscription page, start checkout, create an account, or view a card page.
Automatic matching. The pixel has Snapchat's "advanced signal collection" enabled. This means that when you type an email address or phone number into anyform on the Site — including the newsletter sign-up — Snapchat's script may detect it and send it to Snap in hashed form (a one-way scramble Snap cannot reverse to read it), so Snap can match you to a Snapchat account. This happens as you use the Site, not only when you buy something.
Purchases. When you subscribe or buy certificate credits we also send Snap a server-side record: your hashed email address, your IP address, your browser user-agent, the Snapchat click identifier from the link you followed, and the amount and product purchased. The browser and server reports of the same purchase carry a shared id so Snap counts it once.
We do not sell your personal information, and we do not share your account email, uploaded card photos, saved cards, or measurement results with any advertising partner.
Third parties we use
- Supabase — authentication, database, and image storage, in their managed cloud.
- Google Gemini & OpenAI — every analysis sends the cropped card photo to these models for background removal, straightening, and surface analysis. Per their public terms, they do not train on data submitted through their paid APIs.
- OpenAI also powers Chat in the App. The questions you type, the conversation so far, and the card, portfolio or watchlist data needed to answer are sent to OpenAI to generate the reply. A photo you attach in Chat is identified by our own card-lookup pipeline (see above); the photo itself is not sent to the chat model. We keep a per-day count of questions to enforce the free allowance, not the transcripts; your conversation history is stored only on your device.
- RevenueCat with the Apple App Store — in-app subscriptions on iPhone. Apple processes the payment; we never see your card number. Stripe processes subscription payments for the website only.
- Firebase Crashlytics — crash and error reporting.
- AppsFlyer and the Meta SDK — mobile attribution and marketing measurement.
- Snap Inc. — the Snap Pixel on the Site plus server-side conversion measurement for Snapchat advertising (see above).
- PostHog — product and interaction analytics, A/B testing, and session replay, covering both the App and the Site. PostHog processes this data on servers in the United States, so if you use the Service from outside the US your usage data is transferred there. Plausible — cookie-less page-view counting on the Site, hosted in the EU. See Information collected automatically above for what each one records.
- Scrydex and PriceCharting — card market-price data. When you view a card's market value we look up prices for that card; no personal data is sent to these providers.
- eBay Partner Network — Midpoint participates in the eBay Partner Network, an affiliate advertising program. Links from the App or website to eBay (for example "recent sales" or "shop this card" links) include an affiliate tracking parameter, and we may earn a commission on qualifying purchases you make on eBay after following one. When you follow such a link, eBay may set cookies and collect data under its own privacy notice. We do not share your account data, card photos, or measurements with eBay.
Each provider has its own privacy policy; we recommend reviewing them.
Maps
Shop pages and the Card shops screen can show a map. On iPhone the map is Apple Maps; on Android and on the Site it is Google Maps, loaded from Google when the map is displayed. Google receives the map area being shown and standard request data (IP address, browser or device details) under Google's privacy policy. Your own position is only shown on the map if you allowed location access on that screen.
Data retention
- Saved cards and uploaded images are kept until you delete them in the App or website, or until you delete your account.
- Unsaved uploads are discarded immediately after analysis completes. Bulk-upload raw files are removed once each card is processed (or when the batch is cancelled).
- Account data is removed within 7 days of you requesting account deletion from Settings.
- Shop listings, claims and owner accounts are kept while the listing is published. A shop can have its listing hidden or its owner account deleted by emailing [email protected]; we may keep a record of the request so the shop is not contacted again.
- Billing records are retained by Apple, Google, or Stripe per their legal-retention obligations; we keep purchase audit rows for tax / accounting.
Your rights
You can request access to, correction of, or deletion of your personal information at any time. The fastest way to delete everything is the "Delete my account" control in Settings — it removes your profile, saved cards, uploaded images, and credit history in one shot. You can also delete individual cards and photos at any time. For anything else, email [email protected].
If you live in the EU/UK, you also have rights under GDPR. If you live in California, you have rights under CCPA. We honor those rights for all users regardless of jurisdiction.
Children
Midpoint - Card Centering Tool is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has signed up, email us and we will delete the account.
Changes to this policy
We will post any material changes to this page and update the "Last updated" date, and may also notify you in the App. Continued use after a change constitutes acceptance.
Contact
Questions, requests, or complaints — [email protected].
I Lov Guitars Inc.
1102-2250 Kennedy Road
Scarborough, Ontario, M1T 3G7, Canada